Privacy Policy
Last updated: August 27, 2026
This policy explains how Yakware ("we", "us") handles personal data in connection with YakPipes. YakPipes plays two distinct roles, and this policy covers both:
- Yakware as controller — for data about you: your account, billing, and your visits to our own websites.
- Yakware as processor — for the data your workflows receive, transform, and send between your connected services. For that data, you are the controller.
1. Data we collect as controller
Account data
When you register we collect your email address, a password (stored only as a salted hash), and optionally an account or display name. We use this data to operate your account, secure it, and send you service emails (verification, password reset, important service notices).
Billing data
Payments are processed by Stripe. We receive and store your subscription status and a Stripe customer reference — never your card number. Stripe's handling of your payment details is described in Stripe's own privacy policy.
Our websites
With your privacy choice, our first-party YakTracks service records coarse page, interaction, error, and product-milestone signals so we can understand and improve YakPipes. We do not enable session replay for YakPipes. If you arrive through an advertising campaign and permit Ad Measurement, we record the Google click identifier and UTM campaign values from the landing URL. When that click leads to signup or purchase, our server may upload the click identifier, conversion type, and time to Google Ads. We do not load a third-party advertising tracker in your browser. See the Cookie Policy for storage, controls, and retention.
2. Data we process on your behalf
When your workflows run, we process the data they touch solely on your instructions, to provide the Service to you:
- Workflow definitions and connector configurations — the graphs you build and the third-party services they call. Connector credentials and secrets are stored encrypted and are decrypted only to execute your workflows.
- Webhook payloads and run data — the request bodies your webhook triggers receive, intermediate step results, and run logs kept so you can inspect and replay runs.
As the controller for this data, you are responsible for having a lawful basis for the personal data your workflows move and for disclosing that processing to the people concerned. We do not use the data your workflows process for our own purposes, and we do not sell it.
3. Subprocessors and hosting
We use a small number of service providers to operate YakPipes:
- Hetzner — cloud infrastructure hosting the Service and its data.
- Stripe — payment processing.
- Google Ads — advertising conversion measurement when a consented ad click converts.
We will update this list before adding subprocessors that handle personal data.
4. Retention
Shared account data is retained while your account exists and deleted within 90 days after we complete a full-account deletion request, except where law requires longer retention (for example, invoicing records). Workflow definitions remain until you delete them or use the YakPipes product-data deletion control. Completed and failed run logs, webhook payloads, and step results are automatically deleted after 90 days by default; a contracted enterprise retention period may differ. Deleting a workflow deletes its runs immediately.
5. Your rights
Depending on your jurisdiction (for example, under the GDPR), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to processing. Workspace administrators can export or delete YakPipes product data in Data lifecycle settings. Contact us at the address below for a full shared-account request or other rights request; we respond within 30 days. If your request concerns data one of our customers moves through their workflows, we will refer you to that customer, who controls the data.
6. Legal bases
Where the GDPR applies, we process account and billing data to perform our contract with you, service emails on the basis of legitimate interest in operating the Service, optional product analytics and advertising measurement on the basis of consent, and data processed on your behalf under your instructions as processor. You may withdraw analytics consent at any time through the privacy controls without affecting earlier lawful processing.
7. Security
Data is encrypted in transit. Connector credentials and secrets are encrypted at rest. Access to production systems is restricted to authorized personnel. Passwords are stored as salted hashes; payment card data never touches our servers.
8. Children
The Service is not directed at children under 16, and we do not knowingly collect their data.
9. Changes
We will post changes to this policy here and, for material changes, notify you by email or in the Service before they take effect.
SMS / mobile messaging
If you enable SMS verification, we use your mobile number only to send one-time verification codes and account/security notifications. We do not sell, rent, or share your mobile number or SMS opt-in with third parties or affiliates for their marketing. Message frequency varies. Message and data rates may apply. Reply STOP to cancel, HELP for help.
10. Contact
Privacy questions and data-subject requests: support@yakware.com.