Privacy Policy
Last updated: March 20, 2026
1. Introduction
IronStack LLC ("Company", "we", "us") operates ReqPour ("the Service"). This Privacy Policy explains how we collect, use, and protect your information when you use our Service.
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Username
- Password (stored as a bcrypt hash, never in plaintext)
- GitHub account information (if you sign in with GitHub): GitHub ID, username, avatar URL, and email
Webhook Data
When webhooks are sent to your ReqPour endpoint, we temporarily store:
- HTTP method, path, and query parameters
- Request headers
- Request body
- Source IP address
- Timestamp and response metadata
This data is stored solely to provide the Service (inspection, replay, and relay) and is automatically deleted according to your plan's retention period (24 hours for Free, 30 days for Pro).
Payment Information
Payment processing is handled entirely by Stripe. We do not store credit card numbers or full payment details. We store only your Stripe customer ID and subscription ID for billing management.
Usage Data
We may collect basic usage data such as page views, feature usage, and error logs to improve the Service. We do not use third-party analytics trackers.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account
- Process payments and manage subscriptions
- Send transactional emails (verification, password resets, billing notifications)
- Respond to support inquiries
- Detect and prevent abuse or fraud
We do not sell your personal information. We do not use your data for advertising. We do not read or analyze the content of your webhook data except as necessary to provide the Service.
4. Data Sharing
We share your information only with:
- Stripe — for payment processing
- Resend — for transactional email delivery
- Railway — for infrastructure hosting
- Vercel — for frontend hosting
- Cloudflare — for DNS and DDoS protection
We may disclose information if required by law or to protect the rights, safety, or property of IronStack LLC, our users, or the public.
5. Data Retention
- Webhook request data: 24 hours (Free) or 30 days (Pro), then automatically deleted
- Account data: Retained while your account is active. Deleted upon account deletion request.
- Payment records: Retained as required by law for tax and accounting purposes
6. Data Security
We implement industry-standard security measures including encrypted connections (TLS/SSL), hashed passwords (bcrypt), and secure infrastructure. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
7. Cookies
We use localStorage (not cookies) to store your authentication token. We do not use tracking cookies or third-party cookies.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data
- Export your data
- Withdraw consent for optional data processing
To exercise any of these rights, contact us at privacy@reqpour.com.
9. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via email. Continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions or requests, contact us at:
IronStack LLC