Privacy Notice

Madam Mimi Marketing (trading as Hook Ledger) is the data controller for personal data processed in Hook Ledger.

Last updated: 18 August 2026 · Madam Mimi Marketing · support@gethookledger.com

1. Who we are

Madam Mimi Marketing, trading as Hook Ledger, operates Hook Ledger at https://gethookledger.com. We act as the data controller for the personal data described here. For any privacy question or request, email support@gethookledger.com.

When you upload or connect your own customers' data (for example Shopify orders or affiliate network reports), you are the controller of that data and we act as your processor, using it only to provide attribution and reporting back to you.

2. What we collect and why

  • Account data — name, email address, login credentials or Google sign-in identifier, workspace and seat membership, role. Used to create and secure your account and to provide the service. Legal basis: performance of our contract with you.
  • Content you create — brand profile, hooks, prompts, captions, uploaded images, audio and video inputs, generated creatives, presets. Used to deliver the features you requested. Legal basis: contract.
  • Campaign and attribution data — tracked links, click events with timestamp, referrer, coarse device and browser information, IP address, and detected traffic source; imported conversions and commission amounts. Used to attribute clicks and revenue to your hooks and to detect fraudulent or bot traffic. Legal basis: contract and our legitimate interest in accurate, fraud-free reporting.
  • Integration data — tokens and identifiers for connected platforms (Shopify, affiliate networks, schedulers, AI providers you bring your own key for). Used only to run the integrations you enabled. Legal basis: contract.
  • Usage and telemetry — pages viewed, features used, credit and quota consumption, error and audit logs, security events. Used for support, billing accuracy, abuse prevention, and product improvement. Legal basis: legitimate interests.
  • Support and communications — messages you send us, notification preferences, email delivery and push-subscription records. Used to answer you and to send the alerts and digests you opted into. Legal basis: contract and consent for marketing or optional digests.

Payment card details are never collected or stored by us — Paddle collects and processes payment data as Merchant of Record.

3. AI processing

When you use a generative feature, the prompt and any input you attach are sent to the AI provider needed to fulfil it (for example Lovable AI, Google Gemini, ElevenLabs, Fal.ai, or Sync Labs). Do not submit personal data you are not entitled to share, and do not submit special-category data. Voice cloning and likeness features require documented consent from the person concerned.

4. Who we share data with

  • Merchant of Record — Paddle, for the sale of our products, subscription management, payments, invoicing, and tax compliance.
  • Infrastructure and service providers — cloud hosting and managed database/authentication, email delivery, push notification delivery, and error monitoring, all acting as our processors under contract.
  • AI providers — only the provider required for the feature you triggered.
  • Platforms you connect — Shopify, affiliate networks, and schedulers, using the credentials you supplied.
  • Professional advisers — legal, accounting, and audit advisers where needed.
  • Authorities — where we are legally required to disclose, or to establish, exercise, or defend legal claims.

We do not sell personal data and we do not share it for third-party advertising.

5. International transfers

Some of our providers process data outside the UK and EEA, primarily in the United States. Where that happens we rely on an adequacy decision or on Standard Contractual Clauses with additional safeguards. You can ask us for details of the safeguards for a specific provider.

6. How long we keep data

Account and content data is kept while your account is active and for up to 30 days after closure so you can export or restore it, then deleted or anonymised. Click and conversion events are retained for up to 24 months for year-over-year reporting. Security, audit, and notification-delivery logs are retained for up to 12 months. Billing and tax records are retained for the period required by law (typically 7 years) by Paddle and by us.

7. Security

We apply appropriate technical and organisational measures: encryption in transit, encryption at rest for stored data and secrets, row-level access controls so each workspace can only read its own records, least-privilege service credentials, admin action auditing, and automated policy and permission checks before each deployment.

8. Your rights

Subject to your local law, you can request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests. Where processing relies on consent — for example marketing emails or push notifications — you can withdraw it at any time in your notification settings or via the unsubscribe link.

Send requests to support@gethookledger.com. We respond within one month. If you are in the UK or EEA and are unhappy with our response, you can complain to your local data protection supervisory authority.

9. Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in, remember your workspace and preferences, and protect against abuse. Tracked affiliate links set a short-lived attribution identifier so a later conversion can be matched to the click that caused it. We do not run third-party advertising cookies. You can clear or block cookies in your browser, but sign-in and attribution will stop working.

10. Changes to this notice

We update this notice when our processing changes. Material changes are announced in the app or by email before they take effect.