Compliance
SOC 2 Type 2
Service Organization Controls (Soc2) (Type II) Trust Services Principles
GDPR
Protect the personal data and privacy of EU citizens for transactions that occur within EU member states
CCPA
California Consumer Privacy Act
Resources
hapily Terms of Service
hapily Privacy Policy
Data Protection Agreement
hapily W9
SOC 2 Type II Report
3rd Party Penetration Test Results
Letter of attestation from a certified 3rd party application security vendor
Frequently Asked Questions
How do you protect my data?
In addition to the process controls described in the Monitoring section below, we enforce the following technical controls:
- All incoming and outgoing data is encrypted in transit using SSL/TLS 1.2.
- All data is encrypted at rest using AES-256-GCM.
- Authentication tokens are encrypted at rest using AES-256-GCM.
- We leverage AWS KMS for secure encryption key storage and management.
What data do you store?
The data we store depends on the hapily product(s) you use. We're happy to discuss specific application data usage with your team.
All products
- Encrypted HubSpot OAuth tokens, restricted to the scopes you authorize access to.
- Following installation of any hapily app, hapily retrieves the names and email addresses of your HubSpot users in order to enable and enforce licensing limitations.
- Application configuration information.
event•hapily
- Encrypted Zoom OAuth credentials, for companies using the hapily Zoom integration.
quote•hapily
- Temporary storage of quote data for quotes created with quote•hapily.
saas•hapily
- Stripe API keys
- Stripe Customer data: ID, name, email, phone, shipping address (30 days).
- Stripe Transaction data: transaction amounts, related customer IDs (30 days).
- Daily transaction volume
Associ8
- Cached association search results that include the search term and the record IDs that matched.
- No PII is stored (unless it's your search term).
Subprocessors
hapily relies on these subprocessors to conduct business.
Amazon Web Services
All compute and storage services reside in the us-east-2 AWS region.
Stripe
We use Stripe to maintain PCI-compliant payment processing and subscription management.
We use Google for email, documents, and collaboration.
We use Google for email, documents, and collaboration.
Slack
We use Slack for collaboration and communication with internal teams and partners.