Hoister Deutsch

Privacy Policy

Last updated: June 2026

This is an English translation provided for convenience. The legally binding version is the German Datenschutzerklärung.

1. Data Controller

Vector & Veneer UG (haftungsbeschränkt)

Rubensstr. 108, 12157 Berlin, Germany

Email: info@vectorandveneer.com

2. What Data We Process

The following personal data is processed when operating this service:

  • Server log data – IP address, date and time of the request, requested URL, HTTP status code, amount of data transferred, referrer, browser and operating-system identifier. This data is collected automatically when the website is accessed.
  • Account data – email address and OAuth profile information (name, profile picture) that you provide when signing in via GitHub or Google.
  • Authentication session data – encrypted session tokens stored in cookies to keep you signed in during a session.
  • Notification integration configuration – the credentials you provide to connect a messaging service (e.g. Slack webhook URLs, Discord bot tokens or webhook URLs, channel identifiers, email recipients). See Section 6.

3. Purposes and Legal Bases of Processing

Server log data

Purpose: ensuring technically error-free operation and detecting attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Retention: a maximum of 14 days, after which it is automatically deleted.

Account data & authentication

Purpose: providing the user account and the service's features (e.g. dashboard, deployment management). Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures). Retention: until the account is deleted.

4. Authentication Service: Clerk

For user management and authentication we use the service Clerk (Clerk, Inc., 2 Park Avenue, Floor 20, New York, NY 10016, USA).

Clerk processes your name, email address and authentication tokens on our instructions as a processor pursuant to Art. 28 GDPR. A data processing agreement (DPA) is in place.

As Clerk is based in the USA, data is transferred to a third country. The transfer is based on the European Commission's Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. More information: clerk.com/legal/privacy.

5. Telemetry Transmitted by the Hoister Agent

If you configure the Hoister agent (hoister/hoister) to connect to this hosted controller instance (HOISTER_CONTROLLER_URL=https://api.hoister.io), the agent periodically transmits the following data to your account:

  • Container metadata – image names (including private registry paths), container labels, mount paths on the host, IP addresses from Docker-managed networks, command-line arguments, and the configuration and status fields returned by the Docker inspect endpoint.
  • Environment variable keys – the agent transmits the names of your environment variables (e.g. INTERNAL_API_HOST). Values of variables whose key suggests a sensitive meaning (password, token, secret, key, webhook and the like) are replaced with ***REDACTED*** in the agent before transmission. This detection list can be extended with your own keys (see the note below).
  • Deployment events – successful or failed container updates, including image digest, hostname, project and service name.
  • Container log excerpts (opt-in only)disabled by default. If the agent is started with HOISTER_REPORT_LOGS=true and a container is in the restarting, exited or dead state, the agent transmits the last ~50 lines of container log (maximum 16 KB). Values of sensitive environment variables are stripped from the log before transmission. Despite this heuristic, logs may still contain sensitive data — only enable this option if you accept that.

Your responsibility for sensitive data

We expressly do not want to receive sensitive data (passwords, tokens, keys, and the like). The key-based redaction is a heuristic and cannot reliably detect every secret variable. You are responsible for ensuring that no secrets are transmitted to the Service: extend the redaction list via redact_keywords (in hoister.toml) or the comma-separated environment variable HOISTER_REDACT_KEYWORDS with your own keys, and avoid placing plaintext secrets in environment variables, container labels, or command-line arguments. This keeps sensitive values from ever reaching our servers. Details: docs.hoister.io/guides/monitoring.

Purpose: displaying the status of your containers and deployment history in your dashboard.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Storage location: EU (servers in Germany).
Retention: container states are held in memory and are lost after a restart of the controller instance. Deployment records are kept until your account is deleted.
Tenant isolation: all transmitted data is stored exclusively under your user ID and is technically inaccessible to other users.

You can object to this processing at any time by running the agent without a HOISTER_CONTROLLER_TOKEN (standalone mode, no telemetry) or by setting up your own controller instance (self-hosted mode). Details: docs.hoister.io/guides/operating-modes.

6. Notification Integrations (Slack, Discord, Email and More)

Optionally, you can connect one or more messaging services to your account so that Hoister notifies you about deployment events (available updates, successful updates, rollbacks). Supported services include Slack, Discord, Telegram, Microsoft Teams, Matrix, Mattermost, Rocket.Chat, Google Chat, Gotify, ntfy, Pushover, email, and generic webhooks. This feature is optional and only active if you set up an integration.

What we store

For each integration we store the credentials you provide that are required to deliver the message — such as a webhook URL, a bot token, a channel or room identifier, or an email address. This data is associated solely with your user ID and is used server-side only; secrets (tokens, full webhook URLs) are never returned to the dashboard but are only marked as "set". Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Retention: until you delete the integration or your account is deleted.

Slack ("Add to Slack")

If you connect Slack via the "Add to Slack" button, you go through Slack's OAuth flow. After you grant consent, Slack provides us with an incoming webhook URL and the name of the target channel, which we store as a Slack integration. We do not request access to your messages or any other workspace data. Slack's Privacy Policy applies.

Discord

For Discord, you provide either an incoming webhook URL or a bot token together with a channel ID. Hoister uses these to deliver notifications to the channel you chose. Discord's Privacy Policy applies.

What data is transmitted

When a deployment event occurs, Hoister sends a notification to the services you have configured containing the image name, image digest, project and service name, and the hostname of the affected container. This transmission happens on your instructions to the recipients you selected. The respective providers (Slack, Discord, etc.) process this content under their own privacy policies; for US-based providers this may involve a transfer to a third country. As you determine the recipient yourself, this transfer is your responsibility.

Email delivery: Resend

For email notifications we use the delivery provider Resend (Resend, Inc., USA) as a processor. The recipient email address and the content of the notification are passed to Resend. The transfer to the USA is based on Standard Contractual Clauses (Art. 46(2)(c) GDPR).

7. Cookies

This website uses strictly necessary cookies only. These cookies are required to keep you authenticated during a session and are set without your separate consent (Art. 6(1)(b) and (f) GDPR). No advertising, tracking or analytics cookies are used.

CookieProviderPurposeLifetime
__sessionClerkAuthentication sessionSession
__client_uatClerkSession verification1 year
slack_oauth_stateHoisterCSRF protection during Slack connectionShort-lived

8. Disclosure of Data

Your personal data is not disclosed to third parties, except to our processors (Clerk for authentication, see Section 4; Resend for email delivery, see Section 6), to the messaging services you set up yourself (see Section 6), and where we are legally obliged to do so.

9. Your Rights

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

To exercise your rights, please contact: info@hoister.io

10. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data. The competent supervisory authority for Berlin is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Friedrichstr. 219, 10969 Berlin, Germany

Web: www.datenschutz-berlin.de

11. Currency of This Policy

We reserve the right to amend this privacy policy in the event of changes to the service or the legal situation. The current version is always available at this URL.

We use strictly necessary cookies for authentication. With your permission we'd also like to use PostHog to anonymously measure how the dashboard is used so we can improve it. See our privacy policy for details.