This Privacy Policy describes how API Clearinghouse collects, uses, and protects information when you use our platform at apiclearinghouse.com.
1. Information We Collect
1.1 Information You Provide
- Email address (required for account creation)
- Name (optional)
- Payment information (processed by Stripe; we do not store card data)
- Communications you send to us
1.2 Information Collected Automatically
- API request logs (endpoint, timestamp, response code, latency)
- IP address and approximate geographic location
- Browser type and operating system
- Usage metrics
1.3 Information We Do NOT Collect
- Content of data returned by Upstream Provider APIs
- Government IDs, financial account numbers, or health information
- Biometric data
- Information about anyone under 18
2. How We Use Your Information
- Provide, operate, and improve the Platform
- Authenticate identity and secure accounts
- Process payments and manage subscriptions
- Enforce rate limits and abuse protections
- Send transactional emails
- Respond to support requests
- Monitor for fraudulent activity
- Comply with legal obligations
We do not use your information for advertising.
3. We Do Not Sell Your Data
We do not sell, rent, trade, or transfer your personal information to third parties for commercial purposes.
4. Information Sharing
4.1 Service Providers
- Stripe — payment processing
- Resend — transactional email
- DigitalOcean — cloud infrastructure
- Cloudflare — CDN and security
4.2 Upstream API Providers
Requests are proxied to Upstream Providers who may log metadata subject to their own policies. We do not share your account identity with them.
4.3 Legal Requirements
We may disclose information if required by law or to protect safety.
4.4 Business Transfers
If involved in a merger or acquisition, your information may transfer with appropriate notice.
5. Data Retention
Account information is retained while your account is active. API logs are retained up to 90 days. Request deletion at [email protected].
6. Security
- TLS/HTTPS for all connections
- AES-256-GCM encryption for stored credentials
- Token rotation and session management
- Rate limiting and abuse detection
7. Cookies
Session authentication and security cookies only. No advertising cookies, tracking pixels, or analytics services.
8. Your Rights
- Access — request a copy of your data
- Correction — request correction of inaccurate data
- Deletion — request account and data deletion
- Portability — request data in portable format
- Restriction — request restricted processing
- Objection — object to certain uses
Contact [email protected]. We respond within 30 days.
9. California Residents (CCPA)
We do not sell personal information. Contact [email protected] to exercise CCPA rights.
10. European Residents (GDPR)
We process data under: contract performance, legitimate interests, and legal obligation. You may lodge complaints with your local data protection authority.
11. Children's Privacy
The Platform is not directed at anyone under 18. We delete any data collected from minors upon discovery.
12. Changes to This Policy
We will provide 14 days' notice of material changes.