Privacy Policy
Last updated: August 2026
1. Information We Collect
We collect account information (name, email address, password hash) when you register, session data (IP address and user agent) when you sign in, and API usage data (request parameters, calculation results, timestamps) to operate and improve the service. Payment processing is handled by our payment provider; we do not store card details.
2. How We Use Information
We use your information to authenticate you, manage your credits and API keys, provide support, and ensure the security and integrity of the service. We do not sell your personal data.
3. Email and OTP
We send transactional emails including verification codes (OTP) required for signup, sign-in, and password recovery. These are necessary for the service to function.
4. Data Retention
We retain different categories of data for different periods, based on the purpose they serve:
- Account data (name, email, company information - if provided) is retained for as long as your account exists and for a reasonable period thereafter where necessary for legal, security, fraud prevention, dispute resolution, or other legitimate business purposes.
- Raw API usage logs (request parameters, calculation results, timestamps) are retained for 90 days. After that period, raw request-level data is deleted.
- Daily usage summaries (aggregate call counts and credits per day, with no per-request detail) are retained for the lifetime of your account to support billing verification and usage trends.
- Financial credit transactions (purchases, grants, adjustments) are retained indefinitely as required by accounting and tax law.
- Session data (including IP address and user agent) is retained for the life of the session and deleted when the session expires.
You may request deletion of your account and associated data at any time by Contact us; financial records we are legally required to keep will be retained in accordance with applicable law.
5. Security
We use reasonable technical and organizational measures to protect your information from unauthorized access, disclosure, alteration, or destruction.
These measures include, where appropriate:
- HTTPS/TLS encryption for data in transit
- Password hashing
- Access controls
- API authentication and authorization
- Security monitoring and logging
However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Cookies
VCFAPI uses session cookies to maintain your login session. These cookies are strictly necessary for the service to function and are not used for tracking or analytics. No third-party cookies are set.
7. Third-Party Services
We use third-party service providers to help operate the Service. These providers may process information on our behalf as necessary to provide their services.
Polar.sh acts as our Merchant of Record (MoR) and handles payment processing, billing, and related payment information. VCFAPI does not store payment card details.
We do not sell your personal data to third parties.
8. International Data Processing
Your information may be processed or stored in countries other than your country of residence, including by third-party service providers that support our Service.
We take reasonable steps to ensure that your information is handled securely and in accordance with applicable privacy laws.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our Service, business practices, or applicable laws.
When we make material changes, we may provide notice through the Service or by other appropriate means.
The "Last Updated" date at the beginning of this Privacy Policy indicates when this Privacy Policy was most recently updated.
10. Contact
Privacy questions? Contact us.