Privacy Policy
What we collect when you use IBANAPI, why we collect it, and the choices you have about it.
Overview
This policy explains what personal data ApisOS FZE, the company behind IBANAPI ("we", "us", "our"), collects through ibanapi.com and our API, why we collect it, who we share it with, and the choices you have. It applies to visitors, registered users, and anyone who calls our API.
Information we collect
We collect information in three ways:
- Account information. When you sign up, we collect your name, email address, password (stored hashed, never in plain text), and the IP address used to register.
- API usage data. Each API request made with your key is logged against your account, endpoint called, timestamp, and result, so we can calculate your usage, enforce your plan's limits, and show you your usage history.
- Payment information. If you upgrade to a paid plan, billing is handled by Stripe, our payment processor. We never see or store your full card number; Stripe shares back only what's needed to identify a saved card, such as its last four digits and expiry.
How we use information
We use the information above to operate the Service: authenticate your requests, meter and bill API usage, respond to support requests, secure accounts against fraud and abuse, and improve the accuracy of our validation engine. We don't use your account data to train external models or share it for advertising purposes unrelated to running IBANAPI.
Data retention
We keep account information for as long as your account is active. API usage logs are retained long enough to support billing, plan enforcement, and abuse investigation, then periodically pruned. If you close your account, contact us and we'll delete personal data we're not otherwise required to keep, for example, for tax or fraud-prevention records.
Security
All traffic to the Service is served over HTTPS. Passwords are stored hashed, never in plain text, and payment details never touch our servers directly. No method of transmission or storage is perfectly secure, but we work to keep these protections current and to limit internal access to personal data to what's needed to operate the Service.
You can regenerate your API key from your dashboard at any time, for example if you think it's been exposed. You may also turn on optional multi-factor authentication (MFA) for your account; once it's enabled, we'll only turn it off following a request sent from your account's registered email address, so someone else can't disable it and lock you out on your own credentials.
Your rights and choices
You can review and update your account details from your profile page at any time. To request a copy of your data, ask us to correct it, or ask us to delete your account, email [email protected]. We'll respond and act on verified requests within a reasonable time.
Children's privacy
The Service is intended for business and developer use and isn't directed at children. We don't knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we'll remove it.
Contact
Questions about this policy or your data? Reach us at [email protected].