Legal

Privacy Policy

What we collect when you use IBANAPI, why we collect it, and the choices you have about it.

Last updated August 8, 2026. Questions about your data? Contact us any time.

Overview

This policy explains what personal data ApisOS FZE, the company behind IBANAPI ("we", "us", "our"), collects through ibanapi.com and our API, why we collect it, who we share it with, and the choices you have. It applies to visitors, registered users, and anyone who calls our API.

Information we collect

We collect information in three ways:

  • Account information. When you sign up, we collect your name, email address, password (stored hashed, never in plain text), and the IP address used to register.
  • API usage data. Each API request made with your key is logged against your account, endpoint called, timestamp, and result, so we can calculate your usage, enforce your plan's limits, and show you your usage history.
  • Payment information. If you upgrade to a paid plan, billing is handled by Stripe, our payment processor. We never see or store your full card number; Stripe shares back only what's needed to identify a saved card, such as its last four digits and expiry.

Cookies and analytics

We use a small number of cookies:

  • A session cookie that keeps you signed in for up to 30 days.
  • Google Analytics and Google Ads cookies, which help us understand traffic patterns and measure the effectiveness of our own ads. You can opt out using your browser settings or the Google Analytics opt-out browser add-on.
  • Crisp, our live chat widget, which sets a cookie so a conversation can continue across page loads if you contact support.

We don't use cookies to sell your data or to track you across unrelated third-party websites.

How we use information

We use the information above to operate the Service: authenticate your requests, meter and bill API usage, respond to support requests, secure accounts against fraud and abuse, and improve the accuracy of our validation engine. We don't use your account data to train external models or share it for advertising purposes unrelated to running IBANAPI.

How we share information

We share data only with the processors that help us run the Service: Stripe for payments, Google for analytics and ad measurement, Crisp for support chat, and our email delivery provider for transactional messages like password resets and receipts. We don't sell personal data, and we only disclose it beyond these processors if required by law or to protect the rights, safety, or property of IBANAPI or our users.

Data retention

We keep account information for as long as your account is active. API usage logs are retained long enough to support billing, plan enforcement, and abuse investigation, then periodically pruned. If you close your account, contact us and we'll delete personal data we're not otherwise required to keep, for example, for tax or fraud-prevention records.

Security

All traffic to the Service is served over HTTPS. Passwords are stored hashed, never in plain text, and payment details never touch our servers directly. No method of transmission or storage is perfectly secure, but we work to keep these protections current and to limit internal access to personal data to what's needed to operate the Service.

You can regenerate your API key from your dashboard at any time, for example if you think it's been exposed. You may also turn on optional multi-factor authentication (MFA) for your account; once it's enabled, we'll only turn it off following a request sent from your account's registered email address, so someone else can't disable it and lock you out on your own credentials.

Your rights and choices

You can review and update your account details from your profile page at any time. To request a copy of your data, ask us to correct it, or ask us to delete your account, email [email protected]. We'll respond and act on verified requests within a reasonable time.

Children's privacy

The Service is intended for business and developer use and isn't directed at children. We don't knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we'll remove it.

Contact

Questions about this policy or your data? Reach us at [email protected].