Privacy Policy
Last updated: 2026
Draft — requires legal review before launch. Complete the bracketed fields and have this reviewed, especially if you accept customers in the EU or UK (GDPR) or California (CCPA).
1. Who we are
This policy explains how [LEGAL ENTITY NAME] (“we”) handles personal data for the Gravitron Data service. Contact: [SUPPORT EMAIL].
2. What we collect
- Account data — your email address and a hashed password.
- Usage data — per request: timestamp, endpoint, response status, duration and whether it was billed. We do not store the product data returned to you.
- Payment data — handled entirely by Stripe. We store only a Stripe customer identifier. We never see or store your card details.
- Waitlist data — an email address, if you ask to be notified about an upcoming API.
3. What we do not collect
We do not use advertising or analytics trackers, and we set no third-party cookies. The only cookie we set is a signed session cookie that keeps you logged in.
4. Why we process it
To provide the service, meter and bill usage, prevent abuse, and respond to support requests. The legal basis is performance of a contract with you, and our legitimate interest in operating the service securely.
5. Sharing
We share data with Stripe (payment processing) and our hosting provider. We do not sell personal data.
6. Retention
Account data is kept while your account is open. Usage records are retained for [12 months] for billing and abuse investigation, then deleted.
7. Your rights
You may request access to, correction of, or deletion of your personal data by emailing [SUPPORT EMAIL]. Deleting your account removes your email and keys; anonymised usage counts may be retained for accounting.
8. Security
Passwords are hashed with Argon2id. API keys are stored only as SHA-256 digests and cannot be recovered from our database. All traffic is served over TLS.