Skip to main content

Financial Data API — Privacy Policy

Last updated: 26 June 2026. This Privacy Policy explains how Financial Data API (“we”, “us”) handles personal data in connection with the Financial Data API and related tools (the “Service”). It covers the people who request access to and use the Service (“you”). For data-protection purposes, we act as the controller of the personal data described here.

1. Data we collect

  • Account and contact data. When you request an API key or contact us, we collect the name, email address, and any organization details you provide.
  • API key metadata. We store a one-way hash of each API key (never the key itself in readable form), plus a short non-secret prefix and fingerprint used to identify the key, and its status and lifecycle timestamps.
  • Usage data. For each request we record operational metadata such as the timestamp, endpoint, HTTP method, response status, latency, the associated client identifier, and the request IP address. This supports security, rate limiting, billing, and debugging.
  • Communications. Records of your support and access correspondence with us.
We do not intentionally collect special-category personal data, and the market and macro data served by the Service is not personal data about you.

2. How and why we use data

We use personal data to:
  • provision and authenticate API access, and operate and secure the Service;
  • enforce rate limits and the Acceptable Use Policy, and detect and prevent abuse;
  • meter usage and administer billing;
  • provide support and respond to your requests; and
  • comply with legal obligations.
Where the GDPR or similar laws apply, our legal bases are: performance of a contract (providing the Service you requested), our legitimate interests (securing, operating, and improving the Service, and preventing abuse), and compliance with legal obligations.

3. Sub-processors and hosting

The Service runs on Amazon Web Services (AWS) in the EU (London, eu-west-2 region), which processes hosting and storage data on our behalf. We may use additional processors for email delivery, payments, and error monitoring; a current list is available on request. We require processors to protect personal data under terms consistent with this policy.

4. International transfers

Where personal data is transferred outside your jurisdiction, we rely on an appropriate transfer mechanism (such as standard contractual clauses) where required by law.

5. Retention

We retain account and key metadata for as long as your account is active and as needed to provide the Service. We retain usage logs for 12 months for security, billing, and operational purposes, after which they are deleted or aggregated. We retain records longer only where required for legal or accounting reasons.

6. Security

We hash API keys, restrict access to operational data, redact secret-like fields and raw provider payloads from operational event logs, and apply encryption and access controls on our infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your rights

Subject to applicable law, you may request access to, correction of, export of, or deletion of your personal data, and may object to or restrict certain processing. To exercise these rights, contact us at support@financialdatapi.com; we will respond within the timeframe required by law. You also have the right to lodge a complaint with your data protection authority.

8. Data breaches

If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected users where and within the timeframes required by applicable law.

9. Children

The Service is not directed to children and is intended for business and developer use. We do not knowingly collect personal data from children.

10. Changes and contact

We may update this policy; material changes will be notified by a reasonable means and take effect on the stated date. Questions or requests: support@financialdatapi.com.