APIHorseRacing

Legal

Privacy

Last updated 10 September 2026

The short version

We hold your email address, your plan, a count of the requests your key made, and any support tickets you open. We do not sell any of it, and there is no advertising, no analytics and no tracking anywhere on this site.

We never see your card details, and we do not store the parameters you send to the API or the data it sends back.

Who is responsible

apihorseracing.com operates this site and the API, and is the data controller for the personal data described here.

For anything about your data, open a support ticket or write to [email protected]. It reaches a person rather than a queue.

What we collect, and where it comes from

From sign-in. Your email address, name, profile picture and the account identifier Google gives us. We ask Google for nothing beyond that, and we do not receive your Google password.

Your key. Stored encrypted so that your account page can show it to you again rather than making you keep a copy. Only this site can decrypt it.

From use of the API. The endpoint called, the day, whether the response succeeded, and any refusal and its reason, counted per day against your key. We do not store the parameters you sent, the response you received, or your IP address against those counts.

From support. Everything in a ticket: the subject, every message in the thread, the address it came from, and your plan and key prefix at the time you opened it. Only write in a ticket what you are content for us to hold.

From email we send you. Recipient, which template, whether it was accepted, and the error if it was not.

From payment. Nothing sensitive. Card details go directly to Stripe and never reach our servers. We store the customer and subscription references Stripe returns, your plan, and when the period ends.

From the documentation. Search terms that returned nothing, so we know what to write next. These are stored as the term alone, with no account attached to them.

From the web server. Ordinary request logs kept by the hosting and by Cloudflare, which include IP addresses. They exist for security and diagnosis and are not joined to your account.

Why we hold it, and on what basis

To provide the service you asked for. Identifying your key, applying your plan, enforcing limits, showing your usage and answering your tickets. The lawful basis is performance of a contract.

To take payment and keep records. Billing you correctly and keeping what tax law requires us to keep. The basis is contract, and legal obligation for the records.

To keep the service working and secure. Spotting endpoints that are failing, keys behaving abnormally, and abuse. The basis is legitimate interest, and the interest is running a service that stays up.

To tell you about your account. Billing, plan changes, ticket replies and breaking changes to the API. The basis is contract. These are not marketing and you cannot unsubscribe from them while you hold an account, because they are how the service tells you things you need to know.

We do not send marketing email, so there is no consent to give or withdraw for it.

We do not profile you, score you, or make any automated decision that has a legal or similarly significant effect on you.

Who else sees it

Google, for sign-in only, and only because you chose to sign in with it.

Stripe, for payment. They are the controller of your card details, not us.

Postmark, which delivers our email, reached through our own sending gateway. They receive the recipient address and the message.

Cloudflare, which sits in front of the site and the API for security and performance, and therefore sees request metadata.

Our hosting provider, because the servers run there.

That is the complete list. No advertising network, no analytics provider, no data broker, and nobody who pays us for access to it.

We do not sell personal data, and we do not share it for anyone else's marketing.

Where it is held

Our servers are in the European Union and in Singapore. Our processors operate internationally, so your data may be processed outside the country you are in.

Where that happens, it is covered by the standard contractual clauses or an equivalent safeguard in our agreement with that processor.

How long we keep it

Account details, for as long as you have an account.

Usage counts, for two years. Long enough to answer a billing question and to plan capacity, and no longer.

Refusal records, for fourteen days. They exist to show which plan a key was reaching for, which is only useful while it is recent.

Support tickets, for three years after the last message, because a question asked once tends to be asked again and the thread is the answer.

Email records, for one year.

Billing records, for seven years, because tax law requires it. This is the one category we cannot delete on request.

Server and Cloudflare logs, for the period those providers keep them, which is weeks rather than years.

Close your account and everything except the billing records goes within thirty days.

Your rights

You can ask for a copy of what we hold, ask for it corrected, ask for it deleted, ask us to restrict what we do with it, object to processing we do on legitimate interest grounds, or ask for your data in a portable form.

Open a ticket or write to [email protected] and it gets done rather than routed into a process. We answer within thirty days and normally much faster.

We will not charge you for this, and we will not make your service worse because you asked.

If you are unhappy with how we have handled it, you can complain to the data protection authority where you live. We would rather you told us first so we can fix it.

Cookies

Two, both ours, neither used for tracking.

A session cookie, so that being signed in survives a page load. It expires when you close the browser or sign out.

A recognition cookie that lasts a year and remembers only that you have been here before, so the header offers you Sign in rather than Register. It holds no identifier and tells us nothing about you.

No analytics cookies, no advertising cookies, and no third-party scripts other than the web fonts these pages are set in.

Because neither cookie tracks you, there is no consent banner. That is a deliberate choice rather than an oversight.

Security

Everything travels over HTTPS. Your API key is stored encrypted rather than in plain text, and the key used to encrypt it is held outside the database.

Card details never reach us at all.

Access to the administrative console is restricted and separate from the site's own sign-in.

No system is perfect. If we ever suffer a breach that puts your data at risk, we will tell you and the relevant authority, and we will tell you what actually happened rather than the smallest thing we can defend.

If you find a security problem, open a ticket. Reporting one responsibly is not a breach of our terms and we will not treat it as one.

Children

This is a data service for developers and analysts, not a service for children, and it is not directed at them. We do not knowingly collect data from anyone under sixteen. If we learn we have, we delete it.

Changes to this notice

The date at the top of this page shows when it last changed.

If we change something that materially affects how we handle your data, we tell you by email before it takes effect rather than quietly editing the page.

Questions

If any of this is unclear, ask rather than guessing: support. A policy nobody understands protects nobody.