Last updated: 2026-08-06
The data controller responsible for the personal information described in this Policy is:
Placeholder[Operator / company legal name - to be provided]
Placeholder[Registered business address - to be provided]
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with data-transfer requirements, your information may be processed in a different country than where you are located, including in connection with the third-party infrastructure providers described in Section 9 (Security).
This API is designed to collect the minimum needed to operate:
POST /signup), we collect the
email address you provide and, optionally, a label for the key.
Email addresses are used to enforce a one-active-key-per-email
limit and are not required for manually issued keys.We do not use cookies, browser fingerprinting, third-party analytics, or advertising trackers. We do not build behavioral profiles of individual end users beyond what is needed for rate limiting and abuse prevention described above, and we do not sell or share any collected data with third parties.
For users in jurisdictions that require a lawful basis for processing personal information (such as the EU/UK GDPR), we process your information on the following bases:
Collected data is used solely to operate, secure, and debug the Service - for example, issuing and enforcing API key scope, detecting abuse, diagnosing errors, and understanding which endpoints are under load.
Request metrics and error logs are held in memory only and are lost on every server restart - they are not persisted to any database. API key records (including the email address associated with a self-service key, if any) are retained for as long as needed to operate the Service, secure it against abuse, and comply with legal obligations.
Revoking an API key does not automatically delete its record - revocation immediately disables the key but the record is retained as an audit trail. Where applicable law grants you a right to request deletion of your personal information (see Section 7), we will act on verified deletion requests, subject to any legitimate need to retain limited records for security, abuse prevention, or legal-compliance purposes.
Depending on your jurisdiction, you may have rights over your personal information, including the right to:
To exercise any of these rights, contact us using the details in Section 10 (Contact). We may need to verify your identity (for example, by confirming the email address on file) before acting on a request.
To serve financial data, the Service makes outbound requests to SEC EDGAR, an unofficial market-data endpoint, and FRED (Federal Reserve Bank of St. Louis). These are one-way data fetches for the Service's own operation - no data about you or your usage is sent to these sources.
We apply reasonable technical measures to protect your information, including:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security of your information.
The Service is not directed at, or knowingly used by, children.
We may update this Policy from time to time. Material changes will be reflected by updating the date at the top of this page.
This Policy should be read together with our Terms of Service, which govern your use of the Service more broadly.
Questions about this Policy, or requests to exercise the rights described in Section 7, can be directed to privacy@ordinexdata.com. You may also raise general questions via GitHub issues.