Legal
Privacy Policy
Last updated: 7 October 2026
Introduction
This Privacy Policy explains how Extract Edge ("APIHiver", "we", "us"), the operator of the APIHiver API marketplace, collects and uses personal data when you visit apihiver.com, use the dashboard, subscribe to or list APIs, or call APIs through our gateway (the "Service").
We act as the data fiduciary (data controller) for the personal data described here. We follow India's Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and its rules. Where other laws, such as the EU/UK GDPR, apply to you, we honour the rights they give you.
This policy doesn't cover how API Providers handle data you send to their APIs. Each Provider is responsible for that under its own privacy terms.
What personal data we collect
| Category | Examples |
|---|---|
| Identity data | Name, username, profile photo, organisation name |
| Contact data | Email address, phone number (if you give it), billing address |
| Account & role data | Whether you're an API Consumer, API Provider, or both; team roles and permissions; your subscriptions and listed APIs |
| Billing data | Plans, invoices, payment status, amounts, refunds, payout details for Providers. Card, UPI and bank details are entered on Razorpay's payment page and never reach us in full |
| Usage & API log data | For each call through our gateway: API and endpoint, time, status, latency, IP address, approximate country, request and response headers and truncated request and response bodies. API keys and Authorization/Cookie headers are never stored |
| Login & device data | Sign-in times, sessions, device and browser details, IP address, security events (for example new-device sign-ins) |
| Communications | Messages to us or to Providers, discussion posts, reviews, support requests, notification preferences |
We collect this data from you (when you register, subscribe, list an API or contact us), automatically (when you use the Service or the gateway), and from third parties: Razorpay (payment status), and GitHub or Google if you choose to sign in with them.
How we use personal data
| Purpose | Examples | Data used | Basis |
|---|---|---|---|
| Provide the Service | Create and secure your account, issue API keys, route and meter API calls, enforce quotas and rate limits | Identity, contact, account, usage, login | Your consent when you sign up; performing the Service you requested |
| Billing | Checkout, invoices, renewals, refunds, Provider payouts, tax records | Identity, contact, billing | Performing the Service; legal obligations (tax, accounting) |
| Analytics & logs for you | Usage dashboards and request logs for Consumers (their own calls) and Providers (calls to their API) | Usage & API log data | Performing the Service |
| Security & fraud prevention | Detecting abuse, suspicious sign-ins, and payment fraud | Login, usage, billing | Legitimate uses permitted by law; legal obligations |
| Service communications | Verification, password reset, security alerts, billing and subscription notices, Provider announcements | Contact, account | Performing the Service |
| Support & disputes | Answering requests and resolving Consumer–Provider issues | Identity, contact, communications, usage | Performing the Service |
| Improving the Service | Understanding which features are used so we can improve them | Usage (aggregated where possible) | Legitimate uses; consent where required |
| Legal compliance | Responding to lawful requests, enforcing our Terms | Any relevant data | Legal obligations |
We don't sell your personal data, and we don't use it for third-party advertising.
Who we share personal data with
| Recipient | Why |
|---|---|
| API Providers | When you subscribe to an API, its Provider can see your username, plan and subscription status, and the request logs for calls you make to their API, so they can support you and run their service |
| Payment partner (Razorpay) | To process payments and refunds |
| Service providers | Hosting, file storage, email delivery and analytics providers that process data on our instructions |
| Professional advisers | Lawyers, accountants and auditors, under confidentiality |
| Authorities | When required by law, court order or a valid government request, or to protect the rights, safety and security of our users or the public |
| Business transfers | A buyer or successor if APIHiver is involved in a merger, acquisition or sale of assets, under this policy |
Cookies and similar technologies
The signed-in dashboard uses essential cookies and browser storage only, to keep you signed in, protect your session, and remember preferences such as table layouts and filters. On the public pages of apihiver.com (home, API listings, documentation, policies and the blog) we measure how the site is used in two ways:
- Our own visitor counter. It records the page visited, the website you came from, and your device and browser type, with no cookie and no IP address stored. Visits are linked only by a code that changes every day, so we cannot follow a person from one day to the next. We don't count visitors who send a "Do Not Track" signal.
- Google Analytics (and Vercel Analytics on the blog), which use cookies or similar identifiers to give us aggregate reports about readership and traffic sources. You can opt out with Google's browser add-on.
You can block or delete cookies in your browser, but the dashboard won't work without the essential ones.
Your choices and rights
Subject to applicable law, you can:
- access the personal data we hold about you, and get a summary of how it's processed;
- correct or update it. Most of it can be edited in your dashboard;
- delete your account and personal data, except what we must keep by law (for example invoices);
- withdraw consent where processing relies on it (this may stop parts of the Service from working);
- nominate someone to exercise your rights if you die or become incapacitated;
- complain to our Grievance Officer (below) and, if unresolved, to the Data Protection Board of India or your local authority;
- stop API announcement notifications with the Get Notifications toggle on an API's page. Security, billing and account emails can't be turned off while your account is active.
Email [email protected] to exercise these rights. We'll verify your identity and respond within 30 days.
Data retention
We keep personal data while your account is active and afterwards only as long as needed for the purposes above, including billing, security, resolving disputes, and meeting legal obligations. Invoices and payment records are kept for the period Indian tax law requires. When data is no longer needed, we delete or anonymise it.
Security
We protect data with encryption in transit (HTTPS/TLS), hashed passwords, encrypted storage of Provider credentials, and access controls. No method of transmission or storage is completely secure, so please keep your password and API keys safe and tell us immediately about any suspected compromise.
International transfers
Our servers and service providers may be located outside India. Where personal data is transferred, we take reasonable steps to protect it in line with this policy and applicable law.
Children
The Service is not directed to anyone under 18, and we don't knowingly collect their personal data. If you believe a child has given us data, contact us and we'll delete it.
Changes to this policy
We may update this policy from time to time. We'll change the "Last updated" date and tell you about significant changes by email or in the dashboard.
Grievance Officer and contact
For privacy questions, requests or complaints, contact our Grievance Officer:
Grievance Officer, Extract Edge
A/73 Rustomjee Royale, J.S. Road, Dahisar West, Mumbai, Maharashtra 400068, India
Email: [email protected] · Phone: +91 97688 36541