Privacy Policy
Last updated: February 26, 2026
The short version
- ✓ We never see, store, or have access to your credit card number, CVV, or full payment details.
- ✓ All payments are processed directly by Stripe — a PCI-DSS Level 1 certified provider.
- ✓ We only store a billing record ID returned by Stripe — not your card data.
- ✓ We do not sell, rent, or trade your personal information to anyone.
This Privacy Policy explains how RealMarketAPI ("we", "us", "our") collects, uses, stores, and protects information when you use our website, API, WebSocket services, and related products (collectively, the "Services"). By using the Services you agree to this policy.
1. Information We Collect
We collect only what is necessary to operate the Services:
- Account information — username, email address, and hashed password (plain-text passwords are never stored).
- Usage & API data — API key activity, request counts, timestamps, IP address, and user-agent string for security and rate-limit enforcement.
- Billing metadata — subscription plan, billing date, and a Stripe-generated billing record ID. We do not store card numbers, CVV codes, expiry dates, or any raw payment instrument data.
- Support communications — messages or feedback you voluntarily send us.
- Technical data — browser type, device information, and error logs for debugging.
We do not collect or have access to your credit card number, CVV, bank account details, or any sensitive payment instrument. These are entered directly on Stripe's secure, PCI-compliant payment forms and never transmitted to our servers.
2. Payment Processing — Powered by Stripe
All subscription payments are processed by Stripe, Inc. — a globally trusted payment processor certified to PCI-DSS Level 1, the highest standard in the payment industry.
- Your payment details (card number, CVV, expiry) are collected and encrypted directly by Stripe through their secure iframe. They never pass through our servers.
- We receive only a non-sensitive billing record ID that confirms your transaction was completed.
- For detailed information on how Stripe handles your data, please review the Stripe Privacy Policy.
3. How We Use Information
- Provide, operate, and maintain the Services.
- Authenticate users and secure accounts and API keys.
- Monitor usage, enforce rate limits, and prevent abuse and fraud.
- Track active subscriptions and billing history.
- Respond to support inquiries.
- Improve reliability, performance, and product experience.
- Comply with legal obligations and enforce our Terms of Service.
4. What We Do NOT Do
- We never sell, rent, or trade your personal data to third parties.
- We never store credit card numbers, CVV codes, or full payment card data.
- We never send unsolicited marketing emails.
- We never share your data with advertisers.
5. Legal Bases (Where Applicable)
- Performance of a contract (providing Services you request).
- Legitimate interests (security, analytics, product improvements).
- Legal compliance obligations.
- Consent, where required by applicable law.
6. Cookies and Analytics
We may use cookies or similar technologies for authentication session management and preferences. We do not use third-party advertising cookies. You can control cookies in your browser settings, but disabling them may affect login functionality.
7. Data Sharing
We do not sell personal data. We may share limited information only with:
- Stripe — for payment processing (see Section 2).
- Infrastructure providers — for hosting and operating the API platform, under strict confidentiality agreements.
- Law enforcement or regulators — only when legally required.
8. Data Retention
We retain account and usage data for as long as your account is active and for a reasonable period afterward for legal and audit purposes. You may request deletion of your account at any time by contacting us — see Section 11.
9. Security
We implement industry-standard technical and organizational safeguards including encrypted connections (TLS), hashed credential storage, and access controls. Payments are protected by Stripe's PCI-DSS Level 1 infrastructure — no payment card data ever reaches our servers. However, no system is 100% secure, and we cannot guarantee absolute security.
10. International Transfers
Your information may be processed in countries other than your own. Where required by law, we apply appropriate safeguards for cross-border data transfers.
11. Your Rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data. You may also request data portability or object to certain processing. Contact us via the contact page to submit a request — we respond within 30 days.
12. Children's Privacy
Our Services are not directed to children under 13 (or the applicable age in your jurisdiction), and we do not knowingly collect personal information from children.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting the updated policy on this page with a revised "Last updated" date. Continued use of the Services after any change constitutes acceptance of the new policy.
14. Contact
For privacy questions, data requests, or concerns, contact us via the contact page.
Back to home.