Privacy Policy
How APIllow collects, uses, and protects information when you use our website, dashboard, and developer API (together, the “Service”). Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Information we collect
- Account information. Your email address, a password (stored only as a salted hash — we cannot read it), and, if you sign in with Google, your Google account identifier and name as provided by Google. Your plan and account settings.
- Payment information. Payments are processed by Stripe. We never receive or store full card numbers. We store Stripe customer and subscription identifiers, the billing name and details you enter at checkout, and transaction records (amounts, dates, invoices).
- API usage data. The requests you send (including queried addresses or property identifiers), timestamps, request counts and quota usage for billing, response status, and technical metadata such as IP address and user agent.
- Website and infrastructure logs. Standard server and gateway logs: IP address, pages or endpoints requested, timestamps, and user agent.
- Email records. The transactional and product emails we send you, along with delivery, bounce, and complaint events reported by our email provider, and your marketing opt-out status.
2. Cookies and analytics
- Session cookie. The dashboard uses one essential, signed session cookie to keep you logged in. It is HttpOnly, sent only over HTTPS, and expires after 8 hours. It is not used for tracking.
- Google Analytics. Our marketing site uses Google Analytics to understand aggregate site traffic. Google may set cookies and process usage data as described in Google’s own privacy documentation.
- Bot protection. Account signup may be protected by Cloudflare Turnstile, which processes limited visitor and device data to distinguish people from bots.
3. How we use information
- To provide and operate the Service: authenticate you, serve API responses, and maintain your dashboard.
- To bill you: measure usage against your plan’s quota, calculate overage under the Terms of Service, and process payments through Stripe.
- To protect the Service: enforce rate limits and quotas, detect and prevent abuse, fraud, and signup spam, and investigate billing disputes.
- To communicate with you: transactional email (verification, receipts, usage and billing notices) and occasional product updates, from which you can opt out at any time.
- To improve the Service: aggregate analytics about how the site and API are used.
- To comply with law and maintain records of transactions and disputes.
4. How we share information
We do not sell your personal information. We share it only with the service providers that operate the Service on our behalf, and as described below:
- Stripe — payment processing and billing.
- Amazon Web Services — hosting, data storage, and email delivery (processed in the United States).
- Google — optional Google sign-in, and Google Analytics on the marketing site.
- Cloudflare — bot protection on signup, where enabled.
- RapidAPI — if you subscribe through the RapidAPI marketplace, RapidAPI processes your account and billing under its own terms, and we receive the request data and marketplace username needed to serve you.
- We may also disclose information if required by law or legal process, to protect the rights, safety, or property of APIllow, our users, or others, or as part of a merger, acquisition, or sale of assets.
5. Data retention
- Account information is retained while your account is active.
- API usage and infrastructure logs are typically retained for up to 12 months.
- Billing, transaction, and dispute records are retained as long as needed for accounting, tax, and legal purposes.
- If you delete your account, we disable access and remove your credentials, but may retain billing and dispute records as required by law.
6. Your choices and rights
- You can view and update your account details, change your plan, or delete your account from the dashboard.
- You can opt out of non-transactional email using the unsubscribe link in any such message; transactional messages (receipts, billing and security notices) are sent as long as you have an account.
- Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information. To exercise them, contact info@apillow.co and we will respond as required by applicable law.
7. Property data in API responses
The Service returns U.S. residential property data sourced from publicly available pages on zillow.com. Responses can include information about third parties, such as listing-agent names and contact details, as published there. We process this information as public listing data and require users, under our Terms of Service, not to use it to harass, dox, or harm anyone. If you believe data about you is being misused through the Service, contact info@apillow.co.
8. Security
We use industry-standard measures to protect your information, including TLS encryption in transit, hashed passwords, scoped API keys, and access controls on our infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children.
10. International users
The Service is operated from the United States and your information is processed and stored there. By using the Service you understand that your information is transferred to and processed in the United States.
11. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated “Last updated” date, and material changes will be announced by email to the address on file. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
12. Contact
Questions about this policy or your data: info@apillow.co.