← Back to API Sunset

Privacy Policy — API Sunset

Effective date: 5 August 2026 Last updated: 5 August 2026

API Sunset is operated by Sajith Pragash, a sole proprietor based in Ontario, Canada ("we", "us", "our").

Contact for any privacy question or request: alerts@apisunset.com

⚠️ Note for the operator: this document is written specifically for your situation — Ontario sole proprietorship, PIPEDA, CASL, with GDPR and CCPA covered because you will have overseas users. It is not legal advice. Confirm your full legal name is written correctly above. If you incorporate, replace the operator line with the corporation's legal name and registration number.

1. The short version

We collect the minimum needed to run an alerting service: your email address, which APIs you want watched, and a scrambled version of your API key.

We do not sell your data. We do not share it for advertising. We do not use your account email to market other things to you. If you signed up for alerts, you get alerts.


2. What we collect and why

CategoryWhatWhy we need itLegal basis
AccountEmail address, plan tierTo create your account and send the alerts you asked forPerformance of a contract (GDPR Art. 6(1)(b)); consent under PIPEDA
BillingStripe customer and subscription IDsTo manage your subscriptionPerformance of a contract
ConfigurationWhich providers you watch, webhook URLTo deliver the servicePerformance of a contract
SecurityA SHA-256 hash of your API key; hashed IP addresses used as daily rate-limit countersTo authenticate you and prevent abuseLegitimate interest (GDPR Art. 6(1)(f))
NewsletterEmail address and a signup source tag, only if you separately opted inTo send the newsletter you requestedConsent (GDPR Art. 6(1)(a)); express consent under CASL

What we deliberately do not collect

rate-limit counters. We cannot recover the original address.

aggregate.

customers.


3. How we use your information — and the limits on that

We use your information only for the purpose you gave it to us for:

Purpose limitation. Under PIPEDA, consent is tied to the purpose it was given for. We will not repurpose your data. Specifically, we will not:

If we ever wanted to use your information for a genuinely new purpose, we would have to ask you first and get fresh consent.


4. Who else processes your data

ProcessorWhat they doWhere
Cloudflare, Inc.Hosting, database, networkGlobal edge network
Stripe, Inc.Payment processingUnited States
Resend (Plus Five Five, Inc.)Sending transactional emailUnited States

Each is a large, established provider with its own published privacy terms. We share only what each needs to do its job.


5. International transfers

We are in Canada. Our processors operate in the United States and globally. Where personal data of people in the EU or UK is transferred, we rely on Standard Contractual Clauses and/or the EU–US Data Privacy Framework as applicable to those processors.

Canada has an adequacy decision from the European Commission for commercial organisations subject to PIPEDA.


6. How long we keep things

DataRetention
Account dataWhile your account is active, deleted within 30 days of a deletion request
Rate-limit countersExpire naturally — they are daily buckets
Newsletter subscriptionUntil you unsubscribe. We keep a record that you unsubscribed, because CASL expects us to be able to show we honoured it
Billing recordsRetained by Stripe as long as Canadian tax law requires

7. Your rights

Under PIPEDA (Canada) you may ask what personal information we hold about you, ask us to correct it if it is wrong, and withdraw consent (subject to legal or contractual limits — withdrawing consent to hold your email means closing your account, since we cannot email alerts to nobody).

Under GDPR (EU/UK) you additionally have rights of erasure, restriction, portability, and objection to processing.

Under CCPA/CPRA (California) you have the right to know, delete, and correct, and the right not to be discriminated against for exercising those rights. We do not "sell" or "share" personal information as those terms are defined in the CCPA.

To exercise any right, email alerts@apisunset.com from your account address. We respond within 30 days.

If you are unhappy with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). EU and UK users may complain to their own supervisory authority.


8. Email and CASL

Canada's Anti-Spam Legislation governs commercial email. We comply as follows:

contact address.

works immediately and remains valid for at least 60 days.

Service messages — your API key, the alerts you configured, billing notices — are not marketing. They are the product you asked for. You can stop them by closing your account or removing the providers you watch.


9. Security

nothing reusable.

No system is perfectly secure, and we will not pretend otherwise. If a breach creates a real risk of significant harm, we will report it to the Privacy Commissioner and notify affected users, as PIPEDA requires.


10. Children

The service is for business use and is not directed at anyone under 16. We do not knowingly collect children's information.


11. Changes to this policy

We will post material changes here and, for significant ones, email account holders at least 14 days before they take effect.