Effective date: 5 August 2026 Last updated: 5 August 2026
API Sunset is operated by Sajith Pragash, a sole proprietor based in Ontario, Canada ("we", "us", "our").
Contact for any privacy question or request: alerts@apisunset.com
⚠️ Note for the operator: this document is written specifically for your situation — Ontario sole proprietorship, PIPEDA, CASL, with GDPR and CCPA covered because you will have overseas users. It is not legal advice. Confirm your full legal name is written correctly above. If you incorporate, replace the operator line with the corporation's legal name and registration number.
We collect the minimum needed to run an alerting service: your email address, which APIs you want watched, and a scrambled version of your API key.
We do not sell your data. We do not share it for advertising. We do not use your account email to market other things to you. If you signed up for alerts, you get alerts.
| Category | What | Why we need it | Legal basis |
|---|---|---|---|
| Account | Email address, plan tier | To create your account and send the alerts you asked for | Performance of a contract (GDPR Art. 6(1)(b)); consent under PIPEDA |
| Billing | Stripe customer and subscription IDs | To manage your subscription | Performance of a contract |
| Configuration | Which providers you watch, webhook URL | To deliver the service | Performance of a contract |
| Security | A SHA-256 hash of your API key; hashed IP addresses used as daily rate-limit counters | To authenticate you and prevent abuse | Legitimate interest (GDPR Art. 6(1)(f)) |
| Newsletter | Email address and a signup source tag, only if you separately opted in | To send the newsletter you requested | Consent (GDPR Art. 6(1)(a)); express consent under CASL |
rate-limit counters. We cannot recover the original address.
aggregate.
customers.
We use your information only for the purpose you gave it to us for:
Purpose limitation. Under PIPEDA, consent is tied to the purpose it was given for. We will not repurpose your data. Specifically, we will not:
If we ever wanted to use your information for a genuinely new purpose, we would have to ask you first and get fresh consent.
| Processor | What they do | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, network | Global edge network |
| Stripe, Inc. | Payment processing | United States |
| Resend (Plus Five Five, Inc.) | Sending transactional email | United States |
Each is a large, established provider with its own published privacy terms. We share only what each needs to do its job.
We are in Canada. Our processors operate in the United States and globally. Where personal data of people in the EU or UK is transferred, we rely on Standard Contractual Clauses and/or the EU–US Data Privacy Framework as applicable to those processors.
Canada has an adequacy decision from the European Commission for commercial organisations subject to PIPEDA.
| Data | Retention |
|---|---|
| Account data | While your account is active, deleted within 30 days of a deletion request |
| Rate-limit counters | Expire naturally — they are daily buckets |
| Newsletter subscription | Until you unsubscribe. We keep a record that you unsubscribed, because CASL expects us to be able to show we honoured it |
| Billing records | Retained by Stripe as long as Canadian tax law requires |
Under PIPEDA (Canada) you may ask what personal information we hold about you, ask us to correct it if it is wrong, and withdraw consent (subject to legal or contractual limits — withdrawing consent to hold your email means closing your account, since we cannot email alerts to nobody).
Under GDPR (EU/UK) you additionally have rights of erasure, restriction, portability, and objection to processing.
Under CCPA/CPRA (California) you have the right to know, delete, and correct, and the right not to be discriminated against for exercising those rights. We do not "sell" or "share" personal information as those terms are defined in the CCPA.
To exercise any right, email alerts@apisunset.com from your account address. We respond within 30 days.
If you are unhappy with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). EU and UK users may complain to their own supervisory authority.
Canada's Anti-Spam Legislation governs commercial email. We comply as follows:
contact address.
works immediately and remains valid for at least 60 days.
Service messages — your API key, the alerts you configured, billing notices — are not marketing. They are the product you asked for. You can stop them by closing your account or removing the providers you watch.
nothing reusable.
No system is perfectly secure, and we will not pretend otherwise. If a breach creates a real risk of significant harm, we will report it to the Privacy Commissioner and notify affected users, as PIPEDA requires.
The service is for business use and is not directed at anyone under 16. We do not knowingly collect children's information.
We will post material changes here and, for significant ones, email account holders at least 14 days before they take effect.