Skip to content
PayloadAPI
  • Catalog
  • Blog
  • Verification
  • Guardrails
  • Workbench
Sign inBrowse APIs

Legal Documentation

PayloadAPI Privacy Notice

Effective date: September 1, 2026 · Version 1.0

Encrypted at Rest
Default 7-day request capture with isolated per-organization keys in regional storage.
Zero-Knowledge Redaction
Permanent stripping of authorization tokens, cookies, API keys, and sensitive financial fields.
Granular Opt-Out
Full sovereign control to disable capture across Organization, Application, API, Endpoint scopes.
GDPR & CCPA Compliant
We do not sell personal data. Comprehensive data subject access, portability, and erasure rights.

On this page

  • 1. Controller & Scope
  • 2. Information We Collect
  • 3. Purposes & Legal Bases
  • 4. Edge Payload Capture
  • 5. Data Retention & Purging
  • 6. Sub-Processors & Transfers
  • 7. Cookies & Storage
  • 8. Your Privacy Rights
  • 9. Security Safeguards
  • 10. Contact & Inquiries

1.Data Controller & Scope

PayloadAPI ("Platform", "we", "us", or "our") is committed to protecting your privacy and ensuring transparency in how we handle personal data. This Privacy Notice describes how we collect, use, process, and disclose information when you visit our website, register for an account, subscribe to or publish APIs, or route traffic through the PayloadAPI Edge Gateway.

This policy applies to both API Consumers (developers, engineering teams, and organizations subscribing to APIs) and API Providers (organizations publishing and monetizing endpoints). For commercial terms, please also review our Terms of Service and Refund Policy.

2.Information We Collect

2.1 Account & Identity Data

When you create an account or organization on PayloadAPI, we collect your name, email address, organization details, authentication credentials (including passkey public keys, session identifiers, and OAuth identifiers), and user role designations.

2.2 Payment & Billing Information

Payment processing and subscription billing are handled by our Merchant of Record, Paddle. When you purchase an API subscription, Paddle collects payment card details, billing address, and tax information. PayloadAPI does not directly store credit card numbers or banking secrets; we only receive tokenized customer identifiers, subscription status, and settlement transaction summaries.

2.3 Gateway Telemetry & Metadata

When requests traverse the Edge Gateway, we collect operational telemetry necessary for quota enforcement and billing reconciliation: HTTP method, path pattern, request timestamp, client IP address (anonymized for analytics), edge latency, status code, and meter consumption units.

3.Purposes & Legal Bases for Processing

We process personal information under the following legal bases in accordance with General Data Protection Regulation (GDPR) and applicable data privacy regulations:

  • Contract Performance: Providing core marketplace functions, routing API requests, enforcing rate limits, authenticating edge keys, and reconciling usage-based billing.
  • Legitimate Interests: Detecting fraud, defending against distributed denial-of-service (DDoS) attacks, preventing credential stuffing, and maintaining edge data plane reliability.
  • Legal Compliance: Complying with tax reporting requirements, anti-money laundering (AML) screening, export control laws, and responding to lawful governmental requests.
  • Explicit Consent: Sending non-essential transactional updates, newsletters, or developer updates where you have opted in. Consent may be withdrawn at any time.

4.Edge Payload Capture & Redaction Policy

4.1 Default 7-Day Encrypted Capture

PayloadAPI provides developer observability by capturing API request and response bodies for a default retention period of 7 days. This telemetry allows engineers to inspect payloads, replay failed requests, and debug edge integration issues.

4.2 Automated Redaction & Zero-Knowledge Storage

Prior to persisting any captured payload to edge storage:

  • Sensitive Headers Redacted: Authorization headers, Bearer tokens, API keys, session cookies, and authentication tickets are permanently replaced with cryptographic redaction markers.
  • Cardholder Data Stripping: Primary Account Numbers (PANs), CVVs, and sensitive payment card tokens are automatically stripped from payload bodies using streaming pattern analyzers.
  • Isolated Cryptographic Keys: Captured bodies are encrypted with per-organization AES-256 keys. Stored objects cannot be decrypted across organizational tenant boundaries.

4.3 Sovereign Opt-Out Controls

Organizations have absolute sovereign control over data capture. You may disable request and response body capture at any time via the Workspace console across any of our four granular scopes: Organization, Application, API, or individual Endpoint. When capture is disabled, payloads pass through memory buffers without persisting to disk.

5.Data Retention & Automated Purging

We retain personal data only for as long as necessary to fulfill the purposes outlined in this notice:

  • Account Credentials & Profile: Maintained for the active lifetime of your Organization. Upon account closure, identifiers are permanently purged within 30 days.
  • Captured API Payloads: Automatically and irreversibly purged upon expiration of the 7-day rolling retention window.
  • Aggregated Meter Telemetry: Anonymized numerical usage counts (requests, tokens, compute milliseconds) are retained for billing verification and historical analytics.
  • Financial Records: Invoices, payout reconciliations, and tax records are retained for seven (7) years to satisfy mandatory statutory compliance obligations.

6.Sub-Processors & International Data Transfers

We partner with vetted, enterprise-grade infrastructure providers to deliver high-availability services:

  • Cloudflare, Inc.: Edge DNS, DDoS protection, edge worker computation, Durable Objects, and encrypted object storage (R2).
  • Paddle.com Market Ltd: Merchant of Record, customer checkout, payment card processing, tax collection, and fraud prevention.
  • Transactional Infrastructure: Dedicated VPS control plane instances in ISO-27001 certified data centers.

When personal data is transferred across international borders, we ensure adequate protections are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission and data processing addenda with strict confidentiality guarantees.

7.Cookies & Local Storage

We strictly limit our use of cookies and browser storage to essential functional mechanisms:

  • Essential Session Cookies: Encrypted HTTP-only cookies (payload_session) used to maintain authenticated sessions and protect against Cross-Site Request Forgery (CSRF).
  • Passkey Authentication: Ephemeral cryptographic challenges stored during WebAuthn / FIDO2 verification flows.
  • UI Preferences: Local storage flags for theme preferences (light/dark mode) and sidebar state.

No Third-Party Ad Trackers: PayloadAPI does not employ third-party behavioral advertising cookies, retargeting pixels, or surveillance scripts. We never sell your personal data to data brokers.

8.Your Data Protection Rights (GDPR & CCPA)

Depending on your location, you hold statutory rights regarding your personal information:

  • Right of Access & Portability: Request an export of your personal data and organization activity logs in structured, machine-readable formats.
  • Right to Rectification: Update inaccurate or incomplete profile and organization details directly via the Workspace console.
  • Right to Erasure ("Right to Be Forgotten"): Request permanent deletion of your account and associated personal data, subject to lawful retention requirements.
  • Right to Restriction & Objection: Object to processing based on legitimate interests or request restrictions on specific processing activities.
  • California Privacy Notice (CCPA / CPRA): We do not sell or share personal information for cross-context behavioral advertising. California residents may exercise access, deletion, and non-discrimination rights.

To exercise any of these rights, email our Data Protection team at privacy@payloadapi.com or submit an inquiry through the Workspace Help Console. We respond to all verified requests within thirty (30) days.

9.Security Safeguards & Cryptographic Isolation

PayloadAPI implements defense-in-depth security controls to protect against unauthorized access, alteration, or destruction of data:

  • Transport Layer Security: All public endpoints and edge proxies strictly mandate TLS 1.3 encryption in transit with HSTS enforcement.
  • Encryption at Rest: Database tables, telemetry streams, and object stores are protected with AES-256 block encryption.
  • Access Control: Granular role-based access control (RBAC), multi-factor passkeys, and strict principle-of-least-privilege credentialing for platform administrators.

10.Changes to This Notice & Contact Information

We may revise this Privacy Notice periodically to reflect technological changes or regulatory updates. Material modifications will be announced via in-app dashboard notifications or direct email notice at least thirty (30) days before taking effect.

If you have questions, concerns, or requests regarding this Privacy Notice or our data handling practices, contact:

  • Privacy & Data Protection: privacy@payloadapi.com
  • Legal & Compliance Officer: legal@payloadapi.com
  • Security Inquiries: security@payloadapi.com

PayloadAPI

A verified API marketplace. Encrypted request capture runs for 7 days by default and can be switched off at any scope.

Marketplace

  • Verified catalog
  • Engineering blog
  • Workbench

Workspace

  • Applications and keys
  • Metered usage

Legal

  • Terms of Service
  • Privacy Notice
  • Refund Policy

PayloadAPI · Verified API Marketplace