Legal
Privacy Policy
Last updated 8 July 2026
This policy explains what personal data GreyhoundAPI ("we", "us") collects when you use our website and API (the "Service"), how we use it, and the choices you have. The racing data served by the API is not personal data and is covered by our Terms.
1. What we collect
- Account data. When you sign in with Google we receive your email address, name and a Google account identifier. We do not receive your Google password.
- API keys and usage. We store a hash of each API key (never the key itself) and records of API usage — request counts per key per day and short-lived per-minute counters for rate limiting, plus a key's last-used timestamp.
- Billing data. Payments are handled by Stripe. We receive billing status and identifiers (such as a Stripe customer ID) but do not receive or store full card numbers.
- Operational logs. Standard server logs (such as IP address and request metadata) are processed to run and secure the Service.
2. How we use it
- To provide, maintain and secure the Service and authenticate your requests.
- To meter usage and enforce rate limits and plan quotas.
- To process subscriptions and send service and billing emails (for example, a notice if a payment fails).
- To detect, prevent and address abuse, security issues and violations of our Terms.
We do not sell your personal data, and we do not use it for third-party advertising.
3. Cookies and sessions
The website uses a single, essential session cookie to keep you signed in to your account. It is
Secure, HttpOnly and SameSite=Lax. We do not use advertising or
cross-site tracking cookies.
4. Processors and third parties
We share personal data only with service providers who process it on our behalf to run the Service:
- Google — sign-in (OAuth) authentication.
- Stripe — subscription billing and payment processing.
- Postmark — transactional email delivery.
- Our hosting provider — infrastructure on which the Service runs.
Each processes data under its own terms and security commitments. We may also disclose data where required by law or to protect our rights and the safety of others.
5. Retention
We keep account and billing data for as long as your account is active and as needed to comply with legal, tax and accounting obligations. Usage counters are retained only as long as needed for metering and are pruned routinely. Key hashes are removed when a key is deleted and your data is removed on account closure, subject to any records we must retain by law.
6. Your rights
Depending on your location, you may have rights to access, correct, export or delete your personal data, and to object to or restrict certain processing. To exercise these, or to close your account and have your data deleted, contact [email protected].
7. Security
We use industry-standard measures including TLS in transit, hashing of API keys, scoped session cookies and access controls. No method of transmission or storage is perfectly secure, but we work to protect your data and to respond promptly to incidents.
8. Children
The Service is intended for adults operating a business or development use case and is not directed to children. Do not use the Service if you are under the age of majority in your jurisdiction.
9. Changes
We may update this policy; the "last updated" date above reflects the current version. Material changes will be given appropriate notice.
10. Contact
Privacy questions: [email protected].