Legal
Privacy Policy
Your privacy matters. This policy explains what we collect, why, and the choices you have.
Overview
CurrencyCore (“we”, “us”) provides an edge-native currency exchange and Purchasing Power Parity API. This policy describes how we handle personal data for our website, documentation, and dashboard.
Data we collect
- Account data: name, email, and authentication identifiers (including Google sign-in profile basics) managed via our auth provider.
- Organization & usage data: organizations you create, API keys (stored hashed), and per-organization request counts used for billing and rate limiting.
- Billing data: handled by our Merchant of Record, Dodo Payments. We store only customer and subscription identifiers, never full card details.
- Technical data: request metadata (timestamps, status, coarse geography) processed at the Cloudflare edge to operate and secure the service.
How we use data
- To authenticate you and operate your organizations and API keys.
- To meter usage, enforce plan limits, and bill accurately.
- To secure the platform, prevent abuse, and debug issues.
- To send transactional email (verification, password reset, billing) via Cloudflare Email.
Subprocessors
We rely on a small set of infrastructure providers: Cloudflare (compute, storage, email routing), and Dodo Payments (billing & tax compliance as Merchant of Record). Each processes data only as needed to provide their service.
Data retention
We keep account and organization data for as long as your account is active. Usage counters are retained for billing history, and customer audit logs are retained according to your plan (up to 24 to 36 months) and then automatically pruned. Billing and tax records are retained as required by law, handled by Dodo Payments as our Merchant of Record. You can delete your data at any time. See Data deletion below.
Your rights
Depending on your jurisdiction (including the EU/UK under the GDPR), you have the right to access, correct, export (portability), restrict, or object to the processing of your personal data, and the right to erasure. To exercise any of these, email [email protected] from your account address and we will respond within 30 days. You may also lodge a complaint with your local data protection authority.
Data deletion
You can delete your personal data in two ways:
- Self-service (immediate). Sign in, open Profile → Delete account, and confirm. This permanently erases your account and any organization you solely own, including its API keys, settings, and usage data. If you solely own an organization that still has other members, transfer ownership or delete that organization first.
- By request. If you can’t sign in or would prefer we handle it, email [email protected] from your account email with the subject “Data deletion request.” We verify your identity and complete the deletion within 30 days.
After deletion we retain only records we are legally required to keep, principally billing and tax invoices held by our Merchant of Record (Dodo Payments) for the statutory period. These are kept solely to meet legal obligations and are not used for any other purpose.
Cookies
The marketing site ships no tracking cookies. The dashboard uses a first-party session cookie strictly to keep you signed in.
Contact
Questions about this policy? Email [email protected].