Privacy Policy
This policy explains what personal data we process when you use our website, API, MCP server, dashboard, checkout, and support channels.
Effective and last updated: 30 August 2026
1. Who we are
OpenFootAPI is the controller for the personal data described in this policy, except where a provider acts as an independent controller. Questions and privacy requests can be sent to openfoot@pm.me.
2. Data we collect
- Account and contact data: email address, authentication identifiers, and information you choose to provide through Clerk, forms, or support messages.
- Subscription and billing references: plan, subscription status, and customer or transaction identifiers. Dodo Payments handles payment-card details; we do not receive or store your full card number.
- API and MCP usage: API-key prefix and secure hash, plan, quota, request counts, account classification, status, creation date, last-use date, HTTP method, normalized endpoint path, response-status class, typed error code, and aggregate latency buckets. Endpoint records exclude query parameters, request payloads, individual match identifiers, network addresses, and the recoverable value of an issued API key.
- Technical and security data: request metadata and information used to detect fraud, abuse, bots, and service failures. Cloudflare may process IP addresses and device or network information when providing hosting and security services.
- Analytics data: page path without query parameters, referring hostname, selected interactions, browser or session identifiers, and similar usage data. Our first-party analytics stores hashed identifiers and retains event data for 90 days.
3. Why we use personal data
We process personal data to provide accounts, API access, subscriptions, support, security, fraud prevention, service diagnostics, and product analytics; to communicate operational information; and to meet legal, tax, and accounting obligations.
Depending on the context, our legal bases are performance of a contract, our legitimate interests in operating and protecting the service, compliance with legal obligations, and consent where the law requires it. You may withdraw consent at any time without affecting earlier lawful processing.
4. Providers and disclosures
We share only the data reasonably needed for the relevant service with:
- Clerk for authentication and account management.
- Dodo Payments, our Merchant of Record, for payments, tax, invoicing, fraud checks, refunds, and chargebacks. Dodo acts as an independent controller for these activities.
- Cloudflare for hosting, database infrastructure, network security, and Turnstile verification.
- Resend for transactional email delivery.
- Google Analytics and Microsoft Clarity for website analytics.
We may also disclose data when legally required, to protect users or the service, or as part of a business reorganisation with appropriate safeguards. We do not sell personal data.
5. Retention
First-party analytics events are retained for 90 days. Account, API-key, usage, support, and subscription records are kept while needed to provide the service and afterwards only as reasonably necessary for security, dispute resolution, legal compliance, or accounting. Payment records are retained by Dodo Payments under its own legal obligations.
6. International transfers
Our providers may process data outside your country. Where required, transfers rely on an adequacy decision, standard contractual clauses, or another lawful safeguard. You may contact us for more information about applicable safeguards.
7. Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability, or objection to processing, and may withdraw consent. You may also complain to your local data-protection authority.
Send a request from the email associated with your account to openfoot@pm.me. We may ask for information needed to verify your identity and will respond within the period required by applicable law.
8. Security, children, and changes
We use reasonable technical and organisational measures to protect data, but no internet service can guarantee absolute security. Keep API keys and account credentials confidential and contact us promptly if you suspect misuse.
The service is intended for professional and developer use and is not directed to children under 16. Purchases may only be made by adults or authorised business representatives.
We may update this policy as the service or law changes. Material changes will be identified by a new effective date and, where appropriate, an additional notice.