Privacy Policy
This Privacy Policy describes how API Express ("we," "us," or "our") collects, uses, stores, and protects personal information when you use our website at https://apiexpress.in, our APIs, and any related services (collectively, the "Services"). This policy is designed to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian data protection regulations.
By using our Services, you agree to the collection and use of information in accordance with this policy.
1. Who We Are
API Express is an India-based API service provider offering custom API services for businesses — including verification, real-time data, and utility APIs. We serve as a Data Fiduciary (as defined under the DPDP Act) for personal data collected from our customers (developers, businesses, and site visitors), and as a Data Processor for personal data our customers submit through our APIs on behalf of their end-users.
| Entity | Details |
|---|---|
| Company name | API Express |
| Website | https://apiexpress.in |
| Country of operation | India |
| Contact email | hello@apiexpress.in |
| GST registered | Yes |
| Founded | 2022 |
2. Information We Collect
We collect three categories of information:
2.1 Information you provide directly
When you sign up, contact us, or use our Services, we collect:
- Account information — Name, email address, phone number, company name, and password (hashed)
- Billing information — GST number, billing address, and payment method details (processed by our PCI-DSS-compliant payment partners, not stored by us)
- Communication data — Content of enquiries, support requests, and feedback you send us
- KYC data — For enterprise clients, we may collect business registration documents and authorised signatory details for regulatory compliance
2.2 Information collected automatically
When you visit our website or use our APIs, we automatically collect:
- Usage data — Pages viewed, features used, referring URLs, and time spent on the site
- Device data — IP address, browser type and version, operating system, and device type
- API usage data — API key used, endpoint called, request/response timestamps, and response times
- Cookies — Session cookies (essential) and analytics cookies (optional, subject to consent)
2.3 Information submitted through our APIs
Our customers submit personal data through our APIs — for example, a mobile number for recharge, an Aadhaar number for KYC, or a vehicle RC number for verification. In this context:
- We act as a Data Processor on behalf of our customer (the Data Fiduciary)
- We process this data only to provide the specific service requested
- We do not retain the input data longer than necessary to complete the request
- We return results to our customer, who is responsible for their own privacy compliance with their end-users
3. How We Use Information
We use the information we collect for the following purposes:
| Purpose | Basis |
|---|---|
| Providing our Services | Contractual necessity |
| Processing payments | Contractual necessity |
| Responding to support requests | Contractual necessity / legitimate interest |
| Preventing fraud and abuse | Legitimate interest |
| Improving our Services | Legitimate interest (with consent where required) |
| Regulatory and legal compliance | Legal obligation |
| Sending product updates and marketing | Consent (opt-in, unsubscribe available) |
| Analytics and site optimisation | Consent (cookie-based) |
We never sell your personal data to third parties. We do not share it for advertising purposes. We do not use it to train machine learning models without your explicit consent.
4. When We Share Information
We share personal data only in the following limited circumstances:
4.1 With service providers (sub-processors)
We share data with a limited set of service providers who help us operate:
- Cloud infrastructure providers — All within Indian data centres
- Payment processors — For billing and payment collection
- Email delivery providers — For transactional and marketing emails
- Analytics providers — For understanding site usage patterns
All sub-processors are contractually obligated to protect your data, process it only as instructed, and comply with Indian data protection laws.
4.2 For legal compliance
We may disclose information when required by law, in response to valid legal requests (court orders, RBI directives, government authorities), or to protect our rights, property, or safety — or those of our users.
4.3 Business transfers
If API Express is acquired, merged, or undergoes a similar change of control, your data may be transferred. We will notify you before any such transfer and ensure the acquiring entity honours this Privacy Policy.
5. Data Storage & Security
All personal data is stored and processed within Indian data centres. We do not transfer personal data across borders without your explicit consent or without a valid legal basis under the DPDP Act.
Security measures
We implement industry-standard security measures to protect your data:
- Encryption in transit — TLS 1.3 for all API and web traffic
- Encryption at rest — AES-256 for all stored data
- Access controls — Role-based access, principle of least privilege, and multi-factor authentication for employees
- Audit logging — All access to personal data is logged and monitored
- Regular security audits — Annual third-party penetration testing
- Incident response — Documented breach response plan with regulatory notification protocols
See our Security page for more detail.
6. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy:
| Data type | Retention period |
|---|---|
| Account information | While your account is active, plus 90 days after closure |
| Billing records | 7 years (as required by Indian tax law) |
| API audit logs | 12 months rolling retention |
| Support communications | 24 months from last interaction |
| Verification request data | Not retained — deleted immediately after response |
| Marketing consent records | Until consent withdrawn plus 12 months |
7. Your Rights Under DPDP Act
Under India's Digital Personal Data Protection Act, 2023, you have the following rights:
Right to access
You can request a copy of the personal data we hold about you. We will respond within 30 days.
Right to correction
You can request correction of inaccurate or incomplete personal data. Most corrections can be made directly in your dashboard.
Right to erasure
You can request deletion of your personal data, subject to legal retention requirements (for example, tax records must be retained for 7 years).
Right to grievance redressal
You can file a complaint with us if you believe your data has been mishandled. We will investigate and respond within 30 days.
Right to nominate
You can nominate another individual to exercise your data rights in the event of death or incapacity.
Right to withdraw consent
Where processing is based on consent (marketing emails, analytics cookies), you can withdraw consent at any time. Withdrawal does not affect the lawfulness of prior processing.
8. Cookies & Tracking
We use a minimal set of cookies:
| Cookie type | Purpose | Duration |
|---|---|---|
| Session | Keep you logged in | Session |
| CSRF protection | Security | Session |
| Preference | Remember settings (theme, language) | 12 months |
| Analytics | Understand site usage (opt-in) | 24 months |
You can control cookies via your browser settings. Disabling essential cookies may break certain features. Analytics cookies are opt-in and can be disabled at any time.
9. Children's Privacy
Our Services are designed for businesses and are not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact us immediately and we will delete it.
10. International Users
API Express primarily serves customers in India. All personal data is processed within Indian data centres. If you access our Services from outside India, you consent to your data being processed in India according to Indian law.
If you are located in the European Union, United Kingdom, or other jurisdictions with specific data protection laws, please contact us before using our Services to discuss compliance implications.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- The "Last updated" date at the top will change
- Material changes will be announced via email to registered users
- Continued use of our Services after changes constitutes acceptance
We encourage you to review this policy periodically. The previous versions are available on request.
12. How to Contact Us
For privacy-related questions, requests, or complaints, contact our Data Protection Officer:
Data Protection Officer
Email: hello@apiexpress.in
Phone: +91 98765 43210
Business hours: Mon – Sat · 9 AM – 7 PM IST
Response time: Within 30 days for data rights requests; within 4 hours for general enquiries
If you are not satisfied with our response to a privacy complaint, you may escalate the matter to the Data Protection Board of India as established under the DPDP Act, 2023.
By using API Express Services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.
Talk to Our Team
Have questions about how we handle your data? Our team responds within 4 hours on business days.