STAT-API
Legal

Privacy Policy

What we collect, why, who we share it with, and the rights you have.

Last updated: 2026-09-27

This Privacy Policy explains how Verum Technologies LLC, a New Jersey limited liability company ("stat-api", "we", "us"), collects, uses, and shares information in connection with the stat-api website, accounts, and API (the "Service"). Note that the sports data the API returns is public statistical and market data, not your personal information; this policy concerns the account, billing, and usage information described below.

1. Who we are

The controller responsible for your information is Verum Technologies LLC, 466 Hackensack Ave #1265, Hackensack, New Jersey 07601, USA, reachable at [email protected]. This policy covers the website, your account, and your use of the API.

2. Information we collect

We collect the following categories of information:

  • Account information — your name and email address, provided when you sign in (currently via Google OAuth).
  • Billing information — handled by our payment processor, Stripe. We store a customer and subscription identifier and your plan, but we do not store full payment-card numbers.
  • API usage information — your API Key identifier and request metadata such as endpoints called, timestamps, IP address, user-agent, rate-limit counters, and error logs.
  • Communications — messages you send us for support and any details you submit through the enterprise inquiry form.
  • Website information — we use Google Analytics to record the pages you view, the time you spend on each page, the links you click, the site that referred you, and any campaign tags in the link (utm_ parameters). When you are signed in, these records carry your numeric account ID, never your email address. Your browser keeps the first page and campaign of your first visit, and if you create an account we store that first page, referring site and campaign with the account. Web fonts are loaded from Google Fonts, which receives your IP address as part of serving those files.

3. How we use information

We use information to provide and authenticate the Service, process billing, enforce rate limits, maintain security and prevent fraud or abuse, respond to support requests, measure which pages and campaigns bring visitors and accounts, understand and improve the product in aggregate, and comply with legal obligations.

4. Legal bases (EEA/UK users)

Where the GDPR or UK GDPR applies, we process information on the bases of performance of our contract with you, our legitimate interests (such as securing and improving the Service), your consent where required, and compliance with legal obligations.

5. Cookies & tracking

We use essential cookies to operate accounts and authentication, and first-party analytics cookies and browser storage to measure how the site is used (see Section 2). We do not use advertising or cross-site tracking cookies. If your browser sends Global Privacy Control or Do Not Track, the site loads no analytics and stores no analytics data.

6. Service providers & sharing

We share information with service providers who process it on our behalf, including Stripe (payments), Google (authentication, web fonts and website analytics), Cloudflare (hosting and content delivery), and our infrastructure providers. We do not sell your personal information.

We may disclose information if required by law or legal process, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets.

7. Data retention

We retain account information while your account is active, usage and security logs for a limited period consistent with security and operational needs, and billing records for as long as required by law. Google Analytics keeps website analytics data for 14 months. The first-visit source stored with an account is kept while the account is active. When you close your account we delete or anonymize your information, except where we must retain it for legal, accounting, or security reasons.

8. Security

We protect information using measures including encryption in transit (HTTPS), storage of API Keys in hashed form (bcrypt), and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. International transfers

We process information in the United States. If you access the Service from outside that region, your information may be transferred and processed there. Where required, we rely on an appropriate transfer mechanism such as the Standard Contractual Clauses.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your information, and to object to or restrict certain processing. EEA/UK residents have rights under the GDPR; California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing (we do not sell or share for cross-context behavioral advertising).

To exercise any right, contact us at [email protected]. We will respond as required by applicable law, and you may appeal a decision or contact your local data-protection authority.

11. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice where required.

13. Contact

For privacy questions or requests, contact [email protected].