Privacy Policy
Last updated
Soldgraph is an API for resale marketplace data. This page says what we collect about you, why, and what you can do about it. We keep it short on purpose. Questions go to hello@soldgraph.com.
#What we collect
When you create an account
- Your email address.
- Your password, stored only as a scrambled hash by our sign-in provider. We can't read it. If you sign in with Google, we get your email address and basic profile from Google and no password.
- The network address (IP address) you signed up from.
- How you found us: the first page you landed on, the site that linked you, and any campaign tags in that link.
When you use the API
- Each request you make: the search, the marketplace, the time, the result status and how long it took.
- Your API keys, stored only as a hash. We show a key once, when you create it.
- How many requests you have used.
When you pay
- Our payment processor, Stripe, collects your card and billing details. We never see or store your card number. We keep a record of your plan and purchases.
When you visit the website
- Anonymous page-view counts. These use no cookies and don't identify you.
- Your browser stores your sign-in session and the "how you found us" note on your own device.
We don't use advertising cookies or trackers.
#Why we collect it
- To run your account and the API.
- To bill you, if you are on a paid plan.
- To prevent abuse of the free plan. This is why we record the sign-up network address and why accounts on the same email address or network share one free allowance.
- To fix problems and keep the service reliable.
- To understand which pages and links bring people to Soldgraph.
We don't sell your personal information. We don't use it to train AI models.
#Who helps us run the service
These companies process data for us, only to provide their part of the service:
| Company | What it does |
|---|---|
| Supabase | Sign-in and our database |
| Sign-in, if you choose "Sign in with Google" | |
| DigitalOcean | The servers that run the API |
| Vercel | Website hosting and anonymous page-view counts |
| Cloudflare | The bot check on the sign-up and sign-in forms |
| Stripe | Payments |
Your searches are sent to the marketplace you are searching. We send the search itself, not who you are.
We may also share information if the law requires it, or to protect Soldgraph and its users from fraud or abuse.
#How long we keep it
- Account details: until you delete your account.
- Request history: up to 90 days. Search results are kept for about 31 days.
- After you delete your account: we keep a scrambled (hashed) copy of your email address and your sign-up network address for up to 31 days. This stops someone from deleting and re-creating an account to reset the free allowance. If an account was suspended for abuse, we keep the hashed email for as long as the suspension matters.
- Payment records: as long as tax and accounting rules require.
#Your choices
- See or correct your data: your email, keys and request history are in your dashboard. Email us for anything else.
- Delete your account: use the Settings page in your dashboard, or email us. This deletes your profile, keys and request history.
- Ask a question or complain: email hello@soldgraph.com. Depending on where you live, you may also have the right to complain to your local data protection authority.
#Security
API keys and passwords are stored as hashes. Connections use HTTPS. Access to production systems is limited. No system is perfectly secure, so keep your API keys secret and revoke any key you think has leaked.
#Children
Soldgraph is not for children. You must be at least 18 to create an account.
#Changes
If we change this policy in a way that matters, we will update the date at the top and tell account holders by email.