Privacy Notice
Last updated 28 August 2026
This notice explains how community campuses, trading as yourapi.dev, handles personal data when you visit our site, create an account, or use the platform. community campuses is the data controller for that personal data and decides how and why it is processed.
1. Data we collect and why
- Account data — email address, username, full name and hashed password. Used to create and secure your account, authenticate you, and provide the Service. Legal basis: performance of our contract with you.
- Subscription and billing records — plan, subscription and invoice references, amounts, payment status and payment provider reference. Used to give you access to the plan you bought and to keep accurate billing records. Legal basis: contract and legal obligation. Card details are collected and processed by our reseller, not by us.
- Gateway and API configuration — gateway names, base URLs, endpoint paths and methods, API key names, key prefixes and key hashes. Used to operate the gateway and validate requests. Legal basis: contract.
- Request logs and usage telemetry — request method, endpoint path, response status, response time, timestamps, counters and quota usage. Used to show you logs and analytics, enforce plan quotas, debug problems, and detect abuse. Legal basis: contract and our legitimate interest in securing the Service.
- Support messages — the subject, content and metadata of tickets you send us. Used to answer you and improve the Service. Legal basis: contract and legitimate interests.
- Technical data — IP address, device and browser information, and login events. Used for security, fraud and abuse prevention, and service reliability. Legal basis: legitimate interests and legal obligation.
- Marketing communications — only where you have asked for them. Legal basis: consent, which you can withdraw at any time.
2. Who we share data with
- Service providers and subprocessors — hosting, managed database and authentication, email delivery, analytics and support tooling, acting on our instructions under contract.
- Merchant of Record — Paddle.com, which acts as reseller and Merchant of Record for our orders and handles checkout, subscription management, payments, tax compliance, invoicing and billing support.
- Professional advisers — legal, accounting and audit advisers where necessary.
- Authorities — where we are required to disclose data by law or to protect our legal rights.
We do not sell personal data.
3. International transfers
Our providers may process data outside your country, including outside the UK and EEA. Where that happens we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses.
4. Retention
We keep account, subscription and invoice records for as long as your account is active and afterwards for as long as required for tax, accounting and legal purposes. Request logs and usage records are kept according to the log retention of your plan and are then deleted or aggregated into anonymous statistics. Support tickets are kept while needed to handle your request and for a reasonable period afterwards. When data is no longer needed we delete or anonymise it.
5. Security
We apply appropriate technical and organisational measures, including encryption in transit, hashed passwords, hashed API keys with one-time reveal, row-level access rules that scope data to its owner, role-based administrative access and audit logging. No system is completely secure, so please use strong, unique passwords and rotate API keys you no longer need.
6. Your rights
Subject to the law that applies to you, you may request access to your personal data, ask us to correct or delete it, ask us to restrict or stop certain processing, object to processing based on legitimate interests, request a portable copy, and withdraw consent where processing relies on consent. In the UK and EEA you also have the right to complain to your supervisory authority. Email support@yourapi.dev and we will respond within one month; we may ask you to verify your identity first. You can also update your username, email and password directly in your account settings.
7. Cookies and similar technologies
We use strictly necessary cookies and local storage to keep you signed in and to protect the Service — these are required for the site to work. Where we use analytics or marketing cookies, we ask for your consent first and you can change your preferences at any time in your browser settings or by contacting us.
8. Changes to this notice
We may update this notice as the Service evolves. Material changes will be announced by email or an in-app notice, and the "last updated" date above will change.
Questions about this page? Contact community campuses at support@yourapi.dev.