1. Introduction
frapi.io ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our APIs and related services (collectively, the "Service").
This policy applies to all users of our Service, including developers who access our APIs through the RapidAPI platform. By using our Service, you consent to the practices described in this Privacy Policy.
We encourage you to read this Privacy Policy in full. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
2. Information We Collect
We have designed our Service with privacy as a core principle. Here is exactly what we do and do not collect:
API Request Data
The data you send to our APIs (e.g., phone numbers, barcode data) is processed in real-time and is not stored, logged, or persisted after the response is returned. Once the API response is delivered, your input data is immediately discarded from memory.
Account Information
We do not directly collect account registration information. All account management, including your name, email, and payment details, is handled by RapidAPI as the hosting platform.
Aggregated Usage Data
We may collect anonymized, aggregated usage statistics including total request counts, error rates, average response times, and API endpoint popularity. This data is compiled in aggregate and cannot be used to identify individual users or their specific requests.
Automatically Collected Information
When you visit our marketing website (frapi.io), standard web server logs may record your IP address, browser type, operating system, referring URLs, and pages visited. This information is used solely for maintaining and improving the website.
3. How We Use Information
We use the limited information we collect for the following purposes:
- To provide and maintain the Service — Processing API requests in real-time and returning responses.
- To improve the Service — Analyzing aggregated, anonymized usage patterns to optimize performance, reliability, and accuracy.
- To monitor and analyze trends — Understanding aggregate usage volumes to plan infrastructure and capacity.
- To detect and prevent abuse — Identifying anomalous usage patterns that may indicate API abuse or unauthorized access.
- To communicate with you — Responding to inquiries and sending service-related announcements (e.g., maintenance windows, policy changes).
We will never use your data for targeted advertising, profiling, or any form of automated decision-making with legal or similarly significant effects.
4. Third-Party Services
Our Service operates within a broader ecosystem of third-party services:
RapidAPI
All API access, subscription management, and billing is handled by RapidAPI. When you use our APIs through RapidAPI, RapidAPI's own Privacy Policy also applies. RapidAPI processes your account information, payment details, and API key management. We do not have direct access to this information.
Analytics Services
We may use privacy-respecting analytics tools for our marketing website to understand visitor behavior and improve the site experience. These tools operate in aggregate and do not track individual users across websites.
No Data Sharing
We do not sell, rent, or share your API request data or personal information with any third parties beyond those described in this section. We have no data brokerage relationships.
5. Cookies and Tracking
Our marketing website (frapi.io) uses cookies and similar technologies for the following purposes:
- Essential Cookies: Required for basic website functionality, such as maintaining navigation state.
- Analytics Cookies: Help us understand how visitors interact with our website in aggregate.
We do not use advertising cookies or third-party tracking pixels. Our cookie usage is minimal and privacy-respecting.
API Interactions: API calls made through RapidAPI are governed by RapidAPI's own cookie and tracking policies, not ours.
6. Data Security
We implement appropriate technical and organizational measures to protect the limited data we handle:
- All API communications are encrypted using TLS/HTTPS.
- API endpoints are authenticated and rate-limited to prevent unauthorized access.
- Our infrastructure follows security best practices including regular updates and vulnerability assessments.
- We maintain a minimal attack surface by not persisting sensitive data.
Since we do not store API request data after processing, the primary security benefit is that there is no database of user requests that could be compromised. The most effective security measure is data minimization.
However, no method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
7. Data Retention
Our data retention policy is simple: we don't retain what we don't need.
API Request Data
Immediately discarded after the response is returned. Zero retention. No logs of phone numbers or barcode data are kept.
Aggregated Metrics
Anonymized usage statistics may be retained indefinitely as they contain no personally identifiable information and cannot be traced back to individual requests.
Website Server Logs
Standard web server logs from frapi.io are retained for a maximum of 90 days and then automatically purged.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
European Economic Area (GDPR)
If you are in the EEA, you have rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, and port your personal data. Given our minimal data collection, the practical scope of these rights is limited — we simply do not hold personal data to exercise them over. However, you may contact us regarding any data held through our website.
California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you the right to know what personal information is collected, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information.
Other Jurisdictions
We respect privacy rights regardless of jurisdiction. If you have privacy concerns about our Service, please contact us and we will address them promptly.
To exercise any of these rights, or if you have questions about what data we hold, please contact us using the information below.
9. Children's Privacy
Our Service is not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe that a child has provided us with personal information, please contact us immediately and we will take steps to delete such information.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, and other factors. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, provide additional notice (such as a banner on our website or an email notification through RapidAPI).
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of those changes.
11. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
frapi.io
Email: privacy@frapi.io
Web: frapi.io
For GDPR-related inquiries, please include "GDPR Request" in the subject line.
For CCPA-related inquiries, please include "CCPA Request" in the subject line.