Legal
Privacy Policy
Last updated: August 23, 2026
This Privacy Policy describes how PolyOrderbooks (“we”, “us”, or “our”) collects, uses, discloses, and protects personal information when you visit polyorderbooks.com, create an account, authenticate (including with Google), or use our historical order-book API (collectively, the “Service”).
Related documents: Terms of Service, Acceptable Use Policy, and Cookie Policy.
1. Who we are
PolyOrderbooks is an independent historical market-data API product. We are not affiliated with, endorsed by, or a partner of Polymarket. For privacy and all other inquiries, contact contact@polyorderbooks.com.
2. Information we collect
- Account data — display name, email address, authentication method (password or Google), profile identifiers returned by Google (such as subject ID and email), and account preferences.
- Credentials & keys — password hashes (we do not store plaintext passwords) and API key metadata once keys are issued. Never share keys in public code.
- Billing data — when checkout is enabled, card and tax details are handled by our payment processor; we retain plan tier, invoice history, billing email, and payment status.
- Usage & technical data — API request timestamps, paths, status codes, approximate volume, rate-limit outcomes, IP address, user agent, referrer, device/browser type, and diagnostic logs needed for security and reliability.
- Communications — emails and messages you send to contact@polyorderbooks.com (support, enterprise, legal, or security topics).
- Cookies & local storage — see our Cookie Policy for session and preference storage.
3. How we use information
- Provide, operate, secure, and improve the website and API.
- Create and authenticate accounts, manage sessions, and provision API access.
- Enforce plan limits, detect abuse, investigate incidents, and prevent fraud.
- Send transactional messages (account, security, billing). Marketing email only with consent where required by law.
- Comply with legal obligations and respond to lawful requests.
- Analyze aggregate, de-identified usage to improve product quality.
4. Legal bases under the GDPR (EEA/UK and similar)
Where applicable, we process personal data under:
- Contract — to provide the Service you request.
- Legitimate interests — security, abuse prevention, product improvement, balanced against your rights.
- Consent — where required (for example certain cookies or marketing).
- Legal obligation — tax, accounting, and regulatory requirements.
5. Sharing and sub-processors
We do not sell personal information. The organisations below process personal data on our behalf, each limited to what its function requires. This list is current as of the date at the top of this page; we update it when a provider changes.
| Provider | Purpose | Data it receives |
|---|---|---|
| Cloud infrastructure provider | Application and database hosting | All account and usage data, at rest and in transit |
| Transactional email provider | Account verification, billing notices, support replies | Email address and message contents |
| NowPayments | Cryptocurrency payments | Email address, plan, and payment metadata |
| Dodo Payments | Card payments | Email address, plan, and payment metadata |
| Optional Google sign-in | Only if you choose it: your Google account identifier and email |
We do not use a third-party analytics service. Website analytics run on software we host ourselves on our own infrastructure, so visit data is never shared with an analytics vendor.
We may also disclose information:
- To professional advisors and authorities where required by law, or to protect rights and safety.
- To a successor entity in a merger, acquisition, or asset sale, with notice where required.
6. Retention
We keep account and usage records while your account is active and for a reasonable period afterward for security, billing disputes, backups, and legal compliance. You may request deletion; we may retain limited records when the law requires or when needed to resolve disputes and enforce our Terms.
7. Security
We apply administrative, technical, and organizational measures appropriate to an API service (access controls, encryption in transit, monitoring). No system is perfectly secure. Protect your passwords and API keys; report suspected compromise to contact@polyorderbooks.com.
8. International transfers
We may process data in the United States and other countries where our providers operate. Where required, we use appropriate safeguards for cross-border transfers.
9. Your rights & data requests
Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of personal data; to object to certain processing; and to withdraw consent. To exercise these rights, email contact@polyorderbooks.com. We may need to verify your identity before responding. You may also lodge a complaint with your local supervisory authority where applicable.
10. Children
The Service is not directed to children under 16 (or the minimum age required in your region). We do not knowingly collect their personal information. If you believe a child has provided data, contact us and we will take appropriate steps.
11. Do Not Track / California notices
We do not currently respond to Do Not Track browser signals in a uniform way. California residents may have additional rights under the CCPA/CPRA (including know, delete, and correct, and the right not to be discriminated against for exercising rights). We do not sell personal information as that term is commonly defined. Submit requests via contact@polyorderbooks.com.
12. Changes
We may update this Privacy Policy by posting a revised version with a new “Last updated” date. Material changes may be highlighted on the site or emailed when appropriate. Continued use after the effective date means you accept the updated policy.
13. Contact
All privacy and data-protection questions: contact@polyorderbooks.com
← Back to home · Privacy · Terms · Acceptable Use · Cookies