Skip to content
Humarket

Legal

Privacy Policy

Last updated: September 9, 2026

Humarket is an API marketplace. We run a single gateway so you can call catalog services with one API key, watch usage, and pay once for a lifetime request quota. This policy describes the personal data we collect when you use the website, dashboard, and gateway.

Information we collect

When you create an account we store your name, email address, and a hashed password. After you sign in we keep a session cookie so you stay authenticated.

To operate the marketplace we also store:

  • API key metadata (name, prefix, last four characters, scopes, and last used time). The secret is stored as a hash and shown in full only once when you create it.
  • Request quotas, subscription status (active, exhausted, or invalidated), and payment records (order ID, amount, requests purchased, status, and OxaPay track ID).
  • Gateway request logs: HTTP method, path, status, latency, errors, requests charged, and client IP. We do not persist request or response bodies in those logs.
  • Usage reports and schedules you configure in the dashboard.

We do not collect phone numbers, postal addresses, payment cards, or bank account details.

How we use it

We use this information to:

  • Create and secure your account
  • Issue API keys and authorize gateway calls
  • Meter usage, deduct request quota, and show dashboard analytics
  • Process OxaPay checkout and prevent abuse

Cookies

Humarket uses session cookies required to keep you signed in. We do not set advertising cookies or third-party analytics cookies.

Who we share data with

We share data only as needed to run the service:

  • OxaPay receives your email, order ID, and payment amount so it can create a crypto invoice and confirm payment.
  • Upstream API providers receive whatever you send through the gateway (headers and body), minus Humarket authentication headers.
  • Google Fonts may see your IP address when the site loads display fonts.
  • Cloudflare Turnstile receives a challenge token and your IP address when you sign in or create an account, so we can tell humans from bots.

We do not sell your personal information.

Retention

Account data is kept while your account is active. Request logs and payment records are retained for billing, abuse prevention, and the usage reports you ask us to generate. You can request deletion of your account and associated personal data.

Your choices

You can update your account details, create or revoke API keys, and sign out at any time. Depending on where you live, you may also have the right to access, correct, or delete personal data we hold about you.

Children

Humarket is not directed at children under 13, and we do not knowingly collect personal information from them.

Changes

If we change how we handle personal data, we will update this page and the date above.

Contact

Questions about this policy can be sent to privacy@humarket.dev.