Privacy Policy

Last updated: March 10, 2026

SharpAPI LLC ("we," "us," or "our") operates the sharpapi.io website and the SharpAPI sports odds API service (collectively, the "Service"). SharpAPI LLC is a limited liability company organized under the laws of the Commonwealth of Pennsylvania. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our Service.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Email address
  • Name (if provided)
  • Authentication credentials managed by our identity provider (Clerk)
  • Organization or team information (if applicable)

1.2 Payment Information

Payment processing is handled entirely by Stripe. We do not store your credit card number, bank account details, or other sensitive payment information on our servers. We receive and store your Stripe customer ID, subscription status, and billing history.

1.3 API Usage Data

When you use our API, we automatically collect:

  • API endpoints called and request methods
  • Request and response timestamps
  • Response status codes and response times
  • Daily request counts (total, successful, failed, rate-limited)
  • Streaming session data (connections opened, duration)
  • Per-endpoint usage breakdowns

1.4 Technical & Security Data

For security and fraud prevention, we collect:

  • IP addresses (from request headers)
  • User-Agent strings (browser/client identification)
  • API key usage patterns for abuse monitoring
  • Rate limit events

1.5 Communications

If you contact us via email or our in-app chat (powered by Crisp), we retain those communications and any information you provide within them.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process subscriptions and billing through Stripe
  • Enforce rate limits and subscription tier access controls
  • Send transactional emails (subscription confirmations, payment receipts, API key notifications)
  • Monitor API performance and reliability
  • Detect and prevent fraud, abuse, and security threats (including rate limiting and usage pattern monitoring)
  • Manage free trial eligibility
  • Generate aggregated, anonymized usage analytics
  • Respond to support requests
  • Comply with legal obligations

3. Third-Party Service Providers

We share information with the following categories of service providers who process data on our behalf:

ProviderPurposeData Shared
StripePayment processingEmail, subscription tier, billing events
ClerkAuthentication & identityEmail, name, session data
UnkeyAPI key managementAPI key identifiers, tier metadata
SupabaseDatabase hostingAccount data, usage stats, audit logs
ResendTransactional emailEmail address, notification content
MixpanelProduct analyticsAnonymized usage events, hashed IP addresses
VercelHosting & analyticsWeb traffic data, performance metrics
CrispLive chat supportChat messages, email (if provided)
SentryError monitoringError reports, stack traces (no PII)

We do not sell, trade, or rent your personal information to third parties. We may disclose information if required by law, subpoena, or court order, or to protect our rights, safety, or property.

4. Data Security

We implement multiple layers of security to protect your data:

  • All API communications are encrypted using TLS/HTTPS
  • API keys are hashed (SHA-256) before storage in our cache layer
  • Row-level security (RLS) policies configured on database tables
  • Automated rate limiting and abuse monitoring to detect unauthorized access patterns
  • Security audit logs track all authentication and key management events
  • Stripe webhook signatures are verified to prevent tampering

While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

5. Data Retention

We retain different types of data for different periods:

Data TypeRetention Period
Account informationDuration of account + 30 days after deletion
API usage statisticsDuration of account (aggregated daily)
Security audit logs90 days
Stripe webhook records30 days
Trial eligibility flagsIndefinite (to prevent trial abuse)
IP addresses (in audit logs)90 days

Upon account deletion, we remove your personal data within 30 days, except where retention is required by law or necessary to prevent fraud (e.g., trial eligibility records).

6. Cookies & Tracking Technologies

Our website uses the following cookies and tracking technologies:

  • Essential cookies: Authentication and session management (via Clerk). These are required for the Service to function and cannot be disabled.
  • Analytics: Vercel Web Analytics collects anonymized page view data (no personal identifiers). Mixpanel tracks anonymized product usage events with hashed IP addresses.
  • Chat widget: Crisp live chat may set cookies to maintain your chat session.

We do not use advertising cookies or cross-site tracking pixels.

7. Your Rights

Depending on your location, you may have the right to:

  • Access your personal information via the API (GET /api/v1/account) or by request
  • Correct inaccurate personal data
  • Request deletion of your account and associated data by emailing us
  • Export your usage data in a machine-readable format
  • Opt out of non-essential analytics
  • Withdraw consent where processing is based on consent

To exercise any of these rights, including account deletion, contact us at privacy@sharpapi.io. We will respond within 30 days.

8. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
  • No Sale of Personal Information: We do not sell personal information as defined by the CCPA. We do not share personal information for cross-context behavioral advertising.

To submit a CCPA request, email privacy@sharpapi.io with the subject line "CCPA Request." We will verify your identity before processing.

9. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following additional rights under the General Data Protection Regulation (GDPR):

  • Legal Basis: We process your data based on (a) performance of our contract with you (providing the Service), (b) our legitimate interests (security, fraud prevention, analytics), and (c) your consent (where applicable).
  • Data Portability: You may request a copy of your data in a structured, machine-readable format.
  • Right to Object: You may object to processing based on legitimate interests.
  • Right to Restrict Processing: You may request that we limit processing of your data in certain circumstances.
  • Supervisory Authority: You have the right to lodge a complaint with your local data protection authority.

International Transfers: Your data may be processed in the United States. We rely on standard contractual clauses and service provider commitments to safeguard data transferred outside the EEA.

10. Children's Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we will send a notification to the email address associated with your account. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Ready to Build?
Start free. Scale when you're ready. No credit card required.

No credit card required

© 2026 SharpAPI LLC. All rights reserved.