Last updated 25 September 2026
Privacy policy
What we collect when you use API Ghana, why, who else handles it, and how to get it changed or deleted.
1. Who is responsible
API Ghana Ltd., Accra, Ghana, is responsible for the personal data described here. We handle it in line with Ghana’s Data Protection Act, 2012 (Act 843). Contact us about your data at info@apighana.com.
2. What we collect
- Account details: your name and email address, and optionally a company name and website.
- Credentials: your password and API key, stored only as one-way hashes, plus the first eight characters of your key so you can recognise it.
- Purchases: which datasets you bought, the amount, currency, payment reference and payment status. Card and mobile money details are handled by Paystack and never reach us.
- Usage: which API endpoints and datasets your account called, and when.
- Preferences: your notification settings, favourites and cart.
- Messages: anything you send us through the contact form or by email.
- If you sign in with Google or GitHub: your name, email address and that provider’s account id, so we can recognise you next time. We never receive your password there, and we ask for nothing else — no contacts, no repositories, no permission to act on your behalf.
We do not sell personal data, and we do not use advertising cookies. With your consent we count anonymous page views on our own servers; you can refuse that under Cookie settings.
3. Why we use it
- to run your account and give you access to the datasets you own;
- to take payments and keep records of them;
- to send account emails — email verification, password resets and payment confirmations;
- to enforce rate limits and keep the service secure;
- to answer your messages;
- with your consent, to understand how the site is used (anonymous page views and product events).
4. Cookies and local storage
We ask for your choice on first visit. Essential cookies always run so the product works. Preferences and Analytics are optional and only start after you Accept all, or turn them on under Manage.
- Essential —
apg_sessionkeeps you signed in. Signing in with Google or GitHub briefly setsapg_oauth, removed when that handoff finishes. A smallsigned_inhint tells the page a session exists. These are httpOnly where sensitive, so scripts cannot read the session itself. We also storeapg_consentso we remember your choice. - Preferences (optional) —
apg_marketand a local currency key remember Ghana / International pricing. - Analytics (optional) — anonymous visitor and session ids in local or session storage for page views and product events. No advertising network. Browsers that send Do Not Track or Global Privacy Control are treated as having rejected Analytics.
Change your mind any time via Cookie settings in the site footer.
5. Who processes data for us
We use these providers to run the service, each only for the purpose listed:
- Supabase — database hosting
- Render — hosting for the API
- Vercel — hosting for the website
- Paystack — payment processing
- Resend — sending account emails
- Google and GitHub — only if you choose to sign in with them, and only to confirm who you are
- Sentry — error reports, which contain no request bodies
Hosting providers may record IP addresses in their access logs. Some providers process data outside Ghana.
6. How long we keep it
We keep your account data while your account is open. When you delete your account — from your account settings, or by asking us — your name, email address, company, website and API key are removed immediately, and your cart, favourites, notifications and settings are deleted. Records of which endpoints were called are kept without any link to you.
The record that a payment was made is kept, with nothing in it that identifies you, because accounting and tax law requires us to keep records of sales. Payment records held by Paystack are kept under Paystack’s own policies and legal obligations.
7. Your rights
You can ask to see the personal data we hold about you, correct it, or have it deleted, and you can object to how we use it. Most of this you can do yourself from your account page; for anything else email info@apighana.com. You can also complain to Ghana’s Data Protection Commission.
8. Security and changes
Passwords and API keys are hashed, sessions use httpOnly cookies, and database access is restricted so only the API can read your data. If we change this policy, the date at the top will change and we will email account holders about material changes.