1. Who is the data controller
YourFoodAPI is operated by Wojciech Skrzek, trading as WebMoose, a Polish sole proprietor (jednoosobowa działalność gospodarcza) registered in Poland under tax number NIP 646-292-67-00, with registered address at ul. Zapolskiej 22/12, 43-100 Tychy, Poland.
For any privacy questions, data subject requests, or breach notifications: api@yourfoodapi.com.
2. What personal data we process
YourFoodAPI is a data API. We do not run user accounts, do not handle payments directly, and do not collect any data you don't actively send us. In practice we process:
2.1 Server access logs
When you visit yourfoodapi.com or your application sends a request to api.yourfoodapi.com, our infrastructure automatically records:
- Your IP address
- Date and time of the request
- Requested URL and HTTP method
- HTTP status code returned
- User agent (browser or library identifier)
- Referrer (where applicable)
These records are kept for up to 30 days and are used solely for security, abuse prevention, and debugging.
2.2 Marketplace data via RapidAPI
Subscriptions, billing, and your API key are handled entirely by RapidAPI (Nordic APIs Inc., d/b/a RapidAPI). When you authenticate against our API through the RapidAPI gateway, we receive an opaque identifier that lets us enforce per-subscription quotas — we do not receive your name, email, or payment details. See the RapidAPI Privacy Policy for how they process your account information.
2.3 Analytics on the landing page
The marketing website yourfoodapi.com uses Google Analytics 4 only after you give explicit consent through our cookie banner. Until you accept, no analytics cookies are set and no data is sent to Google. If you accept, Google Analytics receives:
- A pseudonymous identifier in the
_gacookie - Page views, session duration, and approximate geographic region
- Device type and browser
IP addresses are anonymized before storage in line with Google Analytics 4 defaults. You can withdraw consent at any time using the "Cookie preferences" link in the footer or by clearing your browser cookies.
3. Legal basis
We rely on the following legal bases under Article 6 GDPR:
| Purpose | Legal basis |
|---|---|
| Operating the API and website (logs) | Legitimate interest, Art. 6(1)(f) |
| Performing the API service for subscribers | Contract performance, Art. 6(1)(b) |
| Security and abuse prevention | Legitimate interest, Art. 6(1)(f) |
| Analytics | Consent, Art. 6(1)(a) |
| Responding to your emails | Legitimate interest, Art. 6(1)(f) |
4. Who we share data with
We do not sell personal data. We rely on the following processors who help us deliver the service:
- Cloudflare, Inc. — DNS, CDN, DDoS protection. Receives request metadata and IP. Data is processed under Cloudflare's DPA with EU SCCs.
- Hosting provider in the EU — runs the API server. Processes logs as described above.
- RapidAPI (Nordic APIs Inc.) — gateway and marketplace operator.
- Google Ireland Ltd. — analytics, only after your consent.
Where data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses and supplementary measures as appropriate.
5. How long we keep your data
- Access logs: up to 30 days, then deleted automatically
- Email correspondence: up to 24 months after the last message
- Analytics events (if you opted in): 14 months in Google Analytics
- Subscription metadata used for rate limiting: for the duration of your subscription, then 30 days for billing dispute resolution
6. Your rights
Under GDPR you can:
- Request access to the personal data we hold about you
- Request correction or deletion
- Withdraw consent (for analytics) at any time
- Object to processing based on legitimate interest
- Request restriction of processing
- Request data portability where applicable
- Lodge a complaint with the Polish Personal Data Protection Office (Urząd Ochrony Danych Osobowych) or your local supervisory authority
To exercise any of these rights, email api@yourfoodapi.com. We will respond within 30 days.
7. Cookies
See the separate Cookie Policy for a per-cookie breakdown of what each cookie does, who sets it, and how long it lasts.
8. Children
YourFoodAPI is a B2B developer tool. It is not directed at children under 16 and we do not knowingly collect personal data from them.
9. Security
We use industry-standard encryption in transit (TLS 1.2+), restrict server access to authorized personnel, and protect data with the gateway's secret-header authentication. No system is perfectly secure — if you discover a vulnerability, please email api@yourfoodapi.com.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced on the landing page and via the email associated with your RapidAPI subscription. The "Last updated" date at the top of this page reflects the current version.