
Privacy
This notice describes data the hosted Ongapi service processes for developer accounts and order sync.
Account data
We store your email, a password hash or Google sign-in subject, session cookies, and API key hashes. Plaintext API keys are shown once at creation.
Shop and order data
For each connected shop we store platform, region, shop id, and encrypted marketplace tokens. Canonical orders may include buyer contact and shipping fields supplied by the marketplace. API responses, outbound webhooks, and logs must not include marketplace access tokens.
Billing
Stripe stores card and invoice data when you start a paid subscription. Ongapi stores your Stripe customer id, plan, and subscription status.
Retention
Event log retention follows your plan (24 hours on Sandbox, longer on paid plans). Disconnecting a shop stops new ingest for that connection. Ask support to delete an account.