Ongapi

Privacy

This notice describes data the hosted Ongapi service processes for developer accounts and order sync.

Account data

We store your email, a password hash or Google sign-in subject, session cookies, and API key hashes. Plaintext API keys are shown once at creation.

Shop and order data

For each connected shop we store platform, region, shop id, and encrypted marketplace tokens. Canonical orders may include buyer contact and shipping fields supplied by the marketplace. API responses, outbound webhooks, and logs must not include marketplace access tokens.

Billing

Stripe stores card and invoice data when you start a paid subscription. Ongapi stores your Stripe customer id, plan, and subscription status.

Retention

Event log retention follows your plan (24 hours on Sandbox, longer on paid plans). Disconnecting a shop stops new ingest for that connection. Ask support to delete an account.