Zum Inhalt springen
IBANforge
Rechtliches

Vertragsdokumente werden auf Englisch bereitgestellt — die englische Fassung ist massgebend.

Privacy Policy

Last updated: August 6, 2026 · Version 1.2

Revision 1.2 (August 6, 2026): the daily account-lifecycle job moved from CI into the API runtime itself — GitHub's runners no longer process account data at all; the GitHub row below is updated accordingly.

Revision 1.1 (August 5, 2026): corrected the hosting region — the API runs in Railway's Amsterdam (EU) region, not Zurich; only Railway's network edge sits in Zurich. Completed the processor list (AI drafting assistance, CI infrastructure, dashboard traffic), added the feedback-reports row and the business-contacts section.

This policy explains what personal data IBANforge (see Legal Notice) processes when you use ibanforge.com and api.ibanforge.com, under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR. The short version: IBANs you submit are validated in memory and are not stored.

1. What we process, and why

DataPurposeStored?
IBANs submitted to the APIValidation and enrichment (performance of the service)No. Processed in memory, never written to storage. One exception: for invalid IBANs, at most the first 12 characters (country + bank identifier — never the account part) may be retained for data-quality diagnostics.
Email address (free key signup)Issuing your key, quota notifications, service messagesYes, while your key exists.
Request metadata (path, status, latency, timestamp, pseudonymised IP, user-agent, key prefix)Abuse prevention, capacity planning, the public status pageYes, 12 months maximum, then automatically deleted.
Aggregated statistics (daily counts by endpoint/country — no personal data)Product analytics, public metricsYes, indefinitely (anonymous).
Payment dataProcessing card or USDC paymentsHandled by Stripe / the x402 facilitator. We never see card numbers; we store the transaction reference.
Feedback reports (free-form report, optional contact address)Investigating data-quality issues, x402 refund decisionsYes, 12 months, then automatically deleted.

IP addresses are pseudonymised before storage: we keep only a salted hash, never the raw address.

2. Where the data lives

The API and its databases run on Railway infrastructure in the Amsterdam, Netherlands region (EU), fronted by Railway's European network edge (Zurich for most Swiss traffic). For EU/EEA customers, processing stays within the EU. For Swiss customers, data is processed in the EU: Swiss law recognises the EU as providing an adequate level of protection, and this policy and the DPA apply regardless of where you are.

3. Processors we use

ProcessorRoleLocation/region
Railway Corp.API hosting & storageRegion: Amsterdam (EU)
Vercel Inc.Website & dashboard hosting — customer data transits its functions when the operator uses the dashboard, and playground submissions are relayed to the APIGlobal CDN
Stripe Payments EuropeCard paymentsEU
Coinbase (CDP facilitator)x402/USDC settlement (x402.org facilitator as fallback)US
Infomaniak Network SATransactional & support email (operator-managed relay)Switzerland
GitHub Inc.Public source code & CI (no customer data — scheduled data-refresh jobs handle public reference files only)US
Anthropic PBCAI-assisted drafting of customer correspondence, operator-triggered, under redaction rulesUS

Where processors are outside Switzerland/EEA, transfers rely on adequacy decisions or standard contractual clauses maintained by the processor.

4. Retention summary

  • Submitted IBANs: not stored (invalid-IBAN prefixes ≤12 characters: up to 12 months as request metadata).
  • Request metadata: 12 months, purged automatically. For API customers who terminate, metadata attributable to their keys is deleted by default 30 days after termination (DPA clause 4.7).
  • Key account (email): lifetime of the key; deleted on request.
  • Anonymous aggregates: kept indefinitely.

5. Your rights

Under the FADP/GDPR you can request access, rectification, deletion, restriction, or a copy of your data, and object to processing. Write to support@ibanforge.com — we answer within 30 days. Deleting your email deactivates your API key. If you are in the EU/EEA you may lodge a complaint with your supervisory authority; in Switzerland, with the FDPIC.

6. Cookies and website

The website uses no advertising trackers. The dashboard uses a session cookie strictly for authentication. Locale preference is stored client-side.

7. Business contacts and prospecting

For sales and support, IBANforge keeps a lightweight record of business contacts: name, role, professional email address, company, the correspondence exchanged with us, and notes about product needs. Legal basis: legitimate interest in B2B communication (art. 6(1)(f) GDPR; FADP balancing test). We may also record publicly available professional contact details of companies that could plausibly use the Service, in order to write to them once, relevantly.

  • These records are never sold, never shared beyond the processors above, and not used for automated profiling.
  • Correspondence is kept for the duration of the business relationship; billing-related records follow statutory bookkeeping duties.
  • If you want out, reply "remove me" to any message or write to support@ibanforge.com — we delete the contact record and stop writing.

8. Changes

Material changes to this policy are announced on this page and in the changelog 30 days before they take effect.

Contact: support@ibanforge.com