Legal · Last updated July 15, 2026

Privacy Policy

How F7 Software, Inc. handles data in connection with the FraudCheck API.

Request data. Screening inputs (IP, email, phone, country) are processed to compute checks on our own infrastructure. The reference data behind the checks is derived from publicly available databases.

1. Information we collect

  • Account data — name, email, company, and a salted hash of your password (we never store passwords in plain text).
  • Billing data — plan, subscription status, and identifiers from our payment processor (Stripe). We do not store full card numbers; card data is handled by Stripe.
  • API request inputs — the values you submit for screening (IP address, email, phone, shipping country). These may constitute personal data of your end users.
  • Usage & operational data — request metadata used for metering, rate limiting, abuse prevention, security logs, and diagnostics.
  • Cookies — strictly necessary cookies for authentication, session, and anti-forgery protection.

2. How we use information

We use information to operate and secure the Service: to authenticate you, meter and bill usage, enforce plan limits, prevent abuse and fraud against the Service, provide support, improve reliability, and comply with legal obligations. We do not sell personal data, and we do not use your screening inputs to build or enrich datasets we offer to other customers.

3. Request inputs & retention

Screening inputs are processed to compute checks against reference datasets on our own infrastructure. We do not store the values you submit for screening (the IP addresses, email addresses, phone numbers, and countries you send) — they are processed transiently to produce the response and are never written to storage. We retain request metadata only (timestamp, which API key was used, the endpoint called, response status, latency, and the returned score) as needed for metering, billing, and abuse prevention, for approximately twelve (12) months. You can request deletion of account data as described below.

4. Cookies & analytics

We use only strictly necessary cookies for sign-in, session management, and anti-forgery protection. Human-facing forms (sign-in, registration, password reset, contact) are protected by Cloudflare Turnstile, which may set its own tokens to distinguish humans from bots. We do not use advertising trackers or third-party product-analytics scripts on this site.

5. Sharing & subprocessors

We share personal data only with service providers that help us run the Service, under contracts that limit their use of the data, including: Stripe (payments and subscription billing), Cloudflare (bot protection via Turnstile), our email/SMTP provider (transactional email), and our hosting/infrastructure provider. We may also disclose information where required by law or to protect our rights and users. We do not sell personal information.

6. Security

We protect data with industry-standard measures: TLS in transit, hashing of credentials (API keys stored as salted hashes; passwords hashed), encryption of stored secrets such as SMTP credentials, role-based access controls, per-account isolation, rate limiting, and an optional per-account IP allowlist. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify affected parties of material incidents as required by law.

7. International transfers, GDPR & CCPA

We may process data in the country where our infrastructure is hosted; where required, transfers rely on appropriate safeguards such as the applicable Standard Contractual Clauses. Where the GDPR/UK GDPR applies, our legal bases are performance of a contract, our legitimate interests in operating and securing the Service, and compliance with law; you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local supervisory authority. Where the CCPA/CPRA applies, we do not sell or "share" personal information as those terms are defined, and California residents have rights to know, delete, correct, and to non-discrimination. For screening inputs about your end users, you are typically the controller/business and we act as processor/service provider on your behalf; enterprise customers who require a Data Processing Addendum may request one.

8. Data retention & deletion

We retain account and billing data for as long as your account is active and as needed to comply with legal, tax, and accounting obligations, then delete or anonymize it. You may request access to, correction of, or deletion of your account data at any time by contacting us; we will respond within the timeframes required by applicable law.

9. Children

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from individuals under 16. Because your browser's Do-Not-Track signals are not yet handled uniformly across the web, we do not respond to them; we simply do not run advertising or cross-site tracking in the first place.

10. Breach notification

We maintain safeguards designed to prevent unauthorized access to personal data. In the event of a personal-data breach that is likely to affect you, we will notify affected customers and, where applicable, the relevant authorities without undue delay and within the timeframes required by applicable law.

11. Changes to this policy

We may update this Policy from time to time. Material changes will be posted here with a revised "Last updated" date and, where appropriate, communicated by email.

12. Contact

Privacy questions or requests:
our contact form
F7 Software, Inc.
Austell, GA 30168 USA