Privacy Policy

Last updated: January 2026

1. Who We Are

BSG API Hub is operated by Business Software Group ("BSG"), a UK company. We are the data controller for information collected through the Service. Contact: support@business-software.group.

2. Information We Collect

Account information: Name, email address, and company name (where provided). If you sign in via a social provider, we receive the profile information they share (typically name and email).

Billing information: Payment transactions are processed by Stripe. We do not store card numbers. We retain transaction records (amounts, dates, token allocations) for invoicing.

Usage data: API call counts, token deductions, timestamps, and IP addresses for rate-limiting and security.

3. How We Use Your Information

  • Provide and maintain the Service
  • Process payments and manage token balances
  • Enforce API key security (IP whitelisting, rate limits)
  • Send service updates and billing notifications
  • Detect and prevent abuse

4. API Request Data

Data submitted through API calls (e.g., postcodes, CV files) is processed in real time and not stored after the response is returned. We do not use API request data for marketing, training, or any purpose other than fulfilling the request.

5. Third-Party Services

We use the following third-party services:

  • Stripe — Payment processing
  • Auth0 — Social login authentication
  • Railway — Application hosting

Each service has its own privacy policy. We only share the minimum data required for each service to function.

6. Data Retention

Account data is retained while your account is active and for up to 6 years after closure for tax and legal purposes. API request content is not stored. Usage logs are retained for 12 months.

7. Your Rights

Under UK GDPR, you have the right to access, correct, or delete your personal data. You may also request export of your data in a portable format. Contact us at support@business-software.group to exercise these rights.

8. Cookies

We use essential cookies for authentication and session management. We do not use advertising or tracking cookies. No consent banner is required for essential-only cookies under UK regulations.

9. Changes

We may update this policy from time to time. Material changes will be communicated via email to registered users.