Privacy Policy
Last updated: 9 July 2026. gankdat ("we", "us") is operated from the United Kingdom by its operator. Contact: info@gankdat.com.
The short version: the only personal data we hold about you is your email address and the operational records needed to run your account. No analytics, no trackers, no ad tech, no selling data. Each dataset we serve states its own personal-data posture in our terms — public-record datasets run Blind Mode (personal data stripped before we store it); the UK sanctions list is served as published, minimized, for compliance use (section 3).
1. What we collect, and why
| Data | When | Why |
|---|---|---|
| Email address | You sign in or join the waitlist | It is your account identity: sign-in links, API-key ownership, plan and quota all attach to it. Waitlist emails are used only to tell you about launch. |
| API keys (hashed) | You create a key | We store only a SHA-256 hash — we cannot recover or display your key after creation. |
| Usage counters | You call the API | Monthly request counts per account, for quotas and the usage display on your dashboard. |
| Billing records | You buy a plan | Your Stripe customer reference, plan, and a credit ledger. Card details go directly to Stripe — we never see or store them. |
| Request metadata | Every API request | Timestamp, endpoint, key identifier, response status, and IP address, in short-lived operational logs — for rate limiting, abuse prevention, and debugging. We do not log request bodies. |
| Correspondence | You email us | To answer you. |
| Feedback | You submit the feedback form | Your message (and email address, only if you choose to give one) is stored so we can act on it and reply. Deleted on request. |
2. Cookies
We set exactly one cookie: fapi_session, an opaque session identifier created when you sign in (HttpOnly, Secure, expires after 30 days or on sign-out). It is strictly necessary to keep you signed in, which is why there is no cookie banner — we have nothing else to ask consent for. No analytics or third-party cookies, ever.
3. Source data — per-dataset posture & "Blind Mode"
The datasets we serve come from official government feeds, and each dataset's personal-data posture is stated in the licence table in our terms. Public-record datasets (Find a Tender procurement notices; planning.data.gov.uk planning applications; TED procurement notices; The Gazette corporate insolvency notices; Companies House new incorporations) run Blind Mode: personal data present in source records — for example planning-applicant names and contact details — is dropped at ingest and never stored or served. We do not build profiles of individuals, and our terms forbid using the service to re-identify anyone.
uk-sanctions is different by nature: the UK Sanctions List is a government publication that names designated persons and entities so that others can comply with sanctions law. We serve it for that purpose, minimized — we drop dates of birth, identity and passport numbers, contact details, and birth places at ingest, keeping designation facts (names, aliases, regime, dates, countries). Our lawful basis is legitimate interests: enabling sanctions compliance and due diligence using data the government publishes for exactly that use. Designated persons' rights requests should be directed to the FCDO, which controls the list; we reflect the official publication and refresh daily.
sam-exclusions follows the same compliance-list posture: the US SAM.gov exclusions list names parties barred from US federal awards so that others can screen against it. We serve it minimized — all addresses, SSN/TIN/NPI identifiers, and free-text comments are dropped at ingest, keeping exclusion facts (name, classification, exclusion type and program, agency, UEI/CAGE codes, dates). Lawful basis is the same legitimate interest; excluded parties' rights requests should be directed to SAM.gov (US GSA), which controls the list; we reflect the official publication and refresh daily.
4. Pay-per-request crypto payments (x402)
Agents may pay per request in USDC without creating an account. Those payments settle on a public blockchain (Base) via a payment facilitator; the paying wallet address is pseudonymous public-ledger data by the nature of blockchains. We do not link wallet addresses to email accounts, and no account is created for x402 usage.
5. Legal bases (UK GDPR)
- Contract — operating your account: sign-in emails, key authentication, metering, billing.
- Legitimate interests — securing the service, preventing abuse and fraud, keeping minimal operational logs, and serving government-published sanctions designations for compliance and due-diligence use (section 3).
- Legal obligation — retaining billing and tax records for as long as UK law requires.
- Consent — the waitlist (you gave us your email for a launch notification; unsubscribe by emailing us).
6. Who processes data for us
| Processor | Purpose | Privacy policy |
|---|---|---|
| Cloudflare | Hosting, storage, DNS, email routing, bot protection | cloudflare.com |
| Stripe | Payment processing and billing portal | stripe.com |
| Resend | Sending transactional email (sign-in links), EU region | resend.com |
| Coinbase Developer Platform | Verifying and settling x402 crypto payments | coinbase.com |
We do not sell personal data, buy contact lists, or send cold email to individuals.
7. International transfers
Some processors are US companies operating global infrastructure. Where personal data leaves the UK, transfers rely on UK adequacy decisions (including the UK–US Data Bridge) or the processors' standard contractual safeguards.
8. Retention
- Account email & keys — kept while your account exists; deleted on request (see rights below).
- Sign-in links — expire after 15 minutes and are single-use; sessions expire after 30 days.
- Usage counters — auto-expire roughly two months after the period they meter.
- Billing and credit-ledger records — kept up to 6 years, as UK tax law requires.
- Operational logs — short-term only.
9. Security
All traffic is TLS-encrypted. API keys are stored only as SHA-256 hashes. Sign-in is passwordless (no password database to breach). Secrets are held in our hosting platform's encrypted secret store, and admin operations use constant-time credential checks.
10. Your rights
Under UK GDPR you may request access, correction, erasure, restriction, objection, or portability of your personal data. Email info@gankdat.com and we will action it — deleting your account removes your email, keys, and sessions (billing records we must keep for tax law are retained until that clock runs out). You may also complain to the Information Commissioner's Office (ICO).
11. Children
The service is a business tool and is not directed at children under 16. We do not knowingly collect their data.
12. Changes
We may update this policy; material changes will be posted here with a new date, and — for signed-up users — flagged by email where the change matters to you.