Legal
Privacy
Last updated 2026-10-11
Draft. This text is a placeholder awaiting review and is not yet the binding version.
What we store
- Your email address, when you sign in with a magic link or with Google. It identifies your account and is where login links and account mail go. Magic-link tokens are stored hashed and expire in fifteen minutes.
- Your Google profile, if you sign in with Google: the Google account id (
sub), the verified email and the name Google returns. We request theopenid email profilescopes and nothing more; no Google data beyond those fields is read or kept. - A session cookie,
dr_session, set byapi.directrate.devwhen you sign in. It is HttpOnly, SameSite=Lax, Secure, host-only, and lives thirty days of inactivity. It holds a random session id, nothing about you; the session record keeps the IP address and user agent that created it so you can recognise it. Signing out deletes it. - A usage log per API call: the key id, the endpoint, the chain, the status, the credits charged
and the timestamp. This is how your invoice and the dashboard’s usage charts are
built; a problem you report with a
request_idis traced in the short-lived request logs, not here. The request body — hotel codes, dates — is not stored with it. - API keys as a hash and the last four characters. The plaintext is shown once and never stored.
What we do not do
No analytics scripts, no advertising trackers, no cookie banner because there is nothing to consent to beyond the session cookie that signing in requires. The home page’s rate card is a build-time snapshot and makes no request on your behalf.
Who sees it
Our hosting provider (Cloudflare, where the API, the database and this site run) and, for login mail, our email provider process the data above on our behalf. Nothing is sold or shared for advertising.
Retention
Account data for as long as the account exists; sessions until they expire or you sign out; usage events for the period needed to invoice and to investigate problems, after which they are rolled up into daily totals.
Your rights
Email hello@directrate.dev to see, correct or delete what we hold about you. Deleting the account removes the email, the Google profile fields, the sessions and the keys; usage totals already invoiced are kept as accounting records.