1. Who is responsible
the operator of ToolsXpo is the data controller for personal data processed through ToolsXpo. Data protection enquiries: privacy@toolsxpo.com.
For payments, Paddle.com Market Ltd is a separate controller. We never see or store your card number.
2. What we collect
Account data
Your email address and a hash of your password (bcrypt — we cannot read your password). If you provide a name, that too. We record the IP address used at signup, to detect people creating multiple accounts to farm free credits.
API keys
Stored only as SHA-256 hashes alongside a short non-secret prefix so you can tell your keys apart. The key itself is shown once at creation and is never recoverable — not by you, and not by us.
Usage records
For each API call we record the tool called, the credit cost, the HTTP status, the calling IP address and the timestamp. This is what your dashboard totals are built from, and it is how billing is auditable.
We do not store the contents of your API requests or the results returned. Inputs are processed in memory to produce a response and are not written to our database.
Billing data
A record of credits bought, granted, spent and expired, and an identifier linking your account to your Paddle customer record. Card details never reach us.
Cookies
A session cookie when you sign in, and an admin session cookie for staff. Both are HttpOnly and strictly necessary. See the Cookie Policy.
3. Why we process it, and on what legal basis
| Purpose | Data | Lawful basis (UK/EU GDPR) |
|---|---|---|
| Providing the Service | Account, API keys, usage | Performance of a contract |
| Billing and metering | Usage, credit ledger | Performance of a contract |
| Service emails (receipts, low balance, renewal notices) | Email address | Performance of a contract |
| Preventing fraud and abuse | IP addresses, signup patterns, payment outcomes | Legitimate interests |
| Security and debugging | Request metadata, error logs | Legitimate interests |
| Meeting tax and accounting obligations | Transaction records | Legal obligation |
We do not use your data for advertising, we do not sell it, and we do not use the contents of your requests to train machine-learning models.
4. Who we share it with
Only the processors needed to run the Service. Each is listed, with what it can see and where, on the Subprocessors page. In summary: Cloudflare (hosting, database, storage), Paddle (payments), and an email delivery provider.
We may also disclose data where legally required, or to establish or defend legal claims. If we are ever compelled to hand over customer data, we will tell you unless legally prohibited from doing so.
5. International transfers
Our infrastructure runs on Cloudflare's global network, so data may be processed in countries outside your own, including the United States. These transfers rely on the UK/EU Standard Contractual Clauses and the providers' own transfer frameworks.
6. How long we keep it
- Account data — until you delete your account, then removed within 30 days.
- API usage records — 24 months, so you and we can audit historical billing.
- Billing and credit ledger — as long as tax law requires, typically 6–7 years. These records survive account deletion because we are legally required to keep them.
- Fraud and abuse records — up to 24 months after the account closes, so a blocked account cannot simply be recreated.
7. Your rights
Depending on where you live, you have some or all of the following rights:
- access a copy of your personal data;
- correct data that is wrong;
- delete your data (subject to the retention obligations above);
- restrict or object to processing, including processing based on legitimate interests;
- receive your data in a portable format;
- withdraw consent, where we relied on it; and
- complain to your data protection authority.
California residents:you additionally have the right to know what is collected and to opt out of "sale" or "sharing" of personal information. We do neither, so there is nothing to opt out of. We will not discriminate against you for exercising any right.
To exercise a right, email privacy@toolsxpo.com from your account address. We respond within 30 days.
8. Security
Passwords are hashed with bcrypt and API keys with SHA-256; neither is recoverable from our database. Traffic is encrypted in transit. Admin access is restricted and separately authenticated. No system is perfectly secure, but a database breach alone would not expose usable API keys or passwords.
If a breach affects your data and creates a real risk to you, we will notify you and the relevant regulator as the law requires.
9. Children
The Service is not for anyone under 16. We do not knowingly collect their data; if we learn we have, we delete it.
10. Changes
We will post any update here and change the date at the top. For material changes we will notify you by email or in the dashboard.