Privacy Policy

Last updated: 11 August 2026

This Privacy Policy explains what personal data CommodityPriceAPI collects when you visit https://www.commoditypriceapi.com/, create an account, or call our commodity price API, why we collect it, who we share it with, how long we keep it, and what rights you have over it.

It applies to our website, dashboard, API and documentation. It does not apply to third-party websites we link to, which have their own policies.

At a glance

  • Who we are: CommodityPriceAPI is the data controller for the personal data described here. You can reach us through our contact page.
  • What we collect: your email address and account details, your API key and API usage records, subscription and billing metadata, support messages, and technical/analytics data about your visit.
  • Why: to run your account and the API, to bill you, to prevent abuse, to support you, and — only with your consent — to measure and advertise our service.
  • Who we share it with: Stripe (payments), Google (sign-in, analytics, ads, reCAPTCHA), Microsoft Clarity (product analytics), and our hosting and email providers. We do not sell your data.
  • If you delete your account: your account data is kept for 90 days and then permanently erased from our databases, and any active subscription is cancelled immediately. A few records have their own retention periods and outlive that window — support correspondence, security logs, your consent record and analytics data; section 8 lists each one. Your financial records — payments, invoices, refunds and subscription history — stay with our payment gateway, Stripe, which keeps them for legal and accounting purposes.
  • Your choices: change cookie preferences any time using the cookie widget on the site, and exercise your data protection rights through our contact page.

1. Information we collect

1.1 Account data you give us

  • Email address and password — required to create an account. Passwords are stored only as a salted hash; we never see or store your password in readable form.
  • Google account details— if you choose "Sign in with Google", Google shares your name, email address and Google account identifier with us so we can create or match your account. We do not receive your Google password.

Providing an email address and password (or a Google account) is a contractual requirement: without it we cannot create an account or issue you an API key.

1.2 API credentials and usage data

  • Your API key — generated for your account. You can regenerate it from the dashboard at any time.
  • API request records — for each call we record the API key used, the endpoint requested, the timestamp, the symbols and parameters requested, the response status, and the originating IP address.
  • Usage counters — the number of requests consumed in the current billing period and historical monthly totals, shown to you in the dashboard.

We need these records to enforce plan limits, to show you your usage, to bill correctly, to debug problems you report, and to detect abuse such as key sharing or scraping.

1.3 Subscription and billing data

Payments are processed by Stripe. Card details are entered on Stripe-hosted checkout pages and are never transmitted to or stored on our servers.

What we store about your subscription:

  • your plan, its price and billing period (monthly or yearly);
  • Stripe customer, subscription, product and price identifiers used to link your account to Stripe;
  • subscription status, current period start and end dates, scheduled cancellation date, and end date;
  • trial start and end dates, the number of trial extensions you have used, whether an extension has been requested, and whether the trial has ended.

1.4 Support and contact data

If you contact us through the support form or by email, we receive your name, email address, the content of your message and any attachments, plus anything else you choose to tell us. If you apply for a trial extension, we also receive the plan and duration requested and the reason you give.

1.5 Technical and log data collected automatically

Like all hosted services, our servers and hosting provider keep log files. These record IP address, browser type and version, operating system, internet service provider, date and time stamps, referring/exit pages, requested URLs and error codes. We use them for security, abuse prevention, troubleshooting and aggregate traffic analysis.

1.6 Analytics, session analytics and advertising data

Where you consent, we use Google Analytics (loaded through Google Tag Manager, container GTM-T4FMX4P9), Microsoft Clarity (project r95q5ww13j) and Google Ads conversion measurement. Microsoft Clarity records page interactions such as clicks, scrolls and mouse movement so we can replay anonymised sessions and heatmaps to improve the site. If you do not consent to analytics or ad storage, Clarity is instructed not to record and Google tags run in denied consent mode.

1.7 Bot protection

Our sign-up form uses Google reCAPTCHA to block automated registrations. Google receives your IP address and interaction signals for this purpose and processes them under its own privacy policy.

2. Why we use your information, and our legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Create and operate your account, authenticate you, issue and reset your API keyAccount data, API credentialsPerformance of a contract
Serve API responses, enforce plan quotas and rate limits, show usage in the dashboardAPI credentials, usage dataPerformance of a contract
Take payment, manage subscriptions, trials, upgrades and refundsSubscription and billing data, emailPerformance of a contract
Service emails: verification, password reset, deletion codes, billing and trial noticesEmail address, account dataPerformance of a contract
Answer support requests and trial extension applicationsSupport and contact dataPerformance of a contract; legitimate interests
Security, fraud and abuse prevention, detecting shared or leaked API keysLog data, usage data, reCAPTCHA signalsLegitimate interests in protecting the service and our customers
Keep accounting and tax recordsBilling data, invoicesLegal obligation
Website analytics, session replay and heatmaps, advertising and ad personalisationCookie and device data, analytics identifiersConsent (withdrawable at any time)

We do not carry out automated decision-making or profiling that produces legal effects for you. Plan quotas are applied mechanically from your subscription and do not involve profiling.

3. Cookies, local storage and similar technologies

When you first visit the site, a consent banner lets you accept all cookies, accept only strictly necessary cookies, or choose per category: Necessary, Analytics, Marketing, Ad personalisation and Ad storage. Non-necessary categories are off by default until you turn them on. You can reopen the cookie widget at any time to change or withdraw your choices; when you withdraw analytics or advertising consent we instruct the relevant tags to stop and actively delete the corresponding Google cookies from your browser.

3.1 Strictly necessary

NameTypePurposeLifetime
jwtHTTP cookie, httpOnlyKeeps you signed in and authorises dashboard and account API calls. This is the actual credential for your session. In production it is scoped to .commoditypriceapi.com so your session works across our subdomains.Until expiry or sign-out
cookie-consentLocal storageStores your cookie choices per category plus the timestamp of the choice, so we can honour them and prove when consent was given.Until you clear it
userLocal storageA hint that a session may exist, so the dashboard knows to load your profile. It is not a credential — the jwt cookie is.Until sign-out
themeLocal storageRemembers your light or dark mode preference.Until you clear it

3.2 Analytics (consent required)

NameSet byPurposeLifetime
_ga, _ga_*Google AnalyticsDistinguishes visitors and sessions.Up to 2 years
_gidGoogle AnalyticsDistinguishes visitors.24 hours
_gat, _gat_gtag_*Google AnalyticsThrottles the request rate.1 minute
_clck, _clsk, MUIDMicrosoft ClarityLinks session recordings and heatmap data to a returning browser.Session to 1 year

3.3 Marketing, ad personalisation and ad storage (consent required)

NameSet byPurposeLifetime
_gcl_au, _gcl_aw, _gcl_dc, _gcl_gb, _gcl_gf, _gcl_haGoogle Ads / Google Marketing PlatformAttributes sign-ups and subscriptions to the ad or campaign that brought you here, and supports ad personalisation where you have allowed it.Up to 90 days
Google advertising cookies set on google.com and doubleclick.netGoogleThird-party ad measurement and personalisation. These are set on Google domains, so we can neither read nor control them.Per Google policy

3.4 Third-party cookies we do not control

  • Stripe sets its own cookies (for example __stripe_mid and __stripe_sid) on its hosted checkout to process payments and prevent fraud.
  • Google reCAPTCHA sets _GRECAPTCHA for bot detection on the sign-up form.
  • Embedded content in blog posts (for example videos) may set cookies from the hosting platform.

You can also block or delete cookies through your browser settings. Blocking strictly necessary cookies will stop you signing in or using the dashboard.

4. Free trial, plans and licences

This section is included here because your plan determines what personal and commercial data handling is permitted, how long usage records are kept, and what we store about your subscription. The binding commercial terms are in our Terms & Conditions.

4.1 The 7-day free trial

  • Every new account gets a 7-day free trial on the Lite plan when you first sign in. No card is required to start. The trial is available once per account and cannot be taken again once a subscription has existed on that account, however that subscription ended.
  • The trial includes 2,000 API requests, intended for testing, evaluation and integration work during those 7 days.
  • Once the 2,000 requests are used up, further calls are refused and your request counter stops increasing for the rest of the trial — so exhausting the trial allowance never runs up a larger figure against your account.
  • When the 7 days end you can either buy a subscription or apply for a trial extension from your dashboard. Short Lite Plan extensions can be granted automatically, up to three times; requests for a longer extension or for a higher plan go to manual review, and we use the plan, duration and reason you supply to make that decision.
  • We store your trial start and end dates, extension count and extension request status for as long as your account exists.

4.2 What the plans include

Paid plans — Lite, Plus and Premium — are available monthly or yearly on the pricing page, with yearly billing discounted. Plans differ across:

  • monthly request quota — how many API calls you may make per billing month;
  • update frequency — how often the price data returned to you is refreshed;
  • symbols per request — how many commodities you may query in a single call;
  • rate limits — how many requests per minute your key may make. Lite is limited to 10 requests per minute; Plus and Premium have no per-minute rate limit;
  • data storage rights and licensing, described below.

Your request quota resets on your billing date— the monthly anniversary of the date the subscription started. On a yearly plan you receive the plan's monthly quota, which resets each month for the twelve months of the annual term, rather than the whole year's allowance up front; the payment is taken once a year in advance. So a yearly Lite subscription gives you the Lite monthly quota every month for twelve months, not twelve months of calls available at once.

Once you have used your full monthly quota, no further API requests are served for the rest of that billing month. Calls beyond your quota are refused rather than charged as an overage, and the quota is not topped up early — it only resets on your next billing date. If you need more calls before then, upgrade your plan.

All API endpoints — latest prices, historical prices, time-series and fluctuation — are available on every plan. The exact figures for each plan are shown on the pricing page and in your dashboard, and are the ones applied to your key.

4.3 Storing the data you receive

  • On Lite and Plus, you may cache API responses in memory or in RAM only — for example an in-process cache or an in-memory store used to reduce duplicate calls. You may not write the data into a persistent database.
  • On Premium and Enterprise, you may additionally store the data in your own permanent database — SQL or otherwise — for your own use, subject to the redistribution limits in the Terms.

4.4 Commercial licence and distribution licence

LicenceWhat it allowsIncluded in
Commercial licenceUse of the data inside your commercial products, services and public-facing websites, including showing it to your own users and sharing outputs with your clients, customers and business partners.Premium and Enterprise
Distribution licenceRedistribution of the data itself — reselling, sublicensing or passing raw or bulk data on to third parties, including as a feed inside your own product.Enterprise only

Lite and Plus include neither licence: they are for your own internal use, research and analysis only. Publishing the data on a business website, showing it to your own users or customers, or using it in a commercial product or platform without at least the commercial licence — available on Premium and Enterprise — is a breach of the Terms, as is redistributing or reselling it without a distribution licence.

4.5 The Enterprise plan

The Enterprise plan is not listed publicly and cannot be bought from the pricing page. We offer it only to individuals and organisations with custom API requirements — for example bespoke endpoints, custom symbol coverage, agreed service levels, or distribution rights. It is the only plan that includes the distribution licence. To discuss it, contact us. Any additional data processing terms for an Enterprise engagement, including a data processing agreement where required, are agreed in writing alongside this policy.

4.6 Where the commodity price data comes from

The commodity prices returned by the API are market data, not personal data — they say nothing about you or your users, and nothing in this policy restricts how we source them. We include this here because customers often need the classification for their own compliance records.

The prices we provide are not raw exchange prices. We return the mid-market price — the average of the bid and the ask — from the real-time market feed of a regulated broker, whose underlying pricing is itself derived from exchange-traded futures contracts (for example Brent from ICE Futures Europe and WTI from NYMEX). For classification purposes, treat the data as aggregated and derived market data, not as a direct exchange feed and not as an official exchange settlement or benchmark price. Data accuracy and availability are covered in section 9.1 of the Terms.

We do not disclose the identity of our upstream data providers, or the terms of our licensing arrangements with them, on the Lite, Plus or Premium plans. Detailed legal and compliance support — including working through licensing documentation with your legal counsel or compliance team, supported by a dedicated contact available on WhatsApp and email 24/7 — is provided under the Enterprise plan only.

5. Cancelling a subscription

You can cancel from your dashboard at any time. Cancellation is not immediate:

  • your subscription stays active until the end of the current billing cycle, and you keep your quota and plan entitlements for that whole period;
  • at the start of the next cycle the subscription is cancelled, no further payment is taken, and API access drops to the entitlements of a non-subscribed account;
  • we record the scheduled cancellation date and the date the subscription actually ended;
  • cancelling a subscription is not the same as deleting your account. Your account and data remain until you delete the account (see section 9) or ask us to erase it. Deleting your account works the other way round: it cancels any active subscription immediately, rather than at the end of the paid period.

A subscription can also end without you cancelling. If three attempts to charge your payment method fail, the subscription is deleted, API access ends, and the free trial cannot be taken again — section 4.4 of our Terms & Conditions is the binding statement of this. Your account and account data remain, and we record the failed-payment outcome and the date the subscription ended as part of the subscription data described in section 1.3.

Refund handling is covered by section 7 (Cancellation and refunds) of our Terms & Conditions. In summary: no refund is given for a billing period in which you have made even a single API request, and where you have made none, a refund must be requested within 24 hours of the payment. Where a refund is agreed the amount returned is what you paid less the payment processing fees our payment provider charged on the original transaction, which are not returned to us when a payment is refunded. Those two conditions are the only route to a refund. If we retire the plan you are on, your subscription continues on that plan and no refund arises; if we discontinue the Service as a whole, no refund of the current billing period is given. Section 7 of the Terms is the binding statement of this.

Where a refund is processed, we and Stripe record the refund amount, date and reason against your account, as part of the billing and subscription data described in section 1 and subject to the retention periods in section 8.

6. Who we share your information with

We do not sell your data. We receive nothing of value in exchange for your personal data, from anyone. We share it only with the processors and services below, each under a contract limiting them to our instructions, and — where you have consented to the advertising cookies described in section 3 — with the advertising providers named there, so that we can measure our own campaigns:

RecipientWhyWhat they receive
StripePayment processing, subscriptions, invoices, taxEmail address, billing details you enter, payment and subscription records
Google (OAuth, Analytics, Tag Manager, Ads, reCAPTCHA)Sign-in, website analytics, conversion measurement, bot protectionAccount identifiers for sign-in; cookie and device data and IP address for the consent-based and security services
Microsoft ClaritySession replay and heatmaps, with your consentInteraction data, device and browser data, IP address
Hosting and infrastructure providersRunning the website, API and databasesAll data necessary to operate the service
Email delivery providerVerification, password reset, deletion codes, billing and support emailEmail address and message content
Blog PlatformPublishing our blog contentNo account data; standard request data if you read the blog

We may also disclose data where we are legally required to, to enforce our Terms, to protect our rights or the safety of others, or as part of a merger or acquisition — in which case we will tell you before your data becomes subject to a different privacy policy.

7. International transfers

Our providers, including Stripe, Google and Microsoft, operate globally, so your data may be processed outside your country, including in the United States. Where data leaves the EEA or the UK, transfers rely on the European Commission and UK adequacy decisions where they apply, or on Standard Contractual Clauses with additional safeguards. You can ask us for details of the mechanism used for a specific transfer.

8. How long we keep your data

DataRetention
Account data (email, name, timezone, password hash)While your account is open, then 90 days after deletion (see section 9)
API key and subscription recordsWhile your account is open, then 90 days after deletion
API request and usage recordsWhile your account is open — we need them for billing, quota enforcement and abuse investigation — then deleted with the rest of your account data 90 days after deletion. Non-identifiable aggregate statistics may be kept
Invoices, payments, refunds and tax records (held by Stripe)Kept by Stripe for the period required by applicable accounting and tax law, typically 6–10 years — this survives account deletion and is not ours to delete
Support and trial extension correspondenceUp to 3 years after the matter is closed, for service quality and dispute handling
Server and security logsShort retention, typically up to 12 months
Cookie consent recordKept as evidence of consent until you change or clear it
Analytics dataPer the provider retention settings, up to 14 months

9. Deleting your account

You can delete your account yourself from the dashboard. Because deletion is irreversible, we verify it first: we email a 5-digit confirmation code to your registered address, and deletion only starts once you enter that code. You are then signed out.

What happens next:

  • Your API key is deactivated immediately, so calls made with it stop working.
  • Any active subscription is cancelled immediately, no further payment is taken, and no refund is due for the remainder of the period you have paid for. This differs from cancelling a subscription on its own (section 5), where access runs to the end of that period — so if you want to use the time you have paid for, cancel first and delete the account at the end of the cycle. Section 7 and section 8 of our Terms & Conditions are the binding statement of this.
  • Your account data is retained for 90 days from the deletion request. This window exists so we can recover the account if the deletion was a mistake or unauthorised, resolve any billing or abuse dispute, and meet legal obligations.
  • After 90 days your account data is permanently deleted from our databases and cannot be recovered.
  • Your financial records stay with our payment gateway. Stripe retains customer, payment, invoice, refund and subscription records for its own legal, accounting, tax and fraud-prevention obligations, and we cannot delete those on your behalf. These records are limited to transaction data — they are not used to keep your account alive or to contact you.
  • Data already sent to analytics and advertising providers is subject to their own retention and deletion processes.

If you want your data erased sooner than 90 days, or want to know exactly what is retained, send us a request through our contact page and we will action what is not subject to a legal retention obligation. Where the law gives you a right to erasure — see section 11 — that right applies regardless of the 90-day window, and section 8 of our Terms & Conditions says the same.

Erasure before the 90-day window closes is not automatic. The 90-day window is an anti-abuse control: it is what stops the same person deleting an account and immediately re-registering to take another free trial, and it is what lets us investigate billing and abuse disputes. So, to have your account data removed from our databases before those 90 days have elapsed, we require either a serious, substantiated reason — for example a verified statutory erasure right under section 11, or a documented safety, fraud or identity-theft concern — or a binding order from a court or competent data protection authority. Where no such reason or order is provided, we will keep the data for the full 90 days and then delete it as described above. This condition affects only the timing of deletion inside the 90-day window; it never extends how long we keep your data beyond it, and it does not apply to the statutory rights in section 11.

10. Security

  • All traffic to the website and API is served over HTTPS.
  • Passwords are stored as salted hashes; we cannot read them and will never ask you for your password.
  • Your session cookie is httpOnly, so page scripts cannot read it.
  • Card data is handled entirely by Stripe, a PCI-DSS Level 1 service provider, and never reaches our servers.
  • Access to production data is limited to staff who need it, and API keys can be rotated by you at any time.

Treat your API key as a secret: keep it server-side, do not commit it to public repositories, and regenerate it from the dashboard if you think it has leaked. If we become aware of a personal data breach likely to pose a risk to you, we will notify the relevant supervisory authority within 72 hours and inform you without undue delay where the risk is high.

11. Your rights (GDPR and UK GDPR)

If you are in the EEA or the UK, you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected or incomplete data completed.
  • Erasure — have your data deleted where we no longer have a lawful reason to keep it.
  • Restriction — have processing paused while a dispute about accuracy or lawfulness is resolved.
  • Objection — object to processing based on our legitimate interests, and to direct marketing at any time.
  • Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another provider.
  • Withdraw consent — withdraw analytics, advertising or marketing consent at any time, without affecting processing already carried out lawfully.
  • Complain— lodge a complaint with your local data protection supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk).

To exercise any of these, submit a request through our contact page, using the email address registered to your account. We respond free of charge within one month. If your request is complex we may extend this by up to two further months and will tell you why within the first month. We may ask for information to confirm your identity before acting, and we may refuse or charge a reasonable fee for requests that are manifestly unfounded or excessive — if we do, we will explain why and tell you how to complain.

12. Your rights (CCPA / CPRA)

If you are a California resident, you have the right to:

  • know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties we disclose it to;
  • request deletion of your personal information;
  • request correction of inaccurate personal information;
  • opt out of any sale or sharing of personal information for cross-context behavioural advertising — you can do this by declining marketing, ad personalisation and ad storage cookies in the cookie widget, and we honour Global Privacy Control signals where we receive them;
  • not be discriminated against for exercising any of these rights.

We do not sell your data. We respond to verifiable requests within 45 days, extendable by a further 45 days where necessary. An authorised agent may make a request on your behalf with proof of authorisation.

13. Children

Our service is for business and professional use and is not directed at children. You may not create an account or use it if you are under 13, or under 16 where your local law sets that higher threshold, or under whatever higher minimum age the law of your country sets for using a service like this one — the same rule as section 3.1 of our Terms & Conditions. We do not knowingly collect personal data from children below those ages. If you believe a child has given us personal data, contact us and we will delete it promptly.

14. Changes to this policy

We reserve the right to update and change this policy from time to time without notice, as our service, our providers or our legal obligations change. The "last updated" date at the top always reflects the current version, and you should review this policy periodically.

Changes take effect when published. Continued use of the service after a change means you accept the updated policy. This mirrors section 16 of our Terms & Conditions, of which this policy forms part.

Nothing in this section limits any non-excludable right you have under the law applicable to you, including any right to be informed about how your personal data is used. Where we would need your consent for a new use of your data, we ask for it separately before that use begins.

15. Contact us

For questions, requests or complaints about this policy or about how we handle your data, reach us through our contact page at commoditypriceapi.com/support. We reply to the email address registered to your account.

See also our Terms & Conditions and pricing page.