Last updated: 11 August 2026
This Privacy Policy explains what personal data CommodityPriceAPI collects when you visit https://www.commoditypriceapi.com/, create an account, or call our commodity price API, why we collect it, who we share it with, how long we keep it, and what rights you have over it.
It applies to our website, dashboard, API and documentation. It does not apply to third-party websites we link to, which have their own policies.
Providing an email address and password (or a Google account) is a contractual requirement: without it we cannot create an account or issue you an API key.
We need these records to enforce plan limits, to show you your usage, to bill correctly, to debug problems you report, and to detect abuse such as key sharing or scraping.
Payments are processed by Stripe. Card details are entered on Stripe-hosted checkout pages and are never transmitted to or stored on our servers.
What we store about your subscription:
If you contact us through the support form or by email, we receive your name, email address, the content of your message and any attachments, plus anything else you choose to tell us. If you apply for a trial extension, we also receive the plan and duration requested and the reason you give.
Like all hosted services, our servers and hosting provider keep log files. These record IP address, browser type and version, operating system, internet service provider, date and time stamps, referring/exit pages, requested URLs and error codes. We use them for security, abuse prevention, troubleshooting and aggregate traffic analysis.
Where you consent, we use Google Analytics (loaded through Google Tag Manager, container GTM-T4FMX4P9), Microsoft Clarity (project r95q5ww13j) and Google Ads conversion measurement. Microsoft Clarity records page interactions such as clicks, scrolls and mouse movement so we can replay anonymised sessions and heatmaps to improve the site. If you do not consent to analytics or ad storage, Clarity is instructed not to record and Google tags run in denied consent mode.
Our sign-up form uses Google reCAPTCHA to block automated registrations. Google receives your IP address and interaction signals for this purpose and processes them under its own privacy policy.
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and operate your account, authenticate you, issue and reset your API key | Account data, API credentials | Performance of a contract |
| Serve API responses, enforce plan quotas and rate limits, show usage in the dashboard | API credentials, usage data | Performance of a contract |
| Take payment, manage subscriptions, trials, upgrades and refunds | Subscription and billing data, email | Performance of a contract |
| Service emails: verification, password reset, deletion codes, billing and trial notices | Email address, account data | Performance of a contract |
| Answer support requests and trial extension applications | Support and contact data | Performance of a contract; legitimate interests |
| Security, fraud and abuse prevention, detecting shared or leaked API keys | Log data, usage data, reCAPTCHA signals | Legitimate interests in protecting the service and our customers |
| Keep accounting and tax records | Billing data, invoices | Legal obligation |
| Website analytics, session replay and heatmaps, advertising and ad personalisation | Cookie and device data, analytics identifiers | Consent (withdrawable at any time) |
We do not carry out automated decision-making or profiling that produces legal effects for you. Plan quotas are applied mechanically from your subscription and do not involve profiling.
When you first visit the site, a consent banner lets you accept all cookies, accept only strictly necessary cookies, or choose per category: Necessary, Analytics, Marketing, Ad personalisation and Ad storage. Non-necessary categories are off by default until you turn them on. You can reopen the cookie widget at any time to change or withdraw your choices; when you withdraw analytics or advertising consent we instruct the relevant tags to stop and actively delete the corresponding Google cookies from your browser.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
jwt | HTTP cookie, httpOnly | Keeps you signed in and authorises dashboard and account API calls. This is the actual credential for your session. In production it is scoped to .commoditypriceapi.com so your session works across our subdomains. | Until expiry or sign-out |
cookie-consent | Local storage | Stores your cookie choices per category plus the timestamp of the choice, so we can honour them and prove when consent was given. | Until you clear it |
user | Local storage | A hint that a session may exist, so the dashboard knows to load your profile. It is not a credential — the jwt cookie is. | Until sign-out |
theme | Local storage | Remembers your light or dark mode preference. | Until you clear it |
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
_ga, _ga_* | Google Analytics | Distinguishes visitors and sessions. | Up to 2 years |
_gid | Google Analytics | Distinguishes visitors. | 24 hours |
_gat, _gat_gtag_* | Google Analytics | Throttles the request rate. | 1 minute |
_clck, _clsk, MUID | Microsoft Clarity | Links session recordings and heatmap data to a returning browser. | Session to 1 year |
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
_gcl_au, _gcl_aw, _gcl_dc, _gcl_gb, _gcl_gf, _gcl_ha | Google Ads / Google Marketing Platform | Attributes sign-ups and subscriptions to the ad or campaign that brought you here, and supports ad personalisation where you have allowed it. | Up to 90 days |
Google advertising cookies set on google.com and doubleclick.net | Third-party ad measurement and personalisation. These are set on Google domains, so we can neither read nor control them. | Per Google policy |
__stripe_mid and __stripe_sid) on its hosted checkout to process payments and prevent fraud._GRECAPTCHA for bot detection on the sign-up form.You can also block or delete cookies through your browser settings. Blocking strictly necessary cookies will stop you signing in or using the dashboard.
This section is included here because your plan determines what personal and commercial data handling is permitted, how long usage records are kept, and what we store about your subscription. The binding commercial terms are in our Terms & Conditions.
Paid plans — Lite, Plus and Premium — are available monthly or yearly on the pricing page, with yearly billing discounted. Plans differ across:
Your request quota resets on your billing date— the monthly anniversary of the date the subscription started. On a yearly plan you receive the plan's monthly quota, which resets each month for the twelve months of the annual term, rather than the whole year's allowance up front; the payment is taken once a year in advance. So a yearly Lite subscription gives you the Lite monthly quota every month for twelve months, not twelve months of calls available at once.
Once you have used your full monthly quota, no further API requests are served for the rest of that billing month. Calls beyond your quota are refused rather than charged as an overage, and the quota is not topped up early — it only resets on your next billing date. If you need more calls before then, upgrade your plan.
All API endpoints — latest prices, historical prices, time-series and fluctuation — are available on every plan. The exact figures for each plan are shown on the pricing page and in your dashboard, and are the ones applied to your key.
| Licence | What it allows | Included in |
|---|---|---|
| Commercial licence | Use of the data inside your commercial products, services and public-facing websites, including showing it to your own users and sharing outputs with your clients, customers and business partners. | Premium and Enterprise |
| Distribution licence | Redistribution of the data itself — reselling, sublicensing or passing raw or bulk data on to third parties, including as a feed inside your own product. | Enterprise only |
Lite and Plus include neither licence: they are for your own internal use, research and analysis only. Publishing the data on a business website, showing it to your own users or customers, or using it in a commercial product or platform without at least the commercial licence — available on Premium and Enterprise — is a breach of the Terms, as is redistributing or reselling it without a distribution licence.
The Enterprise plan is not listed publicly and cannot be bought from the pricing page. We offer it only to individuals and organisations with custom API requirements — for example bespoke endpoints, custom symbol coverage, agreed service levels, or distribution rights. It is the only plan that includes the distribution licence. To discuss it, contact us. Any additional data processing terms for an Enterprise engagement, including a data processing agreement where required, are agreed in writing alongside this policy.
The commodity prices returned by the API are market data, not personal data — they say nothing about you or your users, and nothing in this policy restricts how we source them. We include this here because customers often need the classification for their own compliance records.
The prices we provide are not raw exchange prices. We return the mid-market price — the average of the bid and the ask — from the real-time market feed of a regulated broker, whose underlying pricing is itself derived from exchange-traded futures contracts (for example Brent from ICE Futures Europe and WTI from NYMEX). For classification purposes, treat the data as aggregated and derived market data, not as a direct exchange feed and not as an official exchange settlement or benchmark price. Data accuracy and availability are covered in section 9.1 of the Terms.
We do not disclose the identity of our upstream data providers, or the terms of our licensing arrangements with them, on the Lite, Plus or Premium plans. Detailed legal and compliance support — including working through licensing documentation with your legal counsel or compliance team, supported by a dedicated contact available on WhatsApp and email 24/7 — is provided under the Enterprise plan only.
You can cancel from your dashboard at any time. Cancellation is not immediate:
A subscription can also end without you cancelling. If three attempts to charge your payment method fail, the subscription is deleted, API access ends, and the free trial cannot be taken again — section 4.4 of our Terms & Conditions is the binding statement of this. Your account and account data remain, and we record the failed-payment outcome and the date the subscription ended as part of the subscription data described in section 1.3.
Refund handling is covered by section 7 (Cancellation and refunds) of our Terms & Conditions. In summary: no refund is given for a billing period in which you have made even a single API request, and where you have made none, a refund must be requested within 24 hours of the payment. Where a refund is agreed the amount returned is what you paid less the payment processing fees our payment provider charged on the original transaction, which are not returned to us when a payment is refunded. Those two conditions are the only route to a refund. If we retire the plan you are on, your subscription continues on that plan and no refund arises; if we discontinue the Service as a whole, no refund of the current billing period is given. Section 7 of the Terms is the binding statement of this.
Where a refund is processed, we and Stripe record the refund amount, date and reason against your account, as part of the billing and subscription data described in section 1 and subject to the retention periods in section 8.
We do not sell your data. We receive nothing of value in exchange for your personal data, from anyone. We share it only with the processors and services below, each under a contract limiting them to our instructions, and — where you have consented to the advertising cookies described in section 3 — with the advertising providers named there, so that we can measure our own campaigns:
| Recipient | Why | What they receive |
|---|---|---|
| Stripe | Payment processing, subscriptions, invoices, tax | Email address, billing details you enter, payment and subscription records |
| Google (OAuth, Analytics, Tag Manager, Ads, reCAPTCHA) | Sign-in, website analytics, conversion measurement, bot protection | Account identifiers for sign-in; cookie and device data and IP address for the consent-based and security services |
| Microsoft Clarity | Session replay and heatmaps, with your consent | Interaction data, device and browser data, IP address |
| Hosting and infrastructure providers | Running the website, API and databases | All data necessary to operate the service |
| Email delivery provider | Verification, password reset, deletion codes, billing and support email | Email address and message content |
| Blog Platform | Publishing our blog content | No account data; standard request data if you read the blog |
We may also disclose data where we are legally required to, to enforce our Terms, to protect our rights or the safety of others, or as part of a merger or acquisition — in which case we will tell you before your data becomes subject to a different privacy policy.
Our providers, including Stripe, Google and Microsoft, operate globally, so your data may be processed outside your country, including in the United States. Where data leaves the EEA or the UK, transfers rely on the European Commission and UK adequacy decisions where they apply, or on Standard Contractual Clauses with additional safeguards. You can ask us for details of the mechanism used for a specific transfer.
| Data | Retention |
|---|---|
| Account data (email, name, timezone, password hash) | While your account is open, then 90 days after deletion (see section 9) |
| API key and subscription records | While your account is open, then 90 days after deletion |
| API request and usage records | While your account is open — we need them for billing, quota enforcement and abuse investigation — then deleted with the rest of your account data 90 days after deletion. Non-identifiable aggregate statistics may be kept |
| Invoices, payments, refunds and tax records (held by Stripe) | Kept by Stripe for the period required by applicable accounting and tax law, typically 6–10 years — this survives account deletion and is not ours to delete |
| Support and trial extension correspondence | Up to 3 years after the matter is closed, for service quality and dispute handling |
| Server and security logs | Short retention, typically up to 12 months |
| Cookie consent record | Kept as evidence of consent until you change or clear it |
| Analytics data | Per the provider retention settings, up to 14 months |
You can delete your account yourself from the dashboard. Because deletion is irreversible, we verify it first: we email a 5-digit confirmation code to your registered address, and deletion only starts once you enter that code. You are then signed out.
What happens next:
If you want your data erased sooner than 90 days, or want to know exactly what is retained, send us a request through our contact page and we will action what is not subject to a legal retention obligation. Where the law gives you a right to erasure — see section 11 — that right applies regardless of the 90-day window, and section 8 of our Terms & Conditions says the same.
Erasure before the 90-day window closes is not automatic. The 90-day window is an anti-abuse control: it is what stops the same person deleting an account and immediately re-registering to take another free trial, and it is what lets us investigate billing and abuse disputes. So, to have your account data removed from our databases before those 90 days have elapsed, we require either a serious, substantiated reason — for example a verified statutory erasure right under section 11, or a documented safety, fraud or identity-theft concern — or a binding order from a court or competent data protection authority. Where no such reason or order is provided, we will keep the data for the full 90 days and then delete it as described above. This condition affects only the timing of deletion inside the 90-day window; it never extends how long we keep your data beyond it, and it does not apply to the statutory rights in section 11.
httpOnly, so page scripts cannot read it.Treat your API key as a secret: keep it server-side, do not commit it to public repositories, and regenerate it from the dashboard if you think it has leaked. If we become aware of a personal data breach likely to pose a risk to you, we will notify the relevant supervisory authority within 72 hours and inform you without undue delay where the risk is high.
If you are in the EEA or the UK, you have the right to:
To exercise any of these, submit a request through our contact page, using the email address registered to your account. We respond free of charge within one month. If your request is complex we may extend this by up to two further months and will tell you why within the first month. We may ask for information to confirm your identity before acting, and we may refuse or charge a reasonable fee for requests that are manifestly unfounded or excessive — if we do, we will explain why and tell you how to complain.
If you are a California resident, you have the right to:
We do not sell your data. We respond to verifiable requests within 45 days, extendable by a further 45 days where necessary. An authorised agent may make a request on your behalf with proof of authorisation.
Our service is for business and professional use and is not directed at children. You may not create an account or use it if you are under 13, or under 16 where your local law sets that higher threshold, or under whatever higher minimum age the law of your country sets for using a service like this one — the same rule as section 3.1 of our Terms & Conditions. We do not knowingly collect personal data from children below those ages. If you believe a child has given us personal data, contact us and we will delete it promptly.
We reserve the right to update and change this policy from time to time without notice, as our service, our providers or our legal obligations change. The "last updated" date at the top always reflects the current version, and you should review this policy periodically.
Changes take effect when published. Continued use of the service after a change means you accept the updated policy. This mirrors section 16 of our Terms & Conditions, of which this policy forms part.
Nothing in this section limits any non-excludable right you have under the law applicable to you, including any right to be informed about how your personal data is used. Where we would need your consent for a new use of your data, we ask for it separately before that use begins.
For questions, requests or complaints about this policy or about how we handle your data, reach us through our contact page at commoditypriceapi.com/support. We reply to the email address registered to your account.
See also our Terms & Conditions and pricing page.