Controller and contact
aabergkvist AB is the data controller for CaddieAPI customer, website and service data. Privacy requests can be sent to hello@caddieapi.com.
Swedish company registration no. 559317-4948
VAT no. SE559317494801
Stålverksgatan 1, 302 50 Halmstad, Sweden
hello@caddieapi.com
What we collect
Checkout collects your email, company and billing details. Stripe processes payment details; CaddieAPI does not store full card numbers. The API records key identifiers, endpoint, status, response time and usage counts. Short-lived, hashed network and email fingerprints limit automated Checkout abuse.
Why we process it
We process customer data to perform the subscription contract, secure and meter the API, prevent abuse, provide invoices and support, and comply with accounting and legal obligations. We use public club-site contact information to build the Intelligence dataset based on our legitimate interests in providing accurate business information.
Processors and transfers
Neon hosts the served database in Frankfurt. Vercel runs the API in Frankfurt. Stripe provides Checkout, billing, tax and the customer portal. These providers process data under their own terms and data-processing commitments and may use approved transfer safeguards where data leaves the EEA.
Retention
Subscription and invoice records are retained as required for accounting. API usage and security logs are retained only as long as needed for metering, abuse investigation and service reliability. Checkout abuse fingerprints are routinely removed after fourteen days.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction or a copy of personal data, and object to processing based on legitimate interests or direct marketing. Club representatives can also request correction of published contact fields. Contact hello@caddieapi.com.
You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or the competent supervisory authority where you live or work.
Security
Raw API keys are shown once and stored only as cryptographic hashes. Keys are scoped by plan and geography. Payment webhooks are signature-verified and processed idempotently. No online system is risk-free; report suspected exposure promptly.
Cookies
The CaddieAPI marketing site currently uses no cookies or similar browser storage. Stripe may use cookies on its own Checkout and customer-portal domains. See our Cookie Policy for details.