Early accessWe're onboarding teams in batches. The sandbox and docs are open to everyone. Request access →

Skip to content
APIserver.in

Legal

Privacy policy

What personal data APIserver.in processes, why, for how long, and your rights under the DPDP Act, 2023.

Last updated 3 October 2026

  1. 01Who we are

    Crewo AI Technologies Pvt. Ltd. operates APIserver.in. This policy explains what personal data we process, why, how long we keep it, and your rights under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

  2. 02Data about you as a customer

    When you request access, sign up or contact us, we collect:

    • your name, work email, company name and, if you give it, phone number and GSTIN (for invoices);
    • billing records: top-ups, invoices and payment references. Card, UPI and bank details are handled by our payment gateway, not stored by us;
    • usage records: API calls made with your keys (time, endpoint, status, amount charged, masked identifiers), IP addresses and basic device information for security;
    • messages you send us.

    We are the Data Fiduciary for this data.

  3. 03Data in API requests

    Identifiers you send to the API (such as a GSTIN, CIN, PAN or DIN), and the results we return, can include personal data about third parties. For this data you are the Data Fiduciary and we act as your Data Processor. We process it only to answer your request, bill it correctly and keep the Service secure.

    Identifiers are masked in request logs (for example ABCDE****F). We do not sell request data, and we do not use it to build profiles or for advertising.

  4. 04Why we use your data

    • to provide the Service, run your API calls and show them in your dashboard;
    • to bill you and issue GST invoices, as tax law requires;
    • to keep the Service and your account secure and prevent abuse;
    • to reply to you and send essential service emails, such as key issuance, low balance and price changes;
    • to send product updates only if you opt in. You can unsubscribe at any time.
  5. 05How long we keep it

    • Request logs with masked identifiers: 90 days, then deleted or aggregated.
    • Responses kept for idempotent retries: 24 hours.
    • Account data: while your account is open, then up to 12 months after closure unless you ask us to delete it sooner.
    • Invoices and payment records: as long as tax and accounting law requires (currently up to 8 years).
  6. 06Who we share it with

    We share data only with service providers who help us run the Service, under contracts that limit what they can do with it:

    • data providers and government sources that answer verification requests, which receive only the identifier being checked;
    • our payment gateway, for top-ups;
    • cloud hosting, email delivery and, where enabled, an AI model provider. Our AI features never receive full PAN, GSTIN or CIN values;
    • authorities, where the law requires us to.
  7. 07Security

    We use encryption in transit, access controls, key hashing, masked logs and separate test and live environments. See our security page for details. No system is perfectly secure. If a breach affects your personal data, we will notify you and the Data Protection Board as the DPDP Act requires.

  8. 08Your rights

    You can ask to access, correct, update or erase your personal data, withdraw consent, and nominate someone to exercise your rights. Email us at the address below and we will respond within 30 days. If data in an API result concerns you, contact the business that ran the check, because they are the Data Fiduciary for that check.

  9. 09Cookies

    We use only the storage the site needs to work: your theme and code-language preference, and your session if you sign in. We do not use advertising or cross-site tracking cookies.

  10. 10Grievance officer and contact

    For privacy requests or complaints, write to our Grievance Officer at grievance@apiserver.in. We acknowledge complaints within 48 hours and aim to resolve them within 30 days. If you are not satisfied, you can approach the Data Protection Board of India.

  11. 11Changes

    We will post changes here and update the date above. For material changes we will also email account holders.

Legal entity
Crewo AI Technologies Pvt. Ltd.