Privacy Policy
Last updated 29 August 2026
Placement API is operated by Future Bets, Inc. This policy explains what we collect, why, and what we do with it. It is short because we collect little.
1What we collect
Your email address. It is how you sign in; there is no password to store. Sign-in links and session tokens are stored only as hashes and expire.
API keys. Stored as a SHA-256 hash with a short non-secret prefix so you can recognise which key is which. We cannot recover a key, only replace it.
Your orders and ledger. What you bought, the target URLs and anchor text you supplied, what it cost, and every credit movement. This is the record of the transaction and we keep it.
API usage counts. Requests and rows returned per key, to enforce rate limits and allowances.
We do not store card details. Payments are handled by Stripe, which is PCI-DSS compliant. We receive confirmation that a payment succeeded and an identifier for it. Card numbers never reach our servers.
We do not ask for a name, a phone number, a postal address, or anything about your clients beyond the URLs you choose to send us.
2Why we hold it
To run the service you asked for: authenticating you, placing and tracking your orders, keeping your balance correct, enforcing spend caps and rate limits, and meeting our tax and accounting obligations. Where a legal basis is required, ours is performance of our contract with you and our legitimate interest in operating and securing the service.
3Who it is shared with
Suppliers receive the target URL and anchor text of the specific placement they are fulfilling, because it cannot be fulfilled without them. They do not receive your identity, your other orders, or your contact details. Purchase orders they see never include our margin.
Processors we rely on: Stripe (payments), Neon (database), Vercel (hosting), Resend (transactional email), and DataForSEO (domain measurement — this receives domain names from the catalogue, never anything about you).
We do not sell your data, do not share it with advertisers, and do not use it to train models.
4Cookies
One cookie, holding a signed session token so you stay signed in. It is HTTP-only, SameSite=Lax, and expires. There are no advertising, analytics or third-party tracking cookies on this site, which is why you were not asked to accept any.
5How long we keep it
Orders and ledger entries are kept for seven years, because they are financial records. Session and sign-in tokens expire within days. Quotes are deleted a day after they lapse. Revoked API keys are kept as hashes so an old key cannot be silently reissued.
Close your account and we delete your email address and keys, and retain the transaction record in the form required for accounting.
6Your rights
You may ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email hello@placementapi.com and we will respond within 30 days. If you are in the UK, EU or California you have these rights by statute; we extend them to everyone because operating two standards is worse than operating the better one.
7Security
Secrets are hashed, never stored in a form we can read back. Everything is served over TLS. Spend limits are enforced in the database rather than in application code, so a bug in the application cannot spend past them. If we discover a breach affecting your data we will tell you.
8Changes and contact
Material changes will be notified by email to your account address before they take effect.
Future Bets, Inc. — hello@placementapi.com. See also our Terms of Service.