privacy policy
account, request and connected-channel data.
01data the service needs
the planned service processes account and sign-in data, private seller contacts, channel configuration, technical request metadata, usage, settlement history, wallet addresses and acceptance records. public channel names and descriptions appear in offers; private contacts are not published.
this data supports authentication, request execution, billing, channel checks, abuse prevention and support. google sign-in supplies profile data permitted by the user and requested by the sign-in configuration; the google password is not provided to 2api.
02who receives requests
request content is sent to the selected channel for execution. the channel owner and its suppliers can technically process that content even when the seller dashboard has no customer-message history. automatic routing may send different requests to different approved channels.
no universal no-retention or no-training promise can be made without checking supplier terms. do not send passwords, access keys or sensitive data without an adequate basis and agreed processing terms. the final revision will specify processor categories and international-transfer arrangements.
03keys and safeguards
the design stores channel keys encrypted and separate from public data. customer and operator interfaces must not reveal the original value. technical 2api services use the key for authorised checks and execution, so this is not a promise that nobody can ever decrypt it.
channel applications transmit the endpoint and key to the server over a secure connection for authorised checks. the key is stored encrypted and is not returned to the interface. do not place secrets in the public channel description.
04retention and deletion
before real applications open, retention periods or criteria will be defined and published for accounts, technical events, verification evidence, settlements and backups. indefinite retention of all data is not the project’s default policy.
users will be able to request access, correction, deletion or restriction within their applicable rights. account deletion does not always immediately remove records required for mandatory accounting or an unresolved dispute; the basis and duration of retention must be explained.
05cookies and preferences
cookies support sign-in sessions and the selected language. optional analytics or advertising tracking are not automatically authorised by accepting seller rules; if introduced, their purpose and any required consent will be handled separately.
contact details and final documents must be published before launch. applicable operator-disclosure, data-retention and settlement requirements still need to be determined. the name “2api” does not replace disclosures required by applicable law.