CannaLib API — Privacy Policy

Interim policy, effective 24 September 2026. It will be replaced by our reviewed policy; we will email account holders before any change that affects them.

This policy covers the CannaLib API and account system at cannalib.org/api/. It does not cover data served by
the API itself (which is catalogue data about plant varieties, not personal information).

What we collect

  • Account information: the email address you sign up with, and the plan and billing status
    attached to your account.
  • Usage logs: API calls made with your key, including timestamp, endpoint, response status and
    the IP address the call came from. Kept to enforce plan limits, investigate abuse, and produce your own usage
    figures in the dashboard.
  • Payment information: we do not collect or store card details. Paddle.com Market Limited, as
    merchant of record, collects and processes your payment information directly; see Paddle’s own privacy policy at
    paddle.com. We receive only your subscription status, plan, and enough billing metadata (such as country, for tax
    purposes) to run your account.
  • Website analytics: we use Umami, a cookieless, self-hosted analytics tool, to see aggregate
    page views and traffic sources on cannalib.org. It does not use cookies or collect personal information, and does
    not track you across other sites.

How we use it

To operate your account and API key, enforce plan limits, send transactional emails (sign-in links, key reveal
links, usage warnings, billing notices), respond to support requests, and detect and prevent abuse. We do not sell
your data, and we do not use your account email for marketing without your separate consent.

Who we share it with

  • Paddle.com Market Limited — payment processing, tax collection and invoicing, as merchant
    of record for all paid plans and credit packs.
  • Postmark — our transactional email provider, used to deliver sign-in links, key reveal
    links and account notifications. Postmark processes your email address and message content only to deliver these
    emails.
  • Cloudflare — provides content delivery and security (DDoS protection, bot filtering) for
    cannalib.org and the API. Cloudflare may process your IP address as part of routing and security filtering.

We do not share your data with any other third party except where required by law.

Retention

Account and billing information is kept for as long as your account is open, and for a limited period afterward
to meet tax and accounting obligations. Usage logs are kept for a limited period (typically a small number of
months) for abuse investigation and then deleted or aggregated. If you close your account, personal data is deleted
after the retention period described above, except where we are required to keep records by law (for example, tax
records relating to payments already made).

Your rights and deleting your data

You can close your account and request deletion of your personal data from your account dashboard, or by emailing
[email protected]. Nothing in this policy limits any right you have under the
Australian Privacy Act or other applicable law to access, correct or delete personal information we hold about
you.

Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to the address on your
account and/or a notice on this page at least 14 days before they take effect.

Contact

Questions about this policy: [email protected].