Scope and controller
This notice applies to stats-api.com, account and dashboard features, API access, support, and subscriptions. Stats API determines how application account, security, usage, first-party website analytics, and Firebase Analytics data is used. Polar separately acts as merchant of record for checkout and payment records under its own privacy terms.
Momo Games, at 802, Vraj Apartment, Vadodara, India, is the operator and data controller for the Stats API application data described in this notice.
Data we collect
- Account information: display name, email address, password hash, verification state, account status, and optional Google account identifier.
- Authentication and API security: hashed sessions, hashed API-key material, key labels and prefixes, verification/reset tokens, login events, request identifiers, and abuse signals. Full API keys are shown once and are not stored.
- API and product usage: route, timestamp, response status, key/account identifiers, request counts, rate-limit state, subscription tier, and billing-period totals.
- Billing records: Polar customer, product, order, subscription, status, period, and verified webhook information. Stats API does not receive or store full card details.
- Support and communications: messages you send, troubleshooting details, and transactional email delivery metadata when email delivery is enabled.
- Support chat: when you select the support control, Crisp receives the conversation, chat-session information, page path, account context, and plan label needed to provide chat support. On the private dashboard, a verified account email and display name may be supplied to Crisp when identity verification is configured.
- Website analytics: page path, external referrer domain, campaign labels, device class, and a daily rotating pseudonymous visitor hash. For signed-in activity, the page view is also linked to the internal Stats API account so the private admin view can show account journeys. The analytics table does not store the raw IP address, full user-agent string, URL query string, form contents, API keys, or an analytics cookie.
- Firebase Analytics: on application pages, Google may receive a sanitized page URL without query parameters, stable page and interaction categories, browser and device attributes, coarse geographic information, and pseudonymous online identifiers under the Firebase and Google Analytics terms. Signed-in events may include a one-way pseudonymous account identifier, account type, and plan tier; Stats API does not send names, email addresses, numeric database IDs, API keys, form values, or request payloads. Stats API does not enable Google advertising storage, advertising-user-data use, or ad personalization through this integration.
- Infrastructure and security logs: IP address, user-agent, requested path, timestamp, response status, and error details may appear temporarily in restricted web-server and security logs.
Where data comes from
Most personal data comes directly from you, your browser, or your API client. Google provides identity information only when you choose Google sign-in. Polar provides verified billing and subscription events. Security and usage records are generated while operating the service.
Why we use personal data
- Perform the service contract: create accounts, authenticate requests, issue keys, apply plans, show usage, provide support, and administer subscriptions.
- Protect legitimate interests: prevent fraud and abuse, secure systems, debug failures, measure website and signed-in product journeys, and improve documentation and product usability.
- Meet legal obligations: retain required transaction, tax, fraud, sanctions, accounting, and dispute records.
- Act on user direction: initiate optional Google sign-in or respond to communications you choose to send.
Service providers and disclosures
- Hetzner hosts the application, database, cache, and restricted logs.
- Polar operates checkout, payment processing, tax handling, invoices, receipts, subscriptions, and its customer portal as merchant of record.
- SendGrid will deliver account email only after that integration is enabled.
- Google processes identity data only when a user selects Google sign-in and that integration is enabled.
- Google processes website and product-journey measurement through Firebase Analytics and Google Analytics unless the browser sends Do Not Track or Global Privacy Control.
- Crisp processes support conversations and functional chat-session data only after a visitor opens the support widget.
- Telegram receives aggregate operational and audience reports without raw website IP addresses, full user agents, payment details, or API keys.
- Data may also be disclosed when required by law, to protect users or the service, or during a legitimate business reorganization subject to appropriate safeguards.
International processing
Service providers may process data outside your country. Where required, Stats API will use appropriate contractual or legal transfer safeguards. Provider privacy terms and locations should be reviewed before account access is enabled in a new jurisdiction.
Retention
- Raw first-party page-view events are retained for 35 days. Browser-derived visitor hashes rotate daily; signed-in page views remain linked to the internal account during that retention window.
- Firebase Analytics event data is retained under the retention settings and controls configured for the linked Google Analytics property. Aggregate reports may remain after event-level retention periods.
- Restricted web and application logs are rotated daily and retained for up to 14 rotations unless a security investigation requires longer preservation.
- Expired sessions are removed after expiry. Used or expired email verification and password-reset records are removed on the scheduled cleanup window.
- Processed Polar webhook payloads are retained for 90 days; exhausted failed events may be retained for up to 180 days for investigation and reconciliation.
- Encrypted or access-restricted database backups are retained according to the documented backup schedule and may preserve a deleted record until that backup expires.
- Account, API usage, support, and billing-linkage records are kept while needed to provide the service and afterward only as necessary for security, disputes, fraud prevention, accounting, or legal obligations.
Security
- TLS is required for the public service, application secrets are excluded from source releases, and production services use restricted operating-system accounts.
- Passwords use a modern one-way password hash. API keys, sessions, verification tokens, and password-reset tokens are hashed at rest.
- Access is limited by authentication, CSRF protection, quotas, rate limits, and administrative authorization. No system can guarantee absolute security.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to complain to a regulator. Some records may be retained where required for security, fraud prevention, tax, accounting, or legal claims.
Send a request from the account email to kolagames07@gmail.com. We may verify identity before acting. Browser Do Not Track or Global Privacy Control prevents Firebase Analytics and first-party page measurement.
Children and changes
Stats API is intended for developers and organizations and is not directed to children. Do not create an account if you cannot legally consent to data processing or enter these terms in your location.
This notice may be updated as the product, providers, or law changes. Material updates will carry a new effective date and will be communicated through the service or account email where appropriate.
Privacy contact
Email privacy and data-rights requests to kolagames07@gmail.com, or write to Momo Games, 802, Vraj Apartment, Vadodara, India.