Legal

Privacy Policy

How GlobeAPI collects, uses, stores and shares personal data, and how to exercise your GDPR rights.

Last updated: August 2, 2026

1. Who We Are

The GlobeAPI platform is operated by GoGlobe Limited, a private company limited by shares incorporated in Ireland under company registration number 785708, VAT number IE 4403614UH, with its registered address at 46 The Flagsman, Marshall Yards, Dublin 3, D03 H2Y3, Ireland.

For the personal data we hold about you as our customer — your account, your billing records, your usage of the platform — we are the data controller. For personal data that you send through the API about your own end users, you are the controller and we act as your processor; that relationship is governed by our Data Processing Agreement, not by this policy.

Our lead supervisory authority is the Data Protection Commission of Ireland. Privacy enquiries: [email protected].

2. Information We Collect

You give us: account details (name, email, company name, and where you complete merchant verification, company registration and billing details), support correspondence, and payment instrument details handled by our payment provider.

We collect automatically: API request metadata (endpoint, timestamp, response code, latency, volume, credit consumed), API key identifiers, IP addresses, user agent, session and authentication data, and diagnostic logs.

We receive from others: payment and chargeback status from our payment service provider, and verification outcomes where you complete identity or business verification.

3. Lawful Bases

We rely on performance of a contract (Art. 6(1)(b)) to operate your account, meter usage and provide support; legal obligation (Art. 6(1)(c)) for accounting, tax and sanctions-screening records; legitimate interests (Art. 6(1)(f)) for platform security, abuse and fraud prevention, capacity planning and aggregated product analytics; and consent (Art. 6(1)(a)) for optional analytics and for marketing email, which you may withdraw at any time.

4. How We Use Your Information

To provide, meter, bill and support the Service; to enforce plan allowances and rate limits; to detect and prevent abuse, scraping, fraud and unauthorised access; to produce your analytics dashboard; to communicate about your account, incidents and material changes; and to comply with legal obligations.

5. Data Storage & Security

Data is stored on infrastructure located within the European Union. We use encryption in transit and at rest, hashed and non-recoverable storage of credentials and API keys, least-privilege access controls, per-request Content Security Policy, audit logging, and documented incident response. No security measure is perfect, and we do not warrant that our systems cannot be compromised.

6. Recipients & Service Providers

We do not sell your data, and we do not disclose it to advertising networks, data brokers or ad-tech intermediaries.

We disclose personal data to service providers acting on our instructions under written Article 28 agreements, in the following categories: cloud, edge and CDN infrastructure; security and anti-abuse; payment processing; transactional and marketing email; mailbox hosting; travel content and booking aggregation; mapping, geocoding and routing; and product analytics. We treat the named identity of individual providers as confidential business information and disclose categories rather than names, as Art. 13(1)(e) GDPR permits. Active business customers may request the current named list, with purpose, region and data categories for each, subject to a reasonable confidentiality undertaking.

We may also disclose personal data where legally required, to establish or defend legal claims, and to a successor in a merger, acquisition or asset transfer, in which case we will notify you.

7. International Transfers

Processing takes place within the EEA by default. Where a provider may route personal data outside the EEA or the United Kingdom, that transfer is covered by the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) and, where relevant, the UK International Data Transfer Addendum, with a Transfer Impact Assessment performed in line with EDPB post-Schrems II guidance.

8. Data Retention

  • Account and profile data — for the life of the account, then up to 3 years after closure for the defence of legal claims.
  • Billing, invoice and tax records — retained as required by Irish accounting and tax law, currently 6 years, even after account closure.
  • API usage and diagnostic logs — retained for a limited operational period and then deleted or aggregated.
  • Security and audit logs — retained as needed to investigate incidents.
  • Aggregated, anonymised statistics — may be retained indefinitely; these are no longer personal data.

9. Your GDPR Rights

You have the right to access, rectify, erase, restrict and port your personal data, to object to processing carried out on the basis of legitimate interests, and to withdraw consent where consent is the basis. Exercise these rights at [email protected]. We respond within one month, extendable by two further months for complex requests.

You may complain to a supervisory authority. Our lead authority is the Data Protection Commission of Ireland (dataprotection.ie); you may also complain to the authority where you live or work.

10. Automated Processing & AI

We use automated systems to enforce rate limits, detect abuse and score content submitted to our moderation endpoints. These are not decisions producing legal or similarly significant effects on you within the meaning of Art. 22 GDPR; where an automated control suspends an account, you may request human review by contacting support. We do not train models on your private content without your explicit consent; aggregated and de-identified usage statistics may be used to improve the Service.

11. Cookies & Local Storage

The dashboard uses strictly necessary browser storage for session management, authentication and security. We do not use advertising cookies or cross-site tracking. Optional first-party product analytics load only where you have consented, and are configured for IP anonymisation.

12. Children

The platform is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16 in the course of operating merchant accounts. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

13. Policy Changes

We may update this policy. Material changes will be notified by email to registered merchants and posted here with a revised “Last updated” date before they take effect.

Questions about this document? Email [email protected].