Legal

Privacy Policy

NodeFlare is committed to protecting your personal data. This policy explains what we collect, why we collect it, how long we keep it, and the rights you have under the General Data Protection Regulation (GDPR).

Last updated: 28 September 2026Effective: 23 June 2026Governing law: Kingdom of the Netherlands
01

Who We Are

NodeFlare (“we”, “us”, “our”) operates the NodeFlare API platform and dashboard at nodeflare.app. We are the data controller for personal data collected through the platform.

For any privacy-related questions or to exercise your rights, contact us at [email protected]. We aim to respond within 5 business days.

02

Data We Collect

We collect only the data necessary to operate the Service:

  • Account data — email address and display name provided when you register. Stored and managed by Clerk, our authentication provider.
  • Billing data — payment method type, last four digits, billing address, and transaction history. Full card numbers are never stored by NodeFlare; they are processed directly by Stripe.
  • API usage counters — the number of requests made per chain per calendar month, keyed to your API key, plus a 90-day pseudonymous daily activity marker distinguishing dashboard tests from external HTTP RPC calls. We do not log request bodies, response bodies, wallet addresses, transaction hashes, or any blockchain data you query.
  • Optional account analytics — retained for up to 90 days. Account identifiers are pseudonymous; no RPC payloads or API keys are collected. Declining stops new optional measurements and removes local attribution data.
  • Technical logs — IP address, user-agent string, and request timestamp, retained for 7 days exclusively for security and abuse prevention purposes.
  • Communication data — emails you send to our support or legal addresses, retained for as long as necessary to resolve the matter.
  • Cookie data — a session cookie set by Clerk for authentication, and a local-storage analytics preference. See Section 08 for details.
  • Analytics data — with optional consent, Vercel measures website visits and performance; NodeFlare records a bounded set of product steps and acquisition categories using a pseudonymous account identifier. RPC payloads, keys, queried addresses and arbitrary URL parameters are excluded. No Google Analytics tag is loaded. See Sections 07 and 08.

We do not collect or process special-category personal data (e.g., health data, biometric data, political opinions).

03

How We Use Your Data

  • To provision, operate, and deliver the NodeFlare API service.
  • To authenticate you and maintain your session.
  • To process subscription payments and issue invoices.
  • To enforce per-plan rate limits and monthly usage quotas.
  • To send transactional emails: account creation confirmation, invoice receipts, plan change confirmations, and service status alerts.
  • To detect, investigate, and prevent abuse, fraud, or violations of our Terms of Service.
  • To respond to your support or legal enquiries.
  • With your optional analytics consent, to measure website visits and product steps and associate a limited acquisition source with a pseudonymous account identifier. This helps us understand which pages lead to useful integrations and purchases.

We do not use your data for advertising, profiling, or any purpose not listed above. We do not sell or rent your personal data to any third party.

05

Data Retention

  • Account data — retained for the lifetime of your account. Deleted within 30 days of account closure, except where a longer retention period is legally required.
  • Usage counters — current-month counts are reset at the start of each billing cycle. Aggregated monthly totals are retained for 12 months to support billing queries.
  • Optional account analytics — retained for up to 90 days. Account identifiers are pseudonymous; no RPC payloads or API keys are collected. Declining stops new optional measurements and removes local attribution data.
  • Technical logs — deleted automatically after 7 days.
  • Billing records — retained for 7 years as required by Dutch tax and accounting legislation.
  • Support correspondence — retained for up to 2 years or until the matter is resolved, whichever is later.
06

Data Sharing

We share your personal data only with the sub-processors listed in Section 07 and only to the extent necessary to operate the Service. We do not sell, rent, or broker your data to any other party.

We may disclose personal data if required to do so by law, a binding court order, or a legitimate request from a competent regulatory authority. Where legally permissible, we will notify you before complying.

07

Third-Party Processors

We use the following sub-processors to deliver the Service. Each operates under a data processing agreement and appropriate safeguards for international transfers (Standard Contractual Clauses where applicable):

  • Clerk (US) — authentication, user management, and session handling. Privacy policy →
  • Stripe (US) — payment processing, billing, and invoicing. Privacy policy →
  • Cloudflare (US) — infrastructure, DDoS protection, CDN, and KV storage. Privacy policy →
  • Vercel (US) — web application hosting and edge delivery; optional Web Analytics and Speed Insights after consent. Privacy policy →
08

Cookies

We use a minimal set of cookies. Functional and security cookies are always active; analytics cookies load only after you accept them via the banner:

  • __session — set by Clerk. Required for authentication. Session-scoped; deleted when you sign out or your session expires. This cookie cannot be disabled without breaking login functionality.
  • __client_uat — set by Clerk. Stores an unsigned timestamp used to detect active sessions without sending the full session token. Session-scoped.
  • nf_analytics_consent_v2 — local storage for your optional analytics preference. Kept until you change it or clear browser storage. Use Analytics preferences in the footer to change your choice.
  • nf_attribution_v2 — optional local storage containing a limited source category, campaign category and public landing path; expires after 30 days. Queries, wallet addresses and API keys are excluded.

You can remove or block cookies at any time via your browser settings. Blocking the Clerk session cookies will prevent you from logging in to the dashboard.

09

Your Rights

Under the GDPR, you have the following rights regarding your personal data. To exercise any of them, email [email protected]. We will respond within 30 calendar days.

  • Right of access (Art. 15) — request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17) — request deletion of your account and associated personal data, subject to legal retention obligations.
  • Right to restriction (Art. 18) — ask us to pause processing of your data in certain circumstances.
  • Right to portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Right to object (Art. 21) — object to processing based on our legitimate interests.
  • Right to lodge a complaint — file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
10

Security

We implement appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure:

  • All data in transit is encrypted using TLS 1.2 or higher.
  • API keys are stored in access-controlled service storage so authenticated users can retrieve and rotate them. They are excluded from optional analytics.
  • Access to production systems is restricted to authorised personnel and protected by multi-factor authentication.
  • We conduct periodic security reviews of our infrastructure and third-party dependencies.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by the GDPR.

11

Changes to This Policy

We may update this Privacy Policy from time to time. For material changes we will provide at least 14 days’ advance notice by email before the revised policy takes effect.

The “Last updated” date at the top of this page always reflects the most recent revision. We encourage you to review this policy periodically.

Questions about this document?

Reach out and we'll get back to you within two business days.