Privacy Policy
Effective June 30, 2026
This Privacy Policy explains how Checkfmt(“we”, “us”) handles information in connection with the Checkfmtwebsite, API, and MCP server (together, the “Service”).Checkfmtis a developer API that validates the format and checksums of IBAN and BIC/SWIFT codes, relays EU VAT lookups to the European Commission’s official VIES service, and decodes VIN values via the US NHTSA vPIC database. By using the Service, you agree to this Policy.
1. Scope
This Policy applies to data we process when you generate or use an API key, make API requests, browse the site, or pay for a plan. It does not cover the practices of the third-party services described below, which operate under their own policies.
2. Information we collect
We keep what we need to authenticate requests, enforce quotas, and bill paid plans:
- Account email: you provide an email address to generate an API key. It is the only contact identifier we store, and it links your key to your plan and usage.
- API key & usage metadata: your issued key, current plan, monthly request limit, request count for the current period, and a lightweight per-call record (the validator used and a timestamp) used to enforce quotas and understand load.
- Billing data: if you upgrade, we store a Stripe customer identifier so we can match a subscription to your key. Payment is handled by Stripe; we never receive or store your full card number or other payment-card details.
Identifiers you submit for validation (IBAN, BIC, VAT, or VIN) are validated in memory or, for VAT and VIN, relayed to the relevant government service to return your result. We do not store the identifiers you submit after producing a response.
3. How we use information
We use the information above to:
- issue and authenticate API keys and operate the Service;
- enforce plan quotas and rate limits and protect against abuse;
- process payments and manage paid subscriptions through Stripe;
- respond to support requests and send service-related messages where needed;
- maintain, debug, and improve the reliability of the Service.
4. Cookies & tracking
We use only essential cookies and similar storage required for the site and API to function. We do not use advertising cookies, third-party ad networks, or cross-site tracking, and we do not sell or share information for behavioral advertising.
5. Third-party services & sub-processors
We rely on a small set of third parties to run the Service. Each processes only what is needed for its function and under its own terms:
- Convex: database and backend that stores account emails, API keys, and usage metadata.
- Vercel: hosting and serving of the website and API.
- Stripe: payment processing and subscription management for paid plans.
- European Commission VIES: receives the VAT identifier you submit to return an EU VAT validation result.
- US NHTSA vPIC: receives the VIN you submit to return vehicle decoding data.
The VAT and VIN lookups send the identifier you provide to these government services to produce your result; we do not retain those identifiers afterward.
6. How we share information
We do not sell your personal data. We share information only with the sub-processors listed above to operate the Service, when required by law or valid legal process, or to protect the rights, safety, and security of the Service and its users. If the Service is ever involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this Policy.
7. Data retention
We keep your account email, API key, and usage metadata for as long as your key is active and as needed to operate the Service, comply with legal obligations, and resolve disputes. Per-call usage records are retained only as needed for quota enforcement and operations, and may be pruned over time. Identifiers submitted for validation are not retained after a response is returned.
8. Your rights
Depending on where you live, you may have rights under laws such as the EU/UK GDPR and the California Consumer Privacy Act (CCPA), including the right to access, correct, or delete your information and to opt out of any sale or sharing of personal data (we do not sell or share personal data). You may exercise these rights, including requesting deletion of your account email and associated key, by emailing us at support@checkfmt.com. We will respond within the timeframe required by applicable law, and we will not discriminate against you for exercising your rights.
9. Security
We use reasonable administrative and technical measures to protect information, including transport encryption (HTTPS) and access controls. API keys are secret credentials, so keep yours confidential. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Children’s privacy
The Service is a developer tool intended for businesses and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
11. International users
We operate the Service on US-based infrastructure, and information is processed and stored in the United States. EU VAT lookups are relayed to the European Commission’s VIES service in the EU. If you access the Service from outside the United States, you understand your information is processed in the United States, which may have different data-protection rules than your country.
12. Changes
We may update this Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, provide notice. Your continued use of the Service after changes take effect constitutes acceptance.
13. Contact
Questions about this Policy or your data? support@checkfmt.com.