Privacy Policy

Last Updated: July 3, 2026

This Privacy Policy explains how NEOVATE TECHNOLOGIES PTE. LTD. (“ApiSmart,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal data when you access or use ApiSmart, including our website, dashboard, APIs, documentation, technical support, billing system, and related services.

Company information:

NEOVATE TECHNOLOGIES PTE. LTD.
UEN: 202552252E
Address: 112 Robinson Road, #03-01, Robinson 112, Singapore 068902

By using our services, you acknowledge that we may process personal data in accordance with this Privacy Policy.

1. Scope of This Privacy Policy

This Privacy Policy applies to personal data that we collect through:

  • our website;
  • account registration and login;
  • dashboard and API key management;
  • API usage and billing;
  • support communications;
  • payment and transaction processes;
  • business communications;
  • security, fraud prevention, and compliance activities.

This Privacy Policy does not apply to third-party websites, services, models, platforms, or payment processors that we do not control. Their own privacy policies may apply.

2. Personal Data We Collect

Depending on how you use ApiSmart, we may collect the following types of information.

2.1 Account Information

We may collect information such as:

  • name;
  • email address;
  • username;
  • company name;
  • country or region;
  • password or authentication credentials;
  • account settings;
  • communication preferences.

2.2 Billing and Transaction Information

We may collect or receive information related to payments, invoices, top-ups, subscriptions, refunds, and billing, such as:

  • billing name;
  • billing email;
  • billing address;
  • company information;
  • tax information;
  • payment method type;
  • transaction amount;
  • currency;
  • payment status;
  • invoice records;
  • refund records.

We do not normally store full payment card numbers. Payment information may be processed by third-party payment processors.

2.3 API Usage Information

When you use our APIs, we may collect technical and usage information such as:

  • API key identifier;
  • request timestamp;
  • selected model;
  • endpoint used;
  • token usage;
  • request status;
  • error codes;
  • latency;
  • route or provider used;
  • account balance and billing records;
  • IP address;
  • user agent;
  • device and browser information;
  • logs required for security, billing, debugging, and abuse prevention.

2.4 Customer Content Processed Through APIs

Customer Content may include prompts, inputs, files, instructions, API requests, or other data submitted through the Services.

ApiSmart is designed to process Customer Content for the purpose of providing API services, routing requests, generating responses, troubleshooting, preventing abuse, and maintaining system reliability.

Unless otherwise stated in a separate written agreement, we do not use Customer Content submitted through the API to train our own foundation models. Where temporary processing or logging is necessary for routing, security, debugging, billing, abuse prevention, legal compliance, or service improvement, we retain such information only for as long as reasonably necessary for those purposes.

You should not submit sensitive personal data, confidential information, regulated data, or data you are not authorized to process unless you have confirmed that your intended use complies with applicable laws and your own internal policies.

2.5 Support and Communications

If you contact us, we may collect:

  • your name and contact details;
  • support ticket content;
  • screenshots or diagnostic files you provide;
  • correspondence history;
  • feedback, complaints, or survey responses.

2.6 Website and Cookie Data

When you visit our website, we may collect information through cookies, pixels, logs, and similar technologies, including:

  • IP address;
  • browser type;
  • device type;
  • pages viewed;
  • referring pages;
  • session duration;
  • language preference;
  • approximate location;
  • analytics events.

You may control cookies through your browser settings. Some features may not work properly if cookies are disabled.

3. How We Use Personal Data

We may use personal data for the following purposes:

  • to create and manage your account;
  • to provide, operate, maintain, and improve the Services;
  • to generate, secure, and manage API keys;
  • to route API requests and return responses;
  • to calculate usage and process billing;
  • to process payments, invoices, top-ups, refunds, and account balances;
  • to provide technical support;
  • to detect, prevent, and investigate fraud, abuse, security incidents, unauthorized access, and policy violations;
  • to monitor service performance, uptime, latency, errors, and system reliability;
  • to communicate service updates, maintenance notices, security alerts, and administrative messages;
  • to improve documentation, user experience, and product performance;
  • to comply with legal, regulatory, tax, accounting, sanctions, and compliance obligations;
  • to enforce our Terms of Service and other policies;
  • to protect the rights, safety, and property of ApiSmart, users, providers, and the public.

4. Legal Bases and Consent

Where required by applicable law, we rely on one or more legal bases to process personal data, including:

  • your consent;
  • performance of a contract with you;
  • compliance with legal obligations;
  • our legitimate business interests;
  • protection of our legal rights;
  • prevention of fraud, abuse, and security threats;
  • other bases permitted by applicable law.

Where we rely on consent, you may withdraw consent where permitted by law. However, withdrawing consent may affect our ability to provide the Services.

5. How We Share Personal Data

We may share personal data with the following categories of recipients.

5.1 Service Providers

We may share information with vendors that help us operate the Services, including:

  • cloud infrastructure providers;
  • AI model providers;
  • payment processors;
  • analytics providers;
  • customer support tools;
  • email delivery providers;
  • security and fraud prevention providers;
  • accounting, legal, and compliance providers.

These providers are authorized to process personal data only as necessary to provide services to us or as otherwise permitted by law.

5.2 AI Model and Infrastructure Providers

To provide AI API services, we may route API requests, Customer Content, metadata, or technical information to third-party AI model providers or infrastructure providers.

The specific provider used may vary depending on selected model, availability, routing logic, latency, failover needs, pricing, or technical requirements.

5.3 Legal and Compliance Disclosures

We may disclose personal data if we believe it is necessary to:

  • comply with applicable law, regulation, legal process, or government request;
  • respond to lawful requests by public authorities;
  • enforce our Terms of Service;
  • investigate security incidents, fraud, abuse, or illegal activity;
  • protect the rights, property, or safety of ApiSmart, users, providers, or others.

5.4 Business Transfers

If we are involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, personal data may be transferred as part of that transaction, subject to appropriate confidentiality and legal safeguards.

6. International Transfers

ApiSmart is based in Singapore. Your personal data may be processed in Singapore and other countries where our service providers, infrastructure providers, payment processors, AI model providers, or business partners operate.

Where required by applicable law, we take reasonable steps to ensure that personal data transferred internationally receives a comparable level of protection, including through contractual safeguards, technical measures, or other lawful transfer mechanisms.

7. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Retention periods may vary depending on the type of data and purpose, including:

  • account data retained while your account is active;
  • billing and transaction records retained as required for tax, accounting, audit, and legal purposes;
  • security logs retained for fraud prevention, abuse detection, and system protection;
  • support records retained for customer service, dispute resolution, and quality assurance;
  • API logs retained for billing, troubleshooting, security, compliance, and service reliability.

When personal data is no longer required, we will delete, anonymize, or otherwise handle it in accordance with applicable law and our internal procedures.

8. Security

We use reasonable administrative, technical, and organizational measures to protect personal data against unauthorized access, loss, misuse, disclosure, alteration, or destruction.

These measures may include access controls, encryption, monitoring, logging, network security, authentication controls, and internal policies.

However, no method of transmission or storage is completely secure. You are responsible for securing your own account credentials, API keys, systems, devices, and integrations.

9. Your Responsibilities

You are responsible for ensuring that your use of ApiSmart complies with applicable privacy, data protection, and confidentiality obligations.

You must not submit personal data to the Services unless you have the necessary rights, permissions, notices, consents, or other legal bases to do so.

If you use ApiSmart on behalf of your own users, customers, employees, or end users, you are responsible for providing any required privacy notices and obtaining any required consents from them.

10. Your Rights

Depending on applicable law, you may have rights regarding your personal data, including the right to:

  • request access to personal data we hold about you;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent;
  • request information about how we use and disclose your personal data;
  • lodge a complaint with a data protection authority.

To exercise your rights, contact us through the support channel listed on our website or dashboard. We may need to verify your identity before processing your request.

Some requests may be limited by legal, security, billing, fraud prevention, technical, or contractual requirements.

11. Marketing Communications

We may send you service-related emails, product updates, security notices, billing notices, and administrative messages.

Where permitted by law, we may also send marketing communications. You may opt out of marketing emails by using the unsubscribe link or contacting us. Even if you opt out of marketing messages, we may still send non-marketing communications related to your account or use of the Services.

12. Cookies and Similar Technologies

We may use cookies and similar technologies to:

  • keep you signed in;
  • remember preferences;
  • improve website functionality;
  • analyze traffic and usage;
  • prevent fraud and abuse;
  • improve security;
  • measure performance.

You may manage cookies through your browser settings. Disabling cookies may affect website or dashboard functionality.

13. Children’s Privacy

The Services are not intended for children under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us and we will take appropriate steps to delete it.

14. Third-Party Links and Services

Our website, dashboard, documentation, or support channels may contain links to third-party websites or services. We are not responsible for the privacy practices, content, or security of third-party services.

You should review the privacy policies of any third-party services you use.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be posted on our website or dashboard with a revised “Last Updated” date.

Your continued use of the Services after the updated Privacy Policy becomes effective means you acknowledge the updated policy.

16. Contact

For questions about this Privacy Policy or our handling of personal data, please contact us through the support channel listed on our website or dashboard.

NEOVATE TECHNOLOGIES PTE. LTD.
UEN: 202552252E
Address: 112 Robinson Road, #03-01, Robinson 112, Singapore 068902

© 2026 ApiSmart. Operated by NEOVATE TECHNOLOGIES PTE. LTD.