WolfMarket — Privacy Policy

Last updated: 5 September 2026

Draft pending legal review. This policy describes what the service actually stores and for how long, based on its implementation. It has not been reviewed by a lawyer and should be before the service takes payment.

What we collect

WolfMarket is a data service, not a consumer product. We collect the minimum needed to run accounts, bill correctly, and keep the service healthy.

DataWhyRetention
Email address, and company name if you provide oneTo identify your account and contact you about the serviceWhile your account exists
Password, stored only as a salted PBKDF2 hashAuthentication. We never store your password itself and cannot recover itWhile your account exists
API keys, stored only as a SHA-256 hash plus a short non-secret prefixTo authenticate API requests and show you which key is whichUntil revoked; revoked keys are retained as a record
Request logs: timestamp, API key id, HTTP method, path, status code, response timeUsage metering for billing, rate limiting, and diagnosing faults90 days, then automatically purged
Your tracked entities and subscriptionsTo deliver the data you asked for and enforce plan limitsWhile your account exists
Email alert preferences and a record of alerts already sentTo send the alerts you opted into, and to avoid sending duplicatesWhile your account exists
Stripe customer and subscription identifiersTo match your account to your billing recordWhile your account exists

Request logs record which endpoint was called, not the contents of any response.

What we do not collect

Cookies

We use a single cookie, wolfmarket_portal, which holds your signed-in session for the customer portal. It is HttpOnly, restricted with SameSite=Strict, and expires after 14 days of inactivity. It exists solely to keep you signed in — there are no advertising or tracking cookies, so there is nothing to opt into.

Email

We email you for account and billing matters. Filing alerts and the weekly digest are opt-in only and off by default; you can turn them off at any time in the portal's Account view.

Who we share with

We do not sell personal data. We share it only with the processors needed to run the service:

We may disclose data if required by law.

Where data is held

Account data and request logs are stored on infrastructure operated by Freebranch LLC in the United States.

Your choices

If you are in a jurisdiction with statutory data rights (for example the UK/EU GDPR or the CCPA), those rights apply and this section is how to exercise them.

Security

Traffic is served over HTTPS. Passwords are hashed with PBKDF2; API keys are stored only as hashes. The API operates against the database under a read-only account with write permissions explicitly denied, apart from the narrow paths needed to record your own subscriptions and usage.

Changes and contact

We will note the date at the top of this page when it changes, and email you about material changes.

Questions or requests: [email protected]. See also our Terms of Service.