This Privacy Policy describes how Haven Group Tech Ltd ("we," "us," or "our") collects, uses, and discloses information — including personal data — when you access or use the HgBest API ("API Services"). We are committed to protecting your privacy and handling your data with full transparency. By using the API Services, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
- Account Information: When you register, you provide your name, email address, and password.
- Billing Information: Subscription payments are processed securely by Stripe. We do not store raw card details.
- API Call Metadata: We collect metadata about API calls — including the API Key used, endpoint accessed, timestamp, response status, and general request parameters — to provide the service, enforce usage limits, and improve the platform.
- Usage Metrics: Volume and frequency of API calls to monitor plan limits.
- Error Logs: Details of failed requests for debugging and improvement.
- AML/KYC Image Data: Identity document images and selfies submitted to the
/aml-kyc/verify endpoint are processed entirely in memory. They are never written to disk, never stored in any database, and are permanently destroyed once the verification analysis is complete. Only the verification outcome (approved/rejected/reason codes) is retained.
2. How We Use Your Information
- To provide, operate, and maintain the API Services
- To process payments and manage subscriptions
- To monitor and enforce usage plan limits
- To improve API performance, reliability, and functionality
- To send service notifications, security alerts, and support responses
- To prevent fraud and unauthorised access
- To comply with applicable legal and regulatory obligations
3. How We Share Your Information
- Service Providers: We share necessary data with trusted providers — including Stripe (payments), Firebase (authentication), Render (hosting), and EmailJS (email delivery) — who are contractually bound to protect your data.
- Legal Requirements: We may disclose your information when required by law, court order, or to protect the rights and safety of Haven Group Tech Ltd and its users.
- Business Transfers: In a merger or acquisition, your data may transfer to the acquiring entity under the same privacy protections.
- With Your Consent: We may share your information for any other purpose with your explicit consent.
We never sell your personal data. We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes in this policy, unless a longer period is required by law. Account and billing data are retained while your account is active and for a reasonable period thereafter for legal and accounting compliance.
AML/KYC image data is never retained — it is processed in memory and destroyed immediately after verification. Only outcome metadata is stored.
5. Data Security
We implement technical and organisational measures to protect your personal data — including HMAC-SHA256 request signing, encrypted API secret storage, and access controls. However, no method of internet transmission is 100% secure, and we cannot guarantee absolute security.
6. Your Data Rights
Depending on your jurisdiction, you may have the right to:
- Access — Request copies of your personal data
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion of your personal data
- Restriction — Request we limit processing of your data
- Portability — Request transfer of your data to another provider
- Objection — Object to our processing of your data
To exercise any of these rights, contact us at info@hgbest.online.
7. International Data Transfers
Your data may be processed on servers located outside your country. Haven Group Tech Ltd is registered in England and Wales and operates in compliance with UK GDPR and applicable data protection law. By using the API Services, you consent to such transfers.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last Updated" date. Continued use of the API Services after changes constitutes acceptance.
9. Contact Us
For questions, concerns, or data rights requests regarding this Privacy Policy:
Haven Group Tech Ltd · Office 9700, 321-323 High Road, Chadwell Heath, Essex RM6 6AX, UK · Company No. 17179874