API Pull
HomeAPI HubPricingAbout UsIssuesForum
  • 简体中文
  • Español (MX)
Contact Us
HomeAPI HubPricingAbout UsIssuesForumContact Us
  • 简体中文
  • Español (MX)

Privacy Policy

This policy describes what API Pull collects when you browse www.apipull.com, when you hold an account, and when you call an endpoint through our gateway. It is written from the actual database schema and client code rather than from a template, so where a practice is imperfect it is described as it is rather than as it should be.

Last updated: Pending confirmation

This document is not final yet

Sections marked “Pending confirmation” depend on corporate registration details that have not been published. Until those are filled in, this page is deliberately excluded from search indexing and should not be relied on as a complete legal instrument. Everything not marked as pending is already accurate and describes how the platform behaves today.

Still missing: Legal entity · Registered address · Governing law · Dispute venue · Data controller · Privacy contact · Effective date · Confirmed by

On this page

  1. 1. Scope
  2. 2. Who is responsible
  3. 3. Account data
  4. 4. Cookies and browser storage
  5. 5. Website analytics
  6. 6. API calls
  7. 7. People you look up
  8. 8. Why we process it
  9. 9. Who else sees it
  10. 10. How long we keep it
  11. 11. Security
  12. 12. Your choices
  13. 13. If a record about you was returned by our API
  14. 14. Cross-border transfers
  15. 15. Changes to this policy

1. Scope

This policy covers the public website (www.apipull.com, including its Spanish and Chinese versions), the developer console, and the API gateway at gateway.apipull.com. It does not cover the systems of the institutions our endpoints query, nor the systems of customers who call our API — those are governed by their own policies.

2. Who is responsible Pending confirmation

The registered entity behind API Pull and its formal role as data controller are listed below. Where a row reads “Pending confirmation”, that fact has not been published and we will not substitute a plausible-looking placeholder for it.

3. Account data

Registration asks for four fields: a username, a display name, an email address, and a password. Passwords are stored hashed, never in a readable form. Email verification and an image CAPTCHA are required to complete signup. After registration the account record also accumulates the IP address and timestamp of your most recent sign-in, your prepaid balance, an API token used to authenticate gateway calls, and an invite code. We do not ask for a government identifier, a date of birth, or a payment card in order to create an account.

4. Cookies and browser storage

The site sets a small, fixed set of identifiers. There is no consent banner today, which means analytics identifiers are set on first visit; if that matters to you, block them in your browser before browsing or clear them afterwards.

  • cd_tracker_device_id — a random UUID used to group page views from the same browser. Stored both as a first-party cookie (12 months, SameSite=Lax) and in localStorage.
  • portal_token — your session token, held in localStorage. It is a JWT and contains your numeric user id.
  • cd_tracker_marketing_name and cd_tracker_marketing_email — populated in localStorage only if you arrive on a link carrying a _source parameter that embeds a name and email, which is how our outbound campaign links attribute a visit. If you arrive by any other route, these stay empty.
  • Google Analytics cookies — set by Google, not by us, under property G-9T785MWVN0.

5. Website analytics

Page views, clicks on links and buttons, and page-exit events are sent to our own endpoint and stored on our own servers. Each record can contain: event name, your user id if signed in, the device identifier above, the page URL and title, the referring URL, user agent, derived device type, browser, operating system, screen resolution, browser language, and IP address. Click events additionally record the clicked element's tag, its visible text truncated to 100 characters, its id, its CSS classes truncated to 200 characters, and the destination URL for links. Google Analytics 4 runs in parallel on every page; that data sits with Google under their terms, not ours.

6. API calls

Two separate records are written when you call an endpoint. The first is billing and operations metadata: your user id, the product and endpoint, a trace id, HTTP method and route, the calling IP address, the user agent, the amount charged, the HTTP status, the response time, and any error message. The second record — written for troubleshooting and billing disputes — additionally stores the request parameters you sent and the response body the upstream source returned.

Be aware of what this means in practice: because our endpoints are queried by identifier, the request parameters we retain include the identifiers you submit — CURP, NSS, RFC, telephone numbers, Colombian document numbers — and the stored response bodies include the personal records returned for them. These are currently held in readable form, and the codebase contains no scheduled job that deletes them; the oldest such record dates from 2026-05-13. We are stating this plainly rather than describing an erasure schedule that does not exist. If this is incompatible with your own obligations, contact us before sending production traffic.

7. People you look up

Most personal data flowing through the platform is not about our customers — it is about the individuals whose records a customer queries. For that data we act on the customer's instruction: the customer decides who to look up and why, and the customer is responsible for having a lawful basis to do so. We do not compile our own marketing database from query results, and we do not resell query results to other customers.

8. Why we process it

  • Operating your account, authenticating you, and authenticating gateway calls.
  • Metering calls and charging your prepaid balance.
  • Diagnosing failures and disputes — the reason request and response bodies are retained.
  • Understanding which pages and endpoints get used, so documentation effort goes where it is needed.
  • Detecting abuse, credential sharing, and automated scraping of the site.

9. Who else sees it

  • Upstream data sources — the institutions and providers listed on our Data Usage page receive the identifier you query, because that is the query.
  • Google — analytics event data via Google Analytics 4.
  • Our hosting and database infrastructure providers, in their capacity as infrastructure.
  • Authorities, where we are legally compelled to disclose.

We do not sell personal data, and we do not share it with advertising networks.

10. How long we keep it

Account records persist for as long as the account exists. Analytics records, API call metadata, and the stored request and response bodies described in section 6 currently have no automated deletion schedule in place. We are not going to state a retention period we do not enforce. A defined retention and purge policy is outstanding work; until it ships, assume records persist. You can ask us to delete your account and its associated records using the contact channels below.

11. Security

The site and gateway are served over HTTPS. Account passwords are hashed. Gateway access requires a per-account API token, and console access requires a session token that expires. What we will not claim is a certification, an audit, or an encryption-at-rest guarantee that we cannot point to. Treat the request and response retention described in section 6 as the honest upper bound on our current data-minimisation posture.

12. Your choices

  • Block or clear cookies and localStorage in your browser to stop device-level analytics grouping.
  • Use Google's opt-out browser add-on, or a tracker blocker, to stop Google Analytics collection.
  • Email us to access, correct, or delete your account data.
  • Strip the _source parameter from a campaign link before opening it if you do not want the embedded name and email stored locally.

13. If a record about you was returned by our API

If you are not our customer but believe your personal data was returned through one of our endpoints, write to us with enough detail to locate the query and we will tell you what was retained and remove it from our own stores. We cannot correct the underlying record: it belongs to the issuing institution, and a correction has to be made there to take effect. The Data Usage page lists each institution and its official channel for exactly this purpose.

14. Cross-border transfers Pending confirmation

Queries about Mexican, Chilean, and Colombian data subjects are served from infrastructure that may sit outside those countries, and Google Analytics data leaves for Google's infrastructure. The formal transfer basis depends on the registered entity and its jurisdiction, which is still pending confirmation.

15. Changes to this policy

Material changes will be reflected in the “Last updated” date at the top of this page. Because this document is generated from the platform's actual configuration, a change in what we collect shows up here rather than being quietly absorbed.

Registered entity Pending confirmation

The registration details for the entity operating API Pull have not been published yet. Rather than print a placeholder here, we are leaving the table empty and keeping this page out of search indexing until the details are confirmed. Until then, the contact channels below are the authoritative way to reach a responsible party.

How to reach us

Questions about this document, requests about your own data, and requests about a record returned by one of our endpoints all go to the same two channels. Written requests by email are preferred because they leave a record on both sides.

Email
partner@apipull.com
Telegram
https://t.me/Api_pull

Related documents

  • Terms of Service
  • Data Usage & Sources
API Pull

Connecting the world through data. Your one-stop API marketplace and integration platform.

Resources

  • Pricing
  • API Hub

Company

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service
  • Data Usage & Sources

Communication

  • curp fintech api
  • curp validator
  • curp citizen data
  • academic records api
  • academic verification api
  • aml api mexico
  • banxico api
  • census api mexico
  • certificate validation api
  • colombia fintech api
  • consultar nss api
  • curp anti fraud api
  • curp api
  • curp birth data api
  • curp compliance api
  • curp customer verification
  • curp database api
  • curp demographic api
  • curp employment verification
  • curp hr api
  • curp identity verification
  • curp integration api
  • curp kyc api
  • curp onboarding api
  • curp online verification
  • curp person lookup
  • curp registration validation
  • curp to nss api
  • curp verification mexico
  • curp verification service
  • customer due diligence api
  • customer verification api mexico
  • degree verification api
  • economic indicators api mexico
  • education certificate api
  • education compliance api
  • education records api
  • education records api mexico
  • financial data api mexico
  • financial indicators api mexico
  • find nss by curp
  • fraud prevention api mexico
  • geographic api mexico
  • get rfc from curp
  • graduate verification api
  • identity verification api mexico
  • imss api
  • imss benefits api
  • imss eligibility api
  • imss employee verification
  • imss enrollment api
  • imss healthcare api
  • imss hr api
  • imss labor history api
  • imss onboarding api
  • imss rights api
  • imss status api
  • imss verification api
  • inegi api
  • mexico aml api
  • mexico api
  • mexico apimarket
  • mexico background check api
  • mexico banking api
  • mexico citizen api
  • mexico citizen data api
  • mexico compliance api
  • mexico currency api
  • mexico customer verification api
  • mexico data api
  • mexico employee verification api
  • mexico exchange rate api
  • mexico fintech api
  • mexico government api
  • mexico government database api
  • mexico hr api
  • mexico identity api
  • mexico identity verification api
  • mexico kyc api
  • mexico kyc solution
  • mexico loan api
  • mexico official records api
  • mexico onboarding api
  • mexico open data api
  • mexico payment api
  • mexico public records api
  • mexico registry api
  • mexico rfc api
  • mexico tax api
  • mexico taxpayer verification api
  • mexico validation api
  • mexico verification api
  • nss api
  • nss checker api
  • nss employee data
  • nss lookup api
  • nss validation api
  • nss validation mexico
  • nss verification service
  • onboarding api mexico
  • population data api mexico
  • professional credential api
  • professional license api
  • professional registry api
  • rfc api
  • rfc business lookup mexico
  • rfc business verification
  • rfc by curp api
  • rfc checker api
  • rfc company verification
  • rfc compliance api
  • rfc corporate api
  • rfc customer verification
  • rfc fintech api
  • rfc fiscal api
  • rfc fraud prevention
  • rfc kyc api
  • rfc legal entity api
  • rfc lookup api
  • rfc onboarding api
  • rfc registration api
  • rfc search api
  • rfc supplier validation
  • rfc tax identification api
  • rfc taxpayer api
  • rfc taxpayer lookup
  • rfc taxpayer validation
  • rfc validation mexico
  • rfc vendor verification
  • rfc verification api
  • sat api mexico
  • sat company api
  • sat compliance api
  • sat rfc api
  • sat taxpayer api
  • sat validation api
  • sep api
  • social security number mexico api
  • social security verification mexico
  • student verification api
  • teacher license api
  • tiie api
  • udi api
  • university verification api
  • validate mexican rfc
  • validate rfc api
  • verify taxpayer mexico
  • vigencia imss api
  • weeks contribution api
Available languages:English·简体中文·Español (MX)

© 2026 API Pull. All rights reserved.