PLUG.
Privacy Policy · Last updated 15 August 2026

Privacy Policy

← Back to the sandbox

This Privacy Policy explains what personal data PLUG collects when you use our developer sandbox, why we collect it, how we handle it, and the rights you have. It applies to the account and usage data we process about you as a registered developer. It does not describe any real end-customer banking service, because the sandbox does not provide one.

1Who we are

The data controller for the personal data described here is PLUGN LTD, with its registered office at Rəşid Behbudov 55, Baku, Republic of Azerbaijan (referred to here as "PLUG", "we", "us"). For any privacy question or request, contact us at plug@plugn.us.

2The data we collect

CategoryExamplesSource
Account dataYour name, corporate email, phone number, company nameYou, at registration
AuthenticationPassword (stored only as a salted hash), one-time verification codes, session tokenCreated during sign-up & login
API credentialsYour Client ID and API Key (the API Key is stored encrypted)Issued by us
Usage & logsThe API endpoints you call, timestamps, response status, and technical logs (including IP address) needed for security and rate limitingGenerated as you use the Service
Sandbox contentThe test requests and configuration you submit (which should contain only fictitious test data)You

We do not intentionally collect special categories of personal data, and you should not submit any through the sandbox.

3Why we use it, and our legal basis

  • To provide the Service — create and authenticate your account, issue and manage your API credentials, and process your API requests. Basis: performance of a contract with you.
  • To secure the Service — detect and prevent abuse, fraud, and unauthorised access; enforce rate limits; keep audit logs. Basis: our legitimate interests in operating a safe service.
  • To communicate with you — send verification and password-reset codes, and important service notices. Basis: performance of a contract and legitimate interests.
  • To improve the Service — understand which features are used and diagnose problems, in aggregate. Basis: legitimate interests.
  • To comply with law — where we are legally required to retain or disclose information. Basis: legal obligation.

4Cookies

We use a single essential, httpOnly session cookie to keep you signed in after you log in. It is strictly necessary for the Service to function and is not used for advertising or cross-site tracking. We do not use third-party analytics or marketing cookies in the sandbox.

5Who we share it with

We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract, to run the Service:

ProviderPurpose
Hosting & deliveryRunning the application and serving the website (cloud hosting provider)
Managed databaseStoring account and sandbox data (managed Postgres provider)
Email deliverySending verification, reset, and notification emails (email/SMTP provider)

We may also disclose personal data where required by law, to protect our rights, or in connection with a corporate transaction, in each case subject to appropriate safeguards.

6International transfers

Our providers may process data on servers located outside the Republic of Azerbaijan (for example, in the European Union). Where personal data is transferred internationally, we take steps to ensure it remains protected by appropriate legal safeguards.

7How long we keep it

We keep your account data for as long as your account is active. We retain security and audit logs for a limited period as needed to keep the Service safe and to meet legal obligations. When you delete your account or we terminate it, we delete or anonymise your personal data within a reasonable period, except where we must retain it by law. You can also clear your sandbox test data at any time from the console.

8How we protect it

  • passwords are stored only as salted scrypt hashes — never in plain text;
  • API keys and sensitive fields are encrypted at rest (AES-256-GCM);
  • connections are served over HTTPS, and sessions use httpOnly cookies;
  • access to the systems that hold personal data is restricted, and administrative tooling is isolated.

No system is perfectly secure, but we work to protect your data using measures appropriate to a sandbox that should not contain real personal or financial information.

9Your rights

Subject to applicable law, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to object to or restrict certain processing, and to receive a copy in a portable format. To exercise any of these rights, contact plug@plugn.us. You also have the right to lodge a complaint with the competent data-protection authority in the Republic of Azerbaijan.

10Not for consumers or children

The Service is intended for businesses and professional developers. It is not directed to consumers or to children under 18, and we do not knowingly collect personal data from children.

11Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date above and, where appropriate, notify you.

12Contact

For any question about this policy or about how we handle your personal data, email plug@plugn.us.