Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how LayerCall ("LayerCall," "we," "us") collects, uses, and protects information when you use our website and fraud & trust-signals API (the "Service"). We built LayerCall to reduce fraud, and we take a data-minimizing approach: we collect only what we need to run the Service.
Information we collect
- Account information. When you sign up, we store your email address and, if you use Google sign-in, the basic profile information Google provides (name, email). We do not store passwords — authentication is handled by Google or a one-time email link.
- API usage. For each API request we record metadata such as the endpoint called, timestamp, whether the result was cached, and which API key was used, to meter usage and bill accurately.
- Data you send to the API. To score a lookup, you send us values such as an IP address, email, phone number, or domain. We process these to return a risk score. We do not use the raw values you submit to build advertising profiles or sell them.
- Cookies. We use a single essential cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
How we use information
- To provide, secure, and improve the Service.
- To authenticate you and protect your account.
- To meter usage, enforce plan limits, and process billing.
- To detect abuse of the Service itself and maintain our fraud-signal accuracy.
- To respond to support requests and send essential service notices.
Our reputation network (privacy by design)
LayerCall maintains a reputation signal built from lookups across the network. This is stored as a one-way SHA-256 hash of the observed value plus counters (how often it was seen, and how many customers reported it as abusive). We do not store the raw IP addresses, emails, phone numbers, or domains in this network — only irreversible hashes. There is no personal data in it to expose.
Data processors we use
We rely on a small number of reputable providers to run the Service:
- Vercel — application hosting.
- Supabase — database and authentication.
- Google — optional sign-in (OAuth).
- Lemon Squeezy — payment processing for paid plans, acting as merchant of record. Card details are handled by them; we never see or store your card number.
- DB-IP — IP geolocation data.
Data retention
We keep account and usage data for as long as your account is active and as needed to provide the Service, comply with legal obligations, and resolve disputes. You can request deletion of your account and associated data at any time (see "Your rights" below). Reputation-network hashes are aggregate, non-personal, and retained to keep the Service effective.
Security
API keys are stored only as hashes, never in plain text. Data is encrypted in transit (HTTPS). We restrict internal access to production data. No system is perfectly secure, but we design to minimize what could be exposed.
Your rights
Depending on where you live (for example under the GDPR or similar laws), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, email us at hello@layercall.com and we will respond within a reasonable time.
International transfers
LayerCall is operated from India and uses providers that may process data in other countries. Where required, we rely on appropriate safeguards for international transfers.
Children
The Service is intended for developers and businesses and is not directed to children under 16. We do not knowingly collect data from children.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notifying you.
Contact
Questions about privacy? Email hello@layercall.com.