Legal
Privacy Policy
What personal information we collect when you use the Akinda B2B platform, why we collect it, who else processes it, and what you can ask us to do about it.
Last updated 7 August 2026
1. Who we are
The Akinda B2B platform at b2b.akinda.io is operated by Akinda Capital Technologies LLC of Dover, Delaware, United States. We are the controller of the personal information described in this policy.
For anything in this policy, write to contact@akinda.io.
2. What this policy covers
This policy covers the B2B platform: this website, the developer dashboard, the Shariah screening API and the AI connector.
It does not cover the Akinda consumer app at akinda.io, which publishes its own policy, and it does not cover the companies whose financial data we screen — that is public company information, not personal information.
3. Information you give us
- Account — email address and password. If you sign in with Google, we receive your email address and basic profile from Google instead of a password.
- Profile — optional first and last name, company, avatar, tags, bio and notes.
- Billing — for paid personal plans, payment is handled by Stripe. We receive the subscription status, the amount, the currency and a masked payment-method label. We never see or store your full card number.
- Applications — if you submit a business or startup application, the contact and company details on that form, including what you tell us about your product.
- Support — messages you send us by email or through the chat widget, and anything you attach to them.
4. Information collected automatically
- API usage — which endpoints your key calls, how often, response status and bandwidth. We need this to enforce your plan limits, bill correctly and investigate faults.
- Device and connection — browser, operating system, approximate location derived from IP, and referring page.
- Behaviour on the site — pages viewed, the order you viewed them in, and interactions such as clicks and form submissions. See section 7.
5. Cookies and similar technologies
- Strictly necessary — a session cookie that keeps you signed in, and an admin profile identifier for staff accounts. The site does not work without these.
- Preferences — your light/dark theme choice, stored in your browser.
- Analytics — identifiers set by Google Analytics and Amplitude to recognise a returning browser and group activity into sessions.
You can clear or block cookies in your browser. Blocking the strictly necessary ones will sign you out and prevent the dashboard from working.
6. Why we process your information
- To provide the service — creating your account, authenticating you, issuing and metering API keys, and delivering data. This is necessary to perform our contract with you.
- To bill you — processing payments, renewals and refunds. Also contractual, and in part a legal obligation for tax and accounting records.
- To keep the service secure and working — detecting abuse, enforcing rate limits, diagnosing faults. Our legitimate interest in running a reliable service.
- To improve the product — understanding which features are used and where people get stuck. Our legitimate interest; see section 7 for how to object.
- To send operational email — password resets, email confirmation, receipts and service notices. Necessary to perform our contract.
- To send marketing email — only with your consent, which you can withdraw at any time.
7. Product analytics
We use Amplitude and Google Analytics 4 to understand how the site is used — which pages people visit, in what order, and where they stop.
When you are signed in, your email address is sent to Amplitude as your identifier, so that activity can be linked to your account. We do this because it lets us answer a real support question about a real account rather than guess from anonymous aggregates. If you would rather we did not, tell us at contact@akinda.io and we will exclude your account.
What is never sent
Password-reset tokens, email-verification tokens, email-preference tokens and Stripe checkout session identifiers are stripped from every URL before any analytics event leaves your browser. Those links arrive by email and act as credentials; they must not reach a third party.
We also do not send passwords, the contents of form fields, the body of API responses, or your API keys.
Your full IP address is not stored by Amplitude; a coarse location is derived from it and the address is discarded. Most browsers offer a Do Not Track or tracking-protection setting, and browser extensions that block analytics scripts work normally on this site — nothing here depends on them loading.
8. Email and your preferences
Email is sent through Brevo from contact@akinda.io. We distinguish two kinds:
- Operational — password resets, email confirmation, receipts, and notices about your subscription or the service. These are part of providing the service and are sent for as long as you have an account. They cannot be switched off, because switching off a password-reset email would lock you out of your own account.
- Marketing — product updates, offers and the newsletter. These require your consent and carry an unsubscribe link in every message.
You can change what marketing you receive at any time from the preference link in any message we send, or by writing to contact@akinda.io. Opt-outs are actioned immediately.
9. Who we share information with
We do not sell your personal information, and we do not share it for anyone else's advertising. We use these processors:
- Stripe — payments and subscription billing.
- Brevo — transactional and marketing email.
- Amplitude — product analytics.
- Google — Analytics, and Google Sign-In if you choose to use it.
- Hosting and infrastructure — providers that run our servers and deliver the site.
We may also disclose information where we are legally required to, or to establish or defend legal claims. If the business is sold or reorganised, information may transfer with it; we will say so before that changes how it is used.
10. International transfers
We are established in the State of Delaware, United States, and our processors operate internationally, so your information may be processed outside the country you live in. Where transfers are subject to data protection law, we rely on the safeguards our processors provide, such as standard contractual clauses.
11. How long we keep information
- Account and profile — while your account exists, and for a short period afterwards in case you return.
- Billing records — for as long as tax and accounting law requires, typically several years, even after an account closes.
- API usage logs — for a rolling operational window sufficient to bill, investigate faults and detect abuse.
- Applications — while we are considering them and for a reasonable period after, so we can pick up a conversation you restart.
- Analytics — retained by the analytics provider under its own retention settings.
12. How we protect information
Traffic is encrypted in transit. Passwords are stored hashed, never in readable form. Session cookies are HTTP-only, so page scripts cannot read them. Access to production data is limited to people who need it.
Your API key authenticates requests as you. Keep it server-side, do not embed it in client-side code or public repositories, and rotate it from the dashboard if it is ever exposed. No system is perfectly secure, and we cannot guarantee absolute security.
13. Your rights
Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, restrict or object to how we use it, receive it in a portable format, or withdraw consent you previously gave.
Some of this you can do yourself: profile details are editable in the dashboard, marketing preferences from any email we send, and an account can be closed on request. For anything else, write to contact@akinda.io and we will respond within the time the applicable law allows. We will never charge you or treat you differently for exercising a right.
Note that closing an account does not delete records we are legally required to keep, such as billing history.
14. Children
The platform is a developer product intended for businesses and adults. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child has given us information, tell us and we will delete it.
15. Changes to this policy
We may update this policy as the product changes. The date at the top of this page shows when it last changed, and where a change materially affects how we use your information we will give notice before it takes effect.
16. Contact
Akinda Capital Technologies LLC
Dover, Delaware, United States
contact@akinda.io
See also our Terms and Conditions and Disclosures.
Questions about this document? Email contact@akinda.io.