Last updated: 27 September 2026
Privacy Policy
This policy explains what ibanchecker.cash collects, why, how long we keep it, and the rights you have over it. In short: the IBANs you check are never stored by us, the free tools need no account, and an account exists only if you create one.
1. Overview & Data Controller
ibanchecker.cash is operated by KÖYLÜ BİLGİSAYAR ELEKTRONİK GIDA İLETİŞİM SANAYİ VE TİCARET LİMİTED ŞİRKETİ (“we”, “us”, “our”), registered in İstanbul, Turkey (MERSİS: 0589045373223843). We are the Data Controller for personal data processed through this platform.
This Privacy Policy applies to everyone who uses our website, free tools and paid Developer API at https://ibanchecker.cash.
We follow the EU General Data Protection Regulation (GDPR), UK GDPR, the California Consumer Privacy Act (CCPA), the Turkish Personal Data Protection Law (KVKK No. 6698), and the data protection laws of the UAE, Saudi Arabia and the other places our users are in.
2. Data We Collect
What we hold depends on what you do. Using the checker and the free tools gives us nothing that identifies you beyond the connection itself.
- Every visit
- Page statistics from Cloudflare Web Analytics: the page path, the referring site, your country, browser, operating system, device type and how fast the page loaded. It sets no cookies, and Cloudflare discards your IP address at its edge.
- Why: Knowing which pages are read and how well they perform. Legitimate interest.
- Every visit
- Your IP address, as part of the connection, handled by Cloudflare while it delivers the page.
- Why: Delivering the site and protecting it from attacks. Legitimate interest.
- Using the Developer API or the report form
- Your IP address, held in a request counter that expires after two hours. With an API key: monthly request counts per endpoint and the time each key was last used. For every validation: the outcome (valid, or which check failed), the IBAN’s two-letter country code and whether bank details were found.
- Why: Enforcing rate limits and your plan, showing your usage, and preventing abuse. Contract and legitimate interest.
- Requesting a free API key by email
- Your email address, held for 24 hours until you open the confirmation link we send, then kept with the key it confirms, so the key appears in your dashboard if you create an account with the same address.
- Why: Delivering the key and linking it to you. Contract.
- Creating an account
- Your email address and name, and a password hash if you sign up with a password. If you sign in with Google or GitHub: your account ID with that provider, the name, email address and profile picture it shares, and the access tokens it issues. Your API keys, which you can view and copy in the dashboard.
- Why: Providing your account and your API keys. Contract.
- Signing in
- A session record: a random token, your IP address and your browser (user agent) at the time.
- Why: Keeping you signed in and letting you review and end your sessions. Contract, and legitimate interest in account security.
- Buying a plan
- Payment details are collected and held by Polar, our merchant of record. We receive your email address and the plan you bought.
- Why: Billing and tax. Contract and legal obligation.
- Reporting a data error
- The bank and the detail you report, your message, and your email address if you choose to give one.
- Why: Checking and correcting our bank directory, and replying to you. Legitimate interest.
3. IBAN Data: Never Stored
Zero IBAN retention by design.
We do notlog, store or share any IBAN you enter. On the website, the checker and the free tools validate IBANs in your browser, and the IBAN itself is not sent to us; to show the bank’s address, the result card asks our server for it by the bank’s BIC. Through the Developer API, including the playground on our API docs page, the IBAN is validated in memory at Cloudflare’s edge and discarded when the response is sent. No IBAN is written to our database, our logs or any third-party system.
One thing stays on your own device: the checker on our homepage remembers your last ten checks in your browser’s local storage so you can open them again. That list never leaves your device, and the Clear history button beside it deletes it.
Our API statistics record only the outcome of a validation (valid, or which check failed), the IBAN’s two-letter country code and whether bank details were found. They never contain the IBAN, your IP address or your key.
4. How We Use Your Data
- • Provide and manage your account, API keys and subscription
- • Process payments through Polar, our merchant of record
- • Enforce rate limits, plan limits and fair use
- • Send transactional emails: API key delivery, password resets, invoices and plan changes
- • Check and correct bank data you report, and reply to you
- • Prevent abuse and keep the platform secure
- • Measure, in aggregate, which pages are used and how fast they load
We do not sell your personal data. We do not show ads and do not use your data for advertising. We share personal data only with the service providers in the next section.
5. Service Providers
These companies process personal data on our behalf, each under its own data protection terms:
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, CDN, security, databases (D1, KV), Web Analytics and Workers Analytics Engine | Global (US HQ) |
| Polar Software Inc. | Merchant of record: checkout, subscription billing and tax. Uses Stripe as its payment processor. | US / EU |
| Resend, Inc. | Transactional email: API keys, password resets, and the notice our data team receives when you report an error | US |
If you choose to sign in with Google or GitHub, that provider handles the sign-in under its own privacy policy and shares with us the details listed in section 2. The terms that apply to API customers’ data are in our Data Processing Agreement.
7. Data Retention
| Data | How long we keep it |
|---|---|
| Account details (email, name, profile picture, password hash) | Until you delete your account in the dashboard, or ask us to |
| Google or GitHub sign-in link and its tokens | Until you delete your account |
| Sign-in sessions (token, IP address, browser) | A session stops working seven days after it was last renewed; the record is deleted when you sign out, end the session in the dashboard, or delete your account |
| Unconfirmed API key requests (email address) | 24 hours |
| API keys, the email address each belongs to, and each key’s last-used time | Until you delete the key or your account, or ask us to |
| Monthly API request counts | Each monthly count expires 35 days after it was last updated |
| Validation outcome statistics (no IBAN, no IP address) | Three months, in Cloudflare Workers Analytics Engine |
| Page statistics (Cloudflare Web Analytics) | Aggregate statistics without personal identifiers, kept by Cloudflare |
| IP address in rate-limit counters | Two hours |
| Data-error reports | While we check and correct the data, then as the record behind the correction; ask us and we delete your email address and message |
| Billing records, held by Polar | As long as Polar is legally required to keep them |
| Anything kept in your browser’s local storage | On your device until you clear it |
| IBANs you check | Never stored |
8. Your Rights (GDPR & UK GDPR)
Under GDPR (EU) and UK GDPR, you have the following rights:
- Access: request a copy of the personal data we hold about you
- Rectification: correct inaccurate data
- Erasure: have your account and its data deleted
- Portability: receive your data in a machine-readable format
- Restriction: have processing restricted in certain circumstances
- Objection: object to processing based on legitimate interest
- Withdrawal of consent: where we rely on your consent, withdraw it at any time
If you have an account, the Account tab of the dashboard lets you download everything we hold about you as a file and delete your account yourself; deleting it removes your account, your API keys and your usage counts. For anything else, email [email protected]. We reply within 30 days. You may also complain to your national data protection authority.
9. Regional Rights
Turkey (KVKK)
Under Article 11 of Law No. 6698 you may ask whether we process your personal data, request information about it, its purpose and the parties it is transferred to, and ask us to correct or delete it. Write to [email protected].
California (CCPA)
California residents have the right to know what personal data is collected, to delete it, and to opt out of its sale or sharing. We do not sell personal data. We do not share it for cross-context behavioural advertising. To exercise your rights, contact [email protected].
UAE (PDPL) and Saudi Arabia (PDPL)
Users in the UAE and Saudi Arabia have rights to access, correct and request deletion of their personal data under their national data protection laws. Contact [email protected] to exercise these rights.
10. Contact
For privacy requests, data deletion, or questions about this policy:
- Email: [email protected]
- Website: https://ibanchecker.cash
We may update this policy from time to time. Material changes will be notified by email to API key holders. Continued use of the service after changes constitutes acceptance.