What data flows through the API
Requests and responses commonly include operational data (addresses, time windows, vehicle capacities) and, when you choose to attach it, personal data about drivers and end customers — for example driver names, customer names, addresses, and phone numbers passed throughproperties fields on resources and orders (see the Properties schema). Kardinal does not require this data; you control what you send.
Hosting and data location
The API is hosted in the EU, and so is your data. Additional regions may be added over time, since Kardinal relies on international managed cloud providers.Tenant isolation
Every access token is scoped to exactly one agency (sandbox or production for builder accounts) — see Authentication. A token cannot read or write data belonging to another agency: a request for another agency’s plan fails with a 404 and code: NOT_FOUND, exactly as if the plan didn’t exist, so that the API never reveals whether another agency’s data exists. There is no way to query across agencies with a single token.
Encryption
All API traffic is encrypted in transit via TLS 1.3+. Data at rest is encrypted using AES-256.Data retention
Plans and their associated orders and resources are automatically removed one year after their last update. You can purge a plan immediately viaDELETE /plans/{planId} instead of waiting for automatic removal.
Billing data is retained indefinitely, and audit logs for two months — neither can be purged on request, including via DELETE /plans/{planId}.
GDPR
Kardinal acts as a data processor for any personal data you submit through the API; you remain the data controller. Contact dpo@kardinal.ai to request a Data Processing Agreement, or to forward a customer’s GDPR rights request.Certifications
Kardinal does not currently hold SOC 2 or ISO 27001 certification, but is working towards SOC 2 Type II.See also
- Authentication and API keys — how a token is scoped to a single agency.
- Limits and quotas — SLA and support commitments.

