API Terms
Last updated: [TBD] · This is a working draft pending legal review.
These API Terms ("API Terms") govern your access to and use of the application programming interfaces, developer tools, documentation, and related software made available by Coded B.V. (the "API"). The API is offered as part of higher subscription tiers of the Coded commerce platform (the "Platform"). By generating an API key, calling an endpoint, or otherwise accessing the API, you ("you", "Developer") agree to these API Terms.
Coded B.V. ("Coded", "we", "us") is a private limited company (besloten vennootschap) registered in the Netherlands and a subsidiary of Coded Holding B.V. Coded operates internationally; the Netherlands is our place of registration and initial launch market, and the Platform serves merchants worldwide. Registered office: De Taling 15, 2761 SL Zevenhuizen, The Netherlands. Netherlands Chamber of Commerce (KvK) number: 42027097. VAT number: NL869368795B01.
These API Terms supplement, and are incorporated into, the agreement under which you use the Platform (the "Main Terms"). If there is a direct conflict between these API Terms and the Main Terms, these API Terms control with respect to the API. Capitalised terms not defined here have the meaning given in the Main Terms.
1. Definitions
- API — the interfaces, endpoints, SDKs, libraries, sample code, and documentation Coded makes available for programmatic interaction with the Platform.
- API Key / Credentials — the access tokens, keys, secrets, or client identifiers issued to you to authenticate API calls.
- Application — any software, service, integration, or workflow you build, operate, or use that calls the API.
- Organization — the tenant account on the Platform on whose behalf the API is accessed.
- Merchant — a seller operating one or more projects (such as branded online shops) on the Platform.
- Platform Data — data made accessible through the API, including catalog, order, payment-status, and fulfilment data, and personal data of an Organization's end customers.
- Documentation — the technical and policy documentation Coded publishes for the API, as updated from time to time.
2. Eligibility and account requirements
The API is available only to Organizations on a subscription tier that includes API access, and only while that subscription is active and in good standing. You must have a valid Platform account, accept these API Terms, and comply with the Main Terms and the Acceptable Use provisions below. You are responsible for everything done through your account and your Application, whether by you, your personnel, or any third party you permit to use your Credentials.
3. Licence scope
Subject to your continuous compliance with these API Terms and payment of any applicable subscription fees, Coded grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable licence, during the term, to:
- access and call the API; and
- use the Documentation, SDKs, and sample code
solely to build and operate an Application that interacts with the Platform on behalf of the Organization(s) you are authorised to act for, and solely for that Organization's legitimate commerce operations.
3.1 Reservation of rights
The API, the Platform, the Documentation, and all related software, trademarks, and intellectual property are and remain the exclusive property of Coded and its licensors. No rights are granted by implication, estoppel, or otherwise except as expressly stated. You receive no ownership interest in the API or any Coded intellectual property.
3.2 Your Application
As between you and Coded, you own the original code of your Application, excluding any Coded materials, SDKs, sample code, or API outputs incorporated into it. You grant Coded no rights in your Application beyond what is reasonably necessary to provide and secure the API.
3.3 Feedback
If you provide suggestions or feedback about the API, you grant Coded a perpetual, irrevocable, worldwide, royalty-free licence to use it without restriction or obligation to you.
4. Authentication and API keys
You must authenticate every request using the Credentials issued to you. You are responsible for:
- keeping Credentials confidential and not embedding secrets in client-side code, public repositories, mobile binaries, or any place where they may be exposed;
- restricting use of Credentials to your authorised personnel and Applications;
- rotating and revoking Credentials promptly when personnel change or when compromise is suspected; and
- notifying us without undue delay at security@coded.co if you believe any Credential has been lost, leaked, or used without authorisation.
All activity authenticated with your Credentials is attributed to you. Coded may rotate, suspend, or revoke Credentials where necessary to protect the security or integrity of the Platform, and will use reasonable efforts to notify you when it does so other than in an emergency.
5. Rate limits and quotas
Coded applies rate limits, call-volume quotas, payload-size limits, and concurrency limits to the API. The applicable limits depend on your subscription tier and are described in the Documentation, which forms part of these API Terms. We may adjust limits to protect the stability, security, and fair use of the Platform.
You must not exceed, circumvent, or attempt to circumvent any limit, including by distributing calls across multiple Credentials, accounts, or IP addresses to evade a quota. If you exceed a limit, Coded may throttle, queue, reject, or delay requests, and may require you to upgrade your subscription tier for sustained higher volume. Repeated or deliberate breach of limits is a material breach of these API Terms.
You should design your Application to handle rate-limit responses gracefully, including by honouring documented retry and back-off signals.
6. Acceptable use
You must use the API only for lawful purposes and in line with the Documentation. You must not, and must not permit any person to:
- use the API to build, train, or operate a product or service that competes with the Platform, or to replicate the Platform's functionality;
- scrape, harvest, mirror, or bulk-extract Platform Data beyond what your Application legitimately needs for the Organization you act for;
- access data of any Organization, merchant, or end customer you are not authorised to access, or attempt to bypass the Platform's multi-tenant isolation;
- introduce malware, attempt to gain unauthorised access, probe or test the vulnerability of the API or Platform except under a separately agreed security-testing arrangement, or otherwise interfere with the integrity, security, or performance of the API;
- use the API in a way that imposes an unreasonable or disproportionate load on the Platform's infrastructure;
- misrepresent your identity, your affiliation with Coded, or the source of data;
- use the API in connection with activity that is illegal, fraudulent, deceptive, or that infringes the rights of others; or
- remove, obscure, or alter any proprietary notices in the API, Documentation, or SDKs.
Coded does not pre-screen Applications and is not responsible for them. You are solely responsible for your Application and its compliance with these API Terms and applicable law.
7. Data handling and privacy
7.1 Roles
Where you access personal data of an Organization's end customers through the API, that personal data is processed on behalf of, and under the instructions of, the relevant Organization. Coded acts as a processor for the Organization in respect of Platform Data, and you must not use such personal data for any purpose other than providing your Application's functionality to that Organization. You may be a separate controller or processor in your own right depending on what you do with the data; you are responsible for determining and meeting your own obligations under applicable data-protection law.
7.2 Universal privacy obligations
Coded designs for privacy by design and operates cookieless analytics. Coded does not sell personal data and does not share personal data for cross-context behavioural advertising. You must uphold equivalent standards. Specifically, you must not, through the API:
- sell personal data, or share it for cross-context behavioural advertising;
- combine Platform Data with other data sources to build advertising or tracking profiles; or
- use personal data for any purpose incompatible with the purpose for which the Organization collected it.
You must comply with all data-protection and consumer-protection laws applicable to your use of the API, including (without limitation and as applicable) the EU and UK General Data Protection Regulation, the California Consumer Privacy Act as amended by the California Privacy Rights Act, and equivalent laws in other jurisdictions. You must honour data-subject and consumer rights requests, and provide the information needed for an Organization to honour them.
7.3 Hosting and security
Platform Data is hosted in the European Union (Frankfurt, Germany), which provides a strong data-protection baseline for data accessed through the API. You must protect Platform Data with appropriate technical and organisational measures, including encryption in transit, access controls, and prompt patching. You must notify Coded without undue delay, and in any event in time for the affected Organization to meet its own legal deadlines, of any personal-data breach affecting Platform Data you hold.
7.4 Data minimisation and retention
Request only the data your Application needs, retain it only as long as needed, and delete it when your access ends or the Organization requests deletion. On termination of your access, you must delete or return Platform Data in your possession except where retention is required by law.
8. Payments-related data
The Platform processes payments through Stripe and Mollie. Coded charges a 0% platform fee on a merchant's payment transactions; merchants pay only the pass-through processing cost charged by Stripe or Mollie. The API exposes payment-status and order information but does not make Coded a payment processor, and you must not use the API to attempt to circumvent, intercept, or re-route payment flows. You must not use the API to collect, store, or transmit full payment-card data; cardholder data handling remains with the relevant payment provider. Your use of any data relating to payments is additionally subject to the terms and rules of the relevant payment provider.
9. Service changes, versioning, and deprecation
The API is under active development. Coded may add, change, version, or remove endpoints, fields, and functionality. We aim to make backwards-compatible changes where practical and to version the API so that you can adopt changes on a predictable schedule.
9.1 Deprecation policy
When Coded deprecates an API version, endpoint, or materially backwards-incompatible field, we will use reasonable efforts to give at least ninety (90) days' notice through the Documentation, changelog, or a direct developer communication channel, unless a shorter period is required to address a security risk, legal obligation, or third-party-provider change outside our control. You are responsible for monitoring our deprecation notices and migrating your Application in time.
9.2 Emergency changes
Coded may make immediate changes to, suspend, or restrict the API without prior notice where reasonably necessary to protect the security, integrity, legality, or availability of the Platform, or to comply with law or a payment-provider requirement. We will restore normal access as soon as reasonably practicable.
9.3 No service-level commitment
Unless a separate written service-level agreement applies to your subscription tier, the API is provided without an availability or uptime commitment.
10. No reverse engineering
Except to the extent this restriction is prohibited by applicable mandatory law (including, where applicable, the limited interoperability exceptions under EU and Dutch law), you must not, and must not permit any person to:
- reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, underlying ideas, or non-public structure of the API, the Platform, or any Coded software;
- access the API to monitor its availability, performance, or functionality for benchmarking or competitive purposes; or
- copy, modify, or create derivative works of the API or Documentation except as expressly permitted.
Where applicable law grants you a non-excludable right to obtain interoperability information, you must first request that information from Coded in writing before exercising any such right.
11. Suspension and termination
Coded may suspend or terminate your access to the API, in whole or in part, with or without notice, if:
- you breach these API Terms, the Main Terms, or the Documentation;
- your Organization's subscription lapses or ceases to include API access;
- your use poses a security, legal, or stability risk to the Platform or other users; or
- required by law or by a payment or infrastructure provider.
You may stop using the API at any time. On termination for any reason, the licence in Section 3 ends immediately, you must stop all API calls, delete your Credentials, and comply with the data-handling obligations in Section 7.4. Sections relating to intellectual property, data handling, disclaimers, liability, and governing law survive termination.
12. Warranties and disclaimers
The API, Documentation, SDKs, and sample code are provided "as is" and "as available", without warranties of any kind, whether express, implied, or statutory, including any implied warranty of merchantability, fitness for a particular purpose, accuracy, or non-infringement, to the maximum extent permitted by applicable law. Coded does not warrant that the API will be uninterrupted, error-free, secure, or that any particular endpoint or data field will remain available. Nothing in this Section limits any warranty or right that cannot be excluded under applicable mandatory law, including mandatory consumer-protection law where it applies to you.
13. Limitation of liability
To the maximum extent permitted by applicable law:
- Coded is not liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, arising out of or relating to the API, even if advised of the possibility; and
- Coded's total aggregate liability arising out of or relating to the API is limited to the amounts paid by your Organization for the subscription tier that includes API access during the three (3) months immediately preceding the event giving rise to the claim.
Nothing in these API Terms excludes or limits liability that cannot be excluded or limited under applicable mandatory law, including liability for fraud, for death or personal injury caused by negligence, or under mandatory Dutch law or the mandatory law of your jurisdiction where it applies.
14. Indemnity
You will defend, indemnify, and hold harmless Coded and its affiliates from and against any third-party claims, damages, and reasonable costs (including reasonable legal fees) arising out of: (a) your Application; (b) your use of the API in breach of these API Terms or applicable law; or (c) your handling of Platform Data, including any personal data, in breach of these API Terms or data-protection law.
15. Changes to these API Terms
Coded may update these API Terms from time to time. Where a change materially affects your rights or obligations, we will use reasonable efforts to give advance notice through the Documentation, the developer changelog, or a direct communication channel. Your continued use of the API after a change takes effect constitutes acceptance of the updated API Terms. If you do not accept a change, you must stop using the API.
16. Governing law and jurisdiction
These API Terms are governed by the laws of the Netherlands, without regard to conflict-of-laws rules. The courts of Amsterdam, the Netherlands have exclusive jurisdiction over any dispute arising out of or relating to these API Terms.
Nothing in this Section deprives you of the protection of mandatory provisions of the consumer-protection or data-protection law of your country of residence or establishment that apply notwithstanding this choice of law and forum, and to that extent those mandatory provisions and the competent courts of your jurisdiction may also apply.
17. General
These API Terms, together with the Main Terms and the Documentation, are the entire agreement between you and Coded regarding the API. If any provision is held unenforceable, the remaining provisions stay in effect. Coded's failure to enforce a provision is not a waiver. You may not assign these API Terms without Coded's prior written consent; Coded may assign them to an affiliate or successor. Notices to Coded under these API Terms should be sent to legal@coded.eu.
Contact
For questions about these API Terms, contact:
- General / legal: legal@coded.eu
- Privacy and data handling: privacy@coded.eu
- Security and credential compromise: security@coded.co
Coded B.V., De Taling 15, 2761 SL Zevenhuizen, The Netherlands, Netherlands. KvK 42027097 · VAT NL869368795B01. Effective date: 11 June 2026.
<!-- OPEN ITEMS FOR COUNSEL: - Confirm entity details: KvK number, VAT number, registered address, effective date, contact email domain (coded.eu (legal/privacy) · coded.co (ops)). - Confirm the 90-day deprecation notice period is one Coded can operationally honour; many providers commit to 90–180 days as policy — set the number deliberately. - Validate the processor/controller framing in Section 7.1 against the actual data flows and against the Platform DPA; align this with the Coded DPA and Privacy Policy so roles are consistent across documents. - Confirm whether any subscription tier carries a real SLA (Section 9.3); if so, cross-reference rather than disclaim. - Verify the reverse-engineering carve-out (Section 10) against EU Software Directive (2009/24/EC) and Dutch Auteurswet interoperability provisions — these interoperability rights are non-excludable; confirm the "request first" mechanism is enforceable. - Confirm the liability cap basis (3 months of API-tier fees) is commercially acceptable and enforceable under Dutch law (reasonableness test under art. 6:233 BW for general terms). - Confirm Stripe/Mollie pass-through and 0% platform fee statements (Section 8) match the commercial terms and that no payment-data obligations from the providers need to flow down to Developers. - Confirm indemnity scope and whether a mutual or capped indemnity is preferred for the developer/partner relationship. - Decide whether API access requires a separate click-through acceptance gate at key-generation time, and whether a registration/identity-verification step is needed. - Consider whether export-control / sanctions compliance and anti-bribery clauses should be added given international operation. -->