Partner terms
The rules for apps that use Moat identities through the API, widgets, sign-in or webhooks. They sit alongside our terms of service and privacy policy.
The short version
- Use Moat data only to show people their own Moat page and to run the features they use in your app.
- Respect each person's visibility settings. Never sell Moat data or use it for advertising.
- Keep keys on your server and verify every webhook signature.
- When a person deletes their page, delete their Moat data. When they unlink your app, stop syncing.
- Tell us promptly about any leaked key or security incident.
1. Access and keys#
We issue each partner app an API key, a webhook secret and an allowlist of domains. Keys are confidential and belong to your app only. Don't share them, embed them in client code, or commit them to public repositories. We may rotate keys, and we'll coordinate rotation with you except in an emergency.
2. Permitted use#
- Show a person's Moat page to them and to other users of your app, at the level of detail they've allowed.
- Pre-fill and keep in sync the parts of your app that describe the person.
- List people, companies and services in directories within your app.
You must not:
- sell, rent or license Moat data, or use it for advertising or advertising profiles;
- combine Moat data with other data to identify people who haven't connected your app;
- show contact details, or full-level fields, beyond what the person's settings allow;
- cache Moat data longer than you need it to run your app, or ignore update, unlink and deletion events;
- exceed rate limits or crawl Moat outside the documented endpoints.
3. Data protection#
For data a person asks us to share with your app, you act as an independent controller and are responsible for complying with data protection law, including publishing your own privacy policy that explains your use of Moat data. You agree to:
- process Moat data only for the permitted uses above;
- delete a person's Moat data within 30 days of receiving
profile.deleted, and stop syncing afterprofile.unlinked; - hide a person's Moat data while they are suspended;
- help us respond to requests from people exercising their data rights where they relate to your copy;
- notify us without undue delay, and within 72 hours, after becoming aware of a breach affecting Moat data.
Where Moat processes personal data on your behalf, for example when your app creates profiles for your users, the data processing terms in Annex B apply.
4. Security#
- Call Moat from your server over HTTPS. Keep the API key and people's private keys server-side.
- Verify
X-Moat-Signatureon every JSON webhook with a constant-time comparison, and reject stale events. - Verify sign-in results with Werify on your server before creating a session or calling Moat.
- Sign in-place editor grants on your server. Never expose the signing key.
- Report suspected key exposure to us straight away so we can rotate it.
5. Changes to the API#
We'll give at least 30 days' notice before a breaking change to a documented endpoint, event or widget attribute, except where a change is needed urgently for security or legal reasons.
6. Suspension and ending#
We may suspend access that puts people or Moat at risk, or that breaks these terms. Either side can end partner access with 30 days' notice. When access ends, stop calling the API and delete Moat data you no longer have a lawful reason to keep.
7. Liability#
The API and widgets are provided as is. Each side's liability is limited as set out in your partner agreement with us, or, if there isn't one, as in our terms of service.
Annex A. Data by access method#
| Access method | Data available |
|---|---|
| No key or public key | Card and public fields of public profiles. Full fields with a public key. Never email or phone. |
| Partner API key | All levels, plus email and phone, for people connected to your app |
| Person's private key | That person's full profile, including email and phone |
| Webhooks | Profile snapshots and lifecycle notices for people connected to your app |
Annex B. Data processing terms#
Where Moat acts as your processor, Moat will:
- process personal data only on your documented instructions, including these terms;
- ensure people authorised to process it are bound by confidentiality;
- apply appropriate technical and organisational security measures;
- use sub-processors only under written terms with equivalent protections, and keep a list available on request;
- help you respond to data subject requests and meet your security, breach and impact-assessment duties;
- delete or return the data at the end of the service, unless the law requires us to keep it;
- make available the information needed to show compliance, and allow reasonable audits.
Questions about these terms: contact the partner team.