Use verification answers only for what the user agreed to. Never try to re-identify anyone from the hashes we return. Keep your keys secret, pay for the extras you use, and protect any data you receive - we act as your processor, and the data protection section below sets those rules.
1. Who this covers
These developer terms apply whenever you integrate Passwave into a website, app, or service - from the moment you create a dashboard project or call the API. They're an agreement between you (the operator) and Passwave Ltd, and they add to, rather than replace, our consumer Terms of service.
If you're on a Custom plan, the order form you signed with us takes precedence wherever it differs from these terms. Everything else here still applies.
2. Accounts & API keys
Your integration is managed from your dashboard. API keys authenticate your servers - treat a live key like a password: never embed it in front-end code, rotate it if it leaks, and revoke keys you no longer use. You're responsible for everything done with your keys until they're revoked.
Keep your project name accurate and recognisable - it's what people see when your site asks them a question, and unfamiliar names get declined.
3. Using answers
Use the answers we return only for the purpose the user consented to. Specifically, you must not: attempt to re-identify a user from the hashes we return, cross-match those hashes against other datasets, resell or share verification results, or attempt to contact a user through any channel Passwave has not provided for that purpose. Honour a user's decision to disconnect immediately. A capability code we return with a share is for that user and your project only: do not pass it to anyone, use it only for the question the user was told about, and treat a refusal as final for that share.
Misusing user answers - reselling them, cross-matching them, or contacting users outside the channels we provide - ends your integration immediately, without refund of prepaid fees.
4. Plans & billing
Over-18 checks are free and unlimited on every plan. You pay only for extras - richer fields, higher volume and rate limits, and premium support - billed as shown in pricing and the docs. Subscriptions renew until cancelled; Custom plans are billed annually against your order form.
Fees are exclusive of tax unless stated. We give at least 30 days' notice of a price change, and it never applies to a period you've already paid for. We may suspend a paid integration for non-payment after a reminder.
Payments are processed by Paddle, our merchant of record: Paddle runs the checkout, issues your receipts and invoices, and we never see your card details. How cancellation works and how to get a refund are set out in the refund policy.
5. Data protection
For any personal data we process on your behalf, you are the controller and we are your processor. We process it only on your documented instructions and to provide the service, publish the current list of sub-processors in the privacy policy and give 30 days' notice before adding one, and apply the security measures described on our security page.
We'll notify you without undue delay of any breach affecting your users, help you respond to data-subject requests, and delete or return the data when your integration ends.
6. Availability & SLA
We work hard to keep the API available and accurate, but the free tier is provided "as is". Premium and Custom plans carry an uptime target and a support response time, set out in your plan or order form; planned maintenance is announced in advance on our status page.
Beyond any SLA credits stated in your plan, our liability to you is limited to the fees you paid us in the twelve months before a claim, and we aren't liable for indirect or consequential loss.
7. Suspension & ending
You can end your integration at any time from the dashboard. We can suspend or close it for a clear breach of these terms or a genuine risk to users, and we'll tell you why unless the law prevents it. Subscription downgrades take effect at the end of the paid period; Custom plans follow the notice period in your order form.
When your integration ends we delete or return the personal data we held for you, and the clauses that should outlast the agreement - on liability, confidentiality, and data protection - continue to apply.
8. Changes & law
We'll update the date above when these terms change and flag material changes in the dashboard before they take effect. Continuing to use the API after that means you accept the update.
These terms are governed by the laws of England and Wales, and disputes go to its courts. Questions:
Passwave Ltd · 20 Wenlock Road, London N1 7GU · Registered in England, no. 17354253