API, Webhooks & Affiliate Program Terms
Developer terms for API keys, rate limits and webhooks — and the full affiliate program: attribution, commissions, withdrawal, payout.
_Last updated: 3 August 2026_
These terms govern two partner-facing surfaces of TrustRating: Part A covers the developer platform — API keys, the documented API and webhooks; Part B covers the affiliate program — referral links, commissions, withdrawal and payout. Both form part of the Business Terms of Service (for API use by companies) and the Terms of Service (for individual affiliates), and both inherit the Acceptable Use Policy in full.
Part A — API and webhooks
A1. Access and keys
API access is a plan entitlement (see the Subscription Terms). Keys are issued in the business panel, are confidential credentials of your company, and everything done with them is attributed to you. Keep keys out of client-side code, repositories and logs; rotate them on staff departure or suspected exposure — rotation is self-service in the panel. We may revoke keys that leak, misbehave or exceed limits, and we notify you when we do.
Security expectations on your side are the standard ones, stated so nobody can claim surprise: keys live in server-side configuration or secret managers, never in a browser bundle or a public repository; each integration gets its own key so a compromise can be revoked surgically; and if you discover a key in the wild — yours or anyone's — you tell us via the contact page rather than testing what it can do. A leaked key's actions remain attributed to the company until the leak is reported, which is the strongest argument for reporting fast.
A2. Licence and permitted use
We grant a limited, non-exclusive, revocable licence to call the documented API endpoints for your company's internal purposes and the integrations your plan describes — retrieving your own profile, reviews and analytics data; sending review invitations under the fairness rules of the Business Terms of Service; and the other documented capabilities. You must not: resell, republish or redistribute API data as a dataset or competing service; use the API to reconstruct a substantial copy of our database (a violation of our database rights — see the Content Integrity, Scoring & IP Policy); access data of companies or users you have no authorisation for; use the API to manipulate rankings, scores or reviews; or exceed or evade rate limits. Where the API returns personal data (for example invitation statuses), you handle it under your own privacy obligations and, where applicable, the DPA.
A3. Rate limits and fair use
Endpoints carry rate limits appropriate to their cost, enforced automatically; responses signal when you should back off, and well-behaved clients honour those signals with exponential backoff rather than immediate retries. Limits exist so that one integration's bug cannot degrade the platform for everyone else's customers; they are generous for documented use cases, and an integration that legitimately needs more should ask rather than evade — quota conversations are easy, enforcement conversations are not. Sustained abusive traffic — hammering after limit responses, parallelising to evade per-key limits, scraping-by-API — leads to throttling, key suspension and, for persistence, plan enforcement under Section 11 of the Business Terms of Service.
A4. Webhooks
Webhooks push event notifications (for example review created, invitation delivered) to endpoints you configure. You are responsible for your receiving endpoint: it must be secured (HTTPS, verification of the signing secret we provide), must respond promptly, and must tolerate retries — deliveries are at-least-once, and we retry failed deliveries on a backoff schedule before marking them failed, so your handler must be idempotent (keyed on the event identifier) to ensure a retried delivery cannot double-process anything on your side. Treat webhook payloads as confidential input and validate them; never execute untrusted content. Endpoints that fail persistently may be disabled automatically; you can re-enable them in the panel after fixing the receiver.
A5. Versioning and availability
The API evolves; we version breaking changes and give reasonable migration notice through the panel or email — additive changes (new fields, new endpoints) may ship without notice, so parse tolerantly and never assume a response's field list is closed. The API is provided without an uptime guarantee unless separately agreed, and the liability framework of the Business Terms of Service applies.
Part B — Affiliate program
B1. Joining
Affiliates are individuals or companies approved to promote TrustRating in exchange for commission on the paid subscriptions they refer. Enrollment is by application (see the affiliate program page) and admin approval, or by direct invitation. The application asks how you would promote the platform and shows us your standing; answer honestly — an application built on borrowed screenshots fails the program's first and only real test. We review applications on quality and fit, may ask follow-up questions or open a conversation through a support ticket, and may decline at our discretion; approval creates an affiliate account with a personal referral link, an affiliate label on your profile, and a dashboard showing clicks, conversions, commissions and payouts. Declined applicants may reapply when their circumstances change; a decline is a fit judgement, not a sanction.
B2. Your terms are individual
Commission parameters — the rate or amount for a first sale, rates for subsequent renewals, the duration of the earning window, maturation requirements (for example, the referred customer remaining subscribed for a minimum period before a commission becomes payable), and any caps — are set per affiliate and shown in your affiliate dashboard, which is authoritative for your deal; if anything there looks different from what you were told, raise it before promoting, not after earning. Where we change your parameters, the change applies prospectively to new referrals after notice, never retroactively to commissions already accrued.
B3. Attribution
Referrals are attributed through your referral link: a visitor who follows it receives an attribution cookie (disclosed in the Cookie Policy) valid for the attribution window of the program, and a subscription started within that window by the referred account is credited to you. Attribution survives the visitor's ordinary journey — moving between the public site and the business signup, returning days later within the window — but it cannot survive the visitor's own choices against it: a user who declines the attribution cookie group, clears cookies, or switches devices breaks the trail, and that is their right, not a bug to engineer around. Attribution follows the recorded referral trail; where the trail is technically absent but a referral is demonstrably genuine, support can attribute manually at our reasonable discretion. What never earns attribution: your own purchases through your own link (self-referral), purchases by accounts you control, and traffic manufactured by the practices banned in B5.
B4. Commissions — accrual, maturation, reversal, clawback
A commission accrues when a referred customer's qualifying payment succeeds. It matures — becomes eligible for payout — when your individual conditions are met (for example the referred subscription surviving its minimum period) and the money it derives from is settled. Commissions are reversed proportionally when the underlying payment is refunded or charged back, in part or in full, under the Payments & Refunds Policy; if a reversal lands after you were already paid, the amount becomes a clawback balance deducted from your future commissions or, for substantial amounts, repayable on request. Statistics in your dashboard — earned, pending, mature, paid, reversed, per currency — are the program's books, and we keep them accurate and inspectable.
B5. A worked example
Numbers make the lifecycle concrete. Suppose your parameters are: 100% of the first sale, provided the referred customer stays subscribed at least two months; then 20% of each subsequent payment for six months. A visitor follows your link in March and subscribes to a plan costing 70 in April. Your dashboard immediately shows a pending first-sale commission of 70. The customer pays again in May and June — the two-month condition is met, so the April commission matures and becomes withdrawable, while May's and June's payments each accrue a 20% commission (14 each) that matures as their own conditions settle. In July the customer receives a partial refund of half of July's payment: July's commission is recalculated proportionally from the original base, not summarily deleted. In October the six-month earning window closes; payments from November onwards accrue nothing new, and everything already matured stays yours. Had the customer charged back April's payment entirely, the first-sale commission would have reversed — and if it had already been paid out, the amount would have become a clawback deducted from future commissions. Every state transition in this story is visible in your dashboard as it happens; the example uses illustrative parameters, and yours are the ones your dashboard shows (B2).
B6. Promotion rules
Promote honestly or not at all — the program pays for genuine advocacy that brings businesses who want honest feedback tooling, and every rule below just draws the perimeter of that sentence. Prohibited: misleading claims about TrustRating (invented endorsements, fake guarantees, "scores can be improved by subscribing" — they cannot, see the Content Integrity, Scoring & IP Policy); spam in any channel — unsolicited bulk email, comment spam, messaging-app blasts; cookie stuffing, forced clicks, iframe stuffing or any technique attributing visitors who did not knowingly follow your link; self-referral and circular schemes (B3); brand-term advertising — bidding on "TrustRating" and confusingly similar terms in search advertising, or using domains/handles impersonating us; incentivised signups where you rebate your commission to the referred customer without our written consent; and promotion on properties containing unlawful or hateful content. You must disclose your affiliate relationship where advertising law requires (it almost always does): a plain "affiliate link" notice satisfies this.
B7. Withdrawal and payout
Payout is request-based: you request withdrawal of your mature balance from the dashboard; requests are reviewed and approved by our team (verifying maturation, reversals, clawbacks and fraud signals), and approved amounts are paid to the payout details you maintain — bank transfer (IBAN validated at entry) or cryptocurrency wallet, as offered in the dashboard. Review exists to protect the program's honesty, not to sit on your money: a clean request from an affiliate with a clean history is a quick approval, while requests showing anomalies get questions before money moves. Where commissions accrued in more than one currency, payouts are processed per currency rather than converted at improvised rates — the remainder stays in your balance for its own payout. Currency handling, processing times and the fraud screening applied to outbound payments are described in the Payments & Refunds Policy. Minimum payout thresholds, where applied, are shown in your dashboard. You are responsible for taxes on your commissions and for the accuracy of your payout details; payments to the details you provided discharge our obligation.
B8. Termination and forfeiture
You may leave the program at any time, for any reason, with a simple notice; mature honest commissions are paid out on exit, and pending ones settle on their normal schedule. We may suspend or terminate an affiliate for breach of these terms — with forfeiture of commissions attributable to fraud (fake referrals, stuffing, self-dealing), which are void from the start, and payout of untainted mature commissions where the law requires. Program termination follows the enforcement and appeal framework of the Moderation & Appeals Policy. We may also modify or discontinue the program prospectively with reasonable notice; accrued honest commissions survive discontinuation.
B9. Relationship
Affiliates are independent contractors — nothing here creates employment, agency, partnership or the authority to bind TrustRating: you cannot make promises on our behalf, settle disputes in our name, or offer terms we did not publish. You may describe yourself as a "TrustRating affiliate" and use the promotional assets we provide, under the brand rules of the Content Integrity, Scoring & IP Policy; you may not present yourself as TrustRating itself.
Changes and contact
Both parts of these terms evolve with the platform, following the change process of the Terms of Service — material changes announced in advance, the date above identifying the version in force. Developer questions, webhook issues, attribution disputes, payout questions: contact us; the affiliate dashboard and the help center answer the common cases.