API & Integration Terms
Last updated 24 September 2026
Scope
These terms apply when you use a Finalizo API key, webhook, Zapier connection, Slack or Notion integration, Stripe Connect connection, or another connected service. They supplement the Terms of Service.
Authorisation and security
You are responsible for the account, API keys, OAuth permissions, webhook destinations, and connected services that you configure. Keep keys and callback credentials secret, use the narrowest available scopes, rotate or revoke credentials when they are no longer needed, and tell us promptly about suspected compromise.
Payloads and client data
Send only the fields needed for the requested workflow. Do not put passwords, private keys, access tokens, payment card data, or unnecessary personal data into webhook payloads, integration notes, URLs, or logs. Finalizo may mask or omit sensitive fields. When Finalizo processes client data for you, the Data Processing Addendum applies.
Rate limits and availability
API and webhook access may be rate-limited, retried, delayed, deduplicated, rejected, or suspended to protect the service and customer data. Webhook receivers should verify the signature where provided, handle duplicate event IDs idempotently, and avoid treating a delivery attempt as proof that a downstream action completed.
Third-party services
A connected provider may have its own terms, privacy policy, retention, outage, and security model. You authorise Finalizo to exchange the minimum data needed for the integration you enable. You remain responsible for the provider account and for confirming that the connection is lawful and appropriate.
Contact
For integration questions or vulnerability reports, contact legal@finalizo.com or security@finalizo.com, as appropriate.