Developer & API Terms
1. Purpose
These Developer & API Terms (“Developer Terms”) govern access to and use of the Bosse Value Network (“BVN”) Application Programming Interfaces (“APIs”), Software Development Kits (“SDKs”), webhooks, developer documentation, testing environments, and related technical services. These Terms supplement the BVN Terms of Service, Privacy Policy, Merchant Terms, and any applicable Enterprise or Partner Agreements.
2. Scope
These Terms apply to:
API Developers Software Vendors Enterprise Customers White-Label Partners Integration Partners Internal Development Teams Third-party Applications Future Marketplace Integrations
3. Definitions
API – An application programming interface made available by BVN for approved integrations. Developer – Any individual or organization authorized to access or integrate with the BVN API. Sandbox – A non-production testing environment. Production Environment – The live environment used for customer-facing services. API Credentials – API keys, client IDs, secrets, access tokens, certificates, or other authentication credentials issued by BVN.
4. API Eligibility
Access to the BVN API is available only to approved developers and organizations. To obtain API access, applicants may be required to:
Create a BVN account. Complete identity or business verification. Agree to these Developer Terms. Meet applicable security requirements. Receive approval from BVN.
BVN may deny API access at its discretion.
5. Developer Registration
Developers may be required to provide:
Legal name Company name Email address Business website Intended API use case Application description Security contact Technical contact IP addresses (if applicable)
Developers must keep this information current.
6. API Credentials
BVN will issue unique API credentials for approved integrations. Developers must:
Keep credentials confidential. Store credentials securely. Never embed secrets in public code repositories. Rotate credentials when compromised. Immediately notify BVN of suspected credential exposure.
Developers are responsible for all activity performed using their credentials.
7. Authentication & Security
Developers must use BVN’s supported authentication methods. Depending on the API, this may include:
OAuth 2.0 API Keys JWT Tokens Mutual TLS (mTLS) IP Allowlisting Multi-Factor Authentication for developer accounts
Authentication requirements may evolve over time.
8. Permitted Uses
Approved Developers may use the API to:
Retrieve authorized account information. Integrate merchant systems. Manage Reward Point programs. Automate reporting. Process approved business workflows. Receive webhook notifications. Build applications that enhance the BVN ecosystem.
Use of the API must remain consistent with the approved use case.
9. Prohibited Uses
Developers may not:
Circumvent security controls. Reverse engineer BVN systems. Scrape data outside authorized endpoints. Exceed published rate limits intentionally. Create competing services using proprietary BVN technology. Access data without authorization. Resell API credentials. Introduce malicious code. Interfere with Platform operations. Use the API for unlawful purposes.
Violation of these Terms may result in immediate suspension of API access.
10. API Rate Limits
BVN may impose limits on:
Requests per minute Requests per hour Requests per day Concurrent connections Payload size File uploads Webhook delivery
Rate limits help maintain Platform stability and may vary based on subscription level, partner status, or enterprise agreement.
11. Data Usage & Privacy
Developers may access only the data necessary for their approved integration. Developers must:
Use data only for authorized purposes. Protect personal information. Comply with applicable privacy laws. Follow BVN’s Privacy Policy. Promptly delete data when no longer required. Not sell or misuse BVN user data.
12. Webhooks & Event Notifications
BVN may provide webhooks for events such as:
Reward Point issuance Point transfers Point conversions Redemption status updates Subscription events Merchant account changes Security alerts
Developers are responsible for validating webhook signatures and handling retries appropriately.
13. Service Availability
BVN will make reasonable efforts to maintain API availability but does not guarantee uninterrupted access. The API may become temporarily unavailable due to:
Maintenance Security incidents Infrastructure failures Upgrades Emergencies Third-party outages
Planned maintenance will be communicated where practical.
14. Versioning & Deprecation
BVN may introduce new API versions and retire older versions over time. Where feasible, BVN will provide advance notice before deprecating major API versions. Developers are responsible for maintaining compatibility with supported API versions.
15. Sandbox Environment
BVN may provide a Sandbox environment for testing and development. Sandbox data:
Is for testing only. Should not contain real customer data unless expressly authorized. May be reset or deleted without notice. Does not guarantee identical production behavior.
16. Production Environment
Production credentials may be issued after successful review and approval. Developers must complete all required testing before moving applications into production. BVN may require additional security reviews for production access.
17. Security Requirements
Developers must implement commercially reasonable security measures, including:
- Encryption in transit
Secure credential storage Access controls Logging and monitoring Regular software updates Vulnerability management Incident response procedures
Developers are responsible for securing their own systems.
18. Incident Reporting
Developers must notify BVN without undue delay after becoming aware of any security incident that could affect:
BVN systems BVN user data API credentials Connected integrations Customer accounts
Notifications should include available details necessary for BVN to assess and respond to the incident.
19. Intellectual Property
BVN retains all rights, title, and interest in its APIs, documentation, SDKs, trademarks, software, and related intellectual property. Except for the limited rights expressly granted under these Terms, no license or ownership interest is transferred to the Developer.
20. Compliance Requirements
Developers must comply with:
BVN Terms of Service Privacy Policy AML/KYC Policy Merchant Terms (where applicable) Acceptable Use Policy Applicable laws and regulations Security standards specified by BVN
Failure to comply may result in suspension or termination of API access.
21. Monitoring & Audits
BVN may monitor API usage to:
Ensure compliance. Detect fraud. Maintain security. Improve performance. Protect the Platform.
Developers agree to cooperate with reasonable compliance reviews related to their API usage.
22. Suspension & Revocation
BVN may suspend or revoke API access if:
These Terms are violated. Security risks are identified. Fraud is suspected. Credentials are compromised. Legal or regulatory obligations require action. Continued access threatens the Platform or other users.
Where appropriate, BVN will provide notice and an opportunity to cure before permanent revocation.
23. Limitation of Liability
To the fullest extent permitted by law, BVN shall not be liable for indirect, incidental, consequential, special, exemplary, or punitive damages arising from the use of the API. Nothing in this section limits liability where prohibited by applicable law.
24. Indemnification
Developers agree to defend, indemnify, and hold harmless BVN, its affiliates, officers, directors, employees, contractors, licensors, and service providers from claims, losses, liabilities, damages, costs, and expenses arising from:
Misuse of the API. Breach of these Terms. Security failures within the Developer’s systems. Violations of applicable law. Infringement of third-party rights.
25. Governing Law
These Developer Terms shall be governed by the governing law specified in BVN’s Terms of Service, unless otherwise agreed in writing between BVN and the Developer.
26. Policy Updates
BVN may update these Developer Terms to reflect:
New API features Security enhancements Technical standards Legal requirements Platform changes Industry best practices
Material changes will be communicated through the Developer Portal or other appropriate channels.
27. Contact Information
Bosse Value Network (BVN) Developer Relations [email protected] API Support [email protected] Technical Support [email protected] Security Team [email protected] Compliance Team [email protected] Website https://www.bossevaluenetwork.com Business Address 650 Hidden Valley Club Dr, Ann Arbor, MI 48104, United States
Appendix A — Future BVN API Endpoints (Illustrative) Future APIs may include:
Authentication
- Account login
- Token refresh
- Multi-factor authentication
User Accounts
- Profile management
- Account status
- Verification status
Reward Points
Issue Reward Points View balances Transfer points Transaction history
Credits
- Convert points to credits
- Credit Wallet balance
- Conversion history
Redemptions
- Create redemption request
- Redemption status
- Withdrawal history
Merchant
- Purchase point packages
- Campaign management
- Analytics
Webhooks
- Transaction updates
- Redemption events
- Security notifications
End of Developer & API Terms This document provides a comprehensive framework for future BVN API access. As your API evolves, you can supplement it with developer documentation, technical specifications,
service-level agreements (SLAs), and endpoint-specific rules. Before production use, it should be reviewed by legal counsel to ensure alignment with applicable laws, your payment providers, and your technical architecture.
Questions about this policy?
Email: [email protected]