Legal
Developer Terms
These terms apply to anyone who requests sandbox access, holds RupeeBiz API credentials or integrates the RupeeBiz SDK or embedded web experience.
Last updated:
Scope
These Developer Terms govern access to the RupeeBiz sandbox, production APIs, SDKs, embedded experiences and documentation (together, the "Developer Resources"). They form part of the Partner Terms, and the Acceptable Use Policy applies in full. Where you access the resources on behalf of a Partner, that Partner remains responsible for your use of them.
Sandbox and production access
Sandbox is provided for integration development and testing. It simulates transaction flows and returns representative responses; it does not move money and must never be used with real customer data.
- Sandbox data may be reset or purged without notice.
- Sandbox behaviour is indicative and may differ from production, particularly in latency and in the range of upstream error conditions.
- Production credentials are issued only after commercial approval and successful completion of the agreed integration checks.
Credentials and security
API keys, secrets, tokens and dashboard logins are confidential and are issued for the named entity only. You shall:
- store credentials in a secure secret store, never in client-side code, mobile binaries, public repositories, log files, screenshots or support tickets;
- call the APIs from your server, not from an end-customer device, unless a client-side flow is expressly documented as such;
- use TLS for all calls and reject invalid certificates;
- restrict access to credentials to personnel who need them, and revoke access promptly when a person leaves the project;
- rotate credentials on the schedule we notify, and immediately on suspicion of compromise;
- notify RupeeBiz without undue delay of any actual or suspected credential compromise or unauthorised use.
All activity carried out with your credentials is treated as your activity.
Rate limits and fair use
APIs are subject to rate limits and fair-use controls, which are communicated in the documentation or with your credentials and may be adjusted to protect platform stability. You shall:
- handle throttling responses gracefully and back off before retrying;
- use idempotency keys as documented so that retries do not create duplicate transactions;
- poll status endpoints only at the documented interval and prefer callbacks where they are available;
- avoid load or penetration testing against production, and request a testing window in advance for sandbox.
Prohibited uses
You must not:
- reverse engineer, decompile or attempt to derive the source of the SDK or platform, except to the extent that restriction is unenforceable by law;
- resell, sub-license or expose the APIs to third parties outside the approved integration;
- probe, scan or test the security of the platform without written authorisation;
- circumvent authentication, rate limits, transaction limits or risk controls;
- use the resources to build a competing service, or to benchmark the platform for publication, without written consent;
- submit fabricated, automated or test transactions into production;
- use the resources for any purpose prohibited by the Acceptable Use Policy or by law.
Data handling
When integrating you shall:
- send only the fields required to complete a transaction, and no unnecessary personal data;
- never transmit card numbers, banking credentials, passwords or one-time passwords to RupeeBiz endpoints;
- mask sensitive identifiers in your own logs and support tooling;
- obtain the consents required from your end customers before sending their data;
- handle personal data consistently with the Digital Personal Data Protection Act, 2023 and with our Privacy Policy.
Logging and monitoring
RupeeBiz logs API requests, responses, status changes and dashboard activity for security, fraud prevention, audit, troubleshooting and capacity planning. Logs may be used to investigate incidents and disputes and may be disclosed where required by law.
You should retain your own request and response references, including your transaction identifiers, so that disputes can be traced. Quote those references when raising a support request.
Change management and deprecation
We may add fields, endpoints and optional parameters without notice; your integration should tolerate additive changes and ignore unrecognised fields rather than failing.
Breaking changes and deprecations will be announced through the developer channels with a reasonable transition period, during which the previous behaviour will normally remain available. Changes required urgently for security, legal or upstream reasons may take effect immediately, and we will explain the reason as soon as we can.
Availability and testing responsibilities
Sandbox is provided without an availability commitment. Production availability depends in part on telecom operators, billers and intermediaries whose systems we do not control. You are responsible for building sensible timeout, retry and reconciliation behaviour into your integration and for not treating a pending transaction as a completed one.
Support channels
Integration questions should be raised through the developer support channel notified with your credentials, or by writing to sales@rupeebiz.com. Include the environment, endpoint, timestamp, your reference identifier and the response received. Never include credentials or unmasked customer data in a support request.
Suspension and termination of access
Credentials may be suspended or revoked where these terms are breached, where a security risk arises, or where the underlying partner engagement ends. On termination you shall stop using the Developer Resources, delete stored credentials and remove the integration from your platform.
Contact
TRUEHOST IT SERVICES PVT LTD. (operating the RupeeBiz platform)
Office No. 1007A, Newa Bhakti Knowledge City, IT-06, Airoli Knowledge City, TTC Industrial Area, Airoli, Navi Mumbai, Maharashtra 400708, India
Email: sales@rupeebiz.com
Phone: +91 95 2222 1213