Vahanse API Terms
Status: DRAFT — FOR LEGAL REVIEW — NOT FOR EXECUTION
Version: 0.9 - Counsel Review Draft
Draft date: 31 August 2026
Operator: Vahanfin Solutions Private Limited (CIN U52290JH2023PTC021512)
Brand: Vahanse
Head office: Vahanfin Solutions Pvt Ltd, Nabibux House, 3rd Floor, Vakola Bridge Road, Santacruz (E), Mumbai 400 055, Maharashtra, India
This document is a Vahanse-specific working draft prepared for Vahanfin Solutions Private Limited (CIN U52290JH2023PTC021512), which operates the Vahanse brand. It is not legal advice and must be reviewed, approved and adapted by qualified Indian counsel before publication, signature or reliance. Commercial values, support contacts, regulatory representations, security commitments, service levels and any customer-specific terms must be validated against actual operations and contracts.
Purpose: Terms governing sandbox and production API/webhook access.
Audience: Developers, enterprise integrations, white-label partners and embedded platforms
1. Scope
These API Terms apply to access to Vahanse APIs, SDKs, sandbox environments, webhook endpoints, developer documentation and related credentials. A signed MSA/Order Form controls where inconsistent.
2. Credentials and Authentication
API keys, OAuth/JWT credentials, secrets and certificates are confidential. Customer must store them securely, restrict access, rotate them when required and notify Vahanse promptly of suspected compromise. Credentials may not be embedded in public client-side code where exposure is reasonably foreseeable.
3. Sandbox
Sandbox data may be synthetic, masked, incomplete or non-production. Sandbox responses are not evidence of production source availability or real vehicle/compliance status.
4. Permitted Use
APIs may be used only for the customer’s authorized product, fleet, customer or business purpose stated in the contract. Customer must have lawful authority to submit vehicle identifiers and process returned information.
5. Prohibited Use
- Unauthorized bulk enumeration or scraping of vehicle/person information.
- Credential sharing outside authorized systems.
- Resale or redistribution of raw API data except as expressly permitted.
- Attempting to identify persons or vehicles for harassment, surveillance or unlawful profiling.
- Circumventing rate limits, security controls or product entitlements.
- Using API responses to falsely claim government certification or guaranteed legal compliance.
- Reverse engineering protocols or exploiting vulnerabilities beyond legally protected security research channels.
6. Rate Limits and Fair Use
Rate limits, concurrency, daily/monthly quotas and burst limits are defined by plan or dynamically applied for stability/security. Vahanse may throttle abusive or anomalous traffic. Enterprise customers may request higher limits subject to capacity and commercials.
7. API Responses and Source Dependency
Responses may include information obtained from customer data, Vahanse systems, government systems or third-party sources. External sources may be unavailable, stale or inconsistent. Response metadata/status should be used to distinguish successful retrieval, no-record, pending, source unavailable and error conditions.
8. Caching and Retention
Customer may cache API data only for the period and purpose permitted by the contract, documentation, source restrictions and applicable law. Sensitive/personal data must not be retained merely because it is technically retrievable.
9. Webhooks
Customer is responsible for authenticating and securely receiving webhooks, handling retries/idempotency and preventing public exposure of webhook secrets. Vahanse may retry or disable failing webhook destinations in accordance with documentation.
10. Versioning and Deprecation
Vahanse may release new API versions and deprecate old versions. For material production APIs, Vahanse will use commercially reasonable efforts to provide advance deprecation notice unless immediate change is required for security, legal, source or third-party reasons.
11. Monitoring and Logs
Vahanse may log API requests, response metadata, authentication events and usage for billing, support, abuse prevention, security and audit. Customer should avoid placing unnecessary personal data in free-text request fields.
12. Fees
API fees may be subscription, minimum commitment, per-call, per-successful-response, per-vehicle, per-event or transaction-based as stated in the Commercial Schedule. Usage records maintained by Vahanse will control absent manifest error.
13. Security Incidents
Customer will immediately revoke/rotate compromised credentials and cooperate with Vahanse incident response. Vahanse may suspend API access to protect data or systems without liability for the period reasonably required to address a material security threat.
14. Data Protection
Personal data accessed through the API is subject to the DPA, Privacy Policy, customer instructions and applicable law. Customer may not expand the purpose of processing solely because an endpoint exposes additional fields.
15. Intellectual Property
Vahanse owns its APIs, documentation, SDKs and related technology. Customer owns its application. Any sample code is licensed under the terms stated with it or, if none, on a limited basis solely to integrate with Vahanse.
16. Availability
Any uptime/response commitments appear only in the SLA. Marketing statements, examples or historical response times are not contractual guarantees unless incorporated into an Order Form.
17. Suspension and Termination
Vahanse may suspend credentials for non-payment, abuse, source-policy breach, legal risk, security threat or material breach. On termination Customer must stop API calls and securely delete data where required.
18. Liability and Governing Terms
Liability, confidentiality, dispute resolution and governing law follow the signed MSA or, if none, the Platform Terms as applicable to a business user.