Addendum

OAuth Integrator Addendum

Rules for registering OAuth applications that request user data through TrueFans CONNECT™.

Effective: May 26, 2026
Last updated: May 26, 2026

This addendum supplements the Developer Agreement and Master Terms. It applies when you register or operate an OAuth application that requests TrueFans CONNECT™ user data through scopes.

1.Scope

You are the data controller for personal data your app receives through OAuth. We are a data processor or independent controller only with respect to the issuance of tokens and the identity assertions we make. Downstream use is your responsibility.

2.App Registration & Accuracy

  • Provide accurate app name, description, logo, support contact, privacy policy URL, terms-of-service URL, and redirect URIs.
  • Keep the privacy policy and terms-of-service URLs live and updated.
  • Do not use a name, logo, or description that misleads users about your identity, affiliation, or function (including resembling a TrueFans CONNECT™ product).

3.Scopes & Minimum-Necessary Access

  • Request only the scopes your app actually needs to deliver its disclosed functionality.
  • Do not use a granted scope to access data outside the disclosed purpose.
  • We may cap, gate, or deprecate scopes (e.g., access to donations, fan rosters, or financial detail) and may require app review before granting sensitive scopes.

5.Token Storage, Rotation & Revocation

  • Store client secrets and access/refresh tokens securely (encrypted at rest where feasible) and limit access on a need-to-know basis.
  • Do not embed client secrets in distributed mobile or single-page applications; use PKCE for public clients.
  • Implement timely revocation when users disconnect or when we instruct.
  • If you suspect a token leak, notify us at [email protected] and rotate immediately.

6.End-User Data Handling

  • Comply with all applicable privacy laws (GDPR, UK-GDPR, CCPA/CPRA, state laws, and others) for end-user data your app receives.
  • Do not sell, rent, or share end-user data to third parties except as necessary to provide your disclosed service and with valid legal basis.
  • Honor end-user rights to access, correct, delete, port, opt out, and limit processing where applicable.
  • Do not use special-category data (health, biometric, sexual orientation, etc.) absent explicit lawful basis.

7.Security & Incident Response

Maintain administrative, technical, and physical safeguards appropriate to the sensitivity of data your app handles. Promptly investigate suspected security incidents and notify us within 72 hours of discovering an incident involving TrueFans CONNECT™-sourced data, including a description of impacted users and remedial steps.

8.Branding & No Impersonation

  • You may indicate that your app "works with" or "integrates with" TrueFans CONNECT™ on factual statements.
  • You may not state or imply that your app is built, endorsed, certified, or operated by TrueFans CONNECT™ or its affiliates without written permission.
  • You may not use our logos, trademarks, or design assets except as permitted by our then-current brand guidelines.

9.Verification Status

We may, but are not required to, designate apps as "verified" based on review of identity, security practices, privacy posture, and product fit. Verification is a courtesy and may be revoked. Users may see warnings for unverified apps; users decide whether to proceed.

10.Suspension & De-Listing

We may suspend, throttle, de-list, or terminate any OAuth app at any time, with or without notice, for suspected violation of these Terms, security risk, privacy concerns, abuse reports, regulatory action, or our reasonable commercial judgment.