Skip to content

Info

QuotWay is a Shopify application developed and operated by EFOLI. These API Terms of Use apply to the QuotWay API and webhooks, and add to our Terms of Service.

API terms of use

Effective date: September 30, 2026 Last updated: September 30, 2026

These API Terms of Use ("API Terms") between QuotWay (a product of EFOLI) ("QuotWay", "we", "us", "our") and you apply to your use of the QuotWay application programming interface at api.quotway.com, the outbound webhooks QuotWay sends to endpoints you configure, the API keys and webhook signing secrets we issue, and the related documentation at /docs/api (together, the "API").

The API is part of the Service described in the QuotWay Terms of Service (the "Terms"). These API Terms add to the Terms; they do not replace them. If these API Terms and the Terms conflict on something specific to the API, these API Terms apply. Words defined in the Terms (such as "Service", "Merchant", and "Your Data") have the same meaning here.

By creating an API key, configuring a webhook endpoint, or calling the API, you accept these API Terms.


1. Who may use the API

1.1 Eligibility

The API is available to Shopify merchants who have installed QuotWay and whose store is on a QuotWay plan that includes it - currently the Enterprise plan, including an Enterprise free trial. The current plan list is at /pricing.

If your store moves to a plan that doesn't include the API (for example, at the end of a trial or on a downgrade):

  • API requests return an error that says a plan upgrade is required.
  • Your API keys are kept, and they work again if you upgrade.
  • Webhook deliveries are paused. Your endpoints are kept, not deleted.

1.2 Who "you" are

"You" means the merchant whose store an API key or webhook endpoint belongs to. Only a staff member with the Admin role in QuotWay can create, roll, or revoke API keys.

You may let someone else use the API on your behalf - for example, an agency, a systems integrator, an integration platform (iPaaS) such as Zapier, Make, or n8n, or your own ERP or CRM vendor. If you do:

  • They act for you, and you are responsible for what they do with the API and with the data they receive through it, as if you had done it yourself.
  • You must make sure they follow these API Terms.
  • You must have a written agreement with them that is at least as protective of the data as these API Terms and your own privacy obligations.

A person or company that uses the API for more than one merchant (for example, an agency managing several stores) must use a separate API key issued by each merchant. Keys are tied to one store and can't be shared between stores.

1.3 Test keys

Test keys (they start with qw_test_) work only on Shopify development stores. Live keys start with qw_live_.


2. API keys and security

2.1 Your responsibilities

An API key is a password for machine access to your store's quote data. Anyone who holds a key can do everything its scopes allow. You are responsible for all activity carried out with your keys.

You must:

  • Keep keys secret. Store them in a secrets manager or an equivalent secure store. Don't put them in client-side code (such as browser JavaScript, theme code, or mobile apps), public repositories, URLs, tickets, chat messages, or email.
  • Grant the fewest scopes needed. Give each integration only the scopes it needs (see §2.3). Use a separate key for each integration, so you can revoke one without breaking the others.
  • Use the controls we provide where they make sense for you: an IP allowlist, an expiry date, and regular key rotation.
  • Revoke a key as soon as it is no longer needed, or when a person or vendor with access to it leaves.

2.2 If a key or secret is exposed

If you know or suspect that an API key or a webhook signing secret has been exposed to someone who shouldn't have it, you must:

  1. Revoke the key (or rotate the webhook secret) right away in Settings → Integrations.
  2. Tell us at security@quotway.com without undue delay, and in any case within 24 hours of becoming aware. Include the key's name and visible prefix (never the full key), when and how it was exposed, and what you have done.

We may revoke a key or disable an endpoint ourselves if we have reason to believe it has been exposed or misused (see §8). Where we can, we will tell you first.

Why the timing matters: QuotWay must notify Shopify within 24 hours of becoming aware of any actual or suspected compromise of merchant data (Shopify API License and Terms of Use §6.2.10). Your prompt report lets us meet that obligation and help you contain the exposure.

2.3 Scopes

Each key carries one or more scopes. A request that needs a scope the key doesn't have is refused.

Scope What it allows
read_quotes Read quotes, quote events, and quote documents
write_quotes Create quotes, post messages on quotes, and send a proposal you've already prepared in QuotWay
read_customer_data Include buyer personal data in quote responses: name, email, phone, company name, shipping and billing addresses, custom-field answers, and notes
read_analytics Read aggregate quote analytics
manage_webhooks Create, list, and delete webhook endpoints

read_customer_data gives access to buyers' personal data. Grant it only to a system that genuinely needs buyer contact details - for example, a CRM that must email buyers. Most reporting, fulfilment, and automation integrations don't need it.

2.4 How we protect keys

We show a key's full value once, when you create or roll it. We store only a keyed hash of the key, so we can't show it to you again and our database alone can't be used to recover it. If you lose a key, roll or revoke it and create a new one.


3. Acceptable use

In addition to the acceptable-use rules in the Terms, you must not, and must not let anyone acting for you:

  1. Exceed or get around rate limits. This includes spreading requests across multiple keys or stores to exceed the limits. The current limits are published in the API documentation. When you receive a 429 response, back off until the time given in the Retry-After header.
  2. Get around scopes, plan limits, or other access controls, or access data belonging to a store you aren't authorized for.
  3. Scrape, crawl, or bulk-copy QuotWay data beyond what your own integration reasonably needs. For example, don't repeatedly re-download your full quote history when you could use the updated_at filters or the events feed.
  4. Resell, sublicense, or provide the API as a service to third parties, or build a product whose main purpose is to extract and redistribute QuotWay data.
  5. Load test, stress test, or benchmark the API, or run automated vulnerability scanners against it, without our prior written permission. Ask at security@quotway.com.
  6. Probe for or exploit security vulnerabilities. Good-faith security research that follows our Vulnerability Disclosure Policy is welcome and is not a breach of these API Terms.
  7. Send spam or unsolicited messages through the API. Messages and proposals you send through the API reach real buyers by email, and they must be part of a genuine quote conversation.
  8. Use the API to process data you don't have the right to process, or in a way that breaks the law, the Terms, Shopify's terms, or a buyer's privacy choices.
  9. Use data obtained through the API to train, fine-tune, or improve machine-learning or artificial-intelligence models, except with the consents Shopify's terms require and only for your own store. Shopify's API License and Terms of Use (§2.3.24) restrict AI training on merchant data. We pass that restriction on here because the API gives you access to data that comes from Shopify.
  10. Misrepresent your integration. Don't name an integration or describe it in a way that suggests QuotWay or Shopify built, endorsed, or certified it.

4. Data protection

4.1 Roles

You are the controller (or the equivalent under the law that applies) of the data you retrieve from the API and of the data you send into QuotWay through it. When you use the API to send data to a system you choose - your ERP, CRM, data warehouse, integration platform, or agency:

  • That transfer is made on your instructions.
  • The recipient is your own processor or recipient. It is not a QuotWay sub-processor, and we don't control it.
  • Once data leaves QuotWay and reaches your system or your recipient's system, it is outside our control and outside the QuotWay Privacy Policy. You are responsible for how it is used, secured, kept, and deleted.

QuotWay continues to process buyer data inside the Service as your processor, as described in the Privacy Policy.

4.2 Your obligations

For data you obtain through the API, you must:

  1. Have a lawful basis, and give buyers any notices and obtain any consents that applicable law requires, before sending their data to another system.
  2. Tell your buyers in your own privacy policy about the systems and recipients their data is shared with, where the law requires it.
  3. Use the minimum data needed. Request read_customer_data only where your integration needs buyer personal data, and don't keep buyer data in downstream systems longer than you need it.
  4. Secure it at least as well as these API Terms require, including encryption in transit and at rest, and restricting who can access it.
  5. Respect buyers' choices. This includes an opt-out of the "sale" or "sharing" of personal data, or a similar choice under the law that applies.
  6. Propagate deletion requests. When a buyer asks to have their data erased, Shopify sends QuotWay a customers/redact request and we erase the buyer's personal data held in QuotWay. We can't delete copies you have already taken out through the API. You must find and delete, or anonymise, those copies in your own systems and your recipients' systems, within 30 days of the request, or sooner if the law requires.
  7. Handle data after you uninstall. When you uninstall QuotWay, your API keys stop working and webhook deliveries stop. We then delete your store's QuotWay data as described in the Privacy Policy. You remain responsible for the copies you have taken out. Some of that data originally came from Shopify's APIs, and Shopify requires apps to delete Shopify data within 30 days of uninstall (Shopify API License and Terms of Use §6.2.3). You must delete those copies, and have your recipients delete them, within 30 days of uninstalling, or sooner if Shopify's terms or the law require.
  8. Follow Shopify's terms. Comply with the Shopify API License and Terms of Use, the Shopify Partner Program Agreement if it applies to you or anyone acting for you, and - where you build on data that comes from Shopify - Shopify's protected customer data requirements (shopify.dev/docs/apps/launch/protected-customer-data).

4.3 Personal data you send us

When you create quotes or post messages through the API, you are responsible for having the right to give us that data. We process it as your processor under the Privacy Policy, the same way we process data entered in the QuotWay admin.

4.4 Records of API use

We keep a log of every API request made with your keys. Each entry records the time, the key, the HTTP method, the endpoint pattern, the response status, the response time, and a one-way hash of the calling IP address. It does not include request or response bodies. You can see recent requests for each key in Settings → Integrations → API keys. Retention periods are in the Privacy Policy.


5. Webhooks

5.1 Your endpoints

You may register HTTPS endpoints to receive event notifications, from the QuotWay admin or through the API with the manage_webhooks scope. An integration platform acting for you may also register endpoints this way. You must own or control every endpoint you register, or be authorized by its owner to receive the data sent to it.

For security, we accept only https:// URLs on standard ports, and we refuse URLs that point to private, internal, or reserved network addresses.

5.2 What we send

Webhook payloads are deliberately minimal. They identify the quote and the event, and include a small snapshot of the quote: its number, status, mode, currency, and totals. They don't include buyer personal data. To get more detail, call the API using the url in the payload; a key with the right scopes is needed.

5.3 Verify signatures

Every webhook is signed following the Standard Webhooks specification (webhook-id, webhook-timestamp, webhook-signature headers). You should:

  • verify the signature on every delivery;
  • reject deliveries with an old timestamp;
  • keep your signing secret as safe as an API key (§2).

We aren't responsible for harm caused by your acting on a webhook whose signature you didn't verify.

5.4 Delivery is not guaranteed

  • At-least-once. A webhook may be delivered more than once. Use the webhook-id header to de-duplicate.
  • No guaranteed order. Deliveries may arrive out of order. Use the sequence value and the quote's updated_at to order them, and fetch the quote from the API when you need its current state.
  • Retries, then stop. If your endpoint doesn't respond with a success status, we retry on a back-off schedule for about four days, then stop trying that delivery. You can recover missed events for up to 30 days from the /v1/events feed.
  • Auto-disable. If an endpoint has failed continuously for five days, we disable it automatically and email you. You can re-enable it once it's fixed.
  • Pauses. We may pause deliveries for all merchants during a security incident or operational emergency (see §8). Paused deliveries are held, not dropped, unless they later exceed the retry window.

Webhooks are a notification mechanism, not a guaranteed record. Don't rely on them as your only copy of any data.


6. Versioning, changes, and deprecation

  • Versions. The API is versioned in the URL (currently /v1). Each response includes a QuotWay-Version header that identifies the response format.

  • Additive changes. Within a version we may add things without notice: new endpoints, new optional request parameters, new fields in responses, new event types, and new values in existing enumerations. Build your integration to ignore fields and event types it doesn't recognise.

  • Breaking changes. A breaking change is one that removes or renames a field or endpoint, changes a field's meaning or type, or makes a request that works today fail. We make breaking changes only in a new version. We will announce the deprecation of a version or endpoint at least 6 months before we remove it. We announce through the changelog at /changelog and by email to the merchant contact on file.

  • Exceptions. We may make a breaking change with shorter notice, or none, where it is needed to:

    • fix a security vulnerability;
    • comply with the law or a requirement from Shopify;
    • respond to a change in a Shopify API the Service depends on.

    We will give as much notice as we reasonably can.


7. Availability and support

The API is provided on the same "as is" and "as available" basis as the rest of the Service (see the Terms). There is no uptime commitment, service-level agreement, or service credit for the API unless we have signed a separate written agreement with you that says otherwise.

We may change the rate limits, the request-size limits, or the number of keys or endpoints a store can have, to protect the Service. Where a change reduces what you can do, we will give reasonable notice unless it is urgent.

API support is provided through support@quotway.com. Include the request_id from the response when you report a problem.


8. Suspension and termination

We may, without liability, revoke or suspend an API key, disable a webhook endpoint, reduce your rate limits, or suspend your access to the API, if we reasonably believe:

  • you, or someone acting for you, have breached these API Terms or the Terms;
  • a key or secret has been exposed or is being misused;
  • your use threatens the security, integrity, or availability of the Service, or of other merchants' data;
  • we must do so to comply with the law, a court order, or a requirement from Shopify.

We will tell you when we do this, and why, unless the law prevents us or telling you would make a security problem worse. Where the problem can be fixed, we will restore access once it has been fixed.

You may stop using the API at any time by revoking your keys and deleting your webhook endpoints. Your right to use the API ends automatically when your right to use the Service ends, or when your store no longer has a plan that includes the API (see §1.1).

The following survive the end of your API access: §4 (data protection) as it applies to data you have already obtained, §9, and §10.


9. Liability and indemnity

The disclaimers, limitation of liability, and indemnification sections of the Terms (§9, §10 and §11) apply to the API. In particular, your indemnity under the Terms covers claims arising from:

  • your integrations;
  • anyone acting for you;
  • endpoints you configure;
  • your use, disclosure, or retention of data obtained through the API
    • including data you send to third-party systems.

10. Changes to these API Terms

We may update these API Terms. For material changes, we will give reasonable advance notice, as described in the Terms. The changes take effect on the stated effective date. Using the API after that date means you accept the changes.


11. Contact

  • API questions and support: support@quotway.com
  • Security reports and exposed keys: security@quotway.com
  • Privacy: privacy@quotway.com
  • Legal notices: legal@quotway.com
  • Postal: QuotWay (a product of EFOLI), Dhaka, Bangladesh

We’d like to set analytics cookies to understand how the site is used. They’re not required — declining changes nothing about how the site works, and you can change your mind any time on our privacy page.