Info
QuotWay is a Shopify application developed and operated by EFOLI. These API Terms of Use apply to the QuotWay API and webhooks, and add to our Terms of Service.
API terms of use
Effective date: September 30, 2026 Last updated: September 30, 2026
These API Terms of Use ("API Terms") between QuotWay (a product of EFOLI) ("QuotWay", "we", "us", "our") and you apply to your use of the
QuotWay application programming interface at api.quotway.com, the
outbound webhooks QuotWay sends to endpoints you configure, the API
keys and webhook signing secrets we issue, and the related
documentation at /docs/api (together, the "API").
The API is part of the Service described in the QuotWay Terms of Service (the "Terms"). These API Terms add to the Terms; they do not replace them. If these API Terms and the Terms conflict on something specific to the API, these API Terms apply. Words defined in the Terms (such as "Service", "Merchant", and "Your Data") have the same meaning here.
By creating an API key, configuring a webhook endpoint, or calling the API, you accept these API Terms.
1. Who may use the API
1.1 Eligibility
The API is available to Shopify merchants who have installed QuotWay
and whose store is on a QuotWay plan that includes it - currently the
Enterprise plan, including an Enterprise free trial. The current
plan list is at /pricing.
If your store moves to a plan that doesn't include the API (for example, at the end of a trial or on a downgrade):
- API requests return an error that says a plan upgrade is required.
- Your API keys are kept, and they work again if you upgrade.
- Webhook deliveries are paused. Your endpoints are kept, not deleted.
1.2 Who "you" are
"You" means the merchant whose store an API key or webhook endpoint belongs to. Only a staff member with the Admin role in QuotWay can create, roll, or revoke API keys.
You may let someone else use the API on your behalf - for example, an agency, a systems integrator, an integration platform (iPaaS) such as Zapier, Make, or n8n, or your own ERP or CRM vendor. If you do:
- They act for you, and you are responsible for what they do with the API and with the data they receive through it, as if you had done it yourself.
- You must make sure they follow these API Terms.
- You must have a written agreement with them that is at least as protective of the data as these API Terms and your own privacy obligations.
A person or company that uses the API for more than one merchant (for example, an agency managing several stores) must use a separate API key issued by each merchant. Keys are tied to one store and can't be shared between stores.
1.3 Test keys
Test keys (they start with qw_test_) work only on Shopify
development stores. Live keys start with qw_live_.
2. API keys and security
2.1 Your responsibilities
An API key is a password for machine access to your store's quote data. Anyone who holds a key can do everything its scopes allow. You are responsible for all activity carried out with your keys.
You must:
- Keep keys secret. Store them in a secrets manager or an equivalent secure store. Don't put them in client-side code (such as browser JavaScript, theme code, or mobile apps), public repositories, URLs, tickets, chat messages, or email.
- Grant the fewest scopes needed. Give each integration only the scopes it needs (see §2.3). Use a separate key for each integration, so you can revoke one without breaking the others.
- Use the controls we provide where they make sense for you: an IP allowlist, an expiry date, and regular key rotation.
- Revoke a key as soon as it is no longer needed, or when a person or vendor with access to it leaves.
2.2 If a key or secret is exposed
If you know or suspect that an API key or a webhook signing secret has been exposed to someone who shouldn't have it, you must:
- Revoke the key (or rotate the webhook secret) right away in Settings → Integrations.
- Tell us at
security@quotway.comwithout undue delay, and in any case within 24 hours of becoming aware. Include the key's name and visible prefix (never the full key), when and how it was exposed, and what you have done.
We may revoke a key or disable an endpoint ourselves if we have reason to believe it has been exposed or misused (see §8). Where we can, we will tell you first.
Why the timing matters: QuotWay must notify Shopify within 24 hours of becoming aware of any actual or suspected compromise of merchant data (Shopify API License and Terms of Use §6.2.10). Your prompt report lets us meet that obligation and help you contain the exposure.
2.3 Scopes
Each key carries one or more scopes. A request that needs a scope the key doesn't have is refused.
| Scope | What it allows |
|---|---|
read_quotes |
Read quotes, quote events, and quote documents |
write_quotes |
Create quotes, post messages on quotes, and send a proposal you've already prepared in QuotWay |
read_customer_data |
Include buyer personal data in quote responses: name, email, phone, company name, shipping and billing addresses, custom-field answers, and notes |
read_analytics |
Read aggregate quote analytics |
manage_webhooks |
Create, list, and delete webhook endpoints |
read_customer_data gives access to buyers' personal data. Grant it
only to a system that genuinely needs buyer contact details - for
example, a CRM that must email buyers. Most reporting, fulfilment, and
automation integrations don't need it.
2.4 How we protect keys
We show a key's full value once, when you create or roll it. We store only a keyed hash of the key, so we can't show it to you again and our database alone can't be used to recover it. If you lose a key, roll or revoke it and create a new one.
3. Acceptable use
In addition to the acceptable-use rules in the Terms, you must not, and must not let anyone acting for you:
- Exceed or get around rate limits. This includes spreading
requests across multiple keys or stores to exceed the limits. The
current limits are published in the API documentation. When you
receive a
429response, back off until the time given in theRetry-Afterheader. - Get around scopes, plan limits, or other access controls, or access data belonging to a store you aren't authorized for.
- Scrape, crawl, or bulk-copy QuotWay data beyond what your own
integration reasonably needs. For example, don't repeatedly
re-download your full quote history when you could use the
updated_atfilters or the events feed. - Resell, sublicense, or provide the API as a service to third parties, or build a product whose main purpose is to extract and redistribute QuotWay data.
- Load test, stress test, or benchmark the API, or run automated
vulnerability scanners against it, without our prior written
permission. Ask at
security@quotway.com. - Probe for or exploit security vulnerabilities. Good-faith security research that follows our Vulnerability Disclosure Policy is welcome and is not a breach of these API Terms.
- Send spam or unsolicited messages through the API. Messages and proposals you send through the API reach real buyers by email, and they must be part of a genuine quote conversation.
- Use the API to process data you don't have the right to process, or in a way that breaks the law, the Terms, Shopify's terms, or a buyer's privacy choices.
- Use data obtained through the API to train, fine-tune, or improve machine-learning or artificial-intelligence models, except with the consents Shopify's terms require and only for your own store. Shopify's API License and Terms of Use (§2.3.24) restrict AI training on merchant data. We pass that restriction on here because the API gives you access to data that comes from Shopify.
- Misrepresent your integration. Don't name an integration or describe it in a way that suggests QuotWay or Shopify built, endorsed, or certified it.
4. Data protection
4.1 Roles
You are the controller (or the equivalent under the law that applies) of the data you retrieve from the API and of the data you send into QuotWay through it. When you use the API to send data to a system you choose - your ERP, CRM, data warehouse, integration platform, or agency:
- That transfer is made on your instructions.
- The recipient is your own processor or recipient. It is not a QuotWay sub-processor, and we don't control it.
- Once data leaves QuotWay and reaches your system or your recipient's system, it is outside our control and outside the QuotWay Privacy Policy. You are responsible for how it is used, secured, kept, and deleted.
QuotWay continues to process buyer data inside the Service as your processor, as described in the Privacy Policy.
4.2 Your obligations
For data you obtain through the API, you must:
- Have a lawful basis, and give buyers any notices and obtain any consents that applicable law requires, before sending their data to another system.
- Tell your buyers in your own privacy policy about the systems and recipients their data is shared with, where the law requires it.
- Use the minimum data needed. Request
read_customer_dataonly where your integration needs buyer personal data, and don't keep buyer data in downstream systems longer than you need it. - Secure it at least as well as these API Terms require, including encryption in transit and at rest, and restricting who can access it.
- Respect buyers' choices. This includes an opt-out of the "sale" or "sharing" of personal data, or a similar choice under the law that applies.
- Propagate deletion requests. When a buyer asks to have their
data erased, Shopify sends QuotWay a
customers/redactrequest and we erase the buyer's personal data held in QuotWay. We can't delete copies you have already taken out through the API. You must find and delete, or anonymise, those copies in your own systems and your recipients' systems, within 30 days of the request, or sooner if the law requires. - Handle data after you uninstall. When you uninstall QuotWay, your API keys stop working and webhook deliveries stop. We then delete your store's QuotWay data as described in the Privacy Policy. You remain responsible for the copies you have taken out. Some of that data originally came from Shopify's APIs, and Shopify requires apps to delete Shopify data within 30 days of uninstall (Shopify API License and Terms of Use §6.2.3). You must delete those copies, and have your recipients delete them, within 30 days of uninstalling, or sooner if Shopify's terms or the law require.
- Follow Shopify's terms. Comply with the Shopify API License and
Terms of Use, the Shopify Partner Program Agreement if it applies
to you or anyone acting for you, and - where you build on data
that comes from Shopify - Shopify's protected customer data
requirements (
shopify.dev/docs/apps/launch/protected-customer-data).
4.3 Personal data you send us
When you create quotes or post messages through the API, you are responsible for having the right to give us that data. We process it as your processor under the Privacy Policy, the same way we process data entered in the QuotWay admin.
4.4 Records of API use
We keep a log of every API request made with your keys. Each entry records the time, the key, the HTTP method, the endpoint pattern, the response status, the response time, and a one-way hash of the calling IP address. It does not include request or response bodies. You can see recent requests for each key in Settings → Integrations → API keys. Retention periods are in the Privacy Policy.
5. Webhooks
5.1 Your endpoints
You may register HTTPS endpoints to receive event notifications, from
the QuotWay admin or through the API with the manage_webhooks scope.
An integration platform acting for you may also register endpoints
this way. You must own or control every endpoint you register, or be
authorized by its owner to receive the data sent to it.
For security, we accept only https:// URLs on standard ports, and we
refuse URLs that point to private, internal, or reserved network
addresses.
5.2 What we send
Webhook payloads are deliberately minimal. They identify the quote
and the event, and include a small snapshot of the quote: its number,
status, mode, currency, and totals. They don't include buyer
personal data. To get more detail, call the API using the url in
the payload; a key with the right scopes is needed.
5.3 Verify signatures
Every webhook is signed following the Standard Webhooks specification
(webhook-id, webhook-timestamp, webhook-signature headers). You
should:
- verify the signature on every delivery;
- reject deliveries with an old timestamp;
- keep your signing secret as safe as an API key (§2).
We aren't responsible for harm caused by your acting on a webhook whose signature you didn't verify.
5.4 Delivery is not guaranteed
- At-least-once. A webhook may be delivered more than once. Use the
webhook-idheader to de-duplicate. - No guaranteed order. Deliveries may arrive out of order. Use the
sequencevalue and the quote'supdated_atto order them, and fetch the quote from the API when you need its current state. - Retries, then stop. If your endpoint doesn't respond with a
success status, we retry on a back-off schedule for about four days,
then stop trying that delivery. You can recover missed events for up
to 30 days from the
/v1/eventsfeed. - Auto-disable. If an endpoint has failed continuously for five days, we disable it automatically and email you. You can re-enable it once it's fixed.
- Pauses. We may pause deliveries for all merchants during a security incident or operational emergency (see §8). Paused deliveries are held, not dropped, unless they later exceed the retry window.
Webhooks are a notification mechanism, not a guaranteed record. Don't rely on them as your only copy of any data.
6. Versioning, changes, and deprecation
Versions. The API is versioned in the URL (currently
/v1). Each response includes aQuotWay-Versionheader that identifies the response format.Additive changes. Within a version we may add things without notice: new endpoints, new optional request parameters, new fields in responses, new event types, and new values in existing enumerations. Build your integration to ignore fields and event types it doesn't recognise.
Breaking changes. A breaking change is one that removes or renames a field or endpoint, changes a field's meaning or type, or makes a request that works today fail. We make breaking changes only in a new version. We will announce the deprecation of a version or endpoint at least 6 months before we remove it. We announce through the changelog at
/changelogand by email to the merchant contact on file.Exceptions. We may make a breaking change with shorter notice, or none, where it is needed to:
- fix a security vulnerability;
- comply with the law or a requirement from Shopify;
- respond to a change in a Shopify API the Service depends on.
We will give as much notice as we reasonably can.
7. Availability and support
The API is provided on the same "as is" and "as available" basis as the rest of the Service (see the Terms). There is no uptime commitment, service-level agreement, or service credit for the API unless we have signed a separate written agreement with you that says otherwise.
We may change the rate limits, the request-size limits, or the number of keys or endpoints a store can have, to protect the Service. Where a change reduces what you can do, we will give reasonable notice unless it is urgent.
API support is provided through support@quotway.com. Include the
request_id from the response when you report a problem.
8. Suspension and termination
We may, without liability, revoke or suspend an API key, disable a webhook endpoint, reduce your rate limits, or suspend your access to the API, if we reasonably believe:
- you, or someone acting for you, have breached these API Terms or the Terms;
- a key or secret has been exposed or is being misused;
- your use threatens the security, integrity, or availability of the Service, or of other merchants' data;
- we must do so to comply with the law, a court order, or a requirement from Shopify.
We will tell you when we do this, and why, unless the law prevents us or telling you would make a security problem worse. Where the problem can be fixed, we will restore access once it has been fixed.
You may stop using the API at any time by revoking your keys and deleting your webhook endpoints. Your right to use the API ends automatically when your right to use the Service ends, or when your store no longer has a plan that includes the API (see §1.1).
The following survive the end of your API access: §4 (data protection) as it applies to data you have already obtained, §9, and §10.
9. Liability and indemnity
The disclaimers, limitation of liability, and indemnification sections of the Terms (§9, §10 and §11) apply to the API. In particular, your indemnity under the Terms covers claims arising from:
- your integrations;
- anyone acting for you;
- endpoints you configure;
- your use, disclosure, or retention of data obtained through the API
- including data you send to third-party systems.
10. Changes to these API Terms
We may update these API Terms. For material changes, we will give reasonable advance notice, as described in the Terms. The changes take effect on the stated effective date. Using the API after that date means you accept the changes.
11. Contact
- API questions and support:
support@quotway.com - Security reports and exposed keys:
security@quotway.com - Privacy:
privacy@quotway.com - Legal notices:
legal@quotway.com - Postal: QuotWay (a product of EFOLI), Dhaka, Bangladesh