These API Terms of Service (“Terms”) govern access to and use of the Refurbed Seller API (formerly “Merchant API”, the “API”), operated by Refurbed Marketplace GmbH, Jakov-Lind-Straße 7, 1020 Vienna, Austria, registered with the Commercial Court Vienna under FN 590622 m (“refurbed”, “we”, “us”). The API is provided over HTTPS and RPC at api.refurbed.com and covers markets, currencies, shipping profiles, offers, market offers, orders, order items, trade-in bids, trade-in orders, tickets, and related resources.
They apply to every party that accesses the API (“you”), whether a refurbed seller or a third party acting for one or more sellers (integrators, channel-management systems, agencies).
You may use the API only as a refurbed seller, integration partner, or party otherwise authorised by refurbed. You accept these Terms by requesting credentials, confirming acceptance, or using the API. You are responsible for all activity under your credentials, must keep them confidential, and must not share, sell, sublicense, or expose them.
You may use the API solely to integrate your systems with refurbed for legitimate seller operations (managing offers, prices, stock, shipping profiles, orders, order items, trade in workflows), in compliance with applicable law, the refurbed Seller Guide, marketplace policies, and the technical documentation.
You must not access the API without authorisation or circumvent authentication, permissions, rate limits, or security controls; scrape, overload, disrupt, reverse engineer, or otherwise misuse it; submit false, misleading, unlawful, or infringing data; or interfere with marketplace operations.
You may use data obtained through the API only for your own seller operations on refurbed and for the authorised integration purpose. Unless expressly permitted by refurbed in writing (including by partner agreement or side letter), you must not (a) resell, sublicense, or redistribute API data to third parties, or (b) use API data to build, operate, or supply benchmarking, market-intelligence, or comparable products or services to third parties. refurbed may grant, condition, or withhold such permission at its discretion.
If you engage a third party to access the API on your behalf, or if you access the API on behalf of a seller: (a) the seller remains fully responsible for compliance with these Terms; (b) the seller must impose obligations at least as protective as these Terms on the service provider and is liable for the provider’s acts and omissions as for its own; and (c) where a party acts for more than one seller, it must maintain meaningful traceability of API actions to the seller concerned and, on request, identify the seller on whose behalf a request was made (e.g. via a meaningful client identifier and internal logs).
API requests must include valid credentials and may be rejected where credentials are missing, malformed, or invalid, or where you lack permission for the requested operation. Rate limits, quotas, permission checks, and other usage controls are set out in the technical documentation and may be applied, modified, or enforced by refurbed at any time.
You are responsible for the accuracy, completeness, and lawfulness of the data you submit. API actions may affect live marketplace operations, customer orders, pricing, availability, fulfilment, and returns, and take effect accordingly.
Where you process personal data received through the API (e.g. order data), you and refurbed each act as a separate, independent controller for your own purposes and not as joint controllers. You must comply with applicable data-protection law, including the GDPR; process such data only as necessary to fulfil refurbed transactions and related seller obligations; rely on a valid legal basis; and conclude an Art. 28 GDPR processor agreement with any provider processing it on your behalf.
You must maintain appropriate technical and organisational measures to protect your credentials and any data obtained through the API, and promptly notify refurbed of any suspected credential compromise, unauthorised access, vulnerability, or misuse. Penetration testing and vulnerability scanning require refurbed’s prior written approval.