OAuth Addendum
Last updated: August 14th, 2025
This OAuth Addendum (“Addendum”) supplements, forms part of, and is incorporated by reference into the seats.aero Terms and Conditions (the “Terms”). Capitalized terms used but not defined here have the meanings given in the Terms. If there is a conflict between this Addendum and the Terms, this Addendum controls solely for your development, distribution, and operation of OAuth applications that access the seats.aero Service; the Terms control in all other respects.
1. Scope
This Addendum applies to any software application, integration, script, service, or tool you build or operate that uses OAuth to access the seats.aero Service or seats.aero Data (each, an “OAuth App”). By creating an OAuth App, you agree to this Addendum and the Terms.
2. Key Definitions
- Developer means the individual or entity registering and operating the OAuth App.
- End User means a natural person who completes the OAuth consent flow and whose seats.aero account authorizes your OAuth App.
- seats.aero Data or Data means any content, information, responses, or metadata returned by the Service ("seats.aero Service") or otherwise obtained via OAuth (including any derived reconstructions of the same).
- Short-Term Caching means strictly ephemeral storage used only to improve performance of your OAuth App, retained for no longer than 24 hours from collection and automatically purged thereafter.
3. Incorporation by Reference
The Terms (including, without limitation, limitations of liability, disclaimers, acceptable use, and dispute resolution) are incorporated here by reference and apply to your OAuth App and your processing of seats.aero Data. Without limiting the foregoing, any use restrictions in the Terms also apply to your OAuth App.
4. Attribution
Whenever your OAuth App displays seats.aero Data to End Users, you must provide clear, legible attribution to seats.aero with a link to https://seats.aero. Attribution must be proximate to the Data (e.g., “Data from seats.aero” or “Powered by seats.aero”) and of equal prominence to any other data-source credits. You may not elsewhere use seats.aero trade names, trademarks, or logos except as permitted by our brand guidelines or with our prior written permission.
5. Data Handling & Storage
- No persistent storage. You may not store seats.aero Data except for Short-Term Caching. Caches must be purely operational and automatically purged within 24 hours.
- No databases. You may not build or maintain offline replicas, archives, or derived datasets (including aggregations capable of reconstituting Data) beyond Short-Term Caching.
- Deletion on revocation. Upon End-User revocation, account closure, or our request, you must immediately cease access and purge all cached Data and tokens related to that End User.
- Written exceptions. Any deviation from the above requires our prior written consent.
6. Public App Requirement
Your OAuth App must be a public app available to external End Users. Private or internal-only apps are not permitted.
You must provide a public landing page describing the OAuth App, a privacy policy, and a support contact method.
7. End-User Consent & Token Isolation
- Individual consent. Each End User must complete the OAuth consent flow themselves. You may not use shared, pooled, or service-account credentials to access multiple End User's data.
- No commingling. Access tokens, refresh tokens, and related secrets must be logically and physically isolated per End User. Do not combine or reuse tokens across accounts.
- Least privilege. Request only the minimum OAuth scopes required for your functionality. You must not attempt to circumvent OAuth, scopes, or authorization screens.
8. Security Requirements
All token exchanges and API calls must use TLS (HTTPS) with current industry standards. Store client secrets and tokens securely (e.g., a secrets manager or KMS). Never embed secrets in client-side code. Rotate credentials and keys regularly and upon suspicion of compromise.
9. Review, Approval & Audit
Your OAuth App is subject to our review, approval, rejection, or removal at any time in our sole discretion. On request, you must provide testing access, documentation, security controls, privacy materials, or other reasonable information.
We may monitor usage for compliance (including via automated means) and may throttle, suspend, or revoke access for suspected violations or risk.
10. Security Incidents
You must notify us at developers@seats.aero within 24 hours of discovering any actual or suspected unauthorized access, breach, or misuse involving seats.aero Data, OAuth tokens, or the OAuth App. Notifications must include known scope, impact, and remediation steps. You must cooperate in investigation and mitigation.
11. Suspension & Termination
We may suspend or terminate your OAuth App or credentials immediately for any violation or risk to End Users, seats.aero, or our systems. Upon suspension or termination, you must stop all access and promptly delete all seats.aero Data and tokens.
12. Changes
We may update this Addendum from time to time. Material changes will be noted by updating the “Last updated” date above. Your continued use of OAuth after the effective date of any change constitutes acceptance of the updated Addendum.
Contact Us
If you have any questions about this OAuth Addendum, You can contact us:
- By email: developers@seats.aero