This document describes the terms and conditions governing the use of the Footbar API, covering both the policy for developers and the terms of sale. It provides a comprehensive framework for developers and companies wishing to integrate the Footbar API into their projects. By accessing or using the Footbar API, you agree to comply with the guidelines and provisions set forth in this document.

Principles 

At Footbar, we are firmly committed to upholding the principles that guide developers in creating applications that not only harness the power of the Footbar API but also respect users' rights and privacy. These principles serve as the basis for responsible and ethical development:

  1. Respect for user data ownership: In line with the philosophy of the General Data Protection Regulation (GDPR), we recognize that player data belongs to the player. We insist that data should never be collected or stored without the user's clear and explicit consent, ensuring transparency in the use of their data.
  2. Privacy protection: Footbar user data must never be used for prohibited purposes, including the sale or use of data for advertising purposes. Developers must prioritize the protection of user privacy and refrain from any action that could compromise this fundamental right.
  3. Transparency and clarity: We emphasize the importance of accurate and comprehensive communication with players. Developers must provide clear explanations about the data collected, the purpose of the collection, and the intended use. Transparent communication helps cultivate trust between developers and users.
  4. Data control offered to users: In accordance with user rights, developers are required to honor requests to delete user data. Respecting user wishes reinforces the idea that data control ultimately lies in the hands of those to whom it pertains.
  5. Data security: Secure handling of user data is non-negotiable. Developers are required to implement robust security practices that ensure the integrity and confidentiality of user data. Demonstrating compliance with these security measures is essential to building user trust.
  6. Minimal and relevant permissions: Developers should only request permissions to access data that is necessary to perform the core functionality of their applications or services. This approach limits data exposure and promotes trust by minimizing unnecessary data manipulation.

These principles underscore our shared commitment to creating applications that not only leverage the capabilities of the Footbar API, but also align with ethical data practices and prioritize user privacy. By adhering to these principles, developers can create experiences that empower users while maintaining the highest standards of responsibility and respect.

Access and use policies 

The entire Footbar ecosystem is governed by this policy and by the Terms and Conditions of Saleterms and conditions of sale, the privacy policy and the legal notices of the Footbar online store, as well as the privacy policy of our mobile application. By using the Footbar API, you acknowledge and agree to adhere to the provisions set forth in this policy, as well as the associated policies and legal documents mentioned above.

Furthermore, as a user of the Footbar API, you are required to comply with all laws and regulations applicable to your use of the API and its associated services. It is your responsibility to keep yourself informed of all legal requirements relating to your use and to ensure that you comply with these conditions at all times. If, for any reason, you are unable to comply with these terms, you must immediately cease using our services.

We reserve the right to suspend and/or terminate your access to the Footbar API and its services if you fail to comply with this policy or if your actions are deemed to be in violation of applicable laws. It is essential that you regularly monitor your compliance with these terms in order to maintain a productive and compliant relationship with the Footbar API.

Appropriate use of the Footbar API  

The Footbar API is designed to enable developers to create applications that enhance the football player experience football respecting the values and goals of the Footbar ecosystem. Applications created using the Footbar API must align with one of the following goals: 

  • Rewarding football practice football Apps can enable football players football receive well-deserved rewards for their dedication and performance on the field.
  • Interaction with a community: Apps can facilitate the sharing of football players' achievements and progress football the entire community, thereby promoting a sense of camaraderie.
  • Performance improvement: Applications can provide football players football to track, measure, and improve their performance over time, contributing to their personal development.
  • Performance analysis and challenges: Apps can offer features that allow football players football their performance data, set challenges for themselves, and participate in friendly competitions to boost their motivation and skills.
  • Integration into a game: Applications can incorporate game elements inspired by football training, offering players an entertaining and immersive experience based on their athletic efforts.

It is important to note that any use case outside the objectives specified above requires explicit approval from the Footbar team. If you have a unique use case in mind that deviates from the predefined objectives, you must request approval by contacting us by e-mail at contact@footbar.com. We encourage innovation and creativity, while ensuring that applications created using the Footbar API remain in line with our values and objectives.

By adhering to these guidelines, developers contribute to an ecosystem that not only leverages the capabilities of the Footbar API, but also respects the integrity of its intent. Together, we can create applications that celebrate the game of football bringing value and enjoyment to players around the world.

Limited use of user data 

Data collected through the Footbar API, as well as all aggregated, anonymized, depersonalized, or derived data, is subject to the following restrictions to ensure responsible data management:

  • Your use of user data must be limited to providing or enhancing your appropriate use case or features that are easily visible and prominent in the requesting application's user interface.
  • Data transfers are only permitted in specific circumstances:
    • To provide or enhance your appropriate use case or user-oriented features, clearly discernible in the requesting application's user interface, and only with the user's consent.
    • For security reasons, for example to investigate abuse.
    • To comply with applicable laws and/or regulations.
    • In the event of a merger, acquisition, or sale of the developer's assets, provided that the user's explicit prior consent is obtained.
  • Human access to user data must be limited, unless
    • The user's explicit consent has been obtained to access specific data (for example, to facilitate password recovery).
    • The data (including derived data) is aggregated and anonymized and is used for internal operations in compliance with applicable legal requirements regarding confidentiality and jurisdiction.
    • It is essential for security purposes, such as investigations into abuse.
    • Compliance with applicable laws and/or regulations is required.

All other transfers, uses, or sales of user data are strictly prohibited, including, but not limited to, the transfer or sale of user data to third parties:

  • The transfer or sale of user data to third parties such as advertising platforms, data brokers, or information resellers, even when aggregated or anonymized.
  • The transfer, sale, or use of user data for advertising purposes, including personalized or interest-based advertising.
  • Using user data to determine creditworthiness or for lending purposes.
  • The use of user data in connection with products or services that may be considered medical devices.
  • The use of user data for purposes involving protected health information.
  • Use user data for activities related to player recruitment.
  • Participate in activities related to the trafficking of football players.

Access to Footbar user data may not be used in violation of this Policy or other applicable Footbar terms or policies, including the following:

  • Creating applications designed for sports other than football encouraging unconventional use of the Meteor tracker, contrary to Footbar's recommendations.
  • The use of Footbar APIs for applications, services, or features intended to collect or merge user data for research involving human subjects, medical research, or other similar activities.

In addition, your application must comply with the design guidelines and style guide provided by Footbar and display the phrase "stats provided by Footbar" in a clearly visible location.

Finally, it is important to note that use of the API does not grant permission to use the Footbar brand or logo, become a reseller of Footbar products, or engage in any activity that may infringe on Footbar's intellectual property rights.

Transparency and user control 

Since the Footbar API processes data related to football, which includes personal and sensitive information, it is imperative that all applications and services incorporate a comprehensive privacy policy. This policy must explain precisely how your application or service collects, uses, and shares user data. This involves detailing the specific entities with which user data is shared, the purpose for which the data is used, data storage procedures, security measures, and the protocol in place when an account is deactivated or deleted.

In addition, applications and services must request access to user data in the appropriate context. This approach makes it easier for users to understand what data they are providing, the justification for the data request, and the intended use of the data. In accordance with applicable laws, the following conditions must be met:

  • A disclosure obligation: Your practices regarding data access, collection, use, and sharing must be disclosed in such a way as to:
    • Precisely identify the application or service requesting access to user data.
    • Reside within the application itself for application-based interactions or in a separate dialog window for web-based interactions.
    • Present the disclosure transparently during normal use of the application or website, without requiring users to navigate through menus or settings.
    • Provide clear and accurate information defining the categories of data that are accessed, requested, and/or collected.
    • Explain how the data will be used and/or shared. If the data is requested for one purpose but is also intended for secondary use, both uses must be communicated to users.
    • Remain separate from unrelated information and cannot be relegated solely to privacy policies or terms of service.
  • Request for consent: Disclosure must accompany and immediately precede a request for user consent. The request for consent must:
    • Present the consent dialogue in a clear and unambiguous manner.
    • Require the user to take positive action (e.g., press the key to accept, check a box, verbally confirm) for consent to be granted.
    • Avoid interpreting actions such as navigating away from the disclosure (e.g., by typing elsewhere, using the "back" or "home" button) as consent.
    • Refrain from using automatic deletion or expiration messages as a consent mechanism.
  • User help documentation: You are responsible for providing user-friendly documentation describing the procedures for users to manage and delete their data from your application.

These measures enhance transparency and control over user data, fostering an environment of trust and accountability between developers and users. By adhering to these guidelines, developers play a vital role in creating a safe and respectful digital landscape.

Secure data management 

The sanctity of user data is of paramount importance to us. That is why we require strict measures to ensure that all Footbar user data remains secure both in transit and at rest. Developers must take reasonable and appropriate precautions to protect applications or systems that utilize Footbar user data from unauthorized access, misuse, destruction, loss, alteration, or disclosure.

Recommended and mandatory security practices to enhance data protection are described below:

Recommended security practices:

  • Information Security Management System (ISMS): Developers are encouraged to adopt and maintain an information security management system that complies with standards such as ISO/IEC 27001. This framework establishes a comprehensive approach to protecting information assets.
  • Robust application architecture: Implementing a robust application or web service structure, free from common security vulnerabilities listed in the OWASP Top 10, strengthens data integrity and protection against potential threats.

Required safety measures:

  • Encryption standards: Use an industry-recognized encryption standard to encrypt user data in the following cases:
    • Data stored on portable devices or portable electronic media.
    • Data stored outside of Footbar's or your systems.
    • Data transmitted over external networks that are not exclusively under the control of your administration.
    • Data at rest on your systems.
  • Secure data transmission: Use secure modern protocols (e.g., HTTPS) when transmitting data to ensure data integrity during transit.
  • Identification data encryption: Ensure that user data and credentials, especially tokens such as OAuth access and refresh tokens, are encrypted when at rest.
  • Key management: Manage keys and key hardware wisely, possibly by storing them in a hardware security module or in a key management system of equivalent robustness.

In addition, developers are required to promptly notify Footbar at contact@footbar.com of any known or suspected unauthorized access to systems, networks, accounts or other locations where Footbar user data is stored, a so-called "security breach". Developers must also cooperate fully with Footbar to rectify any confirmed or suspected security breach. In such cases, developers are expected to communicate with Footbar before making any public statement regarding the flaw.

By adhering to these secure data management practices, developers play a crucial role in preserving user trust and maintaining the sanctity of data within the Footbar ecosystem.

Flexibility of access and blocking

At Footbar, we understand that every developer's needs are unique. To accommodate this diversity, the Footbar API features a two-tiered access approach designed to cater to the preferences of both free and paid members. This approach combines flexibility and resource optimization, ensuring an efficient and tailored experience for all users. In addition, detailed information on throttling values and pricing can be found in the API specifications.

For those exploring the capabilities of the Footbar API or looking to integrate it into smaller-scale projects, our free version is an ideal starting point. This version has predefined throttling limits that ensure fair distribution of resources among users. These limits help maintain a high level of service quality while preventing abuse.

For developers with ambitious projects or larger user bases, our paid membership option offers expanded access and more generous limits. By subscribing to this option, developers unlock increased API usage capabilities, facilitating more frequent and comprehensive API requests.