Terms of Service
Last updated: 14 July 2026
These Terms of Service ("Terms") govern access to and use of lockapi, an API platform that lets a tenant ("you", "Tenant") connect and control smart locks from multiple vendors through one unified API. By creating an account or using the API, you agree to these Terms.
1. The service
lockapi provides a REST API and dashboard for linking vendor lock accounts (TTLock, Nuki, Akiles, Tedee, and others as added), managing devices, and issuing time-bound access codes to your own end users ("Guests"). lockapi does not manufacture or install physical locks and is not responsible for hardware failure, lock/gateway connectivity, or a vendor's own API availability.
2. Accounts and API keys
You are responsible for maintaining the confidentiality of your dashboard credentials and API keys, and for all activity under your account. Notify us immediately of any suspected key compromise so it can be revoked. API keys are prefixed sk_test_ or sk_live_ — TEST-mode keys never touch real vendor hardware; LIVE-mode keys do. Do not use a LIVE key in a context where a TEST key would do.
3. Acceptable use
You may not use lockapi to:
- Obtain or attempt to obtain unauthorized physical access to a property or lock;
- Register a webhook endpoint or perform requests intended to probe, scan, or reach internal/private network addresses (including cloud metadata endpoints) reachable from our infrastructure;
- Circumvent rate limits, attempt credential stuffing, or otherwise abuse the authentication endpoints;
- Resell or sublicense API access outside your own product without our written consent;
- Violate any applicable law, including data protection law in the jurisdictions where your Guests are located.
4. Your responsibilities as a data controller
For any Guest data you submit to lockapi (name, access codes, unlock activity), you are the data controller and lockapi is your data processor — see the Privacy Policy for what that means in practice. You are responsible for having a valid legal basis to collect and share that Guest data with us, and for your own obligations to your Guests (notices, consent where required, honoring their rights).
5. Billing
Paid usage is billed via Stripe on a usage basis (active LIVE-mode device count), per the plan shown in your dashboard at signup. TEST-mode usage is never billed. Fees are non-refundable except as required by law.
6. Availability
lockapi is provided on an "as available" basis. We do not currently offer a contractual uptime SLA. Physical lock operations depend on third-party vendor APIs and hardware (gateways, bridges, network connectivity) outside our control, and can fail or report an uncertain result even when our own systems are healthy.
7. Intellectual property
We retain all rights to the lockapi platform, API, and dashboard. You retain all rights to your own data and to content you submit through the API. You grant us a license to process that data solely to provide the service.
8. Disclaimer of warranties
THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT PHYSICAL LOCK OPERATIONS WILL SUCCEED OR THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE.
9. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS WILL NOT EXCEED THE FEES YOU PAID US IN THE 12 MONTHS PRECEDING THE CLAIM, AND WE WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, OR CONSEQUENTIAL DAMAGES, INCLUDING DAMAGES ARISING FROM A FAILED OR DELAYED PHYSICAL UNLOCK.
10. Indemnification
You agree to indemnify and hold us harmless from claims arising from your use of the service in violation of these Terms or applicable law, including claims brought by your Guests relating to data you submitted about them.
11. Termination
Either party may terminate at any time. We may suspend or terminate access immediately for a material breach of these Terms, including violations of the acceptable use section above. On termination, your API keys are revoked and your data is handled per the retention terms in the Privacy Policy.
12. Governing law
These Terms are governed by the laws of Spain, without regard to conflict-of-law principles, and subject to the exclusive jurisdiction of the courts of Spain, unless mandatory local consumer-protection law provides otherwise.
13. Changes to these Terms
We may update these Terms from time to time. Material changes will be notified via the dashboard or the email on file. Continued use after a change takes effect constitutes acceptance.
14. Contact
Questions about these Terms can be sent to the contact address listed in your dashboard.