Skip to main content
Closed binder and pen on a steel bench under gold lamp light, dark mist behind.

Partner API Terms

Separate from Consumer Terms. Versioned. Acceptance required before credential claim.

Version 1.0. Effective 2026-08-22.

These Partner API Terms (the “Partner Terms”) govern access to and use of the TRIGR Partner API, Partner Portal, sandbox and production API credentials, webhooks, and related developer documentation (together, the “Partner API”).

They apply to Partner organizations, authorized Partner contacts, and systems that use Partner API credentials. They do not apply to ordinary TRIGR consumer app users. Consumer use of TRIGR is governed by the separate TRIGR Terms of Service and Privacy Policy.

The Partner API is invite-only and staff-managed. It is not a public entitlement.

Contracting party

These Partner Terms are between you (the Partner) and Creative Lid LLC (“TRIGR,” “we,” “us”).

If TRIGR and a Partner have a separate signed written agreement governing API access and that agreement conflicts with these Partner Terms, the signed written agreement controls for that conflict.

Acceptance

An authorized Partner contact must accept the current material Partner Terms version before claiming any API credential (sandbox or production). Acceptance is recorded with the Partner organization, the accepting contact, the Terms version, and the acceptance timestamp.

Accepting the Partner Terms does not grant scopes, approve production access, change rate limits, create credentials, or reactivate a suspended Partner. Those remain staff-controlled authorization decisions.

Staff cannot mark Partner Terms as accepted on a Partner’s behalf.

API access

API access is granted by TRIGR, limited by environment (sandbox or production), controlled through API credentials and assigned scopes, and subject to rate limits and quotas. Credentials grant only the access TRIGR specifically authorizes.

Production access additionally requires active Partner status, staff authorization, permitted production access, a valid production credential, approved scopes, and current required Partner Terms acceptance.

Credentials and security

API credentials remain controlled by TRIGR. Partners may not transfer access to another organization, sell credentials, allow unrelated third parties to use them, or use them outside approved integration purposes unless TRIGR gives written approval.

Partners must reasonably protect API credentials, secret values, webhook signing secrets, and Partner Portal access. Do not publish credentials, commit them to public repositories, or share them beyond authorized systems and personnel. Rotate compromised credentials and notify TRIGR promptly of suspected compromise.

Scopes and resource authorization

Every credential has assigned permissions (scopes). Scopes determine the types of permitted actions. Partners may not bypass scopes, attempt unauthorized endpoints, attempt privilege escalation, exploit authorization weaknesses, or access resources outside their authorization.

Possession of a credential does not mean unrestricted access to TRIGR data. Even with a broad scope (for example a shooter-profile read scope), access remains limited by assigned scopes, applicable authorization, available data, privacy rules, and the Partner relationship.

Sandbox

The sandbox environment is for development and testing. It is isolated from production, may contain synthetic or test data, may be reset or modified, should not be relied on as permanent storage, and may differ from production while features evolve. Sandbox has no service-level agreement.

Rate limits and quotas

API access may include per-minute limits, burst limits, daily or monthly quotas, endpoint-specific limits, and custom Partner limits. Partners may not attempt to bypass limits using multiple credentials, distributed systems, credential cycling, or other evasion.

TRIGR does not currently bill for Partner API usage. These Partner Terms do not create API subscription or invoice obligations.

Authorized use

Use the Partner API only for authorized integration purposes. Prohibited uses include unrelated scraping, unauthorized datasets, enumerating private users, unauthorized account access, cross-partner data access, privilege escalation, denial-of-service behavior, intentionally malformed or malicious traffic, and unlawful activity.

Data access and partner responsibilities

The Partner API may expose appropriately authorized data related to shooter profiles, matches, match results, and competition information. Actual access depends on assigned scopes, environment, data authorization, the Partner relationship, and API design. These Partner Terms do not imply every Partner receives every category of data.

Where a Partner receives personal information through the API, the Partner must use it only for the approved integration, maintain reasonable security, restrict access appropriately, comply with applicable privacy obligations, avoid unnecessary retention, and respect deletion or correction restrictions communicated through the service where applicable. These Partner Terms are not a full Data Processing Agreement.

Partners should not intentionally collect or store more TRIGR personal information than reasonably required for the authorized integration.

Permitted use of API-derived data

Permitted use of API-derived data is governed by assigned scopes, resource authorization, API documentation, these Partner Terms, and any written Partner-specific agreement. Depending on the integration, that may include displaying, caching, synchronizing, or providing competition/result functionality to users.

Possession of an API credential never grants unrestricted rights to TRIGR or shooter data. A separate written Partner agreement may further restrict or expand permitted use.

Partner writes and submissions

Where write permissions exist, Partner-supplied data must be submitted under proper authorization, must not intentionally contain malicious content, must not violate known rights, and must be reasonably accurate to the extent within the Partner’s control.

TRIGR receives the limited rights needed to receive, store, process, normalize, associate, display, and use that data within the authorized TRIGR service. The Partner retains ownership of its own data subject to third-party rights.

Competition data and provenance

Competition information can have multiple sources, including TRIGR, the Partner, a match organization, a scoring system, a shooter, or another provider. TRIGR does not claim ownership of everything it stores or displays. A Partner does not own an entire multi-source match merely because it submitted data.

TRIGR may identify source, provider, external IDs, ingestion date, and submitting Partner for match or results data. Partners must not intentionally misrepresent the source of submitted information.

API documentation

Partners must follow current documented API behavior for authentication, versioning, pagination, idempotency, errors, scopes, rate limits, and webhooks. Use required idempotency mechanisms where documented. Low-level header names and payload shapes belong in API documentation, not in these Partner Terms.

Webhooks

Partners are responsible for reasonably protecting webhook signing secrets, validating signatures, accepting duplicate or retried events safely, maintaining valid endpoints, and securing webhook receivers.

TRIGR may disable webhook endpoints that repeatedly fail, create security risk, violate these Partner Terms, or are misconfigured.

Partners may not intentionally configure webhook endpoints designed to access TRIGR internal systems, exploit network infrastructure, attack private or internal services, misuse redirect behavior, or exploit SSRF-style weaknesses.

Security and incidents

Partners must use reasonable integration security, including HTTPS where applicable, credential protection, access controls, prompt reporting of credential compromise, no unauthorized security testing against production, and no attempts to bypass controls. These Partner Terms do not require specific third-party certifications.

Partners should notify TRIGR promptly and without unreasonable delay after becoming aware of compromised API credentials, compromised webhook secrets, unauthorized TRIGR-data access, or a material security incident involving TRIGR data.

Branding

These Partner Terms do not require mandatory “Powered by TRIGR” attribution. Partners may not misuse TRIGR trademarks, logos, or branding, or imply endorsement beyond the actual relationship. Any required co-branding must be agreed separately in writing.

Intellectual property

TRIGR retains rights in the Partner API, API implementation, documentation, TRIGR SDKs if created, TRIGR branding, and TRIGR-owned technology. The Partner retains rights in Partner software, integration code, and Partner-owned data, subject to third-party rights.

No exclusivity

API access does not create an exclusive partnership unless a separate signed agreement explicitly says so. TRIGR remains free to work with other integrations and providers.

API versioning and availability

APIs evolve. TRIGR will use reasonable versioning, documentation, deprecation notices, and migration guidance where practical. These Partner Terms do not promise a fixed multi-month compatibility window.

The Partner API is provided on an as-available basis, subject to maintenance, outages, security incidents, and infrastructure changes. There is no formal uptime SLA in these Partner Terms. Strategic Partners may negotiate separate guarantees in a written agreement.

TRIGR does not promise 24/7 support, guaranteed response times, a dedicated support engineer, or a dedicated account manager unless separately agreed in writing.

Material Partner Terms updates

Material Partner Terms updates receive a new version and effective date. Editorial changes (typos, formatting, non-substantive clarifications) do not require Partner reacceptance.

For a material update, TRIGR will publish the new version, email notice to active authorized Partner contacts, display a prominent reacceptance notice in the Partner Portal, mark the Partner as reacceptance required, and allow existing API integrations to continue during a 30-calendar-day grace period. Claims of new credentials remain blocked until the current Terms are accepted. Reasonable reminder notices may be sent during the grace period.

If the Partner has not accepted by the end of the grace period, TRIGR may suspend API access and affected webhook delivery until acceptance. Partner Portal access remains available so an authorized contact can review and accept. TRIGR will not delete credentials, Partner records, historical competition records, or audit history merely because acceptance expired.

After an authorized contact accepts the current Terms, otherwise-valid API access is restored automatically where practical (Partner active, credential active, scopes valid, credential not expired or revoked, no separate suspension).

TRIGR may use a shorter notice period or an immediate change where reasonably required for law or regulation, urgent security issues, abuse prevention, or protecting TRIGR or users. That exception is not a loophole for routine Terms changes.

Suspension and termination

TRIGR may suspend API access for credential compromise, security concerns, abuse, unlawful activity, rate-limit circumvention, material Partner Terms violations, risk to TRIGR or users, or partnership termination. Suspension does not erase historical audit records.

When API access ends, credentials stop working, production access stops, applicable webhook delivery stops, and the Partner must stop unauthorized API usage. Continuing data and security obligations remain where applicable. Termination does not automatically erase shared historical competition data or corrupt matches, rankings, or results involving other users.

Confidentiality

Each party should treat non-public technical and commercial information received from the other in connection with the Partner API as confidential and use it only for the Partner relationship, except for information that is public, independently developed, or required to be disclosed by law. These Partner Terms are not a full mutual NDA. Strategic Partners may execute a separate NDA.

Disclaimer and limitation of liability

The Partner API is provided as-is and as-available. To the extent permitted by law, TRIGR disclaims warranties of merchantability, fitness for a particular purpose, and non-infringement.

To the extent permitted by law, TRIGR is not liable for indirect, incidental, special, consequential, or exemplary damages arising from Partner API use. These Partner Terms do not set a fixed dollar liability cap.

Governing law and venue

These Partner Terms are governed by the laws of the State of Arizona and the United States, without regard to conflict-of-law rules that would send the dispute elsewhere. Exclusive venue for disputes is the state and federal courts located in Maricopa County, Arizona, except where a separately negotiated written Partner agreement provides otherwise.

Contact

Partner legal and security notices related to these Partner Terms may be sent through the TRIGR contact form on trigr.app, or other channels TRIGR designates for Partners.

Related: Developers · Privacy Policy · Consumer Terms.