Zonelytix legal
API and webhook terms
Version 1.1 · Last updated
Zonelytix exposes a small read-only public API for the track record, sends signed webhooks to endpoints you register, and serves the Expert Advisor through a private API. These terms govern all three and form part of the Terms of service.
Contents
- 1. What these terms cover
- 2. The public API
- 3. Outgoing webhooks
- 4. The Expert Advisor endpoints
- 5. Rate limits and fair use
- 6. Redistribution and attribution
- 7. Secrets, signatures and your endpoint
- 8. Availability and changes
- 9. Deprecation notice
- 10. Data you receive
- 11. No warranty, liability
- 12. Suspension and termination
- 13. General
1. What these terms cover
These terms apply to every programmatic interface we provide: the public endpoints under /api/public, outgoing webhooks configured in Settings → Webhooks, the Expert Advisor endpoints under /api/ea, and any SDK, sample code or documentation we publish for them (together, the “API”). By calling the API, registering a webhook or running the EA you accept these terms together with the Terms of service, the Disclaimer and, for the EA, the Expert Advisor licence.
2. The public API
The public endpoints return the same information as the public track record and the markets pages: closed signals published 10 minutes after they closed, aggregate statistics and the current public zones. They require no key, are served with permissive cross-origin headers and are rate limited by IP. They never return active signals, member data, approvals or anything behind a plan. Anyone may use them under these terms for personal, research, educational and non-competing commercial purposes, with attribution as set out below.
3. Outgoing webhooks
Members on plans that include webhooks may register HTTPS endpoints to receive events (new signal, signal update, signal closed, trade closed, and others listed in the webhook reference in Settings → Webhooks). Events contain only data your plan entitles you to see. Deliveries are signed, retried once on failure as documented, and are not guaranteed to arrive, to arrive once or to arrive in order. Your endpoint must respond quickly with a 2xx status, must verify the signature and timestamp, and must be yours or operated for you alone. An endpoint that keeps failing is paused automatically and shown as paused in Settings.
4. The Expert Advisor endpoints
The endpoints under /api/ea exist for the Zonelytix Bridge Expert Advisor and for software you write for your own linked MT5 accounts under the same protocol. They require a licence key and the matching account number, enforce your plan and settings on every call, and may be called only on behalf of accounts you control. Spoofing balances, fills or heartbeats, or using the endpoints to feed any account that is not linked to your Zonelytix account, is a breach of these terms and of the Expert Advisor licence.
5. Rate limits and fair use
- Rate limits are enforced per IP for the public API, per account for webhooks and per licence key for the EA endpoints. Current limits are returned in response headers and documented; they may change.
- Poll the public API no more often than the data changes: closed signals are added at most a few times an hour, statistics hourly. Cache responses and honour cache headers.
- Use pagination as documented. Do not enumerate the whole dataset repeatedly, run parallel crawlers, rotate IPs to evade limits or disguise automated traffic as a browser.
- A client that exceeds the limits receives 429 responses and should back off exponentially. Persistent abuse is blocked.
6. Redistribution and attribution
- Public data may be displayed, analysed and quoted with a visible attribution “Data: Zonelytix” linking to zonelytix.com, and with the disclaimer that results are hypothetical and not financial advice. You may not present it as your own track record, remove losing signals, or alter outcomes.
- Plan data received by webhook or by the EA endpoints, including active signals, is for your own use within your account. You may feed it into your own tools, dashboards and journals. You may not forward, publish, sell, broadcast or share it with anyone else, operate a signal service, group, channel or copy-trading offering on it, or use it to train a model or build a competing product. Each payload carries identifiers that let us trace leaks.
- You may not use the Zonelytix name or logo in a way that suggests we endorse your product, and you may not register domains, app names or social handles containing it.
7. Secrets, signatures and your endpoint
Webhook secrets and licence keys are shown once and stored hashed; we cannot recover them. Keep them out of client-side code, public repositories and screenshots. Rotate a secret immediately if it may have been exposed, from Settings. Verify every webhook with the documented HMAC signature and reject requests whose timestamp is older than five minutes. You are responsible for the security, availability and content of your endpoint and for anything done with a secret issued to you until you rotate or revoke it. Report a suspected compromise to security@zonelytix.com.
8. Availability and changes
The API is provided on an “as available” basis with no uptime commitment and no service credits. We may change, add or remove endpoints, fields, limits, event types and authentication methods. We may suspend the API for maintenance, security or to protect the Service, and we may block any client that threatens stability. Status is published on the status page.
9. Deprecation notice
For documented endpoints and fields we will give at least 90 days’ notice in the changelog and by email to accounts that used them in the previous 30 days before removing them or making a change that is not backward compatible. Additive changes (new fields, new event types, new optional parameters) can happen at any time, and your client must tolerate unknown fields. Security fixes may be deployed immediately.
10. Data you receive
The API returns market analysis and your own account data. It does not return personal data about other members. Where a webhook payload includes your own data (for example a trade closed on your account), you are the controller of that data once it reaches your systems and are responsible for it. Everything returned is educational analysis under the Disclaimer; use of it to trade is at your own risk under the Risk disclosure.
11. No warranty, liability
The API, its documentation and sample code are provided “as is” without warranty of any kind, and the warranty disclaimer and limitation of liability in the Terms of service apply. We are not liable for any loss caused by a delayed, missing, duplicated, out-of-order or malformed delivery, by a change to the API, by downtime, or by anything you or your systems do with data received.
12. Suspension and termination
We may suspend or revoke API access, keys or webhooks at any time for breach of these terms, abuse, security risk or legal requirement, with notice where practical. Access ends when your account or plan ends. You may stop using the API and delete your webhooks and keys at any time in Settings. On termination you must stop using plan data received through the API, except data about your own trades, which remains yours.
13. General
These terms are governed by the laws of the jurisdiction in which the company operating Zonelytix is established, and the dispute resolution, consumer protection, severability, assignment and notice provisions of the Terms of service apply. If these terms conflict with the Terms of service on a matter concerning the API, these terms prevail. Questions: legal@zonelytix.com.