Skip to main content
This page is the Investorlift Marketplace API Terms, version marketplace-api-terms-v2026-09-18. You accept them on the Investorlift consent page when you first authorize an application with a marketplace scope. They are an addendum to the Mogul Terms of Service, which governs your account and the marketplace. The Developer Agreement governs the God Mode API, not the Marketplace API. Version marketplace-api-terms-v2026-09-18 Effective: on your acceptance These Terms are the contract between you and Investorlift Inc. for the Investorlift Marketplace API: every route under https://api.investorlift.com/marketplace, the Events and webhook deliveries it sends, the content it returns and its documentation at https://developers.investorlift.com/marketplace (together, the “Marketplace API”). They are an addendum to the Mogul Terms of Service Agreement, effective June 3, 2026, at https://mogul.investorlift.com/terms-of-service (the “Terms of Service”), and are Supplemental Terms under it. The Terms of Service governs your account and the marketplace. These Terms add the rules for reaching the marketplace through the Marketplace API, and they alone govern it. Section 16 of the Terms of Service requires that disputes between you and Investorlift, including disputes under these Terms, be resolved by binding individual arbitration, not in court, which means no jury trial and no class or representative action. You may opt out within 30 days (Terms of Service Section 16.10; Section 16 of these Terms).

1. Parties and acceptance

1.1 These Terms are between Investorlift Inc., which operates the marketplace as Mogul (“Investorlift”, and “Mogul” where the Terms of Service uses that name), and you. “You” is the person who accepts and, where Section 1.3 says an organization is bound, that organization. If you accept for an organization, you represent that you may bind it; if that authority was lacking, you stay bound personally. 1.2 You accept by ticking “I have read and agree to the Investorlift Marketplace API Terms” and choosing Allow on the Investorlift consent page (the “Consent Page”). That click is your electronic signature. Investorlift records this version’s identifier, the time, your IP address and your browser’s user agent against the account or organization the acceptance binds, as evidence. Using a Token also accepts the version in force for you under Section 11.4. 1.3 Who is bound follows the Scopes the authorize request names. A request that names a Seller Scope binds the organization you act for: the acceptance is recorded against that organization, and every member who later authorizes a Connected Application with a Seller Scope acts under it. A request that names a Buyer Scope binds you as a person. A request that names both binds both. A request that names only Scopes that belong to neither side (your profile, the events feed) binds you as a person. The Consent Page asks for acceptance once for each entity a request binds, and again for a new version. 1.4 The account holder answers for all use through the account, its Tokens and every Connected Application it authorizes, and an organization answers for the use of every member and every Connected Application authorized for it. You represent that you are at least 18, able to contract, hold one Investorlift account with true, current details, and are not barred from the Services by law or by a suspension or termination under the Terms of Service. 1.5 The Marketplace API is offered from the United States to the Users the Terms of Service admits (its Section 15). Nothing in these Terms changes who may hold an Account, list a Property or make an offer; the Terms of Service decides that.

2. Definitions

Capitalized terms the Terms of Service defines (Account, Buyer, Seller, Listing, Listing Agent, Property, Services, User, User Content, Licensed Data, Platform Messages, Supplemental Terms) keep its meanings. In these Terms:
  • Business Day: a day other than a Saturday, a Sunday or a United States federal holiday.
  • Buyer Contact: a buyer’s name, entity name, email address and telephone number, and the consent evidence beside them, as the Marketplace API returns them to a seller. They arrive on the offers, inquiries, address requests and leads of the seller’s own deals and in the Events about them.
  • Buyer Scope: a Scope that only a buy-side route uses, as the Documentation lists it.
  • Cache Period: 24 hours after retrieval (Section 5.3).
  • Connected Application: software that holds a Token for you after you authorize it on the Consent Page, whether Investorlift has reviewed it (a “Registered Application”) or not (an “Unregistered Application”), including software you wrote and run yourself.
  • Developer Agreement: the Investorlift Data Services Developer Agreement (Beta) at https://developers.investorlift.com/guides/terms, which governs the God Mode API and the Data it returns.
  • Documentation: the pages under https://developers.investorlift.com/marketplace, including the caps, the event catalogue and the changelog they publish.
  • Event: a record of something that happened on your side of the marketplace, delivered on the events feed or to a Webhook Endpoint, in the shape and with the fields the Documentation states for its type.
  • Integrator: the operator of a Connected Application that serves organizations or people other than the operator itself.
  • Marketplace Data: the content the Marketplace API returns to you, including Events and webhook deliveries, in any format, and every copy or excerpt of it.
  • Mogul Privacy Policy: the Privacy Policy of Mogul, a division of Investorlift Inc., at https://mogul.investorlift.com/privacy-policy.
  • Scope: a permission an authorize request names and the Consent Page describes in one sentence, granted to one Connected Application.
  • Seller Scope: a Scope that only a sell-side route uses, as the Documentation lists it.
  • Support Address: support@investorlift.com.
  • Token: an access token or refresh token the Investorlift issuer grants to a Connected Application for the Marketplace API after your consent.
  • Webhook Endpoint: an HTTPS address you register to receive Events.
  • Your Own Data: as a seller, your organization’s drafts and deals, the offers, inquiries, address requests and leads on them (Section 6 governs the Buyer Contact they carry), the reviews of your organization and your responses, and your Webhook Endpoints. As a buyer, your own offers, inquiries, address requests, buy boxes and Webhook Endpoints. Every other item of Marketplace Data is not Your Own Data, including a deal you read as a buyer, a deal.matched Event, and another seller’s public profile and reviews.

3. The Marketplace API and the documents that govern it

3.1 What the Marketplace API is. The Marketplace API is every route under https://api.investorlift.com/marketplace, in every version (today /marketplace/v1), the Events and webhook deliveries it sends, the Marketplace Data it returns, and the Documentation. An act through the Marketplace API is an act on the Services. A deal you publish is a Listing, an offer you submit is an offer, an inquiry or an address request is a Platform Message, and a review you read is User Content. Each has the meaning and the consequences the Terms of Service gives it. 3.2 The Terms of Service. These Terms are Supplemental Terms for the Marketplace API and add to the Terms of Service, which continues to govern your Account, the Listings, Properties, offers, transactions and communications on the marketplace, and Investorlift’s rights over them. Where these Terms and the Terms of Service differ about the Marketplace API, these Terms control, as the Terms of Service provides for Supplemental Terms. Nothing here relaxes a restriction of the Terms of Service. 3.3 The Developer Agreement. The Developer Agreement governs the God Mode API (the routes under https://api.investorlift.com/v1 and the MCP endpoint) and the Data it returns. These Terms alone govern the Marketplace API: Marketplace Data is not “Data”, and the Marketplace API is not “the API”, under the Developer Agreement. Where the two texts could be read to differ about the Marketplace API, these Terms control. A Token gives no access to the God Mode API and a Key under the Developer Agreement gives no access to the Marketplace API; an account that uses both is bound by each for its own subject. 3.4 The Mogul Privacy Policy describes how Investorlift handles personal information on the marketplace, including through the Marketplace API (Section 13). It is a notice, not a contract. 3.5 The Documentation states the routes, fields, Event types, caps and error codes. Where these Terms point at a figure or a list, the Documentation as published when the conduct happened is the figure or the list.

4. License and fees

4.1 Subject to these Terms and within your Scopes and caps, Investorlift grants you a limited, revocable, non-exclusive, non-transferable, non-sublicensable license while these Terms last. The license is to (a) call the Marketplace API through your own systems and through Connected Applications you authorize, (b) receive Events and webhook deliveries, and (c) use Marketplace Data inside your own systems and Connected Applications for your own marketplace activity. As a seller, that activity is to list, market and sell your organization’s own deals and to work the buyers who act on them. As a buyer, it is to find, evaluate, inquire about and make offers on deals for your own account. Nothing in this Section allows what Section 5 or Section 6 forbids. 4.2 As between you and Investorlift, Investorlift owns the Marketplace API, its design, the Documentation and the compilation, selection and arrangement of Marketplace Data, and every right not expressly granted; there are no implied licenses. Your User Content stays yours under Section 4.4 of the Terms of Service, and Marketplace Data other than Your Own Data is Licensed Data under its Section 4.3. 4.3 An Integrator’s license is the license of the customer whose Token it holds, exercised for that customer alone (Section 7). 4.4 The Marketplace API carries no fee of its own. A seller’s use is part of the organization’s Mogul plan, and an act through the Marketplace API costs what the same act costs in the app (Terms of Service Section 8). A buyer’s use is free with a verified account. A fee for the Marketplace API, if Investorlift introduces one, is a change under Section 11 and binds you only with your consent at checkout.

5. Restrictions

Except as Section 4 allows, you will not, and will not let a Connected Application or anyone else acting for you: 5.1 Build a competing marketplace, feed or dataset. Use Marketplace Data to build, seed, enrich or operate a marketplace, a listing feed, a lead list, a buyer database or any dataset or data product that substitutes for or competes with the marketplace. Offer Marketplace Data as data (a file, feed, export, API, download or bulk report). 5.2 Republish Marketplace Data. Publish, post, syndicate, sell, license, share or otherwise make Marketplace Data available to anyone outside the organization (for a Seller Scope) or the person (for a Buyer Scope) that authorized the Token, or display it outside your own systems and Connected Applications. Showing a deal you listed, as its seller, wherever you choose is not republication; Section 5.4 applies where you show it with the fields the Marketplace API added. 5.3 Keep a deal beyond the Cache Period. Hold Marketplace Data that is not Your Own Data for more than 24 hours after retrieval (the “Cache Period”); after it, read the record again or delete it. You may keep the public identifiers the Marketplace API assigns (the prefixed identifiers of deals, offers, inquiries, buyers, sellers, reviews, webhooks, events and buy boxes) as references while these Terms last, and a tombstone under Section 6.5. Your Own Data is yours to keep, subject to Section 6 for Buyer Contact. 5.4 Show a deal outside Mogul without attribution. Show a deal outside Mogul using Marketplace Data without the words “Listed on Investorlift” or “Source: Investorlift”, legibly and beside the deal, and, where the medium allows a link, a link to the deal’s page on mogul.investorlift.com. This applies to a deal you read as a buyer, and to a deal you listed where you show its Mogul identifier, verification status or another field the Marketplace API added. Your own description, photographs and documents of a deal you listed need no attribution when shown without those fields. Investorlift may change the attribution words by email, and you show the new words within 30 days. 5.5 Aggregate across customers. As an Integrator, pool, combine, compare, match or index Marketplace Data across the organizations or people it serves, or build a cross-customer view of deals, buyers, sellers, offers or reviews. Use one customer’s Marketplace Data for another customer’s benefit, or for the Integrator’s own product beyond serving each customer. Operational metrics that identify no deal, person, organization or offer are not aggregation. 5.6 Create accounts by automation. Create an Investorlift account or an organization other than by a person acting by hand, or hold more than one account per person. Open a second account or organization to obtain more caps, a higher trust tier or a way around a hold, a suspension or a revocation. Registering an OAuth client by the dynamic registration the Documentation describes is not account creation. 5.7 Circumvent a cap, the release flag or the gateway. Evade a cap, a rate limit, a per-deal ceiling, a trust tier, the hold queue, the release flag, a suspension, a revocation or the gateway. The “release flag” is the flag Investorlift uses to turn the Marketplace API on for an account or an organization. Evasion includes a retry loop that ignores Retry-After, spreading one workload across accounts, organizations, Connected Applications or Tokens, using another person’s Token, and reaching the Marketplace API or the systems behind it through any host but api.investorlift.com. 5.8 Scrape the Consent Page or the Documentation. Crawl, scrape or automate the Consent Page, the account settings pages or the Documentation, or harvest the Documentation in bulk. The Documentation’s own features (its search, its copy and open-in-assistant menu, its documentation MCP server and the OpenAPI document it publishes) are yours to use. 5.9 Test security without consent. Probe, scan, load-test or try to penetrate the Marketplace API, the gateway, the Consent Page, the issuer or the Documentation without Investorlift’s written consent, requested at the Support Address; report a vulnerability to the same address. 5.10 Misrepresent. State or imply that Investorlift endorses, operates, has verified or is responsible for your product or a Connected Application, or pose as Investorlift or Mogul. A Registered Application may say that Investorlift registered it and show the badge Investorlift gives it, and nothing more. Use the names or marks Investorlift or Mogul beyond the attribution words of Section 5.4 and a truthful plain-text statement that your product uses the Investorlift Marketplace API. 5.11 Act on the marketplace other than in good faith. Submit an offer, counter, inquiry or address request that is not the real act of the person the Token names, or submit an offer to probe a price or to hold a deal. Publish a deal you do not have the right to sell or market, or send a message the Terms of Service or the law forbids. Sections 1.3, 1.4, 1.6, 1.7, 4.4 and 5 of the Terms of Service, and the Non-Circumvention Agreement the marketplace attaches to an address request, apply to every act through the Marketplace API as they apply in the app. 5.12 Use the Marketplace API unlawfully or in violation of anyone’s rights.

6. Buyer Contact

6.1 What a seller receives. On the offers, inquiries, address requests and leads of your organization’s own deals and in the Events about them, the Marketplace API returns a buyer’s name, entity name and buyer identifier. It returns the buyer’s email address and telephone number only while the Token holds the contacts:read Scope, which an owner or administrator of the organization must hold, and within the daily contact caps the Documentation publishes. A buyer Investorlift recommended to your deal who has not acted on it is returned as an identifier and a status with no name or contact, until the buyer acts on the deal or you move the lead forward in the app. No route returns a buyer who has not acted on your own deal. Investorlift may withhold Buyer Contact from an organization until the organization is verified. 6.2 Use for that deal only. You use Buyer Contact to respond to and work the buyer’s inquiry, offer, address request or lead on the deal it came with, and to complete that transaction, and for nothing else. Not for another deal, not for a marketing list or a drip, not for another organization or person, and not to sell, share, enrich or append it. A further use rests on consent the buyer gives you directly and on your own compliance with law, never on these Terms or on the Marketplace API. 6.3 You are the caller or sender. The Marketplace API conveys no consent from Investorlift for you to call, text, email or visit anyone. If you or anyone acting for you contacts a buyer using Buyer Contact, or using contact details obtained elsewhere for a buyer the Marketplace API identified, you are the caller, sender or initiator for legal purposes. Compliance with the Telephone Consumer Protection Act, the Telemarketing Sales Rule, the National Do Not Call Registry, state do-not-call and telephone-solicitation laws, the CAN-SPAM Act, state anti-spam and consumer-protection laws and every other law that governs the contact is yours alone. Investorlift registers no messaging campaign for your texting and lends you no telephone number, brand or sender identity of its own. 6.4 The consent evidence. A payload can carry consent evidence: the source of the buyer’s act on Mogul, when it was captured, the version of the text the buyer saw and whether the buyer opted in to text messages. That evidence is information about what the buyer did on Mogul under Section 1.11 of the Terms of Service and the Mogul Privacy Policy. It is not a license, a certification or a warranty from Investorlift that you may call or text the buyer, that the consent meets your legal need or that it is still in force. You decide whether it does, and you keep your own record. 6.5 Opt-outs and redaction. Honor every opt-out the platform records and sends you (a text-message opt-in of false, a buyer’s request through Mogul to stop, and the Events below) and every opt-out a buyer gives you directly, within the time the law allows and without re-adding the buyer. A buyer.redacted or lead.redacted Event carries an identifier and nothing else. When Investorlift sends one, delete every copy of that buyer’s Buyer Contact from your systems and every Connected Application within 10 Business Days, and pass the Event to every vendor that holds it for you. Do not restore the contact from a backup or re-acquire it. Keep the identifiers the Event names and the Event identifier as a tombstone, so the buyer does not return under a later read, and keep what the law requires you to keep about a completed transaction. A redaction Event is not a breach by Investorlift of any promise about a lead. 6.6 Independent controller. For Buyer Contact and for personal information you collect from a buyer, you are an independent controller or business under applicable privacy law, including the California Consumer Privacy Act; you are not Investorlift’s service provider or contractor, and Investorlift is not your processor. Investorlift makes Buyer Contact available only for the limited and specified purposes Section 6.2 allows. You will give it the protection that Act requires of a business, tell your buyers what you do with it in your own privacy notice, and cooperate under Section 6.7 on requests from the people concerned. You will tell the Support Address promptly if you can no longer meet these obligations. Investorlift may take reasonable and appropriate steps, including under Sections 9 and 10, to make sure your use is consistent with its own obligations and, on notice, to stop and remediate unauthorized use. 6.7 Requests from buyers. Forward any request to access, correct, delete or stop using information about a buyer that reached you through the Marketplace API to the Support Address within 5 Business Days, with the identifiers, the requester’s details and the subject “Privacy request”. Tell the requester you have. Forwarding does not discharge your own duties under privacy law; act on the request under your own law from your own receipt, whether or not Investorlift has acted. 6.8 Not a consumer report. Marketplace Data, including a buyer’s trust tier, verification state, proof-of-funds flag or reviews, is not a consumer report, and Investorlift is not a consumer reporting agency. You will not use it as a factor in deciding anyone’s eligibility for credit, insurance, employment, housing or a lease, or for any other purpose the Fair Credit Reporting Act governs, and will not use Buyer Contact to locate, track, harass or discriminate against anyone. 6.9 A buyer’s side. As a buyer, the Marketplace API returns no seller’s personal email address or telephone number; a seller is shown by company, handle and the telephone number Investorlift assigns to the platform for that seller, which Investorlift may change. Sections 5.11 and 6.3 apply to every message you send a seller.

7. Connected Applications, Integrators and Tokens

7.1 Your authorization. You choose which Connected Application holds a Token and which Scopes it holds, on the Consent Page, which names the application (or shows “Unregistered application” and its redirect host) and describes each Scope in one sentence. A Connected Application acts as you, within its Scopes, your role and your caps; what it does with Marketplace Data is your use under these Terms. Investorlift does not review an Unregistered Application, does not vouch for it and is not responsible for what it does. You may revoke a Connected Application at any time in your Investorlift account settings; revocation ends its refresh token and every access token minted from it, and pauses its Webhook Endpoints (Section 8.5). 7.2 Unregistered Applications. A Connected Application that registered itself holds consent from at most one organization and three people. The fourth consent is refused, and the Consent Page points the operator at registration. Investorlift may set a personal client’s write caps below the person’s own, as the Documentation states. 7.3 Registered Applications. Investorlift registers an application after a review against the criteria the Documentation publishes: a named company, a privacy policy, HTTPS redirect URIs, the Scopes requested and why, how the application keeps each customer’s data apart, and a security contact. Investorlift aims to answer within 10 Business Days; that time is a target, not a commitment. A Registered Application carries a verified badge on the Consent Page, may connect many organizations and people, and gets the higher caps the Documentation states. Investorlift may refuse, condition, suspend or withdraw a registration at any time under Section 10, and a registration is not an endorsement. 7.4 The operator’s acceptance. The operator of a Connected Application accepts these Terms for itself when it registers the application or when the application first uses a Token. They bind it as they apply to a Connected Application and an Integrator (this Section 7 and Sections 5, 6, 8, 10 and 13 to 18), and it answers for the application whether or not each customer also accepted. An operator that will not be bound must not hold a Token. 7.5 Integrator duties. An Integrator has eight duties:
  • it acts on each Token only on the instructions and for the benefit of the organization or person that authorized it;
  • it keeps each customer’s Marketplace Data apart (Section 5.5), by access control at least, and shows a customer only its own;
  • it binds each customer, in its own terms, to duties over Buyer Contact no less protective than Section 6;
  • it passes a buyer.redacted or lead.redacted Event to the customer within the 10 Business Days of Section 6.5 and deletes its own copy in the same time;
  • it publishes a privacy policy that covers Marketplace Data;
  • it tells the Support Address within 72 hours of learning of a security incident that affects Marketplace Data, and tells the affected customers;
  • it keeps a record of which customer’s data it holds and when it deleted it, and produces the record on Investorlift’s reasonable written request;
  • it gives Investorlift, on request, the contact of the customer for whom it acts, so that a notice under Section 17 reaches the right organization.
7.6 Tokens. A Token is for the Connected Application, the person and, for a Seller Scope, the organization the consent names, and for no one else. Keep refresh tokens and client secrets confidential, store them encrypted, send an access token only to api.investorlift.com, and never place a Token in a URL, a log or a client-side page. Report a compromise to the Support Address within 72 hours and revoke the Token at once. Access tokens are short-lived and refresh tokens rotate, as the Documentation states; a banned or suspended user’s Token stops at the next request. 7.7 When a person leaves. When the person who authorized a Connected Application leaves the organization, or the organization removes their role, the Tokens that person’s consent minted for the organization stop and the Webhook Endpoints that person created pause. Investorlift emails the organization’s owner to confirm or delete them within 7 days (Section 8.5). The organization arranges a new consent from a current member.

8. Webhooks and Events

8.1 Your endpoint. A Webhook Endpoint is an HTTPS address you control. At registration Investorlift resolves its host, refuses private, loopback, link-local and cloud-metadata addresses, follows no redirect and sends a challenge that your endpoint echoes before it is active; the check repeats at every delivery. You register at most the number of endpoints per side the Documentation states, each with the Event types it wants and the contract version it pins. 8.2 Your security. Investorlift signs every delivery as the Documentation describes (an HMAC over the delivery identifier, the timestamp and the body, in the standard webhook headers). You verify the signature and the timestamp on every delivery inside the replay window, reject what fails, keep the signing secret confidential (it is shown once and can be rotated), and treat the Event identifier as the key that removes duplicates. A delivery that was not verified is not Investorlift’s delivery. 8.3 Delivery. Delivery is at least once and in no guaranteed order; a delivery may be retried and later re-sent. The events feed is the replay path and holds Events for the period the Documentation states, today 30 days. Investorlift keeps a delivered payload for redelivery for the period the Documentation states and then keeps only its hash. A missed or late delivery is not a breach by Investorlift and gives no remedy; read the feed. 8.4 What an Event carries. An Event carries the fields the Documentation states for its type, about the resource and the actor, and no more; Buyer Contact rides only on seller-side Events delivered to an endpoint whose creator holds the contacts:read Scope. You do not use a Webhook Endpoint or the feed to obtain personal data beyond the payload, and Section 6 governs the Buyer Contact a payload carries. An Event about a recommended buyer is sent when the buyer first acts, not before. 8.5 Failure, pause and disablement. Investorlift retries a failed delivery as the Documentation states, then re-queues it, and disables an endpoint that has failed for 3 days, with an email and a webhook.disabled Event. An endpoint pauses when its creator’s consent is revoked, the creator leaves the organization or its Connected Application is disabled; the organization’s owner confirms or deletes it within 7 days of the email, after which Investorlift deletes it. Investorlift may pause or disable an endpoint at once for a security risk. 8.6 Your obligations to others. You answer for what your Webhook Endpoint and the systems behind it do with an Event, including under Section 6, and for anyone who operates the endpoint for you.

9. Trust tiers, caps and the hold queue

9.1 Investorlift’s controls. Investorlift protects the marketplace and its Users with controls that apply to every Token:
  • trust tiers computed from facts about your account (a verified email address, a verified telephone number, a verified identity and proof of funds, a completed transaction, an attached legal entity);
  • daily caps by tier and per-minute request limits by kind of Connected Application;
  • per-deal ceilings on inbound offers, inquiries and address requests;
  • a hold queue that delays a write for review, and a review of the first writes of a new account or Connected Application;
  • a rule that treats accounts sharing a telephone number, identity, payment instrument, device or network address as one actor for the caps;
  • the release flag (Section 5.7);
  • the seller-side switch that decides whether a seller’s deals accept offers through the Marketplace API.
The Documentation publishes the caps in force, and GET /me shows your tier, its facts and what is left of your caps today. 9.2 Reaching a cap is not abuse. A request refused at a cap answers with the cap and the time to retry, and reaching a cap is not a breach of these Terms. Evading one is (Section 5.7). 9.3 A held write. A write in the hold queue is not delivered to the other side until Investorlift releases it, and Investorlift tells the seller that a write is held. Investorlift may release, refuse or delete a held write and owes nothing for a write it holds or refuses, except to tell you the outcome. 9.4 Changes to the controls. Investorlift may change the tiers, the caps, the ceilings and the hold rules. A change that lowers a cap you have is a change under Section 11 and gets the notice it provides. A change that raises a cap, adds a tier fact or adds a control that binds no compliant use may take effect when the Documentation publishes it. A change required by security, by abuse in progress, by the law or by a third party’s demand may be immediate.

10. Suspension and termination

10.1 Suspension. Investorlift may suspend or revoke a Token, a client identifier (so that every Token the Connected Application holds stops), a Webhook Endpoint, a registration under Section 7.3 or your access to the Marketplace API, and may hold or refuse a write. The grounds are a breach of these Terms, abuse or a pattern that looks like it, a security risk, a legal requirement, a court order, or a complaint from a buyer whose contact you received. Investorlift tells you by email, naming the rule and describing the conduct (with request identifiers, or a sample and the period, where requests are the evidence), unless law or security prevents it, and then as soon as it allows. Investorlift’s usual order (a warning, a lowered cap, a revoked Token, then closure of access) is its practice, not your entitlement, and a serious breach of Sections 5 to 8, a security risk or a legal requirement can be met at once and without notice. A client.revoked Event tells your Connected Application. 10.2 Appeal. Write to the Support Address with the subject “Appeal”, from your account email, within 14 days of the notice, quoting the request identifiers or the period it named and saying what happened and what has changed. Investorlift answers in writing and aims to do so within 10 Business Days; that time is a target. An appeal does not pause the action, and reinstatement is at Investorlift’s discretion. 10.3 Ending by you. You end these Terms for a Connected Application by revoking it, and for yourself or your organization by revoking every Connected Application and deleting your Webhook Endpoints; closing your Account under Section 14 of the Terms of Service ends them too. 10.4 Ending by Investorlift. Investorlift may end these Terms for you, or end the Marketplace API as a whole, on 30 days’ email notice for convenience, and at once for cause under Section 10.1. Ending the Marketplace API does not close your Account or change your Mogul plan. 10.5 Effect. On termination the license ends, you stop calling the Marketplace API, and within 30 days you delete Marketplace Data that is not Your Own Data, except the identifiers Section 5.3 lets you keep and what the law requires you to keep. Buyer Contact you hold stays under Section 6 (use for the deal only, deletion on redaction) for as long as you hold it. Sections 2, 4.2, 5, 6, 7.4, 7.5, 8.6, 10.5 and 13 to 18, and any amount already due, survive. 10.6 The Terms of Service. Investorlift’s rights under the Terms of Service (its Sections 5.2, 6 and 14 among them) are unaffected by these Terms. A suspension under these Terms does not by itself close your Account, and a suspension or termination of your Account under the Terms of Service stops every Token.

11. Changes

11.1 Additive changes. The Marketplace API is versioned and meant to be additive: new routes, fields, values, Event types and tools arrive without notice, and a Connected Application must tolerate an unknown field or Event type. 11.2 30 days’ notice. Investorlift gives at least 30 days’ email notice to every account and organization with an active Token or Webhook Endpoint before it removes or renames a documented route, field, Event type or tool. The same notice comes before it otherwise breaks a documented request, before it retires a contract version a Webhook Endpoint can pin, and before it lowers a cap you have (Section 9.4). The Documentation’s changelog records each such change and its date. 11.3 Immediate changes. A change required by security, by abuse in progress, by the law, by a court order or by a third party whose rights the change protects may take effect at once; the email says so and, where the change is temporary, when it ends. 11.4 Changes to these Terms. Investorlift changes these Terms by publishing a new version at https://developers.investorlift.com/marketplace/terms under a new version identifier and emailing every account and organization bound by the version in force. The new version is presented on the Consent Page at your next authorization. It takes effect for you on the earlier of your acceptance and 30 days after that email, if you use the Marketplace API after that date. Investorlift may require acceptance before a further authorization and may stop a Token whose holder has not accepted a version in effect. A change that only benefits you (a wider license, a higher cap, a corrected error) may take effect on publication; a change required by law or for security may take effect sooner, and the email says so. If you do not agree, revoke your Connected Applications and stop using the Marketplace API before the new version takes effect. A change to the dispute terms these Terms adopt follows Section 16.12 of the Terms of Service. 11.5 The version in force. Conduct is judged by the version in force when it happened; the acceptance record names it.

12. The Investorlift Zapier application

12.1 Moving onto these Terms. Investorlift’s Zapier application for the marketplace (the “Zapier Application”) becomes a Connected Application under these Terms on the date Investorlift names in its notice (the “Reconnect Date”). From that date its triggers are Events, the data it delivers is Marketplace Data, the buyer fields it delivers are Buyer Contact under Section 6, and each connected organization is bound as Section 1.3 provides for a Seller Scope. 12.2 Notice. Investorlift tells every organization connected to the Zapier Application by a banner in the app and by email to the organization’s owners, at least 30 days before the Reconnect Date, naming the date, what changes and how to reconnect. The notice is a change to the Services under the Terms of Service’s change procedure and a change to these Terms under Section 11.4. 12.3 Dual delivery. For 90 days from the Reconnect Date the Zapier Application receives both the legacy triggers and the Events, so an existing Zap keeps working after reconnection. After the 90 days the legacy triggers stop, except the triggers Investorlift names in the notice as staying until their Events exist. The legacy field that carried a buyer score is not delivered from the Reconnect Date. 12.4 Acceptance. Reconnecting the Zapier Application through the Consent Page is acceptance of these Terms for the organization. An organization that does not reconnect and continues to receive the legacy triggers after the Reconnect Date is bound by these Terms from that date as to what it receives, as the Terms of Service’s change procedure provides. Its legacy triggers stop when the dual delivery ends.

13. Privacy

13.1 The Mogul Privacy Policy governs. The Mogul Privacy Policy describes what Investorlift collects about Users and what it discloses, including through the Marketplace API and webhooks; it is a notice, not a contract, and may be updated. The Investorlift Data Services Privacy Notice at https://developers.investorlift.com/guides/privacy does not describe the Marketplace API. 13.2 What Investorlift records. Investorlift records your acceptance (Section 1.2), each consent with its Connected Application, Scopes and the entity it binds, each request (route, status, timing, request identifier, client, account and organization), each Event and each delivery, the hold-queue evidence and each enforcement step. For every delivery that carried Buyer Contact, Investorlift keeps a delivery record (the client identifier, the organization, the buyer identifier and the Event identifier) for 4 years, so that it can name the recipients of a buyer’s contact on the buyer’s request. It removes the contact fields from its own Event and delivery rows when a buyer is redacted. 13.3 The seller as recipient. A seller and its Connected Applications receive a buyer’s contact as independent controllers under Section 6.6, for the deal the buyer acted on. Investorlift is not their processor and does not control what they do with it beyond these Terms. The Mogul Privacy Policy tells buyers that a seller and its connected applications receive their contact when they act on a deal, and how to ask Investorlift to stop. 13.4 Your notices. You give the people whose personal information you receive or collect through the Marketplace API the notice your law requires, in your own privacy notice, and you do not represent that Investorlift’s notices are yours.

14. Disclaimers

14.1 As is. The Marketplace API is part of the Services, and Sections 1.8, 1.9, 1.12, 11.1, 11.2, 11.3 and 12.3 of the Terms of Service apply to it and to Marketplace Data. Marketplace Data is User Content and Licensed Data as received, unverified. A listing, an offer, a review or a buyer’s contact can be stale, wrong, incomplete or another person’s. A trust tier, a verification state or a match is Investorlift’s estimate from the facts it holds. Investorlift does not verify that a record is accurate, complete or lawful for your purpose. THE MARKETPLACE API AND MARKETPLACE DATA ARE PROVIDED “AS IS” AND “AS AVAILABLE”, WITH ALL FAULTS, AND INVESTORLIFT DISCLAIMS EVERY WARRANTY THE TERMS OF SERVICE DISCLAIMS. 14.2 Not a party. Investorlift is not a party to any transaction, offer, communication or agreement between a buyer and a seller made through the Marketplace API, and Sections 1.8 and 9 of the Terms of Service apply to disputes between Users that arise from it. 14.3 No availability commitment. Investorlift commits to no level of availability, latency, throughput, delivery time or recovery time for the Marketplace API, the events feed or webhook deliveries. It may interrupt or limit them at any time for maintenance, a release, a security measure or a legal requirement, and gives no service credit. Support is by email to the Support Address, and its response times are targets for United States business hours, not commitments.

15. Liability, indemnity and release

15.1 Limitation of liability. Section 12 of the Terms of Service (Limitation of Liability), including its disclaimer of certain damages (12.1), its cap on liability (12.2) and its basis-of-the-bargain clause (12.5), applies to every claim arising out of or relating to these Terms or the Marketplace API. In it, “the Agreement” includes these Terms and “Services” includes the Marketplace API. For that cap, the amount paid to Mogul includes the fees of the Mogul plan through which a seller used the Marketplace API in the period the cap names. 15.2 Indemnity. Section 10 of the Terms of Service (Indemnification) applies to these Terms. The matters it covers include your Connected Applications and Webhook Endpoints, your use of Marketplace Data and Buyer Contact, your messages to buyers and sellers, an Integrator’s customers, and your breach of these Terms. 15.3 Release. Section 9 of the Terms of Service (Release) applies to a dispute you have with another User that arises from an act through the Marketplace API. 15.4 Limits the law sets. Nothing in these Terms limits a liability the law does not allow to be limited, and nothing limits your own liability for a breach of Sections 5 to 8 or under your indemnity.

16. Disputes and governing law

16.1 Arbitration. Section 16 of the Terms of Service (Dispute Resolution) applies to every dispute, claim or controversy between you and Investorlift arising out of or relating to these Terms or the Marketplace API, which is a “Dispute” under its Section 16.1. That means binding individual arbitration under its Sections 16.1 to 16.9 and 16.11, after the informal dispute resolution conference of its Section 16.2, with the waivers of jury trial (16.3) and of class and non-individualized relief (16.4). Where these Terms and Section 16 of the Terms of Service refer to the same step, Section 16 governs the step. 16.2 Opt-out and changes. The 30-day right to opt out in Section 16.10 of the Terms of Service applies; if accepting these Terms is the first time you become subject to that Arbitration Agreement, the 30 days run from your acceptance. A valid opt-out under the Terms of Service covers these Terms. A change to the Arbitration Agreement follows Section 16.12 of the Terms of Service. 16.3 Law, venue and time. These Terms and any Dispute are governed by the laws of the State of California, consistent with the Federal Arbitration Act (Terms of Service Section 18.7). A claim that may be brought in court is brought in the state or federal courts in California (Section 18.6). The one-year limitation period in the General Provisions of the Terms of Service (the clause captioned “Limitation Period”) applies.

17. Notices

17.1 From Investorlift. Investorlift gives you notice by email to your Investorlift account address and, for an organization, to the addresses of its owners, effective when sent; keep them current. A banner in the app, an Event, a field of GET /me or a line of the Documentation is information that supports a notice, not the notice itself, except where Section 12 makes the banner part of one. 17.2 From you. You give Investorlift notice by email to the Support Address, support@investorlift.com, from your Investorlift account email, effective on receipt except where these Terms say otherwise. The subject line routes it: “Marketplace API” for support and questions, “Appeal” under Section 10.2, “Abuse report” to report misuse, “Security” for a vulnerability or a compromised Token, and “Privacy request” or “Removal request” for a request about a person. Where the Terms of Service requires a notice by post (the notice of a dispute under its Section 16.2 and the opt-out under its Section 16.10), send it as the Terms of Service says.

18. General

18.1 Entire agreement and order of precedence. The entire agreement about the Marketplace API is these Terms, the Terms of Service with its other Supplemental Terms, the Non-Circumvention Agreement the marketplace attaches to an address request, and the caps, event catalogue and attribution words the Documentation publishes. It supersedes every earlier understanding about the Marketplace API; the Mogul Privacy Policy is a notice, not a contract. On the Marketplace API, these Terms control over the Terms of Service (Section 3.2) and over the Developer Agreement (Section 3.3); on everything else, the Terms of Service controls. 18.2 Assignment, force majeure, waiver, severability. Sections 18.2 (Assignment), 18.3 (Force Majeure), 18.10 (Waiver) and 18.11 (Severability) of the Terms of Service apply to these Terms. Investorlift may assign these Terms to an affiliate or to a successor to the marketplace. 18.3 Export and territory. Sections 15 and 18.12 of the Terms of Service apply; the Marketplace API is offered from the United States, and Investorlift may refuse or close access from outside it. 18.4 Electronic contracting. Section 18.1 of the Terms of Service applies. You consent to contract, and to give and receive notices, disclosures and signatures, electronically under the E-SIGN Act and the Uniform Electronic Transactions Act, and may ask for a copy of these Terms by email to the Support Address. 18.5 Third parties. No one but you and Investorlift has rights under these Terms, with one exception. The Mogul Parties named in Sections 9, 10 and 12 of the Terms of Service may rely on Sections 14 and 15 of these Terms as those Sections of the Terms of Service provide. Investorlift may change or waive these Terms without any beneficiary’s consent. 18.6 Interpretation. Headings are for convenience; “including” means including without limitation; a reference to a Section of the Terms of Service is to the text at https://mogul.investorlift.com/terms-of-service in force when the conduct happened, and its captions identify the clause where its numbering does not. By ticking “I have read and agree to the Investorlift Marketplace API Terms” and choosing Allow, you accept these Terms for yourself and, where Section 1.3 provides, for the organization you act for, as of the time Investorlift records it.