Terms of Service
Effective Date: September 19, 2026
Last Updated: September 22, 2026
Platform Provider: Startum Identity Platform ("Startum", "we", "us", or "our")
1. Acceptance of Terms
By accessing or using the Startum Account Portal, Developer Portal, OpenID Connect authentication endpoints, or developer APIs (collectively, the "Service"), you agree to be bound by these Terms of Service ("Terms"). If you are using the Service on behalf of an entity or organization, you represent and warrant that you have authority to bind that entity to these Terms.
If you do not agree to these Terms, you may not access or use the Service.
2. Infrastructure & Governing Jurisdiction
Startum is headquartered and hosted in Canada. Platform DNS resolution, network edge routing, and Web Application Firewall (WAF) services are facilitated through Cloudflare infrastructure.
These Terms shall be governed by and construed in accordance with the federal laws of Canada and the applicable laws of the province in which Startum operates, without regard to conflict of law principles.
3. Account Registration & Credentials
- Account Creation: You must provide accurate, current, and complete information when registering an account on Startum.
- Credential Security: You are solely responsible for maintaining the confidentiality of your credentials (including passwords, developer API keys, and Client Secrets). You must notify Startum immediately of any unauthorized access or breach of security.
- Account Responsibility: You are responsible for all activities occurring under your account or client applications registered under your developer profile.
4. License to Developer Platform & OAuth APIs
Subject to compliance with these Terms, our Acceptable Use Policy, and the official Developer Documentation, Startum grants developers a non-exclusive, non-transferable, revocable license to:
- Integrate Startum OpenID Connect (OIDC) authentication into web, desktop, and mobile applications.
- Register OAuth 2.0 client applications and use Startum token endpoints for user authentication.
- Display official "Continue with Startum" SSO brand assets in accordance with our design system.
5. Platform Availability & Service Levels
- Availability Target: Startum strives to provide high service availability for core authentication and token endpoints (
/oauth/authorize,/oauth/token,/oauth/userinfo). - Maintenance & Updates: We reserve the right to perform scheduled or emergency maintenance. We will make reasonable efforts to announce planned maintenance in advance via the Developer Portal.
- Rate Limits & Throttling: Startum enforces API rate limits to maintain security and quality of service. Exceeding rate limits may result in temporary automated request throttling or response codes (
HTTP 429 Too Many Requests).
6. User Privacy & Data Protection
Startum respects user privacy and enforces Pairwise Subject Identifiers (sub) to prevent cross-app user tracking in compliance with Canadian privacy legislation (PIPEDA). Both developers and end users must comply with our Privacy Policy. Application developers must:
- Prompt end users for explicit consent before requesting identity claims (
profile,email). - Collect only the minimum identity claims necessary for application functionality.
- Maintain a clear, accessible privacy policy for their applications.
7. Prohibited Conduct & Termination
You may not engage in any of the following activities:
- Attempting to bypass, alter, or disable PKCE verification or state parameters.
- Requesting identity claims for unauthorized tracking, phishing, or identity theft.
- Reverse-engineering or attempting to extract the Startum internal Pairwise Master Key.
- Using the Service for automated spam, token harvesting, or denial-of-service attacks.
Startum reserves the right to suspend or terminate any account or disable registered OAuth client applications immediately upon violation of these Terms or the Acceptable Use Policy.
8. Disclaimer of Warranties
THE SERVICE IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.
9. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, STARTUM SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS OR REVENUES, WHETHER INCURRED DIRECTLY OR INDIRECTLY, ARISING FROM YOUR ACCESS TO OR USE OF THE SERVICE.
10. Modifications to Terms & Terms Re-Acceptance
Startum reserves the right to modify these Terms at any time. When material updates are made to these Terms or associated policies, users and developers will be notified via our 7-day progressive terms banner or in-flow OAuth re-acceptance screens. Continued use of the Service following effective updates constitutes acceptance of the modified Terms.
11. Contact & Legal Inquiries
For questions regarding these Terms, contact:
Email: [email protected]
Developer Portal: https://develop.startum.cloud