DOOLAE API terms
The short version of what you agree to when you build on DOOLAE.
1. Landlords own their data
You may access a landlord's data only after they connect your application, only within the scopes they approved, and only to provide the service you described to them. Stop using it — and delete what you don't legally need to keep — when they disconnect.
2. Tenants' personal data
Tenant names, phone numbers, email addresses and payment history are personal data under Thailand's PDPA. Process them lawfully, keep them secure, never sell them or use them for unrelated marketing, and tell DOOLAE within 72 hours if you suspect a breach.
3. Keep your keys secret
API keys are secrets. Keep live keys on your servers; never put them in apps, browsers, public repositories or URLs. Rotate a key you think was exposed. You are responsible for requests made with your keys.
4. Messages to tenants
Send LINE messages only about a tenant's tenancy (bills, payments, building notices). No advertising. DOOLAE may limit or stop sending for an account that receives complaints.
5. Payments
The API never lets you mark a bill or payment as paid; payment status comes only from the payment provider. Don't present anything to tenants as a payment confirmation unless the API reports it paid.
6. Fair use and limits
Respect rate limits and Retry-After. Don't attempt to access accounts that didn't connect your application, probe for vulnerabilities outside DOOLAE's disclosure process, or resell raw API access.
7. Plans and billing
Plans are prepaid per 30 days. Usage beyond a plan's included requests is invoiced monthly at the published rate and is due within 14 days; DOOLAE may pause live access while an invoice is overdue.
8. Changes and availability
DOOLAE keeps /v1 backwards-compatible; breaking changes come in a new version with at least 12 months' notice for anything removed. The API is provided as is; DOOLAE may suspend applications or developer accounts that break these terms or put landlords or tenants at risk.