Policies Partner-facing policies

API Use Policy

Who can use Map.ca's APIs, how, and what limits and data-handling obligations apply to integrators.

Version
0.1.0
Effective
May 20, 2026
Last reviewed
May 20, 2026
Review cycle
every 12 months
Master Policy Index entry
§4 #68

Policy text

The API Use Policy defines the relationship between Map.ca and the developers who build on it. APIs are powerful: they extend Map.ca’s reach, but they also extend the harm surface if used carelessly. The policy defines registration, authentication, rate limits, allowed data classes, attribution requirements, prohibited derivations (surveillance products, re-identification, bulk scraping by another name), and the review process for sensitive data classes.

It applies to every developer, integrator, and partner with API credentials. Misuse triggers credential revocation under the Scraping and Automated Access Policy.

Principles this policy enforces

  • Collect less, protect more
  • Public data and personal data are not the same thing
  • Community benefit must survive scale

What it requires

  • Register every application and identify its operator.
  • Honour documented rate limits.
  • Respect the data-handling tier assigned to each API surface.
  • Provide attribution where the public-attribution requirement applies.

What it forbids

  • Do not use the API to bulk-scrape Map.ca content.
  • Do not derive surveillance, behavioural, or re-identification products from Map.ca data.
  • Do not relicense Map.ca data outside the Data Licensing Policy.
  • Do not bypass rate limits with rotated credentials.

How it applies

References