Reference
API Terms, Acceptable Use and DPA
What you accept with your first live key.
Version 2026-10-01. Accepted once, by an owner or admin, when your organisation makes its first live key. These sit alongside our terms of service and privacy policy.
API Terms
- What you get. Access to the Jusa API to send airtime, data and ZESA tokens to your own users and to reward people for things they do, paid from your organisation's prefunded Jusa Credit.
- Price. Face value, always. We earn our margin from our supplier, not from you.
- Jusa Credit is a prepayment for Jusa products. It cannot be moved to another organisation or cashed out. Card payments are not refunded to the card; a send that fails comes back as Jusa Credit, as the settlement guarantees describe.
- Delivered is final. A delivered send cannot be reversed. If your user says it did not arrive, open a dispute and we will look.
- Wrong numbers and meters. Sends go where you tell us. With
confirm=best_efforta ZESA send goes to the meter as typed, even when ZESA could not confirm it: that choice, and its risk, are yours. - Keys are yours to keep secret. You are responsible for what is done with your keys. Revoke a key you think has leaked at once; we may revoke one we find in public.
- We may pause. We can freeze sends on an organisation that breaks these terms or the policy below, or pause the live API to protect our users; test mode stays up.
- You are first-line support for your own users; the send SMS names you
(
statement_descriptor).
Acceptable Use policy
- No reselling. The API is for platforms that give airtime, data and ZESA to their own users, not for dealers. There is no reseller programme and no sub-accounts.
- No gambling payouts to minors, and no lotteries or prize draws unless we have switched the feature on for you after a legal review.
- No SIM farming, and nothing built to game rewards: many identities for one person, bought numbers, automated claims.
- No harm. Nothing unlawful, no harassment, no messages your users did not ask for.
- Health and other sensitive data only in programs we have approved for it.
Data processing (DPA)
- You are the controller of your users' data; Jusa is your processor. We process it only to deliver what you send, to keep the records the law needs, and to stop fraud.
- You tell your users, and have a lawful basis (
lawful_basison a program) for, sharing their phone number or meter with us. - API request logs and events are kept 30 days, with tokens and phone numbers masked. The recipient erasure API removes a person's data and keeps the money history, masked.
- We tell you without undue delay about a breach that affects your users.
- Data is processed by us and by the suppliers our privacy policy names.
Questions: jusa@localhost.co.zw.