← Back to home

Marketplace Terms

Version 1.0 · Effective: August 27, 2026 · Entity: AiTrade LLC, a Florida limited liability company

Draft. These terms are a working draft, published so creators and buyers can read them before paid transactions are enabled at scale. They will be reviewed by counsel before adoption. If something reads unfairly, say so at legal@railcall.ai — that is the actionable form of feedback right now.
Counsel — is this a preview or the operative agreement?The banner above may already be wrong.The live pricing page, fetched 2026-08-27, states that “32 modules are live from roughly 20 publishers today,” that publishers “keep 95% of every sale,” and that “payouts go to you.” If any money has actually moved, these are not terms published in advance of transactions — they are the operative agreement for transactions that have already occurred, under whichever version was live at the time, and calling them a draft understates their status to the people bound by them. Confirm whether paid transactions have settled. If they have, drop the draft framing, state which version governed each period, and publish the superseded v0.1 at a stable URL. The fee schedule in §6.1 changed to 0% seller / 15% buyer on 2026-08-27, after that fetch. Any sale that settled before the change settled under 5% / 10% / 95%, which makes the question above load-bearing rather than academic: those publishers were paid 95% and are owed a statement saying so.Counsel — staged adoptionVersion 0.1 of these terms promised Publishers at least 14 days’ notice before a material change. Most of Version 1.0 is favourable or corrective and can take effect immediately, but §8.2 (non-circumvention) and §17.3 (publisher indemnity) are new obligations adverse to existing Publishers and imposing them on publication day would breach the notice promise in the version they replace. Set those two to take effect 14 days (or 30, to match Terms of Service §0.5) after publication for anyone who held a publisher account on that date. Everything else can publish immediately.CounselPublication date — set the effective date above to the date these terms actually go live at railcall.ai/legal/marketplace. This version replaces v0.1 in the same change: two live versions disagreeing about refunds and fees is worse than either one alone.

This is not the software licence. RailCall Station, RailHub Studio, and the RailCall CLI that you download and run are governed by their own licence, published at railcall.ai/legal/licensing. That licence is permissive and these terms do not narrow it. Nothing here restricts what you may do with RailCall source code you already hold — fork it, modify it, build commercial products on it, sell them. This document governs one thing: a service we operate, that you chose to use, to reach buyers we introduced you to.

0. What this covers, and what it does not

This one document covers both sides of the RailCall Marketplace: publishing a Listing and buying one. It is an agreement between you and AiTrade LLC ("RailCall", "we"). It binds you when you create a Marketplace account, publish a Listing, or buy one — and it binds nobody else.

Three documents, three subjects:

  • Licensing notice — the software you download and run yourself.
  • These Marketplace Terms — publishing, buying, fees, payouts, review, takedown.
  • Terms of Service — accounts, the hosted gateway, and any other service we operate.

Where they overlap, the more specific one governs its own subject. Where one of them appears to restrict what the software licence already grants you, the software licence wins.

1. Definitions

  • Publisher — the person or entity that lists a Listing for sale or free distribution.
  • Buyer — anyone who acquires a Listing through the Marketplace, paid or free.
  • Listing — a signed, installable package distributed through the Marketplace, together with its public catalogue page. Today the Marketplace accepts governed workflow templates and workflow libraries, policy packs, prompt bundles, connectors, integrations, and signed modules. We may add Listing types; we will say so here when we do.
  • Manifest — the machine-readable declaration inside every Listing: identity, version, publisher public key, the credentials it requires, the network destinations it may reach, and for every command it registers, whether that command reads or writes.
  • Blast-Radius Declaration — the part of the Manifest stating what systems the Listing touches, which of its actions are irreversible, where it may send traffic, and what it can spend.
  • Acceptance Criteria — §4. Exhaustive for approval decisions.
  • Good Standing — a Publisher with no unresolved security removal, no unpaid balance owed to RailCall, and no more than one upheld rejection for a materially inaccurate Blast-Radius Declaration in the trailing twelve months.

2. Accounts

You need a Marketplace account to buy or sell, and you must be able to enter a contract in your jurisdiction. You are responsible for what happens under your credentials. Keep your password out of scripts, screenshots, and repositories.

Publishing additionally requires a seller profile, a registered Ed25519 publisher public key, and — for any paid Listing — completion of the payment processor's onboarding and identity verification. Free Listings require the account and the key only.

Counsel — the badge says more than this paragraph doesA Publisher who has completed no identity verification currently carries a badge reading “Verified Publisher.” The badge is automatic on key registration, and by the paragraph above a free Listing needs only an account and a key. The Trademark Policy §5.2 is careful about this — it says the badge is “a statement about key registration, not about quality, security, or conduct” — but the word on the badge is “Verified,” and a buyer reads the word, not the policy. That is the exact harm Trademark Policy §4.9 prohibits third parties from causing, and we would be committing it first. §6.3 is corrected above to distinguish paid from free, which narrows the gap but does not close it. Two clean fixes: rename the badge to “Signed Publisher” or “Key-Registered Publisher,” which is what it actually means; or gate it on identity verification for everyone. Decide before the badge is on more pages.

No account is required to download, install, or run RailCall. The account exists for the Marketplace.

3. Who may publish

3.1 Publishing is open

Publishing is open on published criteria. It is not curated by relationship, invitation, introduction, partnership status, employment history, geography, company size, or whether we have heard of you. A Publisher qualifies if, and only if, they:

  • hold a Marketplace account and can enter a contract in their jurisdiction;
  • complete the payment processor's onboarding and identity verification, for paid Listings;
  • register an Ed25519 publisher public key;
  • are not subject to sanctions or export restrictions applicable to either party; and
  • submit a Listing that meets the Acceptance Criteria in §4.

Nothing else is a condition of publishing. Applying is free and joining is free. These terms are offered on the same basis to everyone, including to people and companies that compete with RailCall. We do not reserve a right to refuse a Listing because it competes with a RailCall product, because it competes with another Publisher, or because we would prefer to build it ourselves.

3.2 First-party Listings

RailCall's own Listings go through the same submission queue and the same Acceptance Criteria, and are labelled as first-party in the catalogue. Search ranking, category placement, and default sort apply the same rules to first-party and third-party Listings. We do not rank a Listing higher because it is ours.

3.3 Reviewer conflicts

A reviewer must not decide on a Listing that competes with one they publish themselves or hold an economic interest in. Where no unconflicted reviewer is available, the conflict is disclosed in the decision and the Publisher may require escalation under §5.4.

4. Acceptance Criteria

These are the only grounds on which a Listing may be refused. A refusal must cite at least one by number.

  • A1 — Manifest completeness. The Listing ships a valid Manifest declaring: identity and version; the publisher public key; every credential it requires, with its risk level and whether it reads or writes; every network destination it may reach; and, for every command it registers, whether that command is a read or a write requiring approval.
  • A2 — Blast-Radius accuracy. The declaration matches the code. Every irreversible action is declared as irreversible. Every destination is listed. Every credential is listed. A materially wrong declaration is a breach of these terms, not a metadata error — see §10.2.
  • A3 — Signature and integrity. The Listing is signed under the Publisher's registered key, the signature verifies over the canonical bundle, and the bundle installs without modification on the runtime versions the Listing states it supports.
  • A4 — Least privilege. The Listing requests no credential, destination, or write capability it does not use. Requesting broad scope "for future versions" fails A4.
  • A5 — No governance weakening. The Listing does not bypass, weaken, disable, or route around the buyer's approval airlock, approval-policy floors, credential vault, dry-run default, or receipt generation, and does not attempt to lower a buyer's configured policy floors. See §10.4.
  • A6 — Listing accuracy. The catalogue page states what the Listing does, what it requires, what it costs, what support the Publisher provides, and which runtime versions it supports. Screenshots and claims reflect actual behaviour.
  • A7 — Rights. The Publisher holds the rights to everything in the Listing, including every third-party dependency, and each dependency's licence permits distribution on these terms.
  • A8 — Not prohibited. The Listing is not caught by §11.
  • A9 — Supportable. The Publisher states a support channel and a response commitment (§12) and, for a subscription Listing, commits to maintaining compatibility with the current stable runtime for the subscription term.

4.1 What is not an acceptance criterion

Not grounds for refusal: commercial competition with RailCall or with any other Publisher; price; the Publisher's identity, size, nationality, or reputation; our own product plans; stylistic preference; or that a similar Listing already exists.

Quality is judged against A1–A9, not against taste. A Listing that is unremarkable but honest, safe, and accurately described passes.

5. Review, service levels, appeal

5.1 Three decisions

  • Approve — the Listing goes live.
  • Needs work — numbered criteria, what failed, and what would fix it. The Listing stays in the queue, is not published, and is not removed or frozen. Resubmission does not go to the back of the queue.
  • Reject — numbered criteria and a written reason. Appealable.

A decision that says only "does not meet our standards" is not a decision under these terms.

5.2 Service levels

Business days, from a complete submission.

SubmissionFirst decision within
First Listing from a new Publisher10 business days
New Listing, Publisher in Good Standing5 business days
Resubmission after needs work3 business days
Patch adding no new destination, credential, or write command2 business days
Security patch to a live ListingSame business day, expedited

5.3 If we miss a service level

A missed service level does not auto-approve the Listing. Auto-approval on a timer, in a marketplace for code that runs on other people's machines, converts our backlog into the buyer's security incident.

Instead: the submission moves to the front of the queue, the Publisher may escalate immediately under §5.4 without waiting, and the seller fee is waived on that Listing for its first ninety days of sales. We pay for our delay out of our own margin, not out of the buyer's safety.

5.4 Appeal

Any reject, any removal under §14, and any suspension may be appealed.

  • File within 60 days, through the publisher dashboard or legal@railcall.ai.
  • The appeal is reviewed by someone other than the original decision-maker. Where the organisation is too small for that to be literally possible, the original reviewer must re-decide in writing against the numbered criteria, and the Publisher may escalate to the founder.
  • A written outcome issues within 10 business days: upheld, overturned, or overturned on condition.
  • If a rejection is overturned, the Listing is published and the seller fee on its first ninety days of sales is waived.
  • Nothing here waives either party's right to go to court or arbitration.
Counsel — the §5.3 / §5.4 remedy is now worth nothingBoth remedies above compensate our delay by waiving the seller fee on the Listing’s first ninety days of sales. As of the 2026-08-27 change order the seller fee is 0%(§6.1), so waiving it transfers nothing to the Publisher and the promise is illusory. Two of the numbered service-level guarantees in §5 depend on it. Either replace the remedy with something that has value at a 0% seller fee — a credit against the Buyer’s assurance fee on that Listing, or an operational remedy such as guaranteed queue position — or delete the sentences and stop offering a remedy we cannot pay. Do not leave them as written.

5.5 Reasons are binding

The reason given in a decision is the reason. We will not reject on one ground, have it overturned, and then reject the same submission on a ground we could have raised the first time — except where the new ground is a security or legal defect discovered later, or arises from a change the Publisher made.

6. Money

No fee exists that is not on this page.

6.1 The two fees

FeeRateWho paysWhen
Seller fee0%Nobody — nothing is deducted from the Publisher’s proceedsEvery sale and renewal
Buyer assurance fee15%Buyer, added at checkout as its own lineEvery purchase and renewal

The Publisher keeps 100% of the list price. The Publisher pays us nothing: no seller fee, no tiers, no volume bands, no listing fees, no placement fees, no featuring fees, no mandatory advertising spend. The single fee on a sale is the Buyer’s assurance fee, and it is disclosed to the Buyer at checkout as its own line rather than deducted from the Publisher’s proceeds.

A Listing at $100: the Buyer is charged $115 — $100 plus a $15 assurance fee, shown separately before payment. The Publisher receives $100, the full list price. Payment-processing costs come out of the assurance fee, not the Publisher's.

CounselConfirm that the payment integration actually pays 100% of the list price and absorbs processor fees out of the assurance fee. This is a harder engineering claim than the 95% split it replaces: at a 0% seller fee there is no margin on the Publisher's side to net processing against, so a payout that quietly deducts the processor's cut would pay about $97 on a $100 Listing and contradict this section. The terms, the payout code, and the pricing page must say the identical thing on the same day.Counsel — §6.7 notice on this very changeThis schedule changed on 2026-08-27from 5% seller / 10% buyer (publisher keeps 95%) to 0% / 15%. §6.7 requires not less than 30 days’ written notice of a rate change, applied prospectively only. The seller-side move from 5% to 0% is favourable and can take effect immediately. The buyer-side move from 10% to 15% is adverse to Buyers, and to Publishers whose Listings become 5% more expensive at checkout without their price changing. Decide the effective date and the notice method for the buyer-side increase before it is charged, and state on this page which schedule governed which period.

6.2 The buyer sees the total before paying

The list price and the assurance fee are shown as separate lines at checkout, and the total is shown before the Buyer pays. We do not add a fee after the Buyer has committed, and we do not describe the assurance fee as anything other than what it is.

This replaces the sentence in v0.1 that said "the listed price is the price you pay — RailCall does not add hidden fees at checkout." A 15% buyer-side fee exists. Disclosing it is the fix.

6.3 What the assurance fee buys

Stated plainly, because a fee called assurance that assures nothing is the fastest way to lose a serious buyer. On every release of every third-party Listing, it buys:

  • verification that the bundle is signed under the Publisher's registered key and is byte-identical to what was signed;
  • provenance — the signature belongs to a registered publisher key, and for a paid Listing, that key belongs to a Publisher who completed the payment processor’s identity verification;
  • validation of the Blast-Radius Declaration against the Buyer's own policy configuration, so the Buyer is told before install what the Listing will touch, what it can reach, and which actions cannot be undone;
  • removal and buyer notification if a security defect is confirmed after purchase (§14);
  • the refund right in §13.2;
  • consolidated invoicing across every Listing the Buyer holds;
  • a signed receipt evidencing each of the above.

It recurs on renewals because the verification recurs on every release.

It does not buy, and no Listing may imply otherwise:

  • a line-by-line audit of the Publisher's code. We verify structure, signatures, and declarations. We do not read every line and do not warrant that no vulnerability exists.
  • a warranty that the Listing is fit for the Buyer's purpose. That is the Publisher's product.
  • indemnity for third-party Listings.
  • any promise that we execute, host, or supervise the Listing. It runs on the Buyer's hardware, under the Buyer's policy, with the Buyer's credentials.

6.4 What comes off before the split

In this order: taxes we or the processor must collect and remit; refunds; chargebacks. A refund or chargeback reverses the whole sale: the Publisher's share is the full list price, so the full list price is what comes back off it, and the Buyer's assurance fee is refunded with the purchase rather than kept by us. We do not retain a fee on a sale that was refunded.

6.5 The closed list

The two fees in §6.1, the deductions in §6.4, and taxes are the complete set of amounts we take from a Publisher's sale. We do not charge to list, to update, to appear in search, to be featured, to be reviewed, to appeal, to withdraw, or to export.

Counsel / Founder — the live pricing page sells one of theseThe live pricing page, fetched 2026-08-27, advertises “optional featured placement available” immediately after “No listing fees.” That cannot coexist with this closed list, with §6.1’s “no placement fees, no featuring fees, no mandatory advertising spend,” or with §3.2’s promise that search ranking and category placement apply the same rules to first-party and third-party Listings. Three of the strongest trust claims in this document turn on the closed list being genuinely closed, so this is not a wording problem — it is a decision about whether the Marketplace sells placement. If it does, these clauses must change and the paid placement must be disclosed as an advertising product distinct from ranking. If it does not, the pricing page must drop the line. Do not publish both.

6.6 Payouts

Sale proceeds are credited to the Publisher's Marketplace balance in the same transaction that marks the sale paid, so the balance always reflects the ledger. Payouts are requested from the publisher dashboard and require a payout method on file, a minimum balance of $50 USD per request, and a review before transfer. Approved payouts transfer within 5 business days. Rejected or failed payouts return the reserved amount to the available balance automatically.

We may withhold or delay a payout where we reasonably suspect fraud or a chargeback pattern, where a breach of §10 or §11 is under investigation, or where required by the processor or by law — for as long as reasonably necessary to investigate, with written reasons and a monthly status update while the hold lasts.

Payout disputes must be raised within 90 days of the statement in question.

CounselDoes holding sale proceeds as a Publisher balance before payout require money-transmitter analysis in Florida or elsewhere, or should funds flow through Stripe Connect so we never hold them? This mechanism is already described on the live v0.1 page; the question has not been answered.

6.7 Rate changes

Not less than 30 days' written notice. Revised rates apply prospectively only — to sales and billing periods after the effective date, never retroactively. A Publisher who does not accept a new rate may withdraw under §7.3 with full continuity for existing Buyers and no penalty.

6.8 Free Listings

A Publisher may list at $0. Free Listings carry no seller fee and no assurance fee, go through the same review, and get the same catalogue treatment. Paid Listings are priced in USD, with a $0.50 minimum imposed by the payment processor.

7. Publisher rights

7.1 You own your work

Publishing transfers no intellectual property to RailCall. The Publisher grants RailCall a worldwide, non-exclusive, royalty-free licence to host, index, verify, market, distribute, and deliver the Listing through the Marketplace, and to display Listing metadata publicly — and nothing more. That licence:

  • ends for new distribution when the Listing is withdrawn or these terms end, surviving only as far as needed to serve Buyers who already purchased (§15.2);
  • does not permit us to modify the Listing, except to refuse to distribute it;
  • does not permit us to sublicense it other than as the end-user licence stated on the Listing;
  • does not permit us to use the Listing's code, design, or content to build a competing first-party Listing (§7.4);
  • does not permit us to use the Publisher's name or marks beyond identifying them as the Publisher.

7.2 You set your price

The Publisher sets the list price, the pricing model (one-time or subscription), and the billing interval, and may change them at any time, prospectively. We do not set, cap, floor (beyond the processor's $0.50 minimum), or require a price as a condition of listing, and we do not run a discount or promotion on a Publisher's Listing without their written agreement.

7.3 You may withdraw

At any time, for any reason, without penalty. On withdrawal:

  • the Listing leaves the catalogue and search within 2 business days;
  • perpetual licences already sold survive — a Publisher does not get to break what Buyers bought;
  • active subscriptions run to the end of the current paid period unless the Publisher supports them longer;
  • accrued balances pay out on the normal cycle;
  • withdrawal is not a breach and does not affect Good Standing.

7.4 We will not clone your Listing

We will not use a Publisher's Listing, its code, its Manifest, its catalogue copy, or non-public data about its performance to build a competing first-party Listing.

Specifically, we will not use, for the purpose of building or specifying a competing Listing: the Publisher's source; their unpublished submissions or drafts; per-Listing sales, conversion, install, or search-demand data not published to all Publishers; or anything learned in review, support, or a dispute.

The honest limit. We build first-party Listings and will keep building them, and some will land in the same category as a Publisher's. This forbids cloning — building from the Publisher's own material or non-public data — not competing. A promise never to enter a category would be a promise we cannot keep.

So the covenant is procedural and checkable:

  • Aggregate only. Category-level demand may inform our roadmap; per-Listing data may not.
  • Notice. Where we publish a first-party Listing in the same category as a live third-party Listing, we notify that Publisher at launch.
  • Separation. Reviewers do not brief first-party product teams on the contents of third-party submissions.
  • Remedy. A Publisher who believes their Listing was cloned may invoke §5.4. If upheld, we withdraw the first-party Listing.

8. Non-circumvention

This is the clause that pays for the introduction. It binds both sides.

8.1 What it covers

A Buyer is a Marketplace-sourced Buyer for a Listing if their first transaction with that Publisher for that Listing — or for anything materially equivalent to it — happened through the Marketplace. We introduced that Buyer. The seller fee is what the introduction costs.

8.2 The Publisher's commitment

For twelve months after a Marketplace-sourced Buyer's most recent Marketplace transaction with the Publisher, the Publisher will not solicit or accept payment outside the Marketplace from that Buyer for the same Listing, a renewal of it, or a materially equivalent substitute, where the purpose or effect is to avoid the seller fee.

8.3 What this is not

It is not a non-compete, an exclusive dealing arrangement, or a claim on the Publisher's business. It reaches one specific Buyer we introduced, for one specific product, for twelve months. It expressly does not restrict:

  • Buyers the Publisher already had. A relationship that predates the Marketplace transaction is outside this clause, and the Publisher's own records are sufficient evidence of it.
  • Buyers who find the Publisher independently, through the Publisher's own site, content, network, or referral.
  • Services. Custom work, consulting, integration, training, and support the Publisher sells for their time — including to a Marketplace-sourced Buyer, at any time.
  • Different products. Anything that is not the same Listing or a materially equivalent substitute, including later and larger products.
  • Selling the same Listing to everyone else, anywhere, through any channel, including the Publisher's own website, at any price. This clause reaches a Buyer, not a market.
  • Free distribution of anything, to anyone.
  • Anything the Marketplace does not carry. If a Listing type is not accepted here, nothing here reaches it.

If a Marketplace-sourced Buyer asks the Publisher, unprompted, to transact off the Marketplace, the Publisher may do so on telling us and paying the seller fee that would have applied.

8.4 Our commitment, the other direction

We will not use a Publisher's Marketplace-sourced Buyer relationship to market a competing first-party Listing to that Buyer specifically, and we will not use per-Listing data that is not published to all Publishers to build or specify a competing Listing (§7.4). Category-wide and catalogue-wide marketing is unrestricted.

Both halves are load-bearing. Neither survives alone.

8.5 Remedy

The remedy for a breach of §8.2 is the seller fee that would have applied to the avoided transactions, plus removal of the Listing and, for repeated breach, termination of the publisher account. We do not claim the Publisher's revenue and do not seek damages beyond that fee.

8.6 Survival

§8 survives withdrawal of a Listing and termination of the account, for the twelve-month period only.

9. Signing, provenance, and independent verification

9.1 What the Publisher signs

Every Listing is signed with the Publisher's registered Ed25519 key over the canonical bundle. The signature and public key ship inside the Listing. The Marketplace verifies at publish; the Buyer's runtime verifies at install.

CounselState accurately what the signature covers. The live v0.1 page says the signature covers listing type, the sha256 of the canonical payload, the price, and the timestamp. The shipping module tooling puts price deliberately outside the signed bundle so a price change needs no republish. Both cannot be true, and §7.2 (change your price at any time) depends on the answer. Resolve against the code before publication.

9.2 What the Buyer's own machine checks, without asking us

  • Signature — the bundle verifies under the Publisher's key and is byte-identical to what was signed.
  • Publisher trust — a Buyer's install can be set to refuse any Listing whose publisher key is not on the Buyer's own allowlist. A valid signature proves someone signed it; the allowlist is what makes it matter that this Publisher signed it. The trust anchor is the Buyer's list and the Marketplace's registry of verified keys — never a key the Listing asserts about itself.
  • Blast radius — declared destinations, credentials, and irreversible actions surface before install and are enforced at runtime.
  • Policy floors — irreversible actions require a human; unclassified actions require a human; changes to the Buyer's own policy require a human. No Listing can lower these.
  • Receipts — every governed action emits a signed receipt whose integrity hash can be recomputed from scratch.

9.3 Off-box verification stays free

A Buyer can take a receipt to a machine that has never run RailCall, fetch the install's published public key, recompute the integrity hash from the receipt's own contents, and verify the signature. Verification requires no account, no network call to us, and no fee, and is intended to stay that way.

This is the Publisher's strongest asset. It is what lets a Publisher tell a sceptical enterprise buyer: do not take my word or RailCall's — check it yourself.

9.4 Keys, rotation, compromise

The Publisher's key is their identity. Losing the seed loses the identity; back it up.

  • Rotation is deliberate and handled by RailCall support, not self-serve. Listings signed under a retired key stay verifiable under that key for Buyers who already hold them.
  • Compromise must be reported immediately. We suspend new installs under the compromised key, notify affected Buyers, and work with the Publisher to reissue under a new key.
  • We never hold, escrow, or access a Publisher's signing seed, and cannot sign on their behalf.

9.5 What signing does not prove

A valid signature proves origin and integrity — this Publisher produced these exact bytes. It does not prove the code is safe, correct, well written, free of vulnerabilities, or fit for any purpose. Provenance is a floor, not a warranty, and no Listing may describe a passing signature check as certification by RailCall (§16).

10. The security bar

10.1 Why it is higher here than in an app store

A Listing is not a sandboxed app on a phone. It executes on someone else's infrastructure, inside their trust boundary, holding their credentials, reaching their systems. A defective Listing does not crash a tab — it writes to a production database, sends a message that cannot be recalled, or moves data somewhere it should not be. Publishers accept obligations proportionate to that.

Scope note. Everything in §10 is about code you ask us to distribute to other people. None of it restricts what anyone may do with RailCall source code they hold under its own licence.

10.2 Declare everything

The Blast-Radius Declaration must be complete and accurate on every release: every destination, every credential, every irreversible action.

A materially inaccurate declaration is a terminable breach, not a metadata error. The declaration is the input to the Buyer's own policy engine. If it under-declares, the Buyer's controls silently fail open on the Buyer's own machine. This is the single most serious thing a Publisher can get wrong.

10.3 Least privilege

Request the narrowest credential scope that works. Pin egress to the hosts actually needed. Mark every command that writes as a write. Do not request scope for features not yet shipped.

10.4 Never route around the buyer's governance

A Listing must not attempt to: bypass, weaken, or disable the approval airlock; lower or evade a Buyer's approval-policy floors; suppress, forge, or omit receipts; read, exfiltrate, or transmit the credential vault; perform undisclosed network egress or telemetry; or execute code fetched at runtime from an undeclared source.

Separately, a Publisher will not circumvent the Marketplace's own entitlement, signing-verification, or metering mechanisms in order to place a transaction outside these terms.

A Listing cannot lower a Buyer's policy floors and must not try. An attempt is a security incident under §14, regardless of intent or whether it succeeded.

10.5 Dependencies

Publishers are responsible for everything they ship, including dependencies. Pin versions. Do not fetch code at install or run time from an undeclared source. Every dependency's licence must permit distribution on these terms. A Publisher should be able to state the provenance of every third-party component on request.

10.6 Secrets

No credentials, API keys, tokens, private keys, personal data, or customer data in a published Listing — ever, in any release, including examples, fixtures, and test data. Secrets belong in the Buyer's own vault. A Listing found to contain a live secret is removed immediately under §14 and the Publisher must treat that secret as compromised.

10.7 Updates

Every release goes through review. Publishers must not use the update channel to widen scope quietly: a release that adds a destination, a credential, or a write command is a scope change and is reviewed as one, whatever the version number says.

10.8 Coordinated disclosure

Publishers must accept vulnerability reports and give a substantive first response within 5 business days. On a confirmed vulnerability, the Publisher works with us on a coordinated fix and Buyer notification. We will not publish details of an unfixed vulnerability before the agreed disclosure date except where Buyers are at active risk. Good-faith security researchers who follow the published disclosure process are not pursued by us for reporting a defect in a Listing or in the Marketplace.

11. Prohibited Listings

A Listing may not:

  • contain malware, backdoors, ransomware, cryptominers, or code whose purpose is concealed from the Buyer;
  • exfiltrate credentials, customer data, or undeclared telemetry;
  • bypass, weaken, or circumvent the airlock, policy floors, vault, dry-run default, or receipt generation (§10.4);
  • infringe third-party rights, including copying another Publisher's Listing;
  • present itself as authored, endorsed, certified, reviewed, or supported by RailCall when it is not (§16);
  • contain, or be primarily designed to produce, illegal content, harassment, or unlawful discrimination;
  • embed credentials, personal data, or customer data (§10.6);
  • be primarily a mechanism for surveilling people without their knowledge, or for evading legal obligations;
  • misrepresent what it does, what it costs, what it touches, or who wrote it;
  • be a functionally empty listing, a placeholder, or a name-squat on a term the Publisher does not use.

We may decline or remove a Listing under this section. Removal under §11 is appealable under §5.4.

12. Support and maintenance

  • The Publisher supports their own Listing. The catalogue page must state the support channel and the response commitment, and both must be accurate.
  • Subscription Listings must be maintained against the current stable runtime for the subscription term, or the catalogue page must clearly state the supported version range.
  • We support the Marketplace — accounts, checkout, payouts, installation, verification — and refer Listing-specific issues to the Publisher.
  • End of life. A Publisher discontinuing a Listing gives Buyers of active subscriptions not less than 60 days' notice through the Marketplace, and does not disable perpetual licences already sold.
  • Abandonment. A Listing with no response to a confirmed security report within 30 days may be removed and its Buyers notified.

13. Buying

13.1 What a Buyer gets

Prices are shown in USD. At checkout the list price and the 15% assurance fee are shown as separate lines, and the total is shown before payment (§6.2).

After payment, the Buyer receives an install command per Listing purchased. Installing writes a signed package into the Buyer's own RailCall workspace. It does not mean any action fires — the local airlock still requires approval for anything with external side effects, on the Buyer's own machine, under the Buyer's own policy.

A Listing is not a service RailCall performs on the Buyer's behalf. Execution happens on the Buyer's machine, under the Buyer's RailCall install, with the Buyer's credentials. The Marketplace is content distribution, not managed hosting.

13.2 Refunds

30 days from purchase, no questions asked. A full refund on request within 30 days of paying, for any reason: didn't solve the problem, described incorrectly, technical failure, changed your mind. Refunds are processed to the original payment method within 5 business days of approval, and the assurance fee is refunded with the purchase.

On refund, your entitlement to the Listing is revoked, and you agree to stop using it and remove it from your systems. We will be straight about this one: licence enforcement is local by design (§15), so nothing on our side can tell whether you did, and we are not going to build something that can — the architecture that makes a purchased Listing keep working without us is the same architecture that makes this unpoliceable. It is stated because the Publisher absorbs the reversal under §13.3, and they should have a claim if someone takes the refund and keeps the goods. Most people will do the right thing, and the ones who do not are not the ones a clause was ever going to stop.

After 30 days, refunds are handled case by case at legal@railcall.ai. There is no hard cutoff for a valid claim — a Listing that turns out to be malicious is refunded past the window. Cases under §11 do not need to be timely.

13.3 How a refund reaches the Publisher

Refunds and chargebacks are reversed against the Publisher's share in the same proportion as the original split. Because the Publisher keeps 100% of the list price, the reversal against the Publisher is the full list price — and the Buyer's assurance fee reverses to the Buyer, so we keep nothing either. Where the available balance cannot cover a reversal, the shortfall is recorded as a debit and nets against future Marketplace sales.

For an individual Publisher, that is the whole remedy. Where the Publisher is an individual rather than an entity, we net the shortfall against future Marketplace earnings and do not pursue it as a personal debt — except where the refund arises from fraud or from a materially false Blast-Radius Declaration.

13.4 Refund abuse

Where a Listing shows a refund rate materially above the catalogue norm, we may require the Publisher to correct the description, may withhold payouts pending investigation (§6.6), and may remove the Listing if the cause is a misdescription the Publisher will not fix.

13.5 Disputes between Publisher and Buyer

We are a venue, not either party's agent, and have no obligation to mediate — though we may assist. The end-user licence is between Publisher and Buyer. We will provide either party with the transaction record they are entitled to.

13.6 Disputes with us

Fee, payout, or settlement disputes: raise within 90 days of the statement. Undisputed statements are final after that. Review, removal, and suspension decisions: §5.4.

14. Takedown, suspension, emergency powers

14.1 Emergency removal

Where we reasonably believe a Listing presents an active security risk to Buyers, we may remove it immediately and without prior notice, and may suspend the Publisher's ability to publish new releases. Buyer safety comes before process.

14.2 What the Publisher is owed, immediately after

Within 1 business day of an emergency removal: written notice; the specific defect and the evidence for it, to the extent disclosure does not itself endanger Buyers; what would resolve it; and the appeal path.

An emergency power without a same-week accounting is a discretionary power wearing an emergency's clothes.

14.3 What Buyers are told

Buyers who installed an affected version are notified of the defect, the affected versions, and what to do. The notice is factual, does not characterise the Publisher's motives, and is corrected publicly if the removal is later overturned.

14.4 Non-security removals

Where a removal is not security-related, the Publisher gets 14 days' notice and written reasons before the Listing comes down.

14.5 The limit on the emergency power

The security removal power exists to protect Buyers and may not be used as a commercial instrument — not to resolve a fee dispute, not to pressure a Publisher on pricing, not to clear the field for a first-party Listing, and not as a substitute for the notice period in §14.4. A removal characterised as security-related and found on appeal to have had no security basis is treated as a non-security removal from its start date.

14.6 Reinstatement

When the defect is fixed and verified, the Listing returns in the expedited lane, Good Standing is restored, and the public record notes the resolution.

15. Termination and export

15.1 By either side

By the Publisher: any time, for any reason, by withdrawing every Listing and closing the account. Accrued balances settle on the normal cycle. Withdrawal is not a breach.

By us — and removing a Listing and terminating a Publisher are different powers with different grounds.

  • A Listing may be refused or removed on any Acceptance Criterion (§4), on the prohibited list (§11), or for a security defect (§14).
  • A Publisher account may be terminated only for: prohibited content (§11); fraud; infringement of a third party's intellectual property; repeated breach of §8.2 after notice; or legal and sanctions compliance. A Listing-level failure — an inaccurate manifest, an over-broad scope request, a page that oversells — costs the Publisher that Listing. It does not cost them the account.

Except in the emergency case (§14.1), termination requires 14 days' written notice, specific reasons, an opportunity to cure a curable breach, and the appeal in §5.4.

15.2 What the Publisher keeps

On any termination, however it arises: their intellectual property, all of it; their money, less amounts properly owed — termination is not a forfeiture event; their signing key and identity, which we never held; their Buyer relationships outside the Marketplace; and their export (§15.3).

And what continues without them: perpetual licences already sold survive, active subscriptions run to the end of the current paid period, and Buyers keep what they bought. A Publisher cannot revoke a Buyer's licence by leaving, and we cannot revoke it by removing the Publisher.

15.3 Export

At any time, and automatically on termination, a Publisher may export a machine-readable file containing their Listings and metadata, release history and version records, aggregate sales and settlement history, and buyer counts by Listing and version — not Buyer identities or Buyer data, which belong to the Buyer. Available for 90 days after termination.

15.4 If we discontinue the Marketplace

  • Notice — not less than 180 days before catalogue closure.
  • Sales window — Listings stay purchasable during the notice period unless withdrawn.
  • Already-sold Listings keep working. Licences already granted are not revoked, and licence enforcement is local by design so a purchased Listing does not need the Marketplace to keep running.
  • Export for every Publisher (§15.3).
  • Settlement — all accrued balances pay out within 30 days of closure, minimum threshold waived.
Counsel / FounderThe third bullet has a live technical dependency. Paid Listings verify an offline-signed licence that carries an expiry with a short grace period. If the licence-issuing service goes away, time-limited licences stop working on the Buyer's own hardware after grace lapses. One of these has to be built before the first paid third-party Listing goes live, not at wind-down: (a) perpetual non-expiring licences reissued to every holder before shutdown; (b) an offline reissue tool plus issuing key material in escrow, released on shutdown; or (c) a signed licence-check bypass in a final runtime release. Until one exists, that bullet is a promise the system cannot keep.

16. Trademarks

Publishing a Listing licenses none of RailCall's trademarks, and neither does the software licence.

A Publisher may state truthfully that a Listing runs on RailCall, is built for RailCall, is compatible with RailCall, or requires RailCall — in plain text, in the ordinary descriptive way.

A Publisher may not:

  • use RailCall's marks, logos, or a confusingly similar name in the Listing's name, the publisher name, a logo, an icon, or a domain name;
  • describe a Listing as official, certified, verified, approved, reviewed, or endorsed by RailCall, or as a RailCall product, when it is not;
  • describe a passing signature check, a completed review, or a first-party label as certification by RailCall. Signature verification is provenance, not certification (§9.5);
  • imply a partnership, affiliation, or authorship relationship that does not exist.

Full terms are in the RailCall Trademark Policy.

CounselConfirm the published URL for the Trademark Policy and that it goes live in the same change as these terms — this cross-reference must not point at a 404.

17. Warranties, liability, indemnity

17.1 The Marketplace is provided as-is

We do not warrant that a specific Listing solves a specific problem. We warrant one thing: that the signature we serve alongside a Listing verifies against the Publisher’s registered key over the canonical bundle as defined in §9.1, and that we do not alter that bundle between the Publisher signing it and you installing it. Your own machine checks this at install without asking us (§9.2), which is the point — the warranty is worth something because you do not have to take our word for it. Individual Listings carry their own author, their own quality, and their own risk profile; the signed provenance record is what we deliver.

CounselThis warranty is the only affirmative one in the package, and it is keyed to §9.1’s definition of the canonical bundle — which §9.1 itself records as unresolved.The live v0.1 page says the signature covers listing type, the sha256 of the canonical payload, the price, and the timestamp; the shipping module tooling deliberately places price outside the signed bundle so a price change needs no republish. Until that is settled against the code, we do not know exactly what we are warranting. An earlier draft warranted “the byte-identical payload the Publisher signed” flatly, which asserts a boundary the drafters could not establish. Resolve §9.1 first; this clause then either tightens or stays as drafted, but it should not publish flatter than the fact.

17.2 Our liability

To the maximum extent permitted by law, our aggregate liability arising out of or related to the Marketplace is limited to the greater of (a) the amounts you paid to us, or that we retained from your sales, on the Marketplace in the twelve months preceding the claim, or (b) one hundred US dollars (US$100). Nothing here limits liability that cannot lawfully be limited, including liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence, or wilful misconduct.

Why the “or retained” and the floor. An earlier draft capped our liability at “the amounts you paid on the Marketplace.” A Publisher does not pay us — we deduct from what they earn — so for every Publisher on the platform that cap read as zero. A zero cap against a solo publisher is the fact pattern that gets a limitation clause struck in its entirety, and it would have taken the buyer-side cap down with it. A cap that survives is worth more than a cap that reads well.

17.3 Publisher indemnity — capped for individuals

Publishers indemnify RailCall against third-party claims arising from their Listings, including infringement, materially false Blast-Radius Declarations, and violations of law.

Where the Publisher is an individual rather than an entity, that indemnity is capped at the greater of the amounts paid to that Publisher through the Marketplace in the preceding twelve months, or $1,000 USD. The cap does not apply to claims arising from fraud, wilful infringement, or a Listing prohibited under §11.

An uncapped indemnity is a rational term between companies and an irrational one to demand of a solo developer clearing a few hundred dollars a quarter.

CounselConfirm the cap and the floor figure — this is a business decision as much as a legal one, and it is drafted to protect long-tail supply.

17.4 No compliance claims

Nothing in the Marketplace, and no Listing in it, is certified by RailCall against any regulatory framework. We hold no SOC 2 report today and make no HIPAA, PCI, or equivalent compliance representation for the Marketplace. Where we obtain an independent report, we will say so and name the auditor.

18. Changes to these terms

Material changes take effect on not less than 30 days' notice, published here and in the Marketplace, and sent to Publishers with live Listings. Rate changes follow §6.7. A Publisher who does not accept a change may withdraw under §7.3 with full continuity for existing Buyers and no penalty. Continued publishing after the effective date is acceptance.

Changes to the Acceptance Criteria (§4) are published as a diff, apply only to submissions made after the effective date, and do not retroactively make a compliant live Listing non-compliant — except where the change closes a security gap, in which case live Listings get a stated remediation window before enforcement.

Every version of these terms is kept at a stable URL so you can read what you agreed to.

19. Entity, law, contact

Entity: AiTrade LLC, a Florida limited liability company. Governing law: Florida, without regard to conflict-of-law principles, matching the published RailCall Terms of Service.

Counsel(a) The entity block still needs AiTrade LLC’s registered business address. Counsel supplied the state of formation on 2026-08-27 and the entity block now reads “AiTrade LLC, a Florida limited liability company”; the address was not supplied and we have not invented one. Related: AiTrade LLC trades publicly as “RailCall” under Florida governing law, and Fla. Stat. §865.09 requires a registered fictitious name to do that — confirm the registration exists, it is about $50, and it is the first thing an opponent checks. (b) §19.1 now incorporates ToS §§18–23, which answers the arbitration question as drafted; confirm that incorporation is enforceable against non-US Publishers and against consumers, and how EU/UK consumer-protection rules interact with the refund and termination terms. (c) Confirm marketplace-facilitator tax obligations by jurisdiction. Separately and before the first payout: W-9 / W-8BEN collection and 1099-K / 1042-S reporting for Publishers. This is cheap through the payment processor’s connected-account flow and expensive to retrofit once money has moved. (d) Confirm whether a §512 designated agent has been registered with the U.S. Copyright Office, since §11 sets up a takedown process that confers no safe harbour without one — and note that §512(i) additionally requires a published, reasonably implemented repeat-infringer termination policy as a precondition. That policy is drafted at Acceptable Use Policy §5.2 and applies to Marketplace Publishers; confirm it, and confirm that a Publisher’s Listings are removed on termination.

Publisher support, review questions, appeals, security reports, and refund requests: the publisher dashboard, the RailCall Discord, or legal@railcall.ai.

Counsel / OpsBefore publication, verify that every channel named here reaches a human, and name the person who owns review escalations. Support policy is Discord-first and the transactional email provider is wired but dormant. An appeal path that routes to an unread inbox is the clause a Publisher tests first, when something has already gone wrong.

19.1 General provisions

Sections 18 to 23 of the Terms of Service apply to these terms and are incorporated by reference — disclaimers, limitation of liability (as modified by §17.2 above, which controls for Marketplace claims), indemnification, changes, governing law, informal resolution, arbitration, the small-claims and injunctive-relief carve-outs, the class-action waiver, the 30-day arbitration opt-out, and the general provisions. Where those sections and these terms conflict on a Marketplace matter, these terms control.

In addition, and stated here so they are not left to inference:

  • Severability. If a provision is held unenforceable it is limited or removed to the minimum extent necessary and the rest stands.
  • Entire agreement. These terms, the Terms of Service, the Acceptable Use Policy, and the Privacy Policy are the entire agreement between us about the Marketplace. They do not modify the licence on any software.
  • No waiver. Not enforcing a right on one occasion is not a waiver of it.
  • Assignment. You may not assign these terms without our written consent, except to a successor to your business. We may assign to an affiliate or in connection with a merger, acquisition, or sale of assets, on notice to you — and if we do, your Listings, your payout entitlements, and your badge status travel with the agreement.
  • Notices. To you, at the email or dashboard address on your Marketplace account. To us, at legal@railcall.ai.
  • Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control. This does not excuse payment of amounts already earned.
  • No third-party beneficiaries, except that §13.2 (buyer refund) and §15 (wind-down) are enforceable by the Buyers and Publishers they name.
  • Independent contractors. Nothing here creates a partnership, joint venture, employment, or agency relationship. A Publisher is not our employee or agent, and we are not a party to the underlying licence between Publisher and Buyer except as these terms state.
  • Interpretation.“Including” means “including without limitation.” Genuine ambiguity is read against us as drafter.

19.2 Survival

The following survive withdrawal of a Listing and termination of an account, together with any provision that by its nature should: §6.4 to §6.6 (as to amounts already earned or owed), §8 (non-circumvention, for its stated twelve-month period only), §9 (what a signature attests), §11 (infringement claims), §12 (Publisher warranties as to Listings already sold), §13.2 and §13.3 (refunds already claimable), §15 (wind-down), §16 (trademarks), §17 (warranties, liability, indemnity), and this §19.

CounselThis section was added during review because these terms previously carried entity, law, and contacts only — no severability, no entire agreement, no waiver, no assignment, no notices, no force majeure, no third-party-beneficiary clause, and a survival provision covering §8 alone. Assignment matters most: publisher agreements should travel on an acquisition, and without a clause they may not. Confirm the incorporation-by-reference approach is preferred to restating §§18–23 in full here — it is shorter and cannot drift, but it does mean a Publisher has to read two documents to find the arbitration clause, and consumer-facing enforceability of an incorporated arbitration provision should be checked separately for non-US Publishers.

Entity: AiTrade LLC, a Florida limited liability company · Governing law: Florida · Last updated: August 27, 2026
See also: Licensing · Trademark Policy · Terms of Service · Privacy Policy