Skip to main content

Permitted use

HFSAA permits you to download, cache, reproduce, and display data returned by the public API while that data remains within the one-hour freshness window described below. This includes complete-dataset snapshots and modified or derived datasets used commercially or noncommercially. When using or redistributing the data:
  • Identify HFSAA as the source.
  • Preserve dataset_version and generated_at metadata when the API supplies them.
  • Clearly disclose material modifications to the data.
  • Do not imply that HFSAA endorses your application, content, organization, or business.
This permission does not grant rights to HFSAA trademarks, service marks, or logos. Separate permission may be required to use an HFSAA logo or official badge.

Verification and attribution

Whenever your product states or implies that a location is certified or halal verified by HFSAA, identify HFSAA and give users reasonable access to that location’s exact verification_url. There is no required wording or placement. The verification link may be associated with the certification statement, the HFSAA name, a badge, a Learn more link, or another clearly related details element. In a digital product it must be clickable. In offline material, print the URL or provide a scannable QR code. Do not construct, shorten, or alter a verification_url. Use the exact location-specific URL returned by the API rather than a generic HFSAA link.

One-hour caching limit

API data may be cached for no more than one hour from the time it is fetched. After one hour, revalidate or fetch a fresh copy before continuing to store, serve, redistribute, or present the data as current HFSAA certification information. The API may keep immutable versions available for longer to support pagination and checksum verification. That server-side availability does not grant permission to cache or retain a local copy beyond one hour. Longer-term archival or historical storage requires separate written permission from HFSAA. The public endpoints return only locations whose current public certification status is certified. Pending, revoked, and not-certified locations are excluded. A location’s status can change during the one-hour cache period, so users should be able to follow its verification_url for current verification.

Public directory fields

The public API exposes a deliberately small set of HFSAA directory fields:

Deliberately excluded fields

The API does not return certificate IDs, certificate dates, images, image URLs, Google Maps URLs, hours, phone numbers, websites, delivery links, map coordinates, personal contact details, internal IDs, or operational metadata. This boundary keeps the API focused on HFSAA-approved directory records. Applications that want third-party enrichment can do so using their own provider relationship and permissions.