Open Source Notices
Last updated: [TBD] · This is a working draft pending legal review.
This page explains how Coded B.V. ("Coded", "we", "us") uses open-source software in the Coded commerce platform (the "Platform"), provides the attributions and license notices required by the open-source components we distribute or rely on, and states Coded's own posture toward open source. We publish it as part of our commitment to building the Platform transparently and to honoring the licenses of the software we depend on.
Coded B.V. is a private limited company registered in the Netherlands (a subsidiary of Coded Holding B.V.) and operates internationally. This page is provided for the benefit of merchants, the people who use their Organizations and projects, their own customers, and the wider community, wherever they are located.
Our use of open-source software
The Platform is built on top of, and incorporates, a large amount of open-source software. Open-source components form part of our application code, our build and deployment tooling, and the runtime environments that serve the Platform's web frontends and backend services. We are grateful to the maintainers and contributors of these projects, and we take seriously the obligation to comply with the terms under which their software is made available.
Open-source software is provided by its authors under a variety of licenses. Each component remains the property of its respective copyright holders and is licensed — not sold — to Coded and, where applicable, to end users. Nothing on this page transfers ownership of any open-source component, and nothing on this page should be read as a representation by Coded about software it does not author.
Where an open-source license requires that we reproduce a copyright notice, a permission notice, a license text, a disclaimer of warranty, or an attribution, we do so in the consolidated notices referenced below (the "NOTICE file"). Where a license requires that we make corresponding source code available, we comply with that requirement through the mechanism described in the "Source code availability" section.
How open-source components relate to the Platform
It is useful to distinguish two ways open-source software is involved in delivering the Platform, because the license consequences differ:
- Software we operate as a hosted service. Most open-source components are used to run the Platform as a hosted, online service that you access over a network. We do not distribute these components to you as installable software; you interact with them only through the Platform's interfaces. Many common open-source licenses attach obligations primarily on distribution of the software, so our hosted use may not trigger the same notice or source-availability duties as shipping a binary would. We nonetheless choose to publish attributions broadly, as a matter of good practice.
- Software we distribute to you. Some open-source components are delivered to your browser or device as part of the Platform's frontend (for example, client-side libraries that run in a merchant dashboard or a project's storefront). For these components, distribution-triggered obligations — such as preserving copyright and permission notices — do apply, and we satisfy them through the NOTICE file referenced below and, where applicable, by retaining notices within the delivered files themselves.
This distinction is a general explanation, not legal advice about any specific license. The authoritative terms for each component are the terms of that component's own license.
Third-party license attributions (NOTICE file)
The complete, machine-readable list of open-source components included in or relied upon by the Platform — together with each component's version, license identifier, copyright notice, and full license text where required — is maintained in a generated NOTICE file:
[to be confirmed]
<!-- [to be confirmed] is a placeholder for the generated open-source attribution manifest (e.g. output of an SBOM / license-scanning tool such as a CycloneDX SBOM plus a generated NOTICE/THIRD-PARTY-LICENSES file). Decide whether to inline it here, link to a hosted NOTICE file, or expose it as a downloadable artifact. -->The NOTICE file is generated from the Platform's dependency manifests and is intended to be authoritative as to the components actually used. Because the Platform evolves, the set of components changes over time; the NOTICE file is updated accordingly and supersedes any partial listing on this page.
Categories of licenses we rely on
The components in the NOTICE file are made available under a range of open-source licenses. These commonly include permissive licenses (for example, the MIT License, the BSD 2-Clause and 3-Clause Licenses, the Apache License 2.0, and the ISC License) and may include weak-copyleft or copyleft licenses for specific components. The following summaries are provided only to help readers orient themselves and do not restate or replace any license — the binding terms are those in each component's own license text as reproduced in the NOTICE file.
- Permissive licenses (e.g. MIT, BSD, ISC). Generally allow use, modification, and redistribution provided the original copyright and permission notices are preserved, and disclaim warranties and liability. We preserve the required notices in the NOTICE file.
- Apache License 2.0. Permissive, with an express patent grant and a
requirement to retain notices and to state significant modifications in
distributed files. Where we distribute Apache-licensed components, we retain
the applicable
NOTICEcontent. - Weak-copyleft licenses (e.g. MPL 2.0, LGPL). May require that modifications to the licensed files themselves, or the source of the licensed component, be made available under the same license, while permitting the surrounding application to remain under its own terms. Where any such component is distributed as part of the Platform, we comply with the corresponding source-availability obligation.
- Strong-copyleft licenses (e.g. GPL, AGPL). Carry broader source-availability obligations. — confirm whether any GPL- or AGPL-licensed component is distributed to end users (as opposed to used only as an internal hosted tool), and confirm compliance for each such component, because AGPL in particular can attach obligations to network-served software.
Warranty and liability disclaimer for open-source components
Open-source software is provided by its authors "as is", without warranties or conditions of any kind, express or implied, to the maximum extent permitted by applicable law. The respective authors and copyright holders of the open-source components are not liable for any claim, damages, or other liability arising from the software or its use. This disclaimer reflects the terms under which those components are licensed; it is given on behalf of those upstream authors and is in addition to, and does not limit, any disclaimers or limitations in Coded's own Terms of Service. Nothing in this paragraph removes any right that a consumer has under the mandatory law of the consumer's own jurisdiction.
Source code availability
For any open-source component whose license requires that corresponding source code be made available to recipients, you may obtain that source. In most cases the component's unmodified source is publicly available from its upstream project (for example, its public package registry or source repository), and the NOTICE file identifies the component and version sufficient to locate it. Where a license requires that we provide source — including any modifications we have made and are obligated to share — you may request it using the contact details below, and we will provide it (or a written offer for it) in the manner and for the period required by the applicable license. We may charge no more than a reasonable cost for fulfilling a physical-media request where a license permits such a charge.
Coded's own open-source posture
Coded builds primarily proprietary software. The Platform, its application code, its product designs, and its trademarks are proprietary to Coded and are not made available under an open-source license except where this page or a specific repository states otherwise. Use of the Platform is governed by Coded's Terms of Service and the applicable merchant, payment, catalog, and fulfilment terms — not by an open-source license.
Where Coded does choose to release any of its own code, content, or
specifications under an open-source license, that release will be accompanied by
its own clear LICENSE file stating the applicable terms, and those terms will
govern that specific release. Absent such an explicit license, no open-source
rights are granted in any Coded software, and all rights are reserved.
— confirm whether Coded currently publishes any of its own components, examples, SDKs, or specifications under an open-source license, and list them here with their license and repository if so. If none, this section stands as a statement that none are offered at this time.
Trademarks
The licenses covering the open-source components do not grant any right to use the names, logos, or trademarks of those components' authors, and this page grants no such right. Likewise, the open-source nature of components we use does not grant any right to use the Coded name, the "Coded" word mark, or Coded's logos, which remain the property of Coded and are governed by Coded's separate trademark and brand terms.
Reporting an attribution or compliance issue
We aim to attribute correctly and to comply with every license we rely on. If you believe a component has been mis-attributed, that a required notice or license text is missing, or that we have not met a source-availability obligation, please tell us using the contact details below. We will investigate promptly and correct any verified omission.
Changes to this page
We may update this page and the NOTICE file as the Platform's dependencies change. The "Last updated" date reflects the most recent revision. Material changes to our open-source posture will be reflected here.
Governing law
This page is governed by the laws of the Netherlands, and disputes relating to it are subject to the exclusive jurisdiction of the courts of Amsterdam, the Netherlands — except that (i) the terms of each open-source component are governed by that component's own license, and (ii) mandatory consumer-protection laws of the jurisdiction where a user is located may also apply and are not displaced by this provision.
Contact
Questions about open-source notices, attributions, or source-code requests can be sent to:
- Open-source and licensing matters: legal@coded.eu
- Security matters: security@coded.co
Coded B.V. De Taling 15, 2761 SL Zevenhuizen, The Netherlands KVK (Netherlands Chamber of Commerce): 42027097 VAT: NL869368795B01 Effective date: 11 June 2026
<!-- OPEN ITEMS FOR COUNSEL: - Replace [to be confirmed] with the generated attribution manifest and decide delivery: inline, linked hosted NOTICE file, or downloadable SBOM (CycloneDX/SPDX). Confirm the generation tooling and that it covers BOTH frontend (distributed-to-browser) and backend/build (hosted) dependencies. - Confirm whether any GPL/AGPL or other strong-copyleft component is DISTRIBUTED to end users vs used only as an internal hosted tool — AGPL can attach network-use obligations; verify per component (marked ). - Confirm whether any weak-copyleft (MPL/LGPL) components are modified by Coded and shipped, triggering same-license source-availability for those files. - Confirm Coded's actual own open-source posture: are any Coded SDKs/examples/specs published under an OSS license? If yes, list with license + repo (marked ). - Confirm the source-code-availability fulfilment process and retention period actually offered for any license requiring it (e.g. the written-offer period). - Verify that this page's disclaimer interacts correctly with the consumer-mandatory-law carve-out and with the limitation-of-liability clause in the main Terms of Service. - Confirm the contact routing (legal@ vs a dedicated oss@ alias) and the domain (coded.eu (legal/privacy) · coded.co (ops)). - Replace 42027097, NL869368795B01, De Taling 15, 2761 SL Zevenhuizen, The Netherlands, 11 June 2026. -->