Skip to content
Legal

Acceptable Use Policy

This policy sets out what you may and may not do with SumPOS. It exists to protect other customers, our infrastructure and the people whose data passes through the platform. It forms part of our Terms & Conditions.

Last updated 1 September 2026Effective 1 September 2026

1. The short version

Use SumPOS to run a lawful business honestly. Do not use it to break the law, to harm other people, to attack our systems, or to abuse the people whose data you hold. Almost everything below follows from that.

2. Prohibited activity

Unlawful use

  • Recording, facilitating or concealing unlawful activity, including tax evasion, money laundering, or trade in goods you are not lawfully permitted to sell.
  • Maintaining parallel or falsified records intended to misrepresent your trading position to an authority.
  • Infringing anyone's intellectual property, including uploading product imagery or content you do not have the right to use.
  • Breaching applicable data protection, consumer protection, employment or marketing law.

Abuse of the platform

  • Attempting to access another customer's account, data or infrastructure.
  • Probing, scanning or testing the vulnerability of our systems without our written permission.
  • Circumventing plan limits, quotas or rate limits, including by creating multiple accounts for what is in substance one business.
  • Reverse engineering or attempting to derive source code, except where that restriction is prohibited by law.
  • Reselling or providing the Platform to third parties without a written partner agreement.
  • Uploading malicious code, or using the Platform in a way that degrades it for others.
  • Automated scraping other than through our published API within its documented limits.

Messaging abuse

  • Sending marketing messages to people who have not consented where consent is required, or after they have opted out.
  • Sending messages that are deceptive, harassing, or that misrepresent who they are from.
  • Uploading purchased or scraped contact lists.
  • Ignoring quiet-hours rules or local messaging regulations.

3. Your obligations to others

  • Give your customers and staff appropriate notice about the data you hold on them and why.
  • Honour opt-out and deletion requests from the people whose data you process.
  • Give each of your staff their own login, and remove access when they leave.
  • Keep credentials and API tokens confidential, and rotate them if you suspect exposure.

4. How we enforce this

Where we believe this policy has been breached, our response is proportionate to what has happened. In most cases we will contact you first and give you an opportunity to put it right.

  1. 1We contact you, explain the concern, and ask you to resolve it within a stated period.
  2. 2If the issue is unresolved or serious, we may restrict the specific capability being abused.
  3. 3For severe or continuing breaches, or where there is a live risk to others, we may suspend the account immediately and explain afterwards.
  4. 4Where there is a legal obligation to do so, we may report the matter to the relevant authority.

Wherever we lawfully can, we will preserve your access to export your data even while other capabilities are restricted.

5. Reporting abuse

If you believe someone is using SumPOS in breach of this policy, tell us at legal@sumpos.com with as much detail as you can. Security vulnerabilities should go to hello@sumpos.com - we do not pursue researchers who report in good faith.