Legal
Acceptable Use Policy
The rules of the road. Most of this is common sense — no illegal apps, no payment fraud, no attacks on the platform, no misuse of End-User data — plus a safe harbor for good-faith security research. Violations can suspend or close a workspace.
On this page
1. About this policy#
This Acceptable Use Policy is part of the CashSDK Terms of Service at cashsdk.com/terms. It applies to everyone who uses the Service — account owners, workspace members, the apps that embed our SDKs, and any tools or agents acting on a workspace's behalf. You are responsible for all use of the Service under your account.
If something seems technically possible but clearly outside the spirit of these rules, assume it is not allowed and ask first: support@cashsdk.com.
2. Illegal or harmful use#
Do not use the Service to:
- Break the law, or sell products or content that are illegal where you offer them.
- Exploit or endanger minors in any way — including operating apps that violate children's privacy law such as COPPA or the GDPR's rules for children.
- Promote or facilitate violence, terrorism, or hatred against people or groups.
- Conduct or support fraud, scams, pyramid schemes, or deceptive money-making offers.
- Violate export-control or sanctions laws, or transact with prohibited parties or embargoed regions.
- Infringe anyone's intellectual property, publicity, or privacy rights.
3. Payment and store integrity#
CashSDK exists to make purchase infrastructure trustworthy. You must not:
- Create, replay, or launder fake transactions, or tamper with receipts, signed transactions, or webhook payloads.
- Use stolen or unauthorized payment instruments, or test cards you have no right to use, anywhere in your purchase flows.
- Manipulate or falsify the transaction data the Service meters so that fees are computed on less than your actual tracked revenue.
- Violate the developer agreements of Apple, Google, or any store your app ships on, including each store's current rules for in-app purchases and alternative payment flows in each region.
- Use the platform for money laundering or to disguise the origin of funds.
4. Honest subscription practices#
Apps monetized through CashSDK must treat their users honestly. You must not:
- Hide the price, renewal term, or auto-renewal of a subscription, or make canceling materially harder than signing up.
- Use countdowns, scarcity claims, or “free” labels that are false.
- Impersonate another company or app, or misrepresent an affiliation.
- Charge for features you knowingly do not deliver.
Consumer-protection and subscription-disclosure laws vary by region; complying with them for your app is your responsibility.
5. End-User data rules#
- Send the platform only data you have the right to send, with the notices and consents your users are owed.
- Do not send special-category or highly sensitive data — health records, biometric identifiers, government ID numbers, precise location, or the like. The platform processes purchase, subscription, and entitlement data; it is not built or authorized to hold medical or biometric records.
- For apps directed at children, comply with the laws and store policies that apply to child audiences, and do not send us more data than the platform needs.
- Honor your users' deletion and privacy requests, and use the Service's tools to reflect them.
- Do not use data obtained through the Service to stalk, harass, or discriminate against anyone.
6. Platform and network integrity#
You must not:
- Probe, scan, or test the vulnerability of the Service without authorization (see Section 8), or breach or circumvent authentication or tenant isolation.
- Access or attempt to access another customer's data, or CashSDK systems not intended for customers.
- Interfere with the Service — denial-of-service attacks, spam, resource abuse, or load patterns designed to degrade the platform for others.
- Upload or distribute malware through any part of the Service.
- Circumvent rate limits, quotas, metering, or usage restrictions, or share accounts to evade billing.
- Scrape or harvest data from our sites or dashboard except through the documented APIs.
7. API and SDK rules#
- Keep secret API keys server-side and out of client apps, repositories, and logs; rotate any key that leaks. Publishable keys are designed for clients.
- Respect documented rate limits and quotas, use the sandbox for load and integration testing, and talk to us before running unusual load against production.
- Automated and agent-driven use is welcome — it is what the platform is built for — within the same limits that apply to any other client.
- Do not misrepresent your integration to the stores or to us, for example by spoofing SDK version or platform metadata.
- Do not resell, white-label, or offer the Service itself as your own competing service. Building products and integrations on top of the APIs for your own apps and customers is encouraged.
8. Security research and responsible disclosure#
We welcome good-faith security research. Report vulnerabilities to security@cashsdk.com and give us reasonable time to fix them before public disclosure. Only test against workspaces and apps you own, never degrade the Service for others, and do not access data that is not yours — if you encounter someone else's data, stop and report it immediately. We will not pursue or support legal action against research that follows these rules.
9. How we enforce this policy#
Enforcement is proportionate. Depending on severity we may warn you, throttle or restrict features, suspend the workspace, or terminate the agreement — immediately for violations involving illegality, fraud, or danger to others. We may remove content, preserve and disclose information when the law requires it, and report unlawful activity to authorities and, where relevant, to the app stores.
We try to notify you and give you a chance to fix problems when doing so won't make things worse. Fees accrued before a suspension remain payable, as the Terms describe.
10. Reporting violations#
If you see abuse of the platform — an app defrauding its users, a workspace breaking these rules — report it to support@cashsdk.com, or security@cashsdk.com for vulnerabilities. Reports are reviewed by a human, and we do not retaliate against good-faith reporters.
11. Changes to this policy#
As the platform and the threat landscape change, we will update this policy. Material changes are announced as described in the Terms, and the “Last updated” date above always reflects the current version. The Terms explain how continued use relates to updated policies.