Acceptable Use Policy
Acceptable Use Policy
STATUS: DRAFT. Requires legal review before publication. Fields marked [TODO: …] need jurisdiction-specific or business-specific input.
>
Last updated: 2026-06-24.
This Acceptable Use Policy ("AUP") sets out the rules that apply to your use of the 4klyft Service. It is incorporated into the Terms of Service by reference. Capitalised terms not defined here have the meanings given in the Terms of Service.
This AUP exists for one reason: to keep the Service safe, reliable, and lawful for every Customer. Violations can result in suspension or termination of your account.
1. Prohibited content
You will not use the Service to store, transmit, or distribute content that:
- Is unlawful, fraudulent, deceptive, or misleading.
- Infringes the intellectual property, privacy, publicity, or other rights of any third party.
- Is defamatory, obscene, pornographic, or contains child sexual abuse material.
- Promotes discrimination, hatred, or violence against any group based on race, ethnicity, national origin, religion, gender, gender identity, sexual orientation, disability, or any other protected characteristic.
- Is malicious code (viruses, worms, trojans, ransomware) or designed to disrupt, damage, or gain unauthorised access to any system, network, or data.
- Violates applicable export-control, sanctions, or trade laws.
2. Prohibited conduct
You will not, and will not permit your authorised users to:
2.1 Abuse the Service
- Use the Service to send spam, unsolicited commercial communications, phishing messages, or any form of bulk unsolicited contact.
- Use the Service to facilitate illegal activity, including unlicensed transport of regulated goods (firearms, controlled substances, hazardous materials except per applicable hazmat regulations, items prohibited by your jurisdiction).
- Use the Service to transport, broker, or coordinate the movement of stolen property, counterfeit goods, or contraband.
- Use the Service in a manner that infringes any applicable transportation, postal, or customs regulation.
2.2 Compromise security
- Attempt to circumvent any authentication, rate-limiting, or security mechanism of the Service.
- Probe, scan, or test the vulnerability of the Service without our prior written authorisation (see the bug bounty programme for the authorised channel).
- Attempt to gain unauthorised access to any account, computer system, or network.
- Reverse-engineer, decompile, or disassemble any part of the Service, except to the extent expressly permitted by applicable law.
- Use the Service to intercept, monitor, or harvest data not intended for you.
2.3 Disrupt the Service
- Send traffic to the Service that exceeds documented rate limits or that we reasonably believe is designed to overload, disrupt, or degrade performance.
- Run denial-of-service attacks, distributed or otherwise.
- Use automated tooling against the Service in a way that is not allowed by the documentation (web scraping the dashboard, abusive crawling of the public Site, etc.).
2.4 Abuse the API
- Use the API in a way that violates the API documentation, including authentication, rate-limit, and pagination requirements.
- Resell, rebrand, white-label, or otherwise commercialise the Service as your own product, unless your Order Form expressly permits it.
- Provide Service access to third parties under the guise of authorised-user provisioning, where the actual operator is a different legal entity from the one under contract with us.
2.5 Misuse data
- Use Personal Data of your end-customers, drivers, or other natural persons in violation of applicable data protection laws.
- Sell, rent, or otherwise commercialise Personal Data 4klyft processes on your behalf, where doing so requires consent you have not obtained.
- Subject data subjects to automated decisions with legal or similarly significant effect (Article 22 GDPR) without complying with the safeguards required by law.
2.6 Misrepresent yourself
- Impersonate any person or entity.
- Forge headers or manipulate identifiers to disguise the origin of any content transmitted through the Service.
- Create accounts using false identities, automated means, or under false pretences.
3. Specific obligations for logistics use
The Service is designed for legitimate commercial logistics use. By using it you confirm that:
- You hold all licences, permits, and authorisations required to operate as a courier, fulfilment provider, e-commerce merchant, or other logistics actor in every jurisdiction you operate in.
- Your drivers and other operators hold the licences and qualifications required to operate the vehicles and handle the goods involved.
- Your vehicles meet applicable safety, insurance, and emissions standards.
- You comply with applicable working-time, rest-break, and labour protection law for your drivers and warehouse staff.
- You comply with applicable customs, import, and export law for cross-border shipments.
- For shipments of hazardous materials, you comply with applicable hazmat regulations (ADR in Europe, IATA for air, etc.) and you do not use the Service to misrepresent the contents of hazmat shipments.
You acknowledge that 4klyft does not inspect physical shipments and cannot verify your compliance with the above. The responsibility is yours.
4. Multi-tenant fairness
If you are a 3PL or other Customer that uses 4klyft to serve sub-tenants (your own merchants), you are responsible for:
- Imposing equivalent acceptable-use restrictions on your sub-tenants by contract.
- Monitoring sub-tenant compliance.
- Responding to abuse reports about your sub-tenants within reasonable time.
We may suspend a sub-tenant directly if we reasonably believe their use violates this AUP and you have not acted within a reasonable time after we've notified you.
5. Bug bounty and responsible disclosure
We welcome responsible disclosure of security vulnerabilities. Authorised testing is described at 4klyft.com/.well-known/security.txt and 4klyft.com/security/bug-bounty.
If you find a vulnerability:
- Report it to
security@4klyft.com. - Do not access, modify, or destroy data that does not belong to you.
- Do not publicly disclose the vulnerability before we have had a reasonable opportunity to fix it (default: 90 days).
- Do not run automated scanners against production beyond what is needed to confirm the vulnerability.
We will acknowledge your report within 3 business days and provide regular status updates until resolution. We will not pursue legal action against good-faith researchers who follow these guidelines.
6. Enforcement
6.1 Investigation
We may investigate suspected violations of this AUP. You agree to cooperate with our investigation, including providing reasonable access to logs, configuration, and other information necessary to determine the facts.
6.2 Suspension
We may suspend access to all or part of the Service immediately, with or without prior notice, if we reasonably believe:
- A violation of this AUP is causing or threatens to cause material harm to 4klyft, other Customers, or third parties.
- Continued processing exposes 4klyft to material legal, regulatory, or reputational risk.
- Suspension is required to comply with a lawful order, court directive, or other legal obligation.
Where reasonable and lawful, we will notify you of the suspension and give you an opportunity to remedy the violation. Where not reasonable or lawful (e.g. ongoing criminal abuse, court order with non-disclosure terms), we may suspend without notice.
6.3 Termination
We may terminate your subscription for cause under the Terms of Service if you materially violate this AUP and fail to remedy the violation within 30 days of receiving written notice of it.
For violations that involve unlawful conduct, child safety, threats of imminent harm, or material risk to other Customers, we may terminate without the 30-day cure period.
6.4 Reporting to authorities
We may report violations of this AUP or applicable law to competent authorities. Where we are legally required to report (e.g. CSAM in the United States under federal law, certain financial offences), we will do so without prior notice to you.
6.5 Cooperation with legal process
We will cooperate with lawful requests from competent authorities for information about your account or your use of the Service. Where the law does not prohibit us from doing so, we will notify you before disclosing your information so you have an opportunity to challenge the request.
7. Reporting violations
If you become aware of a possible violation of this AUP by another user, please report it to abuse@4klyft.com with as much detail as you can provide. We investigate every credible report. We do not disclose the identity of reporters except where required by law or to facilitate the investigation.
8. Changes to this AUP
We may update this AUP from time to time. For material changes, we will:
- Update the "Last updated" date at the top.
- Notify active Customers by email at least 15 days before the change takes effect.
Continued use of the Service after the effective date constitutes acceptance.
9. Contact
- Abuse reports:
abuse@4klyft.com - Security:
security@4klyft.com - Legal:
legal@4klyft.com - General questions:
support@4klyft.com