Core requirement: Summit One may be used only by legitimate businesses to manage lawful orders and related operations. It may not be used to provide financial services, conceal business activity, facilitate prohibited transactions, or harm people, systems, or networks.
1. Purpose and applicability
This Acceptable Use Policy ("AUP") forms part of the Terms of Service and applies to every customer, authorized user, integration, API client, and person accessing Summit One services. Customers are responsible for users and activity under their accounts.
Examples below are illustrative and not exhaustive. Conduct that is technically possible is not necessarily permitted.
2. Lawful and transparent use
You may use Summit One only for lawful business purposes and in compliance with applicable consumer-protection, privacy, employment, accessibility, tax, export, sanctions, product-safety, marketing, and industry requirements. You may not use false, incomplete, misleading, or stolen identity or business information.
You must maintain accurate account and billing information, cooperate with reasonable review requests, and possess rights to all data, content, integrations, and instructions submitted to the Services.
3. Prohibited or restricted business activity
Unless Summit One provides express prior written approval and all applicable legal, security, and contractual requirements are satisfied, the Services may not be used for:
- Illegal goods, controlled substances sold unlawfully, counterfeit items, stolen property, or products designed to evade law enforcement;
- Weapons, explosives, regulated firearm transactions, or instructions primarily intended to cause physical harm;
- Human trafficking, exploitation, escort services, non-consensual sexual content, or commercial sexual services;
- Gambling, lotteries, sweepstakes administration, fantasy wagering, sports betting, or games of chance involving value;
- Cryptocurrency exchange, token issuance, mixing, mining-investment programs, money services, stored value, remittances, escrow, lending, securities, investment schemes, or fundraising that requires financial licensing;
- Debt collection conducted unlawfully, credit repair, deceptive lead generation, pyramid schemes, or get-rich-quick programs;
- Unlicensed medical products, controlled pharmaceuticals, or healthcare uses that require a regulated environment not expressly contracted by Summit One;
- Sale of data obtained without lawful permission, invasive surveillance, doxxing, identity theft, or credential trafficking;
- Sanctioned parties, prohibited jurisdictions, export-control evasion, money laundering, fraud, bribery, corruption, or tax evasion; or
- Any activity Summit One reasonably determines creates unacceptable legal, safety, security, financial, or reputational risk.
Ordinary restaurants, retailers, wholesalers, and service-commerce businesses remain subject to product-specific laws and must accurately describe what they sell.
4. Security and technical misuse
You may not:
- Probe, scan, penetrate, or test systems without written authorization;
- Bypass authentication, authorization, rate limits, access controls, usage restrictions, or security mechanisms;
- Introduce malware, ransomware, spyware, destructive code, or hidden access methods;
- Use automated tools in a manner that degrades availability, generates abusive traffic, or interferes with other customers;
- Access or attempt to access another customer’s account, data, credentials, or non-public system;
- Share credentials, create deceptive accounts, or use compromised login information;
- Use the Services to attack, disrupt, impersonate, phish, defraud, or exploit any person or system; or
- Publish vulnerability details before Summit One has had a reasonable opportunity to investigate and remediate.
Good-faith security research must follow the responsible disclosure process in our Security Overview.
5. Prohibited content and data
You may not submit content that is unlawful, infringing, fraudulent, defamatory, threatening, abusive, exploitative, discriminatory, or that violates another person’s privacy or publicity rights. You may not upload unnecessary sensitive data, including full payment-card information, authentication secrets, government-issued identification numbers, or protected health information, unless expressly supported and contracted in writing.
Customer order records should contain only information reasonably necessary for fulfillment, support, accounting, or lawful operational needs.
6. Messaging and customer communications
Where the Services support notifications or connected communications, you must comply with consent, opt-out, sender-identification, quiet-hour, and content requirements. You may not send spam, purchased-list campaigns, deceptive messages, phishing, harassment, or communications unrelated to a legitimate customer or business relationship.
You are responsible for message recipients, templates, timing, contact information, and third-party carrier or provider terms.
7. Platform and intellectual-property integrity
You may not copy, resell, sublicense, frame, scrape, reverse engineer, or use non-public Summit One technology to develop a competing offering except where a restriction is prohibited by law. You may not remove notices, misrepresent affiliation, or use our trademarks without permission.
You may not use unreasonable amounts of resources, create excessive duplicate records, circumvent plan limits, or use an account primarily as general-purpose file storage, a public data repository, or infrastructure for third parties.
8. Review and enforcement
Summit One may investigate suspected violations and request information reasonably necessary to understand an account’s business, products, data sources, or activity. Subject to applicable law and contract, we may remove content, restrict a feature, suspend access, block integrations, or terminate an account when necessary to protect the Services or address an actual or suspected violation.
Where appropriate, we will consider severity, recurrence, customer cooperation, impact, and whether the issue can be cured. We may preserve information and cooperate with authorities when legally required. Summit One is not obligated to monitor every transaction or customer record.
9. Reporting concerns
Report suspected abuse to abuse@summitone.app. Include the relevant business name, account or order reference, date, a clear description, and supporting information. Do not include passwords, full payment-card information, or unrelated sensitive data.
Security vulnerabilities should be reported to security@summitone.app under the responsible disclosure process. Emergency threats to physical safety should be reported to appropriate local authorities.