1. Application and responsibility
This Acceptable Use Policy applies to every Customer, authorised user, app, integration and person using a HYPRCART service. The Customer is responsible for use under its accounts, storefronts, domains, API credentials and integrations.
The policy supplements the Terms. It does not require us to monitor all content or determine the legality of a Customer's business. Customers must obtain their own advice for the products, markets and recipients they choose.
2. Illegal and harmful activity
You must not use HYPRCART to offer, promote, facilitate, store or transmit:
- unlawful products, services, content or transactions;
- unsafe, recalled, counterfeit, stolen or materially misdescribed goods;
- child sexual abuse material, exploitation, trafficking or non-consensual intimate content;
- terrorist content, credible threats, targeted harassment or unlawful discrimination;
- fraud, phishing, deceptive impersonation, pyramid schemes or money laundering;
- malware, credential theft, botnets or instructions primarily designed for cyber abuse;
- infringement of intellectual-property, privacy, publicity or other third-party rights; or
- activity that breaches sanctions, export controls, court orders or applicable sector rules.
Regulated goods or services—including medicines, weapons, age-restricted goods, financial products, gambling and high-risk chemicals—may be used only if expressly supported and the Customer holds every required authorisation.
3. Security and service integrity
You must not:
- probe, scan or test systems without written authorisation;
- bypass authentication, tenant boundaries, rate limits, billing or usage controls;
- access another customer's data or use credentials you are not authorised to use;
- introduce malicious code or create excessive load that risks service availability;
- reverse engineer the service except where mandatory law permits and after requesting necessary interoperability information;
- scrape non-public interfaces or use automated access outside documented APIs; or
- remove security, attribution, safety, legal or rights-management controls.
Good-faith vulnerability reports should be sent privately to hello@hyprcart.com before disclosure.
4. Communications, reviews and AI-assisted use
Email must comply with the Email Policy. Reviews, questions, ratings and testimonials must not be fabricated, purchased without clear disclosure, manipulated or presented in a misleading way. Incentives and verification status must be disclosed as required by law.
AI-assisted content and actions require meaningful Customer oversight. You must not represent unverified output as professional, safety, legal, medical or financial advice; use AI to make unlawful discriminatory decisions; or allow an automated agent to place orders, change material terms or contact people without appropriate authority, controls and disclosure.
5. Investigation and enforcement
We may use security signals, automated detection and human review to investigate suspected breach. We may request information, preserve evidence, remove or restrict affected content, disable a function, throttle traffic, suspend an account, or report conduct when reasonably necessary and proportionate.
We consider severity, intent, recurrence, affected persons, legal urgency and the Customer's cooperation. Where required and lawful, we provide reasons and an opportunity to complain. Urgent safety, security or legal action may occur before notice. Customers may contact legal@hyprcart.com to challenge a decision.
6. Reporting content or abuse
Use the Illegal Content Notice process for allegedly illegal hosted content. Email and security abuse may be reported to legal@hyprcart.com. Include exact URLs, factual reasons and evidence, and avoid sending unnecessary personal or sensitive data.