MYZAP is shared infrastructure used by many shops. This policy sets out what is not permitted, so that the platform stays safe, lawful and reliable for everyone.
1.Who this applies to
This Acceptable Use Policy applies to every person who accesses MYZAP, including shop owners, administrators, staff accounts, delivery users and anyone using an API or integration. It forms part of the Terms of Service.
2.Prohibited activity
You must not:
- Attempt unauthorized access to any account, workspace, shop, server or data
- Hack, attack, overload or otherwise disrupt MYZAP or its infrastructure
- Introduce malware, viruses, ransomware or malicious code
- Circumvent or disable security controls, rate limits or access restrictions
- Scrape or harvest the service unlawfully or by automated means without permission
- Reverse engineer, decompile or disassemble the software where prohibited by law
- Abuse APIs, exceed documented limits, or resell access without authorisation
- Use another user's credentials, or share your own with unauthorised persons
- Upload unlawful, infringing, obscene or harmful content
- Use MYZAP for fraud, money laundering or other criminal activity
- Generate knowingly false or fraudulent invoices, GST records or tax documents
- Violate applicable laws, including tax, consumer, IP and data-protection laws
- Interfere with other users, their data, or the stability of shared infrastructure
3.Data and privacy conduct
When entering data about other people into MYZAP you must:
- Have lawful authority to collect and process that data
- Collect only what you need for your business purpose
- Avoid uploading sensitive personal data you are not entitled to process
- Keep staff access limited to what each role requires
- Respond to requests from your own customers about their data
4.Messaging and communications
Invoice sharing, notifications and reminders sent through MYZAP must be genuine business communications. You must not:
- Send unsolicited bulk or promotional messages in breach of applicable regulations
- Send messages to recipients who have opted out
- Misrepresent the sender or the purpose of a message
- Breach the policies of WhatsApp, SMS or email providers used by MYZAP
5.Security testing and research
Do not run penetration tests, vulnerability scans, load tests or automated attacks against MYZAP without our prior written permission. If you discover a potential vulnerability, report it privately to our security contact and do not access, modify or disclose other users' data. We appreciate responsible disclosure and will work with you in good faith.
6.Fair use of resources
Plans are sized for normal business use. Sustained activity that materially exceeds normal use — for example excessive API calls, bulk imports designed to strain the system, or storage far beyond documented limits — may be throttled. We will contact you first where practicable and discuss a suitable plan.
7.Enforcement
Depending on the seriousness of a violation, and subject to applicable law and your subscription agreement, we may:
- Contact you and request that the activity stop
- Apply rate limits or temporarily restrict specific features
- Suspend the affected account or user
- Terminate the subscription for serious, repeated or unlawful violations
- Report unlawful activity to the competent authorities where required
Where practicable and lawful, we will give notice and an opportunity to remedy a violation that can be remedied. Immediate action may be taken where there is a live security threat, fraud, or a legal requirement.
8.Report abuse or a vulnerability
Report misuse of MYZAP, suspected fraud or a security vulnerability using the contacts below.
