Acceptable Use Policy

Last updated June 2026

This Acceptable Use Policy (“AUP”) governs how merchants and their authorized users may use the FlowAcq payment orchestration platform, APIs, and dashboard (the “Services”). It is part of, and incorporated into, your Terms of Service. Violations may lead to restriction, suspension, or termination of your access.

FlowAcq is a payment orchestrator, not a payment service provider or acquirer. This AUP applies in addition to — and does not replace — the rules of the underlying payment providers and card networks we route to, and applicable law.

1. Lawful, business-only use

The Services are for business use only. You must use them lawfully and only to process transactions for the business model and vertical you disclosed and that we approved during onboarding and Know-Your-Business (KYB) review.

You must not use the Services for any activity that is unlawful in any jurisdiction applicable to you, your customers, or the relevant payment corridor.

2. Prohibited & restricted activities

You must not use the Services for any business category we list as prohibited, and you must meet all conditions we set for any restricted category. The full prohibited and restricted list is shared and confirmed during KYB; see our Prohibited Businesses policy.

Without limiting that list, you must not use the Services to:

  • facilitate money laundering, terrorist financing, sanctions evasion, or transactions with sanctioned persons, entities, or regions;
  • process payments that are deceptive, fraudulent, or unauthorized by the cardholder or payer;
  • engage in transaction laundering, factoring, or processing on behalf of an undisclosed third party or a different business than the one onboarded;
  • circumvent KYB, sanctions/PEP screening, risk controls, or live-mode approval;
  • process payouts or disbursements to payees who have not completed required payee KYC, or to evade payee screening; or
  • misrepresent your business, ownership, location, or vertical.

3. Platform integrity & security

You must not:

  • attempt to access another tenant’s data or breach tenant isolation;
  • probe, scan, or test the vulnerability of the Services without authorization;
  • share, expose, or fail to secure API keys, or use keys beyond their granted scope;
  • exceed documented rate limits, or use the Services to build a competing payment orchestrator using scraped data;
  • introduce malware, or interfere with the integrity or performance of the Services; or
  • reverse engineer the Services except where that restriction is unenforceable by law.

You must promptly report any suspected security incident, key compromise, or unauthorized access affecting your account.

4. Data & privacy obligations

You must handle your customers’ personal data lawfully as a controller, with a valid legal basis, and consistent with our Privacy Policy and, where applicable, our Data Processing Addendum.

You must not transmit raw primary account numbers (PAN) or sensitive authentication data through FlowAcq in a way that places FlowAcq in scope to store such data — card data is tokenized and vaulted by the underlying payment provider. You must not send unlawful, excessive, or special-category personal data in transaction metadata where it is not necessary for the transaction.

5. Honest representations to customers

You must clearly identify your business to your customers, present accurate pricing and refund terms, deliver the goods or services paid for, and not engage in deceptive billing, hidden subscriptions, or dark patterns.

6. Enforcement

We may investigate suspected violations, request information, and apply graduated enforcement: warning, restriction (for example, reverting your account to test mode), suspension, or termination. For legal, sanctions, fraud, or security reasons, we may apply immediate emergency suspension without prior notice. Enforcement actions are recorded in our append-only audit trail.

7. Reporting violations

You can report suspected abuse through our support channel. We cannot guarantee confidentiality where disclosure is legally required.

8. Changes

We may update this AUP; we’ll post the revised version here with an updated date and, where material, notify you.

This is a working draft provided for completeness. It will be replaced with finalized, counsel-reviewed terms before launch — please don't rely on it yet.