Preparing the details that protect your business.
Preparing the details that protect your business.
Clear boundaries for Accounts, staff access, communications, AI, automations, payments, Credits, Mini Stores, Trust Passports, public content, personal data, integrations, and platform security.
This Acceptable Use Policy explains the conduct permitted and prohibited when using KOMERRA websites, applications, Accounts, Workspaces, Mini Stores, Trust Passports, AI features, APIs, connected channels, public pages, file services, integrations, and other KOMERRA products or services.
The Policy protects businesses, Business Customers, staff members, KOMERRA personnel, service providers, the public, and the security, integrity, availability, and reputation of the platform.
It forms part of the KOMERRA Terms of Service. By accessing or using KOMERRA, you agree to follow this Policy and ensure that people using the Services through your Account or Workspace also follow it.
This Policy should be read together with the Terms of Service, Privacy Policy, Responsible AI framework, Security & Trust page, Mini Store terms, Trust Passport policies, Refund and Cancellation Policy, Responsible Disclosure Policy, and applicable provider requirements.
KOMERRA is operated by KOMERRA Technologies Limited, a company registered in the Federal Republic of Nigeria with registration number 9681120.
Questions about this Policy, reports of suspected misuse, and requests for review may be sent to support@komerra.app.
Use “Acceptable Use Report” in the subject when reporting prohibited conduct or suspected platform misuse.
Use “Security Report” where the concern involves a vulnerability, unauthorized access, credential exposure, cross-tenant access, malware, or another security risk.
This Policy applies to every visitor, Account holder, Workspace owner, Authorized User, administrator, staff member, contractor, developer, integration partner, Mini Store operator, Business Customer, API user, and person who accesses or interacts with KOMERRA.
It applies whether access occurs through a browser, web application, mobile application, API, connected provider, webhook, automation, public page, support process, or another interface.
A Workspace owner is responsible for taking reasonable steps to ensure that its Authorized Users understand and follow this Policy.
A person remains responsible for conduct performed through their credentials, devices, API keys, integrations, or automated systems unless the activity resulted from verified unauthorized access that was reported promptly.
KOMERRA is provided to help legitimate businesses organize business information, customers, products, orders, documents, inventory, communications, payments recorded, reminders, reports, Mini Store activity, Trust Passport information, and other supported operations.
You may use KOMERRA only for lawful, honest, authorized, and commercially legitimate purposes consistent with the functionality and limitations of the Services.
The availability of a field, upload option, AI feature, integration, API route, public page, or automation does not mean that every possible use of that capability is permitted.
You are responsible for determining whether your intended use is lawful and appropriate for your business, industry, customers, staff members, and jurisdiction.
Do not use KOMERRA to commit, encourage, facilitate, conceal, coordinate, advertise, finance, or benefit from unlawful, fraudulent, deceptive, harmful, abusive, or unauthorized conduct.
Do not use KOMERRA in a way that infringes another person’s rights, compromises security, harms consumers, damages provider relationships, disrupts the Services, or creates unreasonable legal, operational, or reputational risk.
You must not attempt prohibited conduct personally, through another person, through multiple Accounts, through an integration, through an AI prompt, through automated requests, or through a third-party service.
Conduct may violate this Policy even where it does not result in a successful transaction, completed attack, delivered message, published listing, or actual financial loss.
Information recorded, communicated, generated, uploaded, or published through KOMERRA must be lawful, authorized, and reasonably accurate for its intended purpose.
You must not knowingly falsify or manipulate customer records, staff records, order information, product information, documents, payment status, delivery status, inventory, business performance, verification information, or transaction history.
You must not use KOMERRA to conceal unlawful income, disguise the true nature of a transaction, coordinate fraudulent activity, mislead investigators, or fabricate records intended to appear genuine.
Corrections to genuine mistakes are permitted and encouraged. Deliberate alteration intended to deceive another person is prohibited.
Do not make, publish, send, generate, or support a statement that you know is false, misleading, materially incomplete, deceptive, or likely to create an incorrect impression.
This restriction applies to product descriptions, availability, prices, discounts, reviews, delivery times, refund terms, warranties, stock levels, business identity, ownership, qualifications, certifications, endorsements, performance, customer numbers, payment status, and Trust Passport information.
A statement may be misleading because of what it says, what it implies, what it omits, how it is presented, or the context in which it appears.
AI-generated wording, templates, suggested claims, or imported content must be reviewed before publication. The fact that a statement was generated by AI does not excuse a misleading representation.
Do not impersonate another individual, business, customer, staff member, regulator, professional, financial institution, provider, government agency, or KOMERRA representative.
Do not create an Account, Workspace, Mini Store, Trust Passport, invoice, message, document, or public page that falsely suggests authorization, ownership, employment, partnership, endorsement, or affiliation.
Do not use another person’s name, image, logo, registration information, contact details, identity document, bank details, or business records without lawful authority.
Parody, commentary, or authorized representation must not be presented in a way that is likely to deceive people about the identity or authority of the speaker.
You must provide materially accurate information when registering, verifying, administering, or recovering an Account or Workspace.
Do not create Accounts using false identities, stolen contact details, fabricated businesses, temporary identities intended to avoid enforcement, or information belonging to an unrelated person.
Do not create multiple Accounts or Workspaces to evade suspension, obtain repeated trials, manipulate limits, conceal coordinated conduct, or avoid payment obligations.
You must update information where a material change makes existing Account, business, billing, verification, or administrator information inaccurate.
You may create, administer, transfer, or close a Workspace only where you have authority to act for the relevant business.
Do not remove a lawful owner, seize administrator control, transfer a Workspace secretly, or use a staff role to take possession of business records.
Do not invite another person using a misleading role or grant access that exceeds the authority given by the Workspace owner.
Disputes concerning ownership, directorship, partnership, employment, or administrator authority must not be resolved through credential theft, deletion, impersonation, or unauthorized data export.
KOMERRA may restrict changes while a genuine Workspace-control dispute is investigated.
Do not disclose passwords, one-time codes, recovery codes, private keys, API secrets, passkeys, session tokens, or other authentication credentials to unauthorized people.
Businesses should provide individual staff Accounts where available instead of sharing one credential among multiple people.
You must not buy, sell, rent, lend, trade, or transfer access to an Account except through an authorized Workspace or Account-transfer process.
Do not request another person’s password, bank PIN, card security code, one-time password, private key, or authentication token through KOMERRA.
You are responsible for removing staff access when it is no longer required and for reporting suspected credential exposure promptly.
Do not access or attempt to access an Account, Workspace, record, file, message, customer profile, provider connection, administrative interface, API, database, storage object, queue, system, or network without authorization.
Do not change identifiers, parameters, file references, tenant values, headers, tokens, or request bodies in an attempt to reach another business’s information.
Do not exploit missing permission checks, broken object-level authorization, insecure direct references, misconfigured storage, cached information, background jobs, or administrative tools.
Accidentally receiving unauthorized access does not authorize continued access, copying, disclosure, modification, testing, or retention. Stop and report the issue privately.
You must not attempt to discover, retrieve, infer, modify, delete, export, or expose information belonging to another KOMERRA business or Workspace.
Do not manipulate AI prompts, retrieval queries, file identifiers, API parameters, search functions, analytics, caches, exports, or connected services to cross tenant boundaries.
Do not use information accidentally exposed from another Workspace for competitive, commercial, personal, investigative, or public purposes.
Cross-tenant administrative functions may be used only by expressly authorized personnel for legitimate and documented purposes.
Do not scan, probe, test, reverse engineer, exploit, or assess KOMERRA systems without authorization except as permitted by the Responsible Disclosure Policy or a written testing agreement.
Responsible research must avoid accessing another person’s information, changing production records, causing service disruption, sending unsolicited messages, creating financial effects, or retaining unnecessary data.
Do not test stolen credentials, conduct social engineering, distribute vulnerability details prematurely, demand payment through threats, or use a suspected vulnerability for personal or commercial advantage.
Automated scanning that materially affects availability or creates excessive traffic is prohibited without written approval.
A public endpoint, client-side script, network response, or exposed identifier is not automatically authorization to test or access the underlying system.
Do not interfere with, overload, degrade, disable, disrupt, corrupt, or impair the Services or another person’s use of them.
Prohibited activity includes denial-of-service behaviour, uncontrolled automated requests, deliberate queue flooding, storage exhaustion, repeated expensive AI requests, malformed payload attacks, and interference with provider communication.
Do not deliberately trigger excessive errors, retries, notifications, background jobs, document generation, exports, or provider calls.
Do not interfere with monitoring, logging, health checks, alerts, abuse controls, fraud controls, incident response, or forensic records.
You must not intentionally exploit a service outage, race condition, retry behaviour, or processing delay to create duplicate actions or inconsistent records.
Do not upload, transmit, store, distribute, generate, or link to malware, ransomware, spyware, credential-stealing code, destructive scripts, malicious documents, unauthorized remote-access tools, or other harmful code.
Do not disguise executable or harmful content as an image, document, receipt, invoice, product file, or ordinary attachment.
Do not use KOMERRA to coordinate malware delivery, collect stolen credentials, operate malicious infrastructure, or communicate instructions intended to compromise systems.
KOMERRA may block, quarantine, remove, preserve, or report content reasonably suspected to create a security risk.
Do not attempt to discover, extract, expose, publish, or misuse KOMERRA credentials, internal keys, private endpoints, system instructions, provider secrets, database credentials, signing material, or confidential security information.
Do not place passwords, private keys, card security codes, bank PINs, recovery codes, or authentication tokens in ordinary prompts, notes, support messages, product descriptions, or public pages.
If you discover an exposed credential or secret, do not test it. Report it privately and delete any unnecessary copy.
Do not ask AI features to reveal hidden system instructions, security policies, another user’s prompts, private provider details, or confidential internal context.
Do not evade, disable, bypass, manipulate, or defeat authentication, authorization, human approval, rate limits, usage limits, safety controls, content controls, provider restrictions, billing controls, or enforcement measures.
Do not use multiple Accounts, rotating devices, proxies, altered requests, coordinated users, automated clients, or third-party services to avoid restrictions.
Do not repeatedly rephrase a prohibited AI request to evade a safety refusal.
Do not disable required confirmation controls or misrepresent a high-impact action as low risk in order to automate it.
Do not interfere with security events, audit records, provider references, transaction histories, or evidence of previous activity.
Use APIs, integrations, scripts, and automated clients only through supported interfaces and within the permissions, documentation, limits, and commercial terms applicable to them.
Do not scrape undocumented endpoints, imitate internal clients, extract bulk data through interfaces not designed for export, or automate browser behaviour to avoid API controls.
Automated requests must identify and authenticate the responsible Account or integration where required.
You must implement appropriate retry limits, idempotency, error handling, security, and rate control in systems connecting to KOMERRA.
You remain responsible for activity initiated by your API keys, integrations, bots, workers, scripts, or connected systems.
Do not scrape, harvest, collect, index, copy, monitor, or aggregate personal data, business information, Mini Store listings, Trust Passport information, product information, customer information, or platform activity at scale without authorization.
Do not use bots, crawlers, browser automation, rotating identifiers, or coordinated Accounts to bypass technical restrictions.
Public visibility does not automatically authorize bulk collection, profiling, resale, republication, competitive surveillance, or use for unrelated AI training.
Search engines and approved indexing services may access designated public pages according to applicable technical directives and agreements.
You must respect removal requests, access controls, robots directives, copyright, privacy obligations, and applicable database rights.
Do not collect, upload, import, connect, process, disclose, sell, or retain personal data without a lawful and legitimate purpose.
Do not place personal data in KOMERRA merely because a note, upload, customer, staff, AI, message, or custom field is available.
You must provide required privacy information and respect applicable rights concerning access, correction, deletion, objection, restriction, consent withdrawal, and portability.
Do not use KOMERRA to build secret profiles, conduct unlawful surveillance, disclose private communications, or process another person’s sensitive information without lawful authority.
You must not combine personal data from multiple sources in a way that is unlawful, deceptive, excessive, or incompatible with the purpose for which it was obtained.
Do not process sensitive personal data unless the processing is lawful, necessary, proportionate, and supported by appropriate safeguards.
Sensitive information may include biometric information, government identifiers, financial information, health information, information about children, and other information capable of creating heightened risk.
Do not store sensitive information in ordinary notes, messages, public pages, product descriptions, or unrestricted uploads where a secure designated workflow is required.
Do not expose identity documents, verification recordings, full identification numbers, facial images, or private financial details through a Trust Passport or Mini Store.
Do not use sensitive characteristics for unlawful discrimination, exploitation, harassment, or inappropriate profiling.
Do not use KOMERRA to exploit, deceive, manipulate, harass, endanger, or unlawfully profile a child or vulnerable person.
Do not collect or process a child’s information without appropriate authority, lawful purpose, required notice or consent, and suitable safeguards.
Do not publish a child’s private information, identity document, precise location, school information, financial information, or other sensitive details through a Mini Store, Trust Passport, message, or public page.
Do not use AI or automated communications to pressure, manipulate, or exploit a child or person whose circumstances make them particularly vulnerable.
Content involving the abuse or exploitation of children is strictly prohibited and may be preserved and reported to appropriate authorities.
You may communicate with customers and prospective customers only where you have an appropriate business relationship, lawful basis, authorization, or other permission required by applicable law and provider rules.
Messages must identify the business accurately and must not conceal the sender’s identity or commercial purpose.
You must provide a reasonable way for recipients to stop non-essential promotional communications where required.
Do not send messages to a person who has clearly objected, unsubscribed, withdrawn consent, or requested that contact stop, unless a necessary transactional or legal communication remains permitted.
You are responsible for maintaining appropriate consent, opt-out, suppression, and communication-preference records.
Do not use KOMERRA, connected channels, APIs, or integrations to send spam, unsolicited bulk messages, repetitive promotions, purchased-list campaigns, automated harassment, or deceptive outreach.
Do not purchase, rent, scrape, exchange, or upload contact lists where the recipients have not lawfully agreed to the intended communication.
Do not disguise marketing as a security alert, invoice, delivery notice, personal message, support communication, or legal obligation.
Do not use multiple sender identities, Accounts, telephone numbers, email addresses, or connected channels to evade blocking, opt-out requests, provider limits, or enforcement.
High message volume does not excuse poor recipient selection, missing permission, misleading content, or failure to respect opt-outs.
Do not use KOMERRA to threaten, intimidate, stalk, shame, blackmail, extort, humiliate, or repeatedly harass another person.
Do not send degrading, hateful, sexually exploitative, or deliberately distressing content.
Do not use customer debt, payment status, personal information, photographs, contacts, or business records to publicly shame or pressure a person.
Legitimate debt reminders, complaint responses, and business communications must remain lawful, proportionate, accurate, and respectful.
Do not impersonate legal authorities, law enforcement, courts, regulators, banks, or collection agencies to frighten a recipient into acting.
Do not use KOMERRA to promote hatred, exclusion, dehumanization, violence, or unlawful discrimination against a person or group.
Do not use customer, staff, or AI-generated information to make unlawful discriminatory decisions.
Do not infer sensitive characteristics for the purpose of denying service, targeting abuse, or exploiting vulnerability.
Business eligibility rules must be based on legitimate, lawful, and proportionate considerations.
KOMERRA may remove public content or restrict communications that create a serious risk of discriminatory harm.
Your use of WhatsApp, Instagram, Facebook Messenger, email, SMS, payment platforms, and other connected providers must also comply with the provider’s applicable terms, policies, permissions, and technical requirements.
Do not obtain a provider connection through stolen credentials, false business information, unauthorized tokens, or deceptive verification.
Do not request broader permissions than are reasonably required for the selected workflow.
Do not use a connected provider to perform conduct prohibited on KOMERRA or use KOMERRA to bypass a provider’s enforcement.
KOMERRA may disconnect, restrict, or refuse an integration where continued use creates legal, security, provider, or platform risk.
Do not submit AI inputs containing information you are not authorized to process.
Do not instruct an AI feature to disclose another business’s records, reveal secrets, bypass permissions, impersonate people, fabricate evidence, or perform prohibited conduct.
Do not embed malicious instructions in documents, webpages, messages, images, product descriptions, files, or retrieved content to manipulate AI behaviour.
Do not use prompt injection, indirect prompt injection, adversarial instructions, or obfuscated requests to override trusted rules or gain unauthorized tool access.
AI inputs remain subject to this Policy even where a model refuses the request or no Output is produced.
Do not use AI Output as verified fact where it has not been appropriately checked.
Do not represent generated content as professionally reviewed, legally approved, audited, certified, verified, or guaranteed when that review did not occur.
Do not use AI to create fabricated transactions, forged documents, false reviews, false identities, misleading product claims, fake Trust Passport evidence, or deceptive customer communications.
Do not use AI to conceal the true source, purpose, recipient, or effect of an action.
Do not rely on AI alone for a high-impact financial, employment, legal, security, healthcare, credit, insurance, or similarly significant decision.
Do not attempt to make an AI feature perform external, destructive, financial, permission-changing, publication, or security-sensitive actions without the required authorization and confirmation.
Do not manipulate tool parameters, tenant identifiers, recipients, amounts, customer references, product identifiers, or workflow state.
Do not instruct the AI to hide an action from the Workspace owner, administrator, customer, audit trail, or affected person.
Do not create automations designed to approve their own actions, bypass human review, or convert uncertain Output into authoritative records.
An authorized user remains responsible for reviewing proposed actions before approval.
Automations must have a legitimate business purpose, defined scope, appropriate permissions, accurate recipients, reasonable limits, and suitable human oversight.
Do not configure an automation to send unlawful messages, manipulate customers, create duplicate activity, conceal failure, or continue after authorization has been withdrawn.
Do not use repeated scheduled actions to harass recipients, evade rate limits, exhaust provider resources, or inflate platform activity.
Businesses must review enabled automations periodically and disable those that are outdated, inaccurate, unauthorized, or no longer required.
An automation must not be used to avoid responsibility for a decision that requires human judgment.
Do not represent KOMERRA AI as a substitute for qualified legal, accounting, tax, financial, medical, employment, insurance, or other professional advice.
Do not use AI Output as the sole basis for a decision producing a legal or similarly significant effect where applicable safeguards are absent.
Do not generate or publish a financial statement, tax position, legal conclusion, medical conclusion, certification, or audit opinion and falsely attribute it to a qualified professional.
You remain responsible for obtaining appropriate professional advice where an error could create a material legal, regulatory, financial, health, employment, or contractual consequence.
Do not submit false payment information, stolen payment credentials, fabricated provider references, manipulated callbacks, altered transaction evidence, or unauthorized payment methods.
Do not replay provider events, forge webhook signatures, manipulate expected amounts, reuse completed references, or interfere with server-side verification.
Do not dispute or reverse a properly authorized KOMERRA payment dishonestly after intentionally consuming the corresponding Credits or services.
Genuine unauthorized, duplicate, failed, misdescribed, or disputed transactions may be reported through the Refund and Cancellation Policy.
Do not attempt to retain both refunded money and the corresponding KOMERRA Credits or paid entitlement.
Do not manipulate the Credit ledger, usage records, action pricing, promotional balances, restoration events, or refund status.
Do not create multiple Accounts or Workspaces to obtain repeated trials, referral rewards, included usage, bonuses, discounts, or promotional entitlements.
Do not sell, exchange, transfer, pledge, counterfeit, or represent KOMERRA Credits as cash, deposits, investments, remittance value, or stored monetary value.
Do not deliberately cause an action to fail after receiving value in order to demand repeated Credit restoration.
Promotions may be withdrawn, reversed, or restricted where eligibility information was false or the promotion was manipulated.
Do not refer yourself, a business you own or control, or a synthetic, duplicate, dormant, or sham business for the purpose of obtaining KOMERRA referral Credits or another referral benefit.
Do not use relatives, employees, contractors, nominees, controlled entities, referral rings, reciprocal referral arrangements, account farms, bots, scripts, rotating devices, false identities, reused verification evidence, or coordinated groups to manufacture referral eligibility.
Do not create or fund a subscription, payment, transaction, refund, reversal, cancellation, or other activity mainly to trigger a referral reward rather than to make genuine commercial use of KOMERRA.
Do not conceal common ownership or control, manipulate business-registration information, reuse payment or settlement identities deceptively, buy or sell referral identities, or assist another person to circumvent referral limits or anti-abuse controls.
Attempted referral abuse may violate this Policy even where KOMERRA detects the conduct before Credits are issued or where the attempt does not succeed.
KOMERRA may hold a referral reward for verification, request supporting information, invalidate an ineligible referral, reverse or claw back referral Credits, offset an outstanding referral clawback against future promotional or referral benefits, restrict referral eligibility, suspend features, or suspend or terminate Accounts or Workspaces for serious or repeated deliberate abuse, subject to applicable law and an available review process.
An automated risk signal is not by itself a final finding of fraud. KOMERRA may use risk signals to place a reward on hold or route it for review, and will distinguish genuine mistakes or coincidental technical signals from deliberate manipulation where reasonably possible.
KOMERRA may withhold exact detection thresholds, scoring rules, fraud indicators, security methods, provider data, or other information where disclosure would make the controls easier to evade.
Do not mark a customer order as paid where payment has not been appropriately confirmed.
Do not create false payment records, forged receipts, fake bank alerts, manipulated screenshots, invented references, or misleading settlement information.
A screenshot or customer claim must not be represented as provider-confirmed settlement.
Do not release, withhold, or redirect another person’s money through KOMERRA without lawful authority.
KOMERRA must not be used as a bank, escrow service, remittance service, investment product, or store of value.
A business operating a Mini Store is responsible for the legality, accuracy, safety, quality, pricing, availability, delivery, warranty, refund terms, and customer service associated with its listings.
The Mini Store operator must have authority to sell or provide each listed product or service.
Do not list unavailable products as available merely to attract customers.
Do not conceal mandatory charges, material conditions, delivery limitations, subscription terms, product risks, or refund restrictions.
Do not use another person’s product images, descriptions, trademarks, reviews, or customer information without authorization.
Do not use a Mini Store to advertise, offer, sell, distribute, coordinate, or facilitate goods or services that are unlawful, unsafe, fraudulent, exploitative, or prohibited by KOMERRA or an applicable provider.
Where goods or services are regulated, age restricted, licensed, prescribed, controlled, or subject to professional requirements, you must obtain and maintain every authorization required to advertise or supply them.
Do not use KOMERRA to evade licensing, age verification, prescription, safety, labelling, tax, customs, professional, or sector requirements.
KOMERRA may restrict categories that are legally permitted in some jurisdictions where provider rules, safety concerns, verification limitations, or platform risk make the category unsuitable.
A business must not represent itself as licensed, accredited, registered, approved, or professionally qualified unless the statement is accurate and current.
KOMERRA may request supporting evidence or remove a listing while eligibility is reviewed.
Product and service descriptions must be materially accurate and must not conceal known safety concerns, defects, restrictions, or conditions of use.
Do not market a product as medically effective, officially approved, risk free, guaranteed, certified, authentic, environmentally beneficial, or professionally endorsed without a reasonable and lawful basis.
Do not alter product images, quantities, labels, measurements, ingredients, origins, weights, expiry information, or specifications in a misleading way.
Recall notices, safety warnings, and material corrections must not be hidden or removed.
A business is responsible for responding appropriately where a product or service may create a safety risk.
Prices, discounts, delivery charges, taxes, quantities, units, and availability must be stated accurately and clearly.
Do not create a false original price, fake scarcity, artificial countdown, fabricated demand, misleading discount, hidden charge, or unavailable promotional offer.
Do not advertise an item as in stock where you know it cannot reasonably be supplied.
Where a price depends on quantity, location, customization, exchange rate, or another condition, the condition must be explained before the customer commits.
A pricing mistake should be corrected promptly and handled fairly according to applicable law and the transaction circumstances.
Do not create, purchase, exchange, manipulate, suppress, or coordinate false customer reviews, testimonials, ratings, complaints, or endorsements.
Do not present a staff member, related business, paid promoter, or AI-generated persona as an independent customer.
Material relationships, incentives, gifts, payments, or sponsorships connected to a testimonial should be disclosed where required.
Do not threaten or punish a customer for submitting a genuine complaint or review.
Do not use KOMERRA to publish fabricated evidence intended to improve a Trust Passport or business reputation.
Trust Passport information must be accurate, current, authorized, and supported by appropriate evidence where a verification claim is made.
Do not manipulate verification status, registration information, ownership information, policies, customer history, ratings, activity indicators, or trust signals.
Do not describe a Trust Passport as a government certification, financial guarantee, insurance policy, credit rating, guarantee of delivery, or endorsement by KOMERRA.
Do not copy another business’s Trust Passport information or use its verification evidence.
A business must update or remove published information where it becomes materially inaccurate.
Public content includes Mini Store pages, Trust Passports, business profiles, product listings, public documents, images, policies, contact information, and other material intentionally made available to customers or the public.
Public content must be lawful, authorized, accurate, and suitable for its intended audience.
Do not publish passwords, authentication secrets, private identity documents, full government identification numbers, private staff information, confidential customer information, or another person’s financial information.
Do not publish content that creates a serious risk of fraud, harassment, exploitation, discrimination, violence, privacy invasion, or consumer harm.
KOMERRA may remove, restrict, de-index, or require correction of public content that violates this Policy.
Do not use KOMERRA to infringe copyrights, trademarks, patents, design rights, database rights, trade secrets, confidential information, publicity rights, or other intellectual-property rights.
Do not upload or publish content copied from another business, creator, supplier, marketplace, competitor, or customer without permission or another lawful basis.
Do not use another person’s logo, brand name, photographs, product images, documents, or advertising material in a way that falsely suggests ownership or affiliation.
AI-generated Output may not be unique or free of third-party rights. You must review Output before publication or commercial use.
KOMERRA may remove or restrict material in response to a sufficiently supported intellectual-property complaint.
Do not disclose, upload, publish, or misuse confidential information belonging to an employer, customer, supplier, partner, professional adviser, or other person without authorization.
Do not use KOMERRA to collect trade secrets, internal pricing, private customer lists, proprietary product information, confidential contracts, or competitor information through deception.
Access to confidential information through employment or Workspace membership does not authorize unrelated use after the relationship ends.
You must apply appropriate access controls and avoid placing confidential information in public or unrestricted fields.
Do not use KOMERRA to operate, promote, coordinate, document, or conceal fraud.
Prohibited activity includes advance-fee fraud, identity fraud, payment fraud, false invoicing, fake delivery, investment fraud, refund abuse, account takeover, transaction laundering, impersonation, and fabricated business opportunities.
Do not recruit customers, staff members, or other businesses into deceptive schemes.
Do not use AI, documents, Mini Stores, Trust Passports, messages, or verification indicators to make a fraudulent scheme appear legitimate.
KOMERRA may preserve relevant records and cooperate with providers or lawful authorities where credible fraud is suspected.
Do not use KOMERRA to disguise the source, destination, ownership, nature, purpose, or control of funds or transactions.
Do not divide, restructure, relabel, fabricate, or route records to conceal suspicious or unlawful activity.
Do not create false orders, invoices, receipts, customers, refunds, deliveries, or business activity to justify unrelated payments.
Do not use Mini Store transactions, Credit purchases, customer records, or documents as a substitute for required financial authorization or regulated payment services.
KOMERRA may restrict activity and request additional information where transaction records appear inconsistent, fabricated, or connected to serious misuse.
Do not use KOMERRA to create false accounting records, conceal taxable activity, fabricate deductible expenses, falsify invoices, or misstate business performance.
Do not backdate, alter, delete, or recreate records with the intention of deceiving a customer, auditor, regulator, bank, investor, court, or tax authority.
Legitimate correction of an inaccurate record is permitted, but the correction must not be designed to conceal the original event where preservation is legally or operationally required.
KOMERRA documents and reports are not a substitute for professional accounting, tax, audit, or legal advice.
Do not threaten, harass, abuse, impersonate, or deliberately mislead KOMERRA support personnel.
Do not submit forged records, manipulated screenshots, false security reports, fabricated payment evidence, or knowingly false complaints.
Do not open excessive duplicate cases, automate support requests, or use multiple Accounts to pressure different outcomes for the same matter.
Good-faith complaints, appeals, vulnerability reports, and disagreement with a decision are permitted and will not by themselves result in retaliation.
Support personnel will not ask for your password, bank PIN, card security code, one-time password, private key, or recovery code.
Do not use the Services in a manner that consumes unreasonable storage, processing, AI, bandwidth, queue capacity, messaging capacity, support capacity, or provider resources.
Do not create meaningless records, repeated files, synthetic traffic, duplicate documents, automated trial Accounts, or artificial business activity for the purpose of exhausting resources or manipulating metrics.
Do not resell shared Account access, provide unauthorized hosted access to KOMERRA, or use consumer-facing features as an unapproved infrastructure service.
KOMERRA may apply technical limits, require a different plan, restrict automation, or suspend unreasonable usage that threatens service availability.
Do not reproduce, white-label, resell, sublicense, rent, or commercially provide access to KOMERRA unless authorized by a written partner, reseller, enterprise, or developer agreement.
Do not charge another person for access to an Account you do not have authority to provide.
Do not copy KOMERRA interfaces, documentation, workflows, templates, brand assets, or protected content to create a misleadingly similar service.
Authorized agencies, consultants, staff members, and service providers may assist businesses only within their granted permissions and applicable agreement.
KOMERRA may investigate suspected violations using relevant Account, Workspace, payment, Credit, authentication, provider, communication, file, audit, security, support, and system records.
We may request information reasonably necessary to confirm identity, authority, transaction ownership, business legitimacy, provider status, or compliance.
You must not knowingly provide false information, conceal material evidence, delete relevant records, or interfere with an investigation.
KOMERRA may consult affected users, providers, professional advisers, regulators, or lawful authorities where appropriate.
An investigation does not necessarily mean that a violation occurred.
KOMERRA may preserve relevant information where reasonably necessary to investigate fraud, unauthorized access, platform abuse, a legal complaint, a security incident, or another serious violation.
Preserved information may include Account records, audit events, files, messages, payment references, provider events, IP information, device details, support communications, and affected Business Content.
Preservation may continue after content removal, Account closure, or suspension where a lawful and legitimate need remains.
Evidence preservation does not authorize unrestricted internal use of the information and remains subject to appropriate access and security controls.
KOMERRA may take proportionate action where it reasonably believes this Policy, the Terms of Service, provider rules, or applicable law has been violated.
KOMERRA may take immediate protective action before giving notice where delay could increase security, fraud, financial, privacy, consumer, safety, provider, or legal risk.
Immediate action may include revoking sessions, blocking access, disabling an integration, removing a public listing, stopping an automation, freezing Credits, or preserving evidence.
Protective action is not necessarily a final decision that a violation occurred.
Where lawful and reasonably safe, KOMERRA will provide an explanation and an opportunity to respond after urgent action has been taken.
Details may be limited where disclosure would compromise security, another person’s rights, provider confidentiality, or an active investigation.
Enforcement decisions may consider the nature, severity, duration, frequency, intent, impact, reversibility, affected people, information involved, prior warnings, cooperation, corrective action, and likelihood of recurrence.
KOMERRA may distinguish an accidental, promptly reported mistake from deliberate, repeated, concealed, or profit-motivated abuse.
The absence of direct financial loss does not prevent enforcement where conduct threatened security, privacy, safety, provider relationships, or platform integrity.
A serious first violation may justify suspension or termination without a previous warning.
Similar conduct may receive different outcomes where the risk, evidence, impact, or Account history differs.
Misuse by an Authorized User may affect the wider Workspace where the Workspace owner enabled, encouraged, ignored, or failed to address the conduct.
KOMERRA may remove the responsible user while leaving the Workspace active where the risk can be contained appropriately.
The entire Workspace may be restricted where abusive conduct is coordinated, administrator controlled, inseparable from the business operation, or likely to continue.
Workspace owners are responsible for reviewing staff permissions, investigating internal misuse, and cooperating with reasonable corrective requirements.
Repeated violations, continued non-compliance after warning, or attempts to evade enforcement may result in stronger restrictions.
Do not create a new Account, use another person’s Account, change identifiers, or transfer activity to another Workspace to avoid a restriction.
Accounts, Workspaces, devices, payment methods, providers, domains, contact details, or related activity may be assessed together where there is credible evidence of coordinated evasion.
An unrelated person or business will not be treated as connected solely because it shares a network, device type, name, location, or provider.
Where appropriate, KOMERRA will notify the affected Account holder or Workspace owner of a restriction, removal, suspension, or termination.
The notice may identify the general policy basis, affected feature or content, required corrective action, review method, and whether the restriction is temporary or permanent.
KOMERRA may withhold specific detection methods, security details, provider information, another person’s private data, or evidence that could enable further abuse.
Failure to receive a notice because Account contact information is outdated does not automatically invalidate necessary protective action.
You may request review where you believe an enforcement action was based on incorrect information, mistaken identity, unauthorized Account activity, or a misunderstanding of legitimate conduct.
Send the request to support@komerra.app with “Acceptable Use Review” in the subject.
Include the Account, Workspace, affected content or feature, approximate date, enforcement notice, explanation, and relevant supporting evidence.
Do not create new Accounts or continue the restricted conduct while the review is pending.
KOMERRA may maintain protective restrictions during review where restoring access would create material risk.
A review may uphold, modify, narrow, reverse, or replace the original action.
KOMERRA will not penalize a person merely for making a genuine complaint, reporting suspected misconduct, questioning a decision, exercising a privacy right, or submitting a good-faith security report.
This protection does not apply to reports that knowingly contain fabricated evidence, threats, harassment, extortion, malicious disclosures, or deliberate attempts to disrupt the Services.
A report may be closed without action where evidence is insufficient, the reported conduct is permitted, or the matter cannot reasonably be verified.
Report suspected fraud, impersonation, unlawful listings, abusive communications, privacy violations, Trust Passport manipulation, payment abuse, AI misuse, or other prohibited conduct to support@komerra.app.
Use “Acceptable Use Report” in the subject.
Include the relevant business, Mini Store, Trust Passport, Account, message, transaction, date, link, request identifier, and a clear description of the concern where available.
Provide only information reasonably necessary to explain the report.
Do not publicly share private personal data, credentials, payment information, or vulnerability details when reporting misuse.
KOMERRA may be unable to disclose the complete outcome of an investigation where doing so would expose another person’s information, security controls, or confidential legal matters.
This Policy does not authorize conduct prohibited by applicable law merely because the conduct is not listed expressly.
KOMERRA may restrict conduct that creates serious safety, security, privacy, fraud, consumer, provider, or platform risk even where the precise legal status has not yet been determined.
Where mandatory law provides a person with rights or protections, this Policy does not remove them.
Where provider terms impose stricter requirements on a particular integration, the stricter applicable requirement may govern use of that integration.
KOMERRA may update this Policy when the Services, AI capabilities, Mini Store categories, providers, legal requirements, abuse patterns, security risks, or operational practices change.
Material changes will be communicated through an appropriate website, application, Account, or email channel where required.
Changes do not retroactively convert previously permitted conduct into a violation, but continued or future conduct must comply with the updated Policy after it takes effect.
KOMERRA may introduce feature-specific restrictions or temporary protective rules where an emerging risk requires faster action.
Questions about whether a proposed use is permitted may be sent to support@komerra.app before the activity begins.
Use “Acceptable Use Question” in the subject and describe the intended business purpose, feature, content, recipients, automation, provider, and relevant safeguards.
A general support response does not override applicable law, provider rules, or a written agreement unless the response expressly states that it grants a specific authorization.
For suspected misuse, use “Acceptable Use Report”.
For a vulnerability or security concern, use “Security Report”.
Do not send passwords, private keys, one-time passwords, card security codes, bank PINs, recovery codes, or unnecessary identity documents through ordinary email.
Report misuse or ask a policy question
Contact support@komerra.app or use the contact form. Privacy and security reports are routed to the responsible team.