Skip to content
StoreFlux
Features Developers Security Pricing Docs FAQ
Sign in Start free
Features Developers Security Pricing Docs FAQ
Start free Sign in
Home/Legal/Acceptable Use

Acceptable Use Policy

The rules for what you may and may not do with the StoreFlux platform, so every store on it stays safe, lawful and fast.

Last updated: October 3, 2026 Applies to storeflux.store, the admin panel and the API
On this page
  1. Lawful use
  2. Prohibited products and content
  3. Security and platform integrity
  4. Messaging and spam
  5. Personal data
  6. AI features
  7. API use
  8. Reporting violations
  9. Enforcement

This Acceptable Use Policy (“AUP”) is part of the Terms of Service and applies to every store, admin user, API client and storefront on the StoreFlux platform. Because StoreFlux is shared infrastructure, one tenant’s misuse can affect everyone, so these rules are enforced.

01Lawful use

You must comply with all laws that apply to you and your store, including consumer-protection, advertising, tax, export-control, sanctions, data-protection and payment-network rules. You must hold any licences or permissions required to sell what you sell.

02Prohibited products and content

You may not use StoreFlux to offer, promote or distribute:

  • Illegal goods or services, or anything that facilitates illegal activity.
  • Weapons, explosives or restricted items where sale is prohibited or you lack the required licences; illegal drugs and drug paraphernalia.
  • Counterfeit, stolen or infringing goods, or content that infringes copyright, trademark or other rights.
  • Child sexual abuse material or any content that sexually exploits or endangers minors.
  • Content that is defamatory, harassing, hateful, threatening or that incites violence.
  • Fraudulent schemes, pyramid or Ponzi schemes, deceptive “get-rich-quick” offers, or misleading product claims.
  • Malware, phishing pages, or anything designed to deceive users into disclosing credentials or payment details.
  • Any product or activity that Stripe, PayPal or another payment provider you use prohibits.

03Security and platform integrity

  • Do not attempt to access data belonging to another tenant, bypass tenant isolation, or probe for vulnerabilities outside of our responsible disclosure terms.
  • Do not interfere with or overload the Service, including through denial-of-service attacks, abusive scraping or deliberately expensive queries.
  • Do not circumvent authentication, rate limits, plan limits or usage metering, or share API keys and accounts beyond your authorised team.
  • Do not reverse engineer, decompile or resell the Service, or use it to build a competing product.

04Messaging and spam

You must not use the Service to send unsolicited bulk email or messages, harvest email addresses, or send marketing to people who have not agreed to receive it where consent is required. Transactional and marketing emails sent through the platform must identify the sender truthfully and include a working opt-out for marketing messages.

05Personal data

You must have a lawful basis and any required notices and consents for the personal data you collect from your shoppers, and you must honour their data-protection rights. Do not store payment card numbers, CVV codes or other sensitive authentication data in product notes, custom fields or any other free-text area; use the payment gateway’s tokenised flow.

06AI features

If you enable AI features with your own provider key, you are responsible for compliance with that provider’s usage policies and for the content you generate and publish.

07API use

  • Respect documented rate limits and back off when you receive HTTP 429 responses.
  • Keep API keys secret, scope them to the minimum permissions they need, and rotate them if exposed.
  • Public endpoints may be called from the browser; do not embed private keys or admin credentials in front-end code.

08Reporting violations

If you see content or behaviour on a store that breaches this policy, email admin.storeflux@gmail.com with the store address and details. For security vulnerabilities, follow the Security & Disclosure process instead.

09Enforcement

We may investigate suspected violations. Depending on severity, we may remove content, throttle or suspend a store or API key, terminate accounts, and report unlawful activity to the authorities. Where reasonable and safe we will contact you first and give you a chance to correct the problem; for serious or urgent risks we may act immediately. We are not obliged to monitor stores, and failure to enforce a rule in one case does not waive it.

Other policies

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund & Cancellation
  • Data Processing (DPA)
  • Security & Disclosure
StoreFlux

The complete headless commerce backend. Build it yourself or let us build it for you.

All systems operational

Product

  • Features
  • API Playground
  • Security
  • Pricing
  • Documentation

Resources

  • Admin panel demo
  • Storefront demo
  • API reference
  • FAQ
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund & Cancellation
  • Acceptable Use
  • Data Processing (DPA)
  • Security & Disclosure

© 2026 StoreFlux. All rights reserved.

· Built on .NET 10, React 19, and PostgreSQL.

StoreFlux