← Go backBasestack Acceptable Use Policy
Last updated: 11 September 2026
This Acceptable Use Policy (“AUP”) applies to the Basestack hosted service at https://www.basestack.co, including Feature Flags, Forms, related APIs, and future hosted products. It supplements the Terms of Service and Privacy Policy.
You are responsible for your account, team members, invited users, API keys, integrations, forms, and customer-facing use of Basestack. A breach of this AUP is a material breach of the Terms of Service, and your indemnity obligations under the Terms apply to any such breach. Report suspected abuse to [email protected].
Prohibited content and data
You must not use Basestack to collect, store, or transmit:
- payment card data subject to PCI DSS, full bank account numbers, government identification numbers, or financial account credentials;
- protected health information, medical records, or data regulated by HIPAA, HITECH, or equivalent health-data laws;
- biometric identifiers, precise geolocation, government clearance information, or special categories of personal data under Article 9 GDPR;
- personal data of children under 16, or data covered by children's privacy laws such as COPPA, unless expressly permitted in writing by Basestack;
- sexual content involving minors, content that exploits or endangers children, or any content prohibited by law;
- malware, ransomware, viruses, worms, trojans, exploit code, or files intended to damage, surveil, or impair systems;
- content that infringes intellectual property, privacy, publicity, or other third-party rights;
- any other content or activity that is unlawful, fraudulent, deceptive, defamatory, or otherwise prohibited by applicable law.
Prohibited uses of Forms
You must not use Forms to:
- phish for credentials, impersonate a brand or person, or mislead submitters about who is collecting their data;
- send unsolicited bulk email, SMS, or other commercial messages through webhooks, integrations, or exports;
- collect personal data without a lawful basis and required privacy notice;
- operate unlawful sweepstakes, lotteries, gambling promotions, or regulated-goods workflows;
- collect data from people who have not received a clear and accurate description of how their data will be used, stored, and shared.
Prohibited uses of Feature Flags
You must not use Feature Flags to:
- target people based on protected characteristics in ways that violate anti-discrimination law or consumer-protection law;
- send Basestack special categories of personal data or regulated data as identity traits;
- make a decision producing legal or similarly significant effects about a person solely through automated flag evaluation, without any required human review or lawful basis.
Service and account integrity
You must not:
- Probe, scan, or test Basestack systems except under a coordinated security disclosure sent to [email protected]
- Bypass, disable, or overload rate limits, plan limits, spam detection, IP-block rules, authentication, authorisation, or access controls;
- Share, sell, leak, or embed API keys, sign-in credentials, OAuth tokens, webhook secrets, or single-tenant access tokens outside your organisation;
- Resell, white-label, benchmark for a competitor, scrape, or reverse engineer the Service without written permission;
- Use the Service, its outputs, or data belonging to Basestack or other customers to train, fine-tune, or develop any machine learning model or competing product without written permission. This does not restrict how you use your own Customer Data.
Worldwide access, sanctions, and export controls
Basestack may be accessible worldwide, but you must not use or access the Service where doing so is prohibited by sanctions, embargoes, export controls, anti-terrorism laws, or other applicable law. You must not use the Service for restricted end uses or provide access to people or entities subject to sanctions.
Submitter and end-user protections
People who submit your forms or are evaluated by your feature flags are your data subjects or your customer's data subjects. You must provide legally required notices, have a lawful basis for processing, honour data-subject requests, and use Basestack deletion and export controls where needed.
Reporting abuse and enforcement
Report suspected violations to [email protected] with relevant details such as a form URL, project, submission ID, or account. We may contact you, ask you to remove content, throttle usage, disable integrations, suspend projects or forms, suspend the account, terminate the account, preserve evidence, or disclose relevant data where required by law.
For high-severity issues such as child exploitation, active phishing, malware distribution, sanctions violations, or threats to life or safety, we may act immediately and without notice.
Changes
We may update this AUP as the Service, abuse patterns, or laws change. Material changes take effect as described in the Terms of Service, and your continued use of the Service after an updated AUP takes effect constitutes acceptance of the changes.