Acceptable Use Policy

Last updated

This Acceptable Use Policy applies to everyone who uses Carrier Crow Connect (the “Service”), however they use it: through the web app, the API, the MCP server or a connected AI assistant. It forms part of our Terms of Service, and capitalised terms not defined here have the meanings given there. “We”, “us” and “our” mean Frozen Crow, as defined in the Terms.

Inboxes and phones belong to the people who receive your messages. Unwanted messages harm them, damage your sending reputation with your Sending Provider and with mailbox providers, and put other customers at risk. That is why we take this policy seriously and enforce it (see Section 10).

Your Sending Provider, mobile carriers and the other platforms you use have their own rules, which may be stricter than this policy. You must follow those too.

1. Send only to people who asked to hear from you

1.1 Permission. Send commercial email, SMS and push messages only to people who have given you permission to send them those messages, or where the law clearly allows you to contact them without it and you can show why. Permission must be given to you: consent someone gave to another business does not transfer to you.

1.2 No bought, borrowed or harvested lists. Do not use contact lists that were purchased, rented, leased, borrowed, traded or shared with you by third parties or affiliates, or that were scraped, harvested or generated, for example by collecting addresses from websites, social media or public directories, or by guessing addresses or numbers. Do not add email addresses or phone numbers to your records from third-party sources (“appending”) without the person’s permission.

1.3 Records of consent. Keep records of how and when each person gave permission, so that you can demonstrate it if asked. The Service keeps consent records, including double opt-in confirmations and SMS consent changes, but you remain responsible for consent you collect outside the Service.

1.4 Signup forms. Public signup forms in the Service use double opt-in. Do not work around it, for example by importing unconfirmed sign-ups as confirmed. On any form you use, be clear about what people are signing up for, and do not use pre-ticked boxes where the law requires consent to be an active choice.

1.5 Old or uncertain permission. Reconfirm permission before sending to contacts you have not messaged for a long time, or whose permission is in doubt.

1.6 Every route in. These rules apply however contacts enter the Service: through a form, a file import, the API or a connected AI assistant.

1.7 Children. Do not knowingly collect personal data from, or send messages to, children unless you comply with the laws that protect them. For example, the US Children’s Online Privacy Protection Act requires verifiable parental consent before personal information is collected online from children under 13.

2. Honour unsubscribes and STOP

2.1 A working unsubscribe in every commercial email. Every commercial email you send must give recipients a clear, working way to unsubscribe. The Service provides unsubscribe links and adds one-click List-Unsubscribe headers to campaign email. Make sure every message includes an unsubscribe link, and do not remove, hide, disable or obstruct either mechanism. Do not require recipients to log in, pay, or give more than their email address and preferences in order to unsubscribe.

2.2 Opt-outs that reach you another way. If someone asks you to stop by replying, emailing, calling or in person, record the opt-out in the Service promptly, and always within any deadline the law sets. For example, the CAN-SPAM Act requires opt-outs to be honoured within 10 business days.

2.3 No re-adding. Do not re-subscribe, re-import or recreate a contact who has opted out in order to get around their opt-out. Add them back only if they give fresh, explicit permission themselves. The Service does not silently reverse an opt-out; do not try to work around that.

2.4 No passing on opt-outs. Do not sell, share or transfer the contact details of people who have opted out, except to a service provider that is helping you honour the opt-out.

2.5 STOP for SMS. Honour STOP and other standard opt-out keywords (such as UNSUBSCRIBE, CANCEL, END and QUIT), and any other reasonable way a person tells you they no longer want texts. The Service records STOP and START replies and tracks SMS consent separately from email consent; do not override them.

3. Be honest about who you are

3.1 Accurate headers. Your From name, From address, Reply-To address and routing information must be accurate and must identify you, or the organisation you are sending for.

3.2 Honest subject lines. Subject lines and preview text must not mislead recipients about what a message contains.

3.3 Identify advertising. Where the law requires it, make clear that a commercial message is an advertisement or promotion.

3.4 Postal address. Include a valid physical postal address in commercial email where the law requires it, as the CAN-SPAM Act and CASL do, together with any other sender information the law requires.

3.5 Domains you control. Send only from domains and addresses that you own or are authorised to use, and set up authentication for them (such as SPF, DKIM and DMARC) as your Sending Provider and mailbox providers require. Never spoof another sender.

3.6 Identify yourself in texts. Identify your business in your SMS messages as the law and carrier rules require.

4. SMS, push and webhooks

4.1 Consent for texts. Obtain the consent the law requires before sending text messages. For marketing texts in the US, this is generally prior express written consent under the TCPA. Keep proof of it.

4.2 Clear disclosures. When you collect a phone number, tell people what kind of messages they will receive and how often, that message and data rates may apply, and how to opt out (reply STOP) and get help (reply HELP), as carrier and industry rules require.

4.3 Quiet hours. Do not send marketing texts at times the law forbids where the recipient is. For example, US federal rules prohibit telephone solicitations before 8 a.m. or after 9 p.m. in the recipient’s local time, and several states set narrower windows. The Service’s scheduling options can help you stay within the hours you choose, but you are responsible for choosing hours that comply.

4.4 Registration and carrier rules. Complete any sender, brand or campaign registration that carriers require for your messages (such as 10DLC registration in the US), and follow carriers’ content rules.

4.5 Changed numbers. Stop texting numbers you know have been reassigned or no longer belong to the person who consented.

4.6 Push notifications. Send push notifications only to people who have opted in to them, and follow the rules of the platforms they are delivered through.

4.7 Webhooks. Send webhooks only to endpoints that you own or are authorised to use. Do not use webhooks to overload, attack or spam other systems.

5. Prohibited content

Do not use the Service to create, send, store or link to content that:

  • is phishing, or tries to collect passwords, payment details or other credentials or sensitive information under false pretences;
  • contains or links to malware, viruses, spyware, ransomware or other harmful code;
  • offers or promotes illegal goods, services or activities, or goods or services you are not licensed to offer where a licence is required;
  • is deceptive, fraudulent or misleading, including scams, fake invoices or prize notifications, pyramid or Ponzi schemes, and false or unsubstantiated claims;
  • impersonates any person or organisation (including Frozen Crow), misrepresents your identity or affiliation, or spoofs another sender’s address or domain;
  • harasses, threatens, bullies, stalks or intimidates anyone, or publishes someone’s private information in order to harm or intimidate them;
  • promotes hatred of, or violence against, people because of characteristics such as race, ethnicity, national origin, religion, disability, sex, sexual orientation, gender identity or age;
  • sexualises minors in any way, or contains child sexual abuse material, which we will report to the appropriate authorities;
  • promotes or incites terrorism or violent extremism;
  • infringes the intellectual property, privacy or other rights of others; or
  • otherwise breaks the law.

Higher-risk categories. Some lawful products and services carry extra legal and deliverability risk. You need our written approval before using the Service to send messages that promote: cannabis, CBD or hemp products; firearms, ammunition or other weapons; gambling or betting; adult content or services; cryptocurrency, trading or other investment opportunities; payday or other high-interest loans; or debt collection. Ask us at support@carriercrow.com. We may attach conditions to an approval, and withdraw it if they are not met.

Your Sending Provider and mobile carriers may restrict further categories of content, and you must follow their rules as well.

6. Security and integrity of the Service

Do not:

  • circumvent, or attempt to circumvent, usage limits, rate limits, plan limits, sending pauses or suspensions, including by opening additional accounts;
  • manipulate, defeat or interfere with the Service’s automated-activity scoring, or falsify engagement data, for example by generating artificial opens or clicks or tampering with tracking;
  • access, or attempt to access, accounts, teams, projects or data you are not authorised to use;
  • probe, scan or test the vulnerability of the Service, or breach its security or authentication, without our prior written permission;
  • introduce malware into the Service, or disrupt or overload it, including through load testing we have not agreed to;
  • share login credentials, or expose API keys or OAuth tokens, for example in public code repositories or client-side code;
  • use the Service’s file storage for anything other than your messages and templates; or
  • reverse engineer the Service, except where the law allows despite this restriction.

If you find a security vulnerability, please report it to security@carriercrow.com, and do not exploit or disclose it before we have had a reasonable opportunity to fix it.

7. Fair use of the API, the MCP server and AI features

7.1 Use the interfaces we provide. Access the Service programmatically only through the API and the MCP server, and respect any rate limits or other limits we set or tell you about. Do not use scripts or bots to automate the web app.

7.2 Reasonable load. Do not place excessive or abusive load on the Service. Slow down when the Service asks you to, and retry failed requests with sensible delays rather than immediately and repeatedly.

7.3 Keys and tokens. Keep API keys and OAuth tokens secret, revoke them if they may have been exposed, and remove those you no longer need. We may revoke keys or tokens we believe are compromised or being misused.

7.4 Connected AI assistants. You are responsible for everything a connected assistant does through your account. Do not instruct an assistant to do anything this policy prohibits, and review the changes it makes. Contacts imported by an assistant are subject to the same permission rules as any other import.

7.5 AI Email Builder. Do not use the AI Email Builder to generate content this policy prohibits, or in a way that breaches the usage policies of the underlying AI provider, Google. Do not try to extract its underlying instructions or bypass its safeguards.

7.6 Your own data. Do not use the API or the MCP server to extract data for purposes unrelated to managing your own messaging, or to build a competing product.

7.7 Sending for others. If you use the Service to send messages for clients (for example, as an agency), you are responsible for each client’s compliance with this policy, and each client’s messages must identify that client as the sender.

8. List quality, bounces and complaints

8.1 Act on bounce and complaint information from your Sending Provider: remove addresses that hard bounce, and stop sending to people who mark your messages as spam.

8.2 Watch your complaint, bounce and unsubscribe rates. High rates are a sign that permission is missing or that people no longer want your messages. Mailbox providers set their own limits for bulk senders, and exceeding them can harm your deliverability.

8.3 We may monitor complaint, bounce and unsubscribe signals, abuse reports, and reports from Sending Providers, mobile carriers and others, to detect misuse of the Service.

9. Reporting abuse

If you received unwanted messages sent with Carrier Crow, or suspect the Service is being misused, please tell us at abuse@carriercrow.com. For email, include the full message with its headers; for SMS, include the sending number, the time and the message text.

To stop receiving messages from a sender, use the unsubscribe link in the email, or reply STOP to a text message.

We review reports and act on them as this policy describes. We may share a report with the customer concerned so that they can resolve it. To report a security vulnerability, see Section 6.

10. Enforcement

10.1 We may investigate suspected breaches of this policy, and you must cooperate with our reasonable requests during an investigation. We are not obliged to monitor content, but we may review content and data in your account as needed to investigate a report or enforce this policy.

10.2 Depending on how serious a breach is, we may:

  • warn you and ask you to fix the problem;
  • require changes to your lists, forms or content;
  • pause campaigns, or pause sending from a project or channel;
  • disable a feature, an API key or a connected app;
  • suspend your account;
  • terminate your account; and
  • report illegal activity to law enforcement or other appropriate authorities.

10.3 We will usually contact you before acting, but we may act immediately and without notice where a breach is serious (for example phishing, malware, or content that sexualises children) or where harm is ongoing or imminent. Suspension and termination are governed by Sections 12 and 13 of our Terms of Service.

10.4 Taking, or not taking, action does not waive our rights or relieve you of your responsibilities under this policy or the Terms.

11. Changes to this policy

We may update this policy to reflect changes in the law, in industry and carrier rules, and in patterns of abuse. The date at the top of this page shows when it was last changed. We will tell you about material changes as described in Section 17 of our Terms of Service.