Política de Uso Aceptable / Acceptable Use Policy
Esta política forma parte del contrato con el negocio suscriptor y se publica y rige en inglés. Si reservaste una cita, consulta el Aviso al cliente en español.
Audience: the business that subscribes to Plaza (the "Tenant") and everyone who uses its account. This is Exhibit B to the Platform Terms of Service (Platform Terms of Service) and forms part of that agreement. A material breach of this Policy is a material breach of the Terms.
1. Why this exists, and the one thing to understand about it
Plaza is multi-tenant. Every business shares infrastructure with every other business — the same database cluster, the same hosting, the same email reputation, and, critically, the same Twilio toll-free number.
That means misuse by one business damages every other business on the platform. A spam complaint against one tenant's marketing blast can get the shared number filtered or revoked by carriers, silencing appointment reminders for every salon, barbershop and auto shop using Plaza. This is not a hypothetical: it is the ordinary way toll-free numbers die.
Because of that, the messaging rules in Section 5 are enforced faster and less forgivingly than everything else in this Policy, and Section 11 permits action without prior notice.
2. Who this binds
This Policy binds the Tenant, every Staff User, and anyone the Tenant permits to access its account or to send messages through it. The Tenant is responsible for the conduct of all of them, whether or not it authorized the conduct (Platform Terms of Service §4.2).
3. Businesses and activities you may not run on Plaza
You may not use the Service for, or in connection with:
- any activity on Stripe's Restricted Businesses list, as it exists from time to time — you are bound to that list by your own Stripe Connected Account Agreement, and violating it is a breach of this Policy as well;
- unlicensed provision of any service that requires a license (including cosmetology, barbering, massage therapy, tattooing, medical, veterinary, or automotive-repair licensing where required);
- adult or sexual services, escort services, or any service where the actual transaction is sexual in nature;
- controlled substances, cannabis and cannabis-derived products where their sale is unlawful in the relevant jurisdiction, tobacco or vape products where prohibited, firearms, ammunition, weapons, or explosives;
- gambling, lotteries, sweepstakes, prize draws, or games of chance;
- multi-level marketing, pyramid schemes, matrix programs, chain referrals, or "get rich quick" offerings;
- debt collection, credit repair, payday lending, cryptocurrency exchange, money transmission, or any activity requiring a money-services or lending license;
- counterfeit, stolen, or infringing goods, or any goods whose sale infringes a third party's rights;
- any activity intended to launder money, evade sanctions, evade tax, or conceal the identity of the true seller.
You must also not use the Service to sell a product or service you do not actually deliver, or to collect deposits for appointments you have no intent or capacity to honor.
4. Content and conduct you may not put into the Service
You may not upload, transmit, store, or display through the Service:
- content that is unlawful, defamatory, harassing, threatening, or that incites violence;
- content that infringes any copyright, trademark, publicity, privacy, or other right;
- sexually explicit material, or material depicting minors in any sexualized way;
- malware, ransomware, keyloggers, or any code intended to disrupt or gain unauthorized access;
- another person's personal information that you have no lawful basis to hold, including client lists you purchased, rented, scraped, or took from a former employer without right;
- false statements about a competitor, or content designed to impersonate another business.
You may not use another business's name, logo, or booking page identity, and you may not configure a booking page so that a customer is misled about which business they are dealing with — that identity is the foundation on which the customer's consent, deposits, and gift cards all rest.
5. Messaging rules (SMS and email) — the strict section
Full allocation and consent mechanics are in Messaging Program Terms (Exhibit C). This Section states the operational rules that bind you.
5.1 You must have consent, and be able to prove it
You may send a message through the Service to a number or address only if you hold consent of the type the message requires:
- Transactional messages (appointment confirmations, changes, reminders, receipts, portal sign-in links) require the recipient's transactional consent, recorded in the Service.
- Marketing or promotional messages (offers, promotions, win-back campaigns, new-service announcements, review requests that carry an offer) require prior express written consent to marketing specifically, meeting the requirements of the TCPA and its implementing rules as they exist from time to time, including a clear and conspicuous disclosure and an affirmative act by the recipient.
Plaza platform rules, in addition to what the law requires. These are Techne's own rules for the shared toll-free number. They are stated as platform requirements, not as a statement of what any particular federal rule currently compels, and they apply whether or not the law requires them:
- One business at a time. A marketing consent captured through the Service is consent for one named business — the business shown beside the checkbox — and for no other. It may not be treated as consent for an affiliate, a successor, a partner, a referral, or any other business. The product works this way: one business per booking-form checkbox.
- Logically associated content. A marketing message must be topically associated with the business and the interaction that produced the consent. A consent given while booking a haircut is not consent for an unrelated offer.
A booking is not consent to marketing. Consent obtained for appointment messages may never be repurposed for promotions.
5.2 Where consent must come from
Consent must be captured through the Service's own consent surfaces — the booking-form checkboxes, or a consent record you create from a documented, lawful source you can produce on demand.
You may not:
- import phone numbers or email addresses obtained from purchased, rented, scraped, harvested, appended, or third-party lists;
- import numbers collected by a previous platform without also being able to produce the original consent evidence for each one;
- create a consent record for a person who did not actually consent, or backdate one;
- pre-check, default-on, bundle, or condition a marketing consent — marketing consent may never be a condition of booking, of service, of a discount that is not separately and lawfully disclosed, or of anything else;
- alter the disclosure language shown beside a consent checkbox. That language is carrier-facing and legally operative; it is pinned in the software and must not be worked around.
5.3 What you must not send
You may not send, through the Service:
- messages to a number after that person has opted out, by any method;
- messages containing content prohibited by carriers or by the CTIA Messaging Principles and Best Practices, including content relating to controlled substances (the "SHAFT" categories: sex, hate, alcohol, firearms, tobacco), high-risk financial offers, debt collection, or unlawful products;
- content that does not match the use case declared in the toll-free verification for the shared number — a mismatch gets the number filtered for everyone;
- messages that conceal or misstate the identity of the sending business;
- unsolicited bulk messaging of any kind;
- messages designed to evade filtering, including deliberate misspelling, URL shorteners that mask the destination, or rotating link domains;
- messages at hours prohibited by applicable telemarketing law.
5.4 Opt-outs must be honored by every method
You must honor an opt-out request received by any reasonable means — not only a STOP reply. That includes a verbal request at your counter, an email, a phone call, a written note, or a message to your staff. The FCC's rules require this, and a request made off-platform is still a request.
When you receive an opt-out outside the Service, you must record it in the Service promptly. The software cannot honor a revocation it was never told about, and a message sent after an unrecorded revocation is a violation for which you are responsible.
5.5 Email
Email you send through the Service must comply with the CAN-SPAM Act: accurate header and "from" information, a subject line that is not deceptive, your valid physical postal address, a clear and working unsubscribe mechanism in any commercial message, and honoring unsubscribes promptly.
5.6 What we may do about messaging, and how fast
Because the toll-free number is shared, we may throttle, pause, suspend, or terminate your messaging immediately and without prior notice if we reasonably believe your traffic violates this Section, violates law or carrier rules, or is generating complaints or carrier action. We will tell you the reason as soon as reasonably practicable. We will not wait for a cure period when the shared number is at risk (Platform Terms of Service §§8.6, 15.2).
6. Payments, deposits, and gift cards
You may not:
- process a transaction that does not arise from a genuine sale of your own goods or services;
- process a payment on behalf of another business, person, or entity ("factoring" or transaction laundering) — every charge on your Connected Account must be your own sale;
- use the Service to test stolen card numbers, or to process a charge you know or suspect is fraudulent;
- take a deposit under a policy you have not disclosed to the customer before charging it, or refuse a refund your own published policy promises;
- use the gift-card feature to create value you did not sell — the balance-adjust function exists for correcting genuine errors, and using it to mint spendable value without a corresponding sale, tender, or receipt is a breach of this Policy and may be a violation of law;
- impose an expiration date or a dormancy, inactivity, or service fee on a gift card by any workaround, including manual balance reduction;
- refuse to honor a gift card you issued, or decline to cash out a small remaining balance where state law requires it.
Your obligations as issuer, including unclaimed-property and escheat obligations, are in Platform Terms of Service §7.
7. Data and privacy
You may not:
- collect personal information through the Service without the notice and legal basis your own obligations require;
- put prohibited data into the Service — payment card numbers outside Stripe's payment form, Social Security or government ID numbers, financial account credentials, HIPAA-covered information, or GLBA-covered information (Data Processing Addendum §10.2);
- use client information for a purpose you did not disclose to the client, or share it with a third party the client would not expect;
- retain, export, or continue to use client data after you no longer have a lawful basis for it;
- use the Service to build a client list for resale, or to sell or rent your client list to anyone.
If you collect sensitive information in a custom form — health conditions, allergies, medications, immigration status, precise location — you are responsible for the consent and assessment obligations that attach (Data Processing Addendum §10.1). Just because the software lets you build the field does not mean the law lets you ask the question.
8. Technical rules
You may not:
- circumvent or attempt to circumvent any capability gate, permission control, rate limit, tenant isolation boundary, or authentication mechanism;
- access, or attempt to access, another tenant's data;
- probe, scan, load-test, or test the vulnerability of the Service, or run penetration testing or automated scanning against it (Data Processing Addendum §9.2);
- scrape the Service, or use bots or automated tools against it outside documented interfaces;
- resell, sublicense, or provide the Service to a third party as a service bureau;
- interfere with the Service's operation or with any other tenant's use of it;
- share account credentials, or allow a person to use a Staff User account that is not theirs.
If you find a security vulnerability, report it to abuse@technestudios.net. Report it; do not explore it. A good-faith report made without exfiltrating data, without accessing another tenant's information, and without public disclosure before we have had a reasonable chance to fix it will not be treated as a breach of this Policy.
9. AI features
You may not use the Service's AI features to generate content that violates this Policy, to impersonate a person, or to make representations to your customers about price, availability, safety, medical matters, or legal matters that you have not verified. You are responsible for everything your business communicates through an AI-assisted feature, exactly as if you had typed it (Platform Terms of Service §11.3).
10. Your own staff
You must not use the Service to monitor staff in a manner prohibited by applicable employment or privacy law, to record a person without a consent that the law requires, or to enforce a scheduling or timekeeping practice that violates wage-and-hour law. The Service records what it records; whether recording it is lawful in your workplace is your determination.
11. What happens if you violate this Policy
11.1 What we may do. Depending on severity, we may: contact you; require a change; throttle or disable a feature; suspend messaging (Section 5.6); suspend the account; terminate the account; preserve and disclose records where law requires or where necessary to protect rights and safety; and report conduct to Stripe, to Twilio, to carriers, or to law enforcement.
11.2 Speed. We will normally contact you first and give a reasonable chance to fix the problem. We will not, where we reasonably believe there is risk to the shared toll-free number, to another tenant's data, to the security or availability of the Service, or of imminent legal exposure — in those cases we act first and explain after (Platform Terms of Service §15.2).
11.3 No refund. Suspension or termination for a violation of this Policy does not entitle you to a refund of Subscription Fees.
11.4 Your indemnity applies. A claim arising from your violation of this Policy is covered by your indemnity in Platform Terms of Service §12.
11.5 We are not obligated to monitor. We do not review tenant content, message contents, or business practices in advance, and we have no duty to. Not acting on a violation is not a waiver of the right to act on it later (Platform Terms of Service §16.6).
12. Reporting a violation
Report suspected abuse, spam, security issues, or unlawful use to abuse@technestudios.net. Include the business name or booking-page address, what happened, when, and any message or screenshot you can provide. We do not commit to a response time, and we will not tell you what action we took about another business's account.
13. Changes
We may update this Policy on notice under Platform Terms of Service §16.2. Where a change is required by law, a carrier, or a payment provider, it may take effect immediately, and we will tell you.
Exhibit B to Platform Terms of Service. Related: Messaging Program Terms (Exhibit C — the consent mechanics) · Data Processing Addendum (Exhibit A) · Privacy Policy.