This Acceptable Use Policy ("AUP") sets out what you may and may not do when using the CARTT.AI platform (the "Service"). It is incorporated by reference into the Subscription Terms of Service.
1. Purpose of this policy
This AUP exists to:
- Protect the integrity, security, and reputation of the Service
- Protect other Subscribers from interference, abuse, or harm
- Comply with Australian and New Zealand law
- Protect End Customers from harmful or unlawful content and conduct
By using the Service, you agree to comply with this AUP. A material breach of this AUP may result in suspension or termination of your account, and where the breach cannot be remedied, falls within section 3.2, or presents an immediate risk to other Subscribers, to End Customers or to the Service, we may act immediately and without the cure period otherwise provided in the Subscription Terms of Service. A material breach that can be remedied gets written notice and a period to fix it before termination. Section 8 sets out the full range of responses and how we choose between them, and governs this paragraph.
2. Who this policy applies to
This AUP applies to:
- All Subscribers
- All authorised users of Subscriber accounts (employees, contractors, agents)
- All content, products, services, conduct, and transactions made available through the Service by a Subscriber or its authorised users
You are responsible for ensuring everyone who uses your account complies with this AUP.
3. Prohibited content
You must not use the Service to host, sell, promote, distribute, or facilitate any of the following.
3.1 Illegal content
- Content that is illegal under Australian or New Zealand law, or under the law of any jurisdiction where your storefront is accessible
- Content that infringes the intellectual property rights of any person (copyright, trademark, design, patent, moral rights)
- Counterfeit, replica, or unauthorised reproductions of branded goods
- Stolen property or proceeds of crime
3.2 Harmful or dangerous content
- Child sexual abuse material — immediate termination and report to law enforcement
- Content that promotes, glorifies, or incites violence or terrorism
- Content that promotes self-harm, suicide, or eating disorders
- Doxxing material (publication of private information about identifiable individuals without consent)
- Non-consensual intimate imagery
3.3 Regulated goods and services without proper licensing
You may sell regulated goods and services through the Service only if you hold all required licences, permits, and approvals, and your storefront complies with all relevant disclosure and verification requirements. Regulated categories include, without limitation:
- Alcohol, tobacco, and vape products
- Prescription medicines and therapeutic goods
- Firearms, weapons, and ammunition
- Gambling products and services
- Financial products and services
- Adult products and services (age-restricted)
We may request proof of licensing at any time and may suspend the relevant storefront pending verification.
3.4 Prohibited categories
The following categories are prohibited entirely on the Service, regardless of licensing:
- Illegal drugs, drug paraphernalia, or precursor chemicals
- Live animals (other than as permitted under Australian biosecurity law and only with our prior written approval)
- Human body parts, fluids, or remains (other than legally permitted hair and similar)
- Hate-group merchandise or material promoting discrimination based on protected characteristics
- "Get rich quick" schemes, multi-level marketing schemes with no legitimate product, or content promoting unrealistic income promises
- Cryptocurrency mining services, ICO/IDO/token sales, or speculative crypto investments aimed at consumers
- Content that infringes our intellectual property or branding
3.5 Misleading or deceptive content
- Content that is misleading or deceptive in breach of the Australian Consumer Law
- False testimonials, fake reviews, or other manipulated social proof
- Misrepresentation of product origin, materials, or compliance certifications
- Fake scarcity, fake countdown timers, or other deceptive urgency tactics
- Phishing pages or attempts to impersonate other businesses
4. Prohibited conduct
4.1 Abuse of the Service infrastructure
You must not:
- Use the Service in a manner that places unreasonable load on infrastructure (denial-of-service, excessive crawler activity, runaway scripts)
- Attempt to gain unauthorised access to other Subscribers' accounts, our systems, or any data not your own
- Probe, scan, or test the vulnerability of the Service except through our responsible-disclosure program
- Circumvent or disable any technical limitation, security measure, or feature gate
- Reverse-engineer, decompile, or attempt to extract source code from the Service
- Use automated tools to scrape, mirror, or harvest content from the Service or from other Subscribers' storefronts
4.2 Unsolicited communications
You must not:
- Send unsolicited commercial electronic messages in breach of the Spam Act 2003 (Cth) or the Unsolicited Electronic Messages Act 2007 (NZ)
- Send marketing communications to recipients who have not given consent or have withdrawn consent
- Buy, sell, share, or use third-party email lists not legitimately obtained
- Send SMS marketing without proper consent and without including opt-out information
4.3 Deceptive payment processing
You must not:
- Use payment processing for purposes other than your declared storefront business
- Process card transactions on behalf of third parties (factoring, transaction laundering)
- Charge customers without clear consent, or in amounts different from what they agreed
- Refuse to honour valid refund requests
4.4 Harm to End Customers
You must not:
- Process End Customer personal information in breach of applicable privacy law
- Fail to deliver products or services that customers have paid for, where you are reasonably able to do so
- Conceal material information about products, terms, or your business identity from End Customers
- Use dark patterns to coerce purchases (forced subscriptions, hidden fees, deliberately confusing interfaces)
4.5 Harm to us or to other Subscribers
You must not:
- Make false or misleading statements about the Service or about CARTT.AI
- Use the Service to compete with CARTT.AI or to build a competing platform
- Attempt to interfere with other Subscribers' use of the Service
- Use the Service to send abuse, threats, or harassment to CARTT.AI staff or to other Subscribers
4.6 Misuse of AI features
You must not:
- Use AI-generated Content to create deepfakes, impersonations, or material misleadingly attributed to real people
- Generate content that promotes any of the prohibited content categories in section 3
- Use AI to mass-produce fake reviews, fake testimonials, or fake user-generated content
- Attempt to extract, expose, or reverse-engineer the underlying AI models or prompts used by the Service
5. Specific marketing-feature requirements
5.1 Email marketing
When you use the Service to send marketing emails:
- You must obtain valid consent from each recipient (express consent or, where permitted, inferred consent)
- You must include clear sender identification — your accurate legal or registered trading name in your home jurisdiction, contact details at which you can be reached that stay valid for at least 30 days after each message is sent — not merely for the life of the campaign — and any registration identifier that applies to you (an ABN for an Australian business, an NZBN for a New Zealand one)
- You must include a functional one-click unsubscribe option in every marketing email, and that unsubscribe facility must keep working for at least 30 days after the message is sent
- You must honour unsubscribe requests within 5 business days
- You must keep records of consent. The Spam Act 2003 (Cth) does not set a retention period; what it does is put the burden on you to prove consent if a recipient or the ACMA questions a message, so the practical requirement is a record clear enough to discharge that burden. As a term of using the Service, keep each consent record for at least two years after the consent is withdrawn or the recipient is last sent a marketing message, whichever is later. Keep it longer where a dispute or an ACMA enquiry is on foot
5.2 SMS marketing
When you use the Service to send marketing SMS:
- Express consent is required (inferred consent is generally not sufficient for SMS)
- Each message must clearly identify you as the sender
- Each message must include "Reply STOP to opt out" or equivalent
- You must honour opt-outs within 5 business days
5.3 Welcome popups and discount capture
- Discount-capture popups must clearly disclose what the visitor is opting in to
- You must not capture email addresses for purposes other than those disclosed
- You must honour the discount you offered in the popup
6. Storefront representation requirements
Your storefront must:
- Clearly display your business name, ACN/ABN (where applicable), and physical or postal contact address
- Publish a privacy policy that complies with the Australian Privacy Principles
- Publish terms of sale that clearly state delivery, refund, and warranty terms
- Display product prices in Australian dollars (or another single primary currency clearly labelled) with GST treatment clearly stated
- Not impersonate any other business, person, or brand
7. Reporting violations
If you become aware of conduct that violates this AUP — whether by another Subscriber, by an End Customer of another Subscriber, or anyone else using the Service — please report it to legal@cartt.ai.
We treat reports confidentially and investigate promptly. We may follow up with you for additional information.
For child sexual abuse material specifically, you may report directly to:
- eSafety Commissioner: esafety.gov.au
- Australian Federal Police: afp.gov.au
We will also report such material as required by law.
8. Our enforcement rights
We may take any of the following actions in response to a suspected breach of this AUP, in our reasonable discretion, taking into account the seriousness of the breach and the apparent risk to others:
- Informal warning — minor or apparently inadvertent breach
- Formal written notice with a cure period — material but remediable breach
- Temporary suspension of specific features — where a specific feature is being misused
- Temporary suspension of the entire account — pending investigation of a serious breach
- Permanent termination of the account — material uncured breach, or any breach of section 3.2
- Removal of specific content — where content breaches this AUP
- Disclosure to law enforcement or regulators — where required or appropriate
- Civil action — where we have suffered loss as a result of the breach
We are not obligated to monitor your use of the Service for compliance, but we may do so. If we identify a breach, we may act on it regardless of when we first identified it.
9. Investigation cooperation
If we investigate a suspected breach, you must:
- Cooperate reasonably with our investigation
- Provide information reasonably requested
- Allow us reasonable access to relevant content stored within the Service
- Not destroy or alter evidence relevant to the investigation
Failure to cooperate may itself be treated as a breach.
10. Severability and updates
If any provision of this AUP is held invalid or unenforceable, the remaining provisions continue in effect.
We may update this AUP from time to time. Where the change is material, we will publish it as a new numbered version and email the administrators on your account. Publication is the step that always happens and is verifiable on this page; the email is sent by us rather than automatically by the platform, so the published version here — not your inbox — is the authoritative record of what is in force. Where we are able to give advance notice we will give at least 30 days; where a change must take effect sooner — for example to close off a form of abuse — we will tell you why. Where the change is non-material (clarifications, examples), it takes effect when published.
Every published version of this AUP carries a version number, an effective date, and a content hash. The version number and effective date are shown at the top of this page, and an abbreviated form of the hash at the foot; the full hash is available on request. We retain the full version history and will provide any earlier version on request to legal@cartt.ai.
11. Contact
Questions about this AUP, and reports of abuse, can be sent to legal@cartt.ai.
Reference: acceptable-use-policy v8 ·
content hash 29dd436cafa7fde3.
Questions before you accept: legal@cartt.ai.