This page provides the intended corporate structure and plain-language content. It must be reviewed against the group’s final legal entities, processing activities, contracts, markets and applicable laws before publication.
1. Scope
This policy provides a corporate baseline for websites, accounts, APIs, communications tools and marketplace technologies operated or supplied by the group. Product-specific rules may add stricter requirements based on the service, market, user type or risk profile.
The final production version must identify the services and legal entities to which it applies.
2. Lawful and responsible use
Users, customers, partners and authorised personnel must use covered systems only for lawful purposes and in a way that does not harm people, undermine platform integrity or interfere with legitimate operations.
- Provide accurate information where verification or account details are required.
- Respect the rights, privacy and safety of other people.
- Follow applicable product rules, content standards and contractual requirements.
- Cooperate with reasonable security, fraud-prevention and compliance checks.
3. Accounts, credentials and authorised access
Account holders are responsible for protecting credentials, using approved access methods and informing the relevant service when unauthorised access is suspected.
- Do not share credentials except through an approved team or delegated-access feature.
- Do not impersonate another person, organisation or authorised representative.
- Do not create accounts to evade restrictions, verification or enforcement.
- Do not obtain, sell or transfer access in a way that violates the applicable service terms.
4. Prohibited conduct
Covered systems must not be used to facilitate exploitation, abuse, deception or unlawful activity. Prohibited conduct includes:
- Child sexual exploitation, trafficking, coercion, non-consensual activity or content involving minors.
- Fraud, scams, money laundering, identity theft, deceptive payment activity or deliberate misrepresentation.
- Threats, targeted harassment, doxxing, extortion, hate-based abuse or encouragement of serious violence.
- Publication or distribution of intimate, confidential or personal information without a lawful basis or valid consent.
- Sale, promotion or facilitation of prohibited goods, services or activities under applicable law.
- Attempts to obstruct reporting, evidence preservation, investigations or authorised enforcement.
5. Technical misuse
Users must not interfere with the availability, confidentiality or integrity of the systems.
- Do not introduce malware, malicious code, destructive payloads or unauthorised automation.
- Do not probe, scan, bypass or exploit security controls without written authorisation.
- Do not scrape, harvest or extract data beyond an approved interface or contractual permission.
- Do not overload systems, manipulate metrics, abuse APIs or interfere with another user’s access.
- Use responsible vulnerability-reporting routes rather than publicly disclosing sensitive details that could create avoidable harm.
6. Investigation and enforcement
Potential violations may be reviewed using account information, content, transaction signals, technical logs, reports and other relevant evidence. Responses should be proportionate to the seriousness, evidence, recurrence and potential harm.
Possible actions may include warnings, content restriction, feature limitation, verification, temporary suspension, termination, preservation of records, referral to another responsible team or cooperation with a valid legal process.
Where appropriate, the applicable service should provide an appeal or correction route.
7. Reporting concerns
Reports should use the route provided by the relevant product or the corporate Contact page. A useful report identifies the service, account or content involved, describes the concern and supplies only the evidence reasonably needed for review.
Do not send passwords, full payment credentials or unnecessary sensitive identity documents through a general reporting form.
8. Regional and product-specific terms
This corporate baseline does not replace the rules published for a specific marketplace, payment workflow, commercial product or regional service. Those rules may include local age requirements, restricted categories, verification standards, transaction controls and reporting obligations.
Where a product-specific rule is stricter than this baseline, the stricter rule should apply to that product.