Draft for review. Full company particulars and outstanding policy and operational details must be finalised before these documents take effect.
LEGALAcceptable Use Policy
Lawful form collection, prohibited activity and safeguards for sensitive data.
1. Lawful and transparent use
Use Onlyform only for lawful purposes, within your plan and with authority to collect and use the data involved. Identify the form owner, explain the purpose of collection and provide an appropriate privacy notice and contact route. Do not present a form as anonymous if identifiers, metadata or integrations can identify respondents.
2. Prohibited activity
- Phishing, impersonation, fraud, scams, deceptive payment requests or collection of another person's passwords, one-time authentication codes, wallet seed phrases or private keys.
- Malware, malicious uploads, unauthorised access, vulnerability exploitation against third parties, or interference with the service.
- Spam, unlawful marketing, purchased-list abuse or messages without a required permission or unsubscribe mechanism.
- Illegal content, child sexual abuse material, exploitation, credible threats, targeted harassment, or infringement of intellectual property or privacy rights.
- Selling personal data unlawfully, secret surveillance, unlawful discrimination or evading sanctions or provider restrictions.
- Bypassing plan limits, access controls, rate limits or payment requirements, or imposing unreasonable load on the service.
3. Restricted data
Do not collect complete card numbers, card security codes or payment account credentials through ordinary form fields. Use a supported payment provider's dedicated interface. Before collecting government identity documents, Aadhaar or other national identifiers, health records, genetic/biometric identifiers, criminal-offence data or other sensitive information, establish a permitted purpose, the required legal basis or explicit consent, appropriate access/retention controls and any legally required agreement. Do not collect it if the chosen deployment cannot meet those requirements.
Do not use ordinary Onlyform deployments for data subject to a required healthcare agreement, certified environment or local-storage restriction unless we have expressly agreed and supplied those capabilities. A form template, signature field, password field or security setting does not certify suitability for a regulated use.
4. Children
Account agreements must satisfy the Terms' legal-capacity requirement. Before directing forms to children or knowingly collecting their personal information, establish the required notices, age/parental-authorisation processes and legal safeguards. Where those safeguards are not available, do not carry out the collection. A customer's generic permission statement is not a substitute for verifiable parental consent where required. Onlyform does not impose a blanket 18+ restriction on form respondents.
5. Tracking, sharing and automation
Before enabling analytics, pixels, tag managers, embedded content or marketing follow-ups, establish the necessary notice, lawful basis and consent/opt-out controls for the respondent's jurisdiction. Do not activate a tag first and ask permission afterwards where prior consent is required.
Check recipients and content before enabling webhooks, email follow-ups, public reports or integrations. Do not use those mechanisms to disclose information beyond the purpose communicated to respondents. Review AI output and do not submit data to an AI provider without authority and appropriate safeguards.
6. Enforcement and reports
We may limit access, disable a form, preserve evidence or cooperate with competent authorities where proportionate and lawful. Where possible, we explain the action and allow a challenge through the company's contact channel. Urgent security or safety action may be taken before notice.
To report abuse, provide the form URL, a brief description and relevant non-sensitive evidence through Company and contact. Do not submit unlawful material or another person's sensitive information to prove a report. Responsible security research should minimise access to data, avoid disruption and be reported privately; this policy is not permission to test third-party systems.