Skip to main content

Zayloft Acceptable Use Policy

This Acceptable Use Policy defines the minimum standards for using Zayloft communications, verification, identity, developer, email, voice, AI/NLP and related services.

The Services may be used only for lawful, authorized and responsible business activity. Customers remain responsible for their recipients, content, consent records, sender identities, applications, users and compliance with channel and destination requirements.

Translations are provided for convenience. If a translated version conflicts with the English version, the English version controls to the extent permitted by applicable law.

Core obligations.

1. Scope and responsibility

This Acceptable Use Policy applies to every Customer, account owner, administrator, user, contractor, application, integration, reseller where authorized, and End User that accesses or uses Zayloft Services.

Customer is responsible for activity performed through its accounts, credentials, applications, sender identities, numbers, domains and integrations, including activity performed by people or systems Customer authorizes.

Customer must use the Services only for lawful purposes and in a manner consistent with the Terms of Service, applicable service terms, channel rules, destination requirements and this Policy.

2. Consent, authorization and recipient rights

Customer must obtain and maintain every consent, permission or other legal basis required before sending communications or initiating automated, prerecorded, synthetic-voice or similar outreach.

Where prior express written consent, opt-in, disclosure, signature, specific wording or another form of authorization is required, Customer must satisfy that requirement before traffic is sent.

Customer must honor legally effective opt-outs, revocations, do-not-contact requests and communication preferences promptly and must maintain suppression controls that prevent prohibited re-contact.

Customer should retain evidence appropriate to the use case, such as the recipient, source, timestamp, method, disclosure presented, scope of consent and subsequent opt-out history.

3. Accurate identity and transparent communications

Customer may not falsify, obscure or materially misrepresent the identity of the sender, caller, organization, domain, return path, traffic origin, purpose of a communication or commercial relationship.

Sender IDs, caller ID information, domains, email headers, display names, links and message content must not be used to impersonate another person or organization without authorization.

Marketing and promotional communications must contain disclosures and sender information required by applicable law and channel rules.

4. Opt-out, suppression and do-not-contact controls

Customer must provide and honor required opt-out methods for each channel. Where a law, carrier or channel recognizes common opt-out words or other reasonable revocation methods, Customer must process those requests as required.

Suppression lists may not be used as prospecting lists. Information retained solely to prevent future contact must be used only for that suppression purpose unless another lawful basis applies.

Customer must not intentionally route around a recipient block, unsubscribe, revocation, complaint, do-not-call status or other legally effective communication restriction.

Prohibited conduct and content.

5. Spam and unsolicited bulk communications

Customer may not use Zayloft to send spam, indiscriminate bulk outreach or promotional communications to recipients for whom Customer cannot demonstrate an appropriate legal basis or authorization when required.

Purchased, rented, scraped, harvested, appended or brokered contact lists may not be used for promotional traffic where the Customer cannot establish that the recipients lawfully agreed to the relevant sender, channel and purpose.

Customer may not engage in consent laundering, misleading lead generation, list washing or other practices designed to create the appearance of permission where meaningful authorization was not actually obtained.

6. Fraud, phishing and deceptive activity

The Services may not be used for phishing, credential theft, advance-fee fraud, impersonation scams, investment scams, romance scams, fake support, fake invoices, deceptive prize or lottery schemes, fraudulent debt collection, fraudulent fundraising or other deceptive schemes.

Customer may not misrepresent price, identity, affiliation, sponsorship, urgency, risk, eligibility, product availability, refund rights or another material fact in order to obtain money, credentials, personal data or action from a recipient.

Links, attachments, QR codes and callback numbers must not knowingly direct recipients to malicious, deceptive or unauthorized destinations.

7. Malware, credential theft and security abuse

Customer may not distribute malware, ransomware, spyware, malicious code, exploit kits or payloads designed to compromise a device, account, application or network.

Customer may not use the Services to obtain passwords, one-time codes, access tokens, financial credentials or other secrets through deception or unauthorized collection.

Credential-stuffing, account takeover, denial-of-service activity, scanning for unauthorized access, exploitation of vulnerabilities and attempts to bypass security controls are prohibited.

8. Harassment, threats and abusive communications

Customer may not use the Services to threaten violence, extort, stalk, repeatedly harass, intimidate or deliberately target a person with abusive communications.

The Services may not be used to coordinate unlawful violence, human trafficking, terrorist activity, or exploitation or abuse of children.

Communications that unlawfully discriminate, incite unlawful violence or constitute illegal hate-based harassment are prohibited.

9. Illegal goods, services and transactions

Customer may not use the Services to facilitate a transaction, product, service or activity that is unlawful in the relevant jurisdiction.

Marketing or communications involving age-restricted, licensed, financial, health-related, gambling, controlled, regulated or similarly high-risk products or services may require additional review, approval, age controls, disclosures, licensing or destination restrictions before use.

Zayloft may refuse or restrict a high-risk use case where the Customer cannot demonstrate appropriate authorization, licensing, disclosures, safeguards or legal basis.

10. Intellectual property, privacy and unlawful data use

Customer may not use the Services to infringe intellectual-property, publicity, privacy, confidentiality or other legal rights of another person or organization.

Customer may not unlawfully scrape, buy, sell, disclose, enrich or combine personal data for communications or targeting in violation of applicable law.

Customer must not submit data obtained through hacking, credential theft, data breaches, unlawful surveillance or other unauthorized means.

Channel-specific requirements.

11. SMS, MMS and rich messaging

Customer must comply with applicable sender-registration, consent, opt-out, message-content, number, short-code, toll-free, template, throughput and destination requirements.

Customer may not use grey routes, SIM boxes, unauthorized traffic pumping, artificial traffic generation, identity spoofing, prohibited sender substitution or other methods intended to evade legitimate network controls or charges.

Delivery receipts and accepted API responses must not be represented as proof that a recipient read, accepted or legally consented to a communication.

12. WhatsApp, RCS and third-party messaging channels

Use of third-party messaging channels is subject to the rules, business policies, template requirements, account eligibility and technical restrictions of the relevant channel in addition to this Policy.

Customer must not attempt to evade template approval, business verification, quality controls, recipient blocks, messaging limits or enforcement actions imposed by a channel provider.

Customer is responsible for maintaining the rights and permissions necessary to use customer-owned business accounts, numbers and messaging assets connected to Zayloft.

13. Email

Commercial email must use accurate header and routing information, non-deceptive subject lines, required sender identification and a functional opt-out mechanism where required by law.

Customer must honor unsubscribe requests and must not use misleading From names, forged domains, hidden redirects or deceptive infrastructure to disguise the source of email traffic.

Customer is responsible for appropriate domain authentication, list hygiene, complaint handling and mailbox-provider requirements applicable to its traffic.

14. Voice and calling

Customer must comply with applicable calling-hour, do-not-call, consent, disclosure, recording, caller-ID, automated-dialing, prerecorded-voice and synthetic-voice requirements.

Caller ID may not be spoofed with intent to defraud, cause harm or wrongfully obtain value, and Customer may not impersonate another party without authorization.

Automated or prerecorded telemarketing and similar high-risk calling use cases may be restricted or require prior account approval and evidence of legally sufficient consent.

15. Verification and one-time codes

Verification services may be used only to authenticate or verify interactions that Customer is authorized to conduct. Customer may not use OTP or verification flows to facilitate credential theft, account takeover, fake-account farms or bypass another service’s security controls.

Customer must implement reasonable abuse controls for repeated verification attempts, suspicious destination patterns, automated sign-up abuse and traffic inflation.

Verification messages should identify the relevant service or context clearly enough to reduce recipient confusion where the channel and use case support that identification.

Platform, developer and AI safeguards.

16. API, SMPP and account abuse

Customer may not probe, overload, disrupt, reverse engineer, bypass or interfere with Zayloft infrastructure, security restrictions, rate controls, authentication, billing controls or access boundaries except to the extent a restriction is prohibited by applicable law.

Customer must not share credentials across unrelated organizations, publish credentials, intentionally evade throughput controls, create accounts to bypass enforcement or rotate identities to continue prohibited traffic.

Automated use must respect documented request, session, connection and payload limits and must implement retries in a manner that does not create duplicate or abusive traffic.

17. Artificial traffic and revenue manipulation

Customer may not generate, induce, buy or route traffic primarily to create artificial message, call, verification, click, conversion, referral, advertising, affiliate or revenue events.

Traffic pumping, OTP pumping, fraudulent sign-ups, manufactured engagement, self-generated premium traffic and arrangements intended to exploit network or platform compensation are prohibited.

Zayloft may apply destination, rate, verification or routing controls when traffic patterns indicate a material risk of artificial or abusive activity.

18. AI, automation and synthetic content

Customer may not use Zayloft AI or automation to facilitate fraud, phishing, deceptive impersonation, credential theft, unlawful surveillance, targeted harassment or other activity prohibited by this Policy.

Synthetic voice, generated text or other automated content must not be presented deceptively as a real person where that representation is unlawful or materially misleading.

High-impact actions should use appropriate authorization, validation, action limits and human review where errors could materially affect rights, finances, safety, access or legal obligations.

19. Security testing and vulnerability research

Security testing of Zayloft systems is not authorized merely because a Customer has an account. Testing must remain within any published vulnerability-disclosure or written authorization terms.

Customer must not access data belonging to another account, degrade service, perform destructive tests, exfiltrate secrets or exploit a vulnerability beyond what is reasonably necessary to demonstrate a concern.

Security concerns should be reported to support@zayloft.com with “Security report” in the subject line.

Compliance, enforcement and cooperation.

20. Monitoring, investigation and evidence

Zayloft is not required to pre-screen every communication, but may review relevant account information, traffic patterns, complaints, delivery signals, content or metadata where reasonably necessary and legally permitted to operate the Services, investigate abuse, protect users, enforce the Agreement or comply with law.

Zayloft may request evidence of identity, business purpose, consent, opt-in source, sender ownership, recipient relationship, licensing, campaign content, domain ownership or other information reasonably necessary to evaluate compliance.

Customer must provide accurate information and must not falsify, alter or fabricate compliance evidence.

21. Enforcement actions

Where Zayloft reasonably believes activity violates this Policy, creates material risk or must be restricted by law or a downstream provider, Zayloft may block or quarantine traffic, disable a sender or credential, rate-limit activity, require remediation, restrict destinations or products, suspend an account or terminate Services as permitted by the Agreement.

Immediate action may be taken where delay could increase fraud, abuse, security risk, recipient harm, legal exposure, network disruption or downstream enforcement.

Amounts already incurred for valid traffic, network usage or third-party charges remain payable unless the applicable agreement, billing correction or mandatory law provides otherwise.

22. Complaints, law enforcement and downstream providers

Zayloft may cooperate with carriers, channel providers, mailbox providers, regulators, courts and law-enforcement authorities where required by law, contract or legitimate platform-protection needs.

Zayloft may preserve records reasonably necessary to investigate abuse, respond to lawful process, resolve disputes, prevent repeat violations or satisfy legal and contractual requirements.

Nothing in this Policy requires Zayloft to disclose Customer data except as permitted or required by applicable law and the applicable privacy and contractual terms.

23. Customer remediation and repeat violations

Customer must promptly investigate complaints and suspected violations, stop affected traffic where appropriate, correct consent or suppression failures, secure compromised credentials and implement reasonable measures to prevent recurrence.

Repeated violations, deliberate evasion of enforcement, fabricated consent, persistent high complaint rates, continuing prohibited traffic after notice or material failure to cooperate may result in stronger restrictions or termination.

24. Changes, questions and relationship to other terms

Zayloft may update this Policy to reflect changes in Services, law, carrier or channel requirements, abuse patterns, security risks or platform operations. Where required by applicable law or contract, additional notice of material changes will be provided.

This Policy supplements the Terms of Service and service-specific terms. If a signed agreement contains stricter requirements for a Customer or use case, those stricter requirements also apply.

Questions about acceptable use or a proposed high-risk use case may be sent to support@zayloft.com before traffic is launched.

Contact compliance support

support@zayloft.com