Acceptable Use Policy
Version 2.1Last update:
This Acceptable Use Policy ("Policy") governs your use of Zenovay's website analytics platform and related services (collectively, the "Services"). By using our Services, you agree to comply with this Policy and our Terms of Service.
This Policy is designed to ensure that our Services are used responsibly, ethically, and in compliance with applicable laws and regulations.
Appropriate Analytics Practices
Zenovay's Services are designed for legitimate website and application analytics purposes. When using our Services, you must:
- Use the Services only for lawful purposes and in accordance with this Policy
- Obtain proper consent from visitors before collecting their data, as required by applicable privacy laws (including GDPR, ePrivacy Directive, CCPA/CPRA, PIPEDA, and other applicable regulations)
- Provide clear and accessible privacy notices to your website visitors
- Honor user opt-out requests and data deletion requests promptly
- Implement reasonable security measures to protect collected data
- Use collected data only for the purposes disclosed in your privacy policy
- Comply with all applicable data protection regulations in your jurisdiction
- Decide for yourself which optional capabilities are appropriate for your site and your audience before switching them on, including session replay, heatmaps and page screenshots, the identify feature, B2B company identification, visitor value scoring, cross-domain tracking and first-party proxy mode, and hold your own legal basis, notice and consent for each
- Take responsibility for every third party you connect to Zenovay, including webhook and chat destinations, warehouse export targets and import sources, and for the credentials, the access scope and the lawfulness of each transfer you direct us to make
Prohibited Tracking Purposes
You may not use Zenovay's Services to track visitors or collect analytics data from websites or applications that:
- Host or distribute illegal content, including but not limited to child sexual abuse material, content promoting terrorism, or content that violates intellectual property rights
- Facilitate illegal activities such as fraud, money laundering, identity theft, or the sale of illegal goods or services
- Promote violence, hatred, discrimination, or harassment based on race, ethnicity, religion, gender, sexual orientation, disability, or other protected characteristics
- Distribute malware, viruses, or other malicious software
- Engage in phishing, scamming, or other deceptive practices
- Target children under 13 (or the applicable age in your jurisdiction) without proper parental consent and COPPA compliance
- Violate the privacy rights of individuals or collect personal data without legal basis
Data Collection Restrictions
When using our Services, you must not:
- Collect or process sensitive personal data (e.g., health information, financial data, biometric data) without explicit consent and appropriate safeguards
- Use tracking scripts to collect data from password-protected areas, payment pages, or other sensitive sections of your website without proper disclosure
- Combine Zenovay analytics data with personally identifiable information (PII) in ways that violate your privacy policy or applicable law
- Share or sell visitor data to third parties without proper consent
- Use the Services to create detailed user profiles for purposes other than analytics and website optimization
- Bypass or circumvent user consent mechanisms, cookie banners, or privacy controls
- Track users across websites (cross-site tracking) without proper disclosure and consent
- Use the Services to facilitate surveillance, stalking, or harassment of individuals
Sensitive Data Categories
You are strictly prohibited from using Zenovay to track, collect, or process the following categories of sensitive data without prior written authorization from Zenovay and implementation of appropriate safeguards:
- Health Information: Medical records, health conditions, treatment information, prescription data, or any data covered by HIPAA or similar regulations
- Financial Information: Payment card numbers, bank account details, credit scores, or detailed financial transaction data
- Biometric Data: Fingerprints, facial recognition data, voice prints, or other biometric identifiers
- Government Identifiers: Social security numbers, passport numbers, driver's license numbers, or national identification numbers
- Precise Location: GPS coordinates or precise geolocation data that could identify an individual's exact location in real-time
- Protected Class Information: Data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, or sexual orientation
- Authentication Credentials: Passwords, security questions, authentication tokens, or any credentials that could be used to access accounts
By using Zenovay, you acknowledge that you bear full responsibility for ensuring that no sensitive data as described above is transmitted to our Services, and you agree to indemnify Zenovay for any claims arising from your violation of this prohibition.
First-Party Proxy Usage
If you configure Zenovay to operate through your own domain (first-party tracking mode), you accept the following additional responsibilities:
- You must disclose in your privacy policy that analytics data is collected through your domain
- You remain fully responsible for obtaining appropriate consent from your users
- You must not use first-party tracking mode solely to circumvent user privacy preferences or ad-blocking tools without appropriate disclosure
- You accept full liability for any legal claims arising from your use of first-party tracking mode
Platform Abuse and Misuse
You must not, and you must not permit or assist any third party to:
- Send excessive API requests, generate abnormal traffic patterns, or attempt to overwhelm our infrastructure or that of our subprocessors through denial-of-service, distributed-denial-of-service, traffic amplification, slow-read, request smuggling, or any other capacity-exhaustion technique
- Attempt to gain unauthorized access to our systems, servers, networks, accounts, data, configurations, or any non-public resource, whether through credential guessing, credential reuse from public breaches, session hijacking, token theft, social engineering of our personnel, or any other method
- Reverse engineer, decompile, disassemble, decrypt, or otherwise attempt to discover the source code, algorithms, or underlying ideas of our Services, except where mandatory law permits a narrow carve-out per the Intellectual Property section of the Terms of Service
- Circumvent or attempt to circumvent any usage limit, rate limit, plan limit, geographic restriction, content filter, abuse-detection mechanism, suspension or termination decision, or billing or payment system
- Scrape, harvest, mass-download, screen-scrape, or otherwise collect data from Zenovay's platform, dashboards, marketing site, documentation, or any other surface beyond what is provided through official APIs within their documented rate limits
- Resell, redistribute, sublicense, white-label, or otherwise commercially exploit our Services, in whole or in part, without a separate written agreement with Zenovay (per-customer reseller terms or agency program where one exists)
- Create multiple accounts, use disposable email addresses, use subaddress patterns, use shared mailboxes, or use any other technique to evade fees, plan limits, free-tier limits, single-trial limits, single-discount limits, prior suspensions, or prior terminations
- Use the Services in a manner that infringes on the rights of other users, that interferes with their use of the Services, that exposes them to security risk, or that defames, harasses, threatens, intimidates, or discriminates against them
- Impersonate Zenovay, our personnel, any other Zenovay customer, or any other person or entity, or misrepresent your affiliation with any of the foregoing
- Share, sell, transfer, broker, or otherwise make available any Authorized User credential, API key, OAuth token, MCP key, session token, or other authentication artifact to any party other than the Authorized User to whom it was issued
- Use the Services to send unsolicited commercial communications (spam), to harvest email addresses or phone numbers for unsolicited use, to operate a botnet command-and-control channel, to host or distribute malware, ransomware, stalkerware, or spyware, or to operate any phishing infrastructure
- Use the Services to host, transmit, store, link to, or otherwise make available any content that is unlawful in the place of access or origin, including without limitation content that depicts or facilitates child sexual abuse, content that infringes intellectual property, content that constitutes hate speech under applicable mandatory law, content that defames a private person, content that promotes terrorism, or content that violates any applicable consumer-protection or commercial-practices law
- Process or attempt to process special-category personal data (sensitive data within the meaning of Art. 9 GDPR / Art. 5 revFADP, including health, biometric, genetic, sexual-orientation, political-opinion, religious-belief, or trade-union data; or children's data within the meaning of Art. 8 GDPR/COPPA) without an appropriate independent legal basis and without notifying Zenovay in writing before that processing begins
- Use the Services in violation of any sanctions, export-control, or trade law, including the Sanctions, Export Control, and Restricted Parties section of the Terms of Service; or to facilitate any sanctioned party's access to the Services or their outputs
- Submit forged, falsified, or misappropriated documents in any verification flow (identity, business, payment instrument, age, sanctions screening), including but not limited to AI-generated identity documents or deepfake-based liveness bypasses
- Submit false abuse reports against other Zenovay customers, or use Zenovay enforcement processes to harass competitors or other parties
- Use the Services in connection with any deceptive AI-content campaign, including but not limited to operating analytics for any site whose primary purpose is to spread AI-generated misinformation, undisclosed synthetic content, or non-consensual deepfake imagery
Unauthorized Security Testing
Zenovay does not authorize, invite, or consent to any form of unsolicited security testing of any Zenovay-operated surface. The operator is a single-person Swiss undertaking without a dedicated security operations team, and unsolicited testing imposes a direct operational, financial, and legal burden that we do not accept. The prohibitions in this section apply in addition to, and without limitation of, the general abuse provisions above.
Without our prior, express, written authorization referencing a specific scope, time window, and contact person, you may not, and you may not procure, fund, instruct, or assist any third party to:
- Conduct penetration testing, red-team exercises, adversarial simulation, or any equivalent activity against any Zenovay surface, including without limitation our public websites, marketing sites, customer dashboards, account portals, REST or GraphQL APIs, gRPC endpoints, CLI tooling, the Zenovay MCP server, edge workers, serverless functions, databases, object storage, message queues, internal admin interfaces, partner integrations, and any subprocessor interface operated under the Zenovay brand
- Perform vulnerability scanning, port scanning, service enumeration, banner grabbing, version fingerprinting, infrastructure fingerprinting, ASN walking, certificate-transparency mining for non-public hostnames, DNS zone enumeration, subdomain brute-forcing, or network mapping against any Zenovay surface
- Conduct fuzzing, automated parameter probing, input mutation testing, schema-based or grammar-based input generation, malformed-payload injection campaigns, or any equivalent automated input variation against any Zenovay surface
- Conduct load testing, stress testing, capacity testing, denial-of-service or distributed-denial-of-service simulations, traffic amplification tests, slow-loris or slow-read attacks, request smuggling tests, or any equivalent activity intended to evaluate or exhaust the capacity, throughput, latency, or resilience of any Zenovay surface
- Reverse-engineer, probe, characterize, map, model, or attempt to circumvent or evade any of the following, to the extent deployed: our authentication systems, session management, multi-factor enforcement, password-strength policies, rate-limiting layers, anti-abuse heuristics, fraud-prevention systems, bot-detection systems, anomaly-detection systems, or any other access-control mechanism, whether operating at the edge, in the application tier, or at the data tier
- Use offensive security tooling, including without limitation vulnerability scanners, exploit frameworks, web-application security testing suites, credential brute-forcing tools, password-spraying tools, hash-cracking tools, network reconnaissance frameworks, command-and-control frameworks, or post-exploitation toolkits, against any Zenovay surface
- Attempt to extract, infer, enumerate, or correlate any non-public information about our infrastructure topology, internal hostnames, IP ranges, security controls, secret material, configuration values, environment variables, build artifacts, or third-party subprocessor identifiers beyond what we publish on our Subprocessors page
- Attempt to access, even briefly, any account, dataset, project, organization, or workspace that does not belong to you, regardless of whether the access path is intentionally exposed
- Conduct any testing activity from infrastructure that you do not control or are not authorized to use, including from anonymizing networks, hijacked residential proxies, compromised hosts, or shared abuse-prone infrastructure
- Train, fine-tune, or evaluate any machine-learning model, including any large language model, using inputs or outputs obtained from probing, scraping, or testing any Zenovay surface
- Publish, share, sell, transfer, broker, or disclose to any third party any technique, finding, payload, exploit, proof-of-concept, screenshot, log excerpt, or telemetry obtained from activity prohibited by this section, including via blog posts, social media, conference talks, paid newsletters, or commercial threat-intelligence channels
Mandatory Cessation Duty on Accidental Discovery
If, while using our Services in good faith and within the scope of normal product use, you become aware of any suspected vulnerability, misconfiguration, exposed data, or anomalous behavior, you must, without exception:
- Immediately cease all access to the affected resource and stop any activity that could expand, deepen, or persist the discovery
- Not view, read, render, copy, download, screenshot, transcribe, mirror, archive, index, modify, alter, delete, encrypt, or transmit any data that you should not have been able to reach, beyond the minimum unavoidable to recognize that the discovery exists
- Not retain any copy of such data on any device, in any cloud storage, in any chat or email, in any code repository, in any backup, or in any third-party system, after the initial recognition
- Not attempt to determine the scope or impact of the discovery by further probing, by enumerating adjacent resources, or by re-triggering the condition
- Report the discovery to security@zenovay.com within twenty-four (24) hours of becoming aware of it, including a concise factual description, the timestamp, the affected URL or endpoint, and the steps you took to cease and contain
- Treat the existence and details of the discovery as strictly confidential until Zenovay confirms, in writing, that coordinated disclosure may proceed and on what terms
- Cooperate in good faith with any forensic, remediation, or notification process Zenovay reasonably initiates, including by preserving relevant logs you control and answering follow-up questions
Consequences of Violation
Any violation of this section, including violation of the cessation, non-exfiltration, or confidentiality duties above, is a material breach of this Policy and of our Terms of Service. We may, at our sole and reasonable discretion, and without prior notice:
- Immediately suspend access to all your accounts, API keys, tokens, and integrations
- Immediately terminate your account and all associated organizations, with no refund of any prepaid fees, no obligation to provide an export window, and forfeiture of any account credit
- Pursue civil remedies, including damages, restitution of testing-induced operational costs, injunctive relief, and attorneys' fees, to the maximum extent permitted under Swiss law
- Refer the matter to Swiss law-enforcement authorities and to the competent prosecutor for criminal investigation under Swiss Penal Code Articles 143, 143bis, and 144bis, and to the law-enforcement authorities of your country of residence and the country from which the activity originated
- Cooperate with criminal investigations, civil proceedings, and regulatory inquiries by other parties affected by your conduct, including by producing audit logs, forensic artifacts, and identity attribution data that we retain for this purpose
- Publish, where lawful and proportionate, a non-identifying post-incident summary, and where the violation is criminal and adjudicated, a fuller description identifying the actor
Coordinated Disclosure
Researchers acting in good faith are welcome to contact us before any testing at security@zenovay.com. We will respond within a reasonable time and, where appropriate, agree on a scope, a window, and a point of contact. Zenovay does not operate a paid bug-bounty program. Researchers who, under a coordinated disclosure agreed in writing with us, identify a substantive and previously unknown issue, may, at our discretion, be credited by name or pseudonym on our Security page after the issue has been remediated. Unsolicited reports may, at our discretion, be acknowledged in the same way, provided the researcher fully complied with the cessation, non-exfiltration, confidentiality, and twenty-four-hour reporting duties set out above. Submission of a report does not create any contractual relationship, payment obligation, or legal immunity, and does not by itself waive our right to enforce this section.
For the avoidance of doubt, this section is operator-protective and reflects the operator's express non-consent. Activities prohibited above may constitute criminal offenses under, inter alia, Articles 143 (unbefugte Datenbeschaffung), 143bis (unbefugtes Eindringen in ein Datenverarbeitungssystem), and 144bis (Datenbeschaedigung) of the Swiss Penal Code, and may also give rise to liability under analogous statutes in your country of residence or the country from which the activity originated. The operator reserves all rights.
Rate Limits
To ensure fair usage and platform stability, the following rate limits apply to all users:
| Endpoint Type | Rate Limit | Window |
|---|---|---|
| General API endpoints | 100 requests | 60 seconds |
| Authentication endpoints | 30 requests | 60 seconds |
| Tracking (burst) | 60 requests | 10 seconds |
| Tracking (sustained) | 5,000 requests | 1 hour |
| External API (per API key) | Pro 30 / Scale 60 / Enterprise 120 requests | 1 minute |
Exceeding these rate limits will result in temporary throttling (HTTP 429 responses). Persistent or intentional abuse of rate limits may result in account suspension or termination.
Compliance with Privacy Laws
You are responsible for ensuring that your use of our Services complies with all applicable privacy and data protection laws, including but not limited to:
- General Data Protection Regulation (GDPR): If you track visitors from the European Economic Area, you must comply with data protection requirements, including obtaining valid consent, providing data subject rights, and implementing appropriate technical and organizational measures.
- CCPA (California Consumer Privacy Act): If you track California residents, you must comply with CCPA requirements, including providing notice, honoring opt-out requests, and maintaining data security.
- COPPA (Children's Online Privacy Protection Act): If your website targets children under 13, you must obtain verifiable parental consent before collecting any personal information.
- ePrivacy Directive: If you track visitors from EU member states, you must comply with the ePrivacy Directive's requirements for cookie consent.
- Other applicable laws: You must comply with any other data protection, privacy, or consumer protection laws applicable in your jurisdiction or the jurisdictions of your visitors.
Enforcement
Zenovay reserves the right to investigate suspected violations of this Policy. We may use various methods to detect violations, including automated systems, user reports, and manual review.
Retention of Evidence After Termination
Notwithstanding any data-deletion obligation in these Terms, the Privacy Policy, the Data Processing Agreement, or any other document, Zenovay may retain, for as long as reasonably necessary and for up to ten (10) years (consistent with the limitation period under Article 127 of the Swiss Code of Obligations), the following minimum dataset associated with any account that we reasonably believe has violated this Policy or these Terms: account identifiers and registration data; IP addresses, user-agent strings, and device fingerprints associated with the conduct under investigation; payment-instrument metadata; authentication and authorization audit logs; copies of communications between you and Zenovay; and any forensic artifacts (including system logs, request payloads, anomaly-detection scores, and abuse signals) that we reasonably consider relevant to investigating, preventing, prosecuting, or defending against the suspected violation. We may share this retained data with our subprocessors (including Stripe, Cloudflare, and Supabase) where necessary for our common abuse-prevention and fraud-prevention interests, with law-enforcement authorities under valid legal process, and with affected third parties where reasonably necessary to mitigate harm. Our lawful bases for this retention are Article 31(2) lit. c of the revised Swiss Data Protection Act (revFADP/nDSG) (compelling interest of the controller), Article 17(3)(e) GDPR (establishment, exercise, or defense of legal claims), and our legitimate interest in operating a safe and abuse-resistant platform. This retention applies in addition to, and not in derogation of, any general legal or regulatory retention obligation.
If we determine that you have violated this Policy, we may take any or all of the following actions:
- Issue a warning and require you to take corrective action within a specified timeframe
- Temporarily suspend your access to the Services
- Permanently terminate your account and delete your data
- Report illegal activities to appropriate law enforcement authorities
- Cooperate with law enforcement investigations
- Pursue legal action for damages, injunctive relief, or other remedies
- Refuse to provide Services to you in the future
We may take immediate action without prior notice in cases involving:
- Illegal activity or content
- Immediate threats to the security or integrity of our Services
- Violations that risk harm to individuals or other users
- Repeated violations after prior warnings
- Legal requirements or court orders
Reporting Violations
If you become aware of any violation of this Acceptable Use Policy, please report it to us immediately. We take all reports seriously and will investigate promptly.
To report a violation, please provide:
- A detailed description of the violation
- URLs or account identifiers associated with the violation
- Evidence supporting your report (screenshots, links, etc.)
- Your contact information for follow-up questions
- Any other relevant information
Changes to This Policy
We may update this Acceptable Use Policy from time to time to reflect changes in our Services, legal requirements, or industry best practices. When we make material changes, we will:
- Update the "Last update" date at the top of this page
- Notify active users via email or through our Services
- Provide a reasonable notice period before the changes take effect (except where immediate changes are required by law)
Your continued use of our Services after changes to this Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you must stop using our Services.
Contact Us
If you have questions about this Acceptable Use Policy or need clarification about what is permitted, please contact us:
Email: contact@zenovay.com
Support: support@zenovay.com
Address: Zenovay, Wanderstrasse 19, 4054 Basel, Switzerland