Acceptable Use Policy

Effective July 28, 2026 · Last updated July 28, 2026

This Acceptable Use Policy (“AUP”) governs what you may do with Payment Recovery System. It is incorporated by reference into the Terms of Service; breaching it breaches the Terms.
Incorporated into the TermsEnforced on noticeImmediate suspension for §6

1. Scope

This AUP applies to every person who accesses the Service — account owners, invited team members, and anyone using your API credentials, whether or not you authorised them. It also applies to the emails the Service sends on your behalf and to the data you load into it.

Capitalised terms not defined here have the meaning given in the Terms of Service.


2. Prohibited Conduct

You must not, and must not permit anyone else to:

  • Use the Service to violate any law or regulation applicable to you, including consumer-protection, debt-collection, anti-money-laundering, sanctions, export-control, and data-protection law;
  • Process payments or send messages on behalf of a Stripe account you do not own or are not authorised to operate;
  • Upload customer data you did not lawfully collect, or that you are not permitted to disclose to a processor;
  • Misrepresent your identity, your business, or your affiliation with any person or organisation — including in the brand name, logo, or sender identity used in recovery emails;
  • Resell, sublicense, or provide the Service to a third party as a standalone product, except under an agency arrangement expressly permitted by your plan;
  • Reverse engineer, decompile, or attempt to derive the source code of the Service, except to the limited extent that restriction is unenforceable under applicable law;
  • Use the Service to build or train a competing product, or to benchmark it for publication without our prior written consent;
  • Circumvent plan limits, billing, usage metering, or access controls.

3. Prohibited Content

You must not transmit through the Service — including in email templates, brand descriptions, or AI prompts — content that:

  • Is unlawful, defamatory, harassing, threatening, or abusive;
  • Sexually exploits or endangers minors;
  • Infringes another party’s copyright, trademark, or other rights (see our DMCA Policy);
  • Contains malware, ransomware, or hostile code;
  • Is designed to phish, defraud, or deceive a recipient into disclosing credentials or payment details;
  • Impersonates a bank, card network, government body, or any brand you do not own — a category we treat with particular severity, because a dunning email is precisely the message a phisher wants to imitate;
  • Threatens, harasses, or misleads a debtor, or otherwise violates the Fair Debt Collection Practices Act or its state analogues where those laws apply to your collection activity.

4. Restricted Businesses

The Service operates on top of Stripe. Any business Stripe prohibits is prohibited here, and Stripe’s Restricted Businesses list governs in the event of any conflict with this section. In addition, we do not support:

  • Third-party debt collection or debt-buying operations;
  • Payday, title, or other high-cost short-term consumer lending;
  • Multi-level marketing, pyramid, or matrix programmes;
  • Unlicensed gambling, lotteries, or sweepstakes;
  • Sale of controlled substances, weapons, or counterfeit goods;
  • “Get rich quick”, forex, or investment schemes promising guaranteed returns;
  • Any business subject to sanctions administered by OFAC, or located in a comprehensively sanctioned jurisdiction.

If your business model is genuinely unclear against this list, ask at legal@paymentrecoverysystem.com before you onboard rather than after we suspend the account.


5. Email & Messaging

Recovery emails are commercial messages sent under your brand. The full rules are in our Anti-Spam Policy, which is also incorporated into the Terms. In summary, you must:

  • Only email people who have an existing business relationship with you — specifically, a customer with a failed or at-risk charge on your connected Stripe account;
  • Never upload purchased, scraped, rented, or appended lists;
  • Honour unsubscribe requests, which the Service processes automatically;
  • Use accurate sender names, subject lines, and reply-to addresses;
  • Include a valid physical postal address, as CAN-SPAM requires.

Sustained hard-bounce or spam-complaint rates above the thresholds in the Anti-Spam Policy will cause sending to be throttled or suspended, because a poisoned sending reputation harms every other customer on the shared infrastructure.


6. Security & Integrity

You must not:

  • Probe, scan, or test the vulnerability of the Service except under our Vulnerability Disclosure Policy;
  • Breach or circumvent authentication, authorisation, or tenancy boundaries;
  • Access another customer’s data, account, or Stripe connection;
  • Interfere with the Service through denial-of-service, flooding, or resource exhaustion;
  • Use automated means to scrape the Service beyond the documented API;
  • Share account credentials, or use a single account for multiple unrelated businesses to avoid per-seat or per-plan pricing.

Violations of this section may result in immediate suspension without prior notice, because the harm is ongoing while notice is pending.


7. Fair Use & Rate Limits

Plan limits are published on the Pricing page. Beyond those published limits, we apply reasonable technical rate limits to API requests, AI generations, and outbound email to protect availability for all customers.

Where usage materially exceeds normal patterns for your plan, we will contact you to agree an appropriate plan before taking any restrictive action, unless the usage is itself causing degradation.


8. AI-Generated Content

The Service uses a third-party large language model to draft recovery email copy. You are responsible for what you send. Specifically, you must not use the AI features to generate content that:

  • Asserts facts about a customer’s account that are untrue;
  • Threatens legal action, credit reporting, or consequences you do not intend and are not entitled to pursue;
  • Creates false urgency about deadlines that do not exist;
  • Makes claims — about refunds, guarantees, or pricing — that your own terms do not support.

AI output is a draft. Review it before it goes to your customers. We make no warranty that generated copy is accurate or legally compliant in your jurisdiction; see Section 9 of the Terms and our Disclaimer.


9. Your Responsibility

You are responsible for all activity under your account, including actions by team members you invite and by anyone who obtains your credentials. Secure your credentials, remove team members promptly when they leave, and report any suspected compromise to security@paymentrecoverysystem.com immediately.


10. Enforcement

Our response is proportionate to the violation and to the harm it is causing:

ResponseWhenNotice
WarningFirst, non-severe, remediable violationEmail, with a cure period
Feature restrictionDeliverability or volume problemsEmail at the time of restriction
SuspensionUncured violation, or §6 security violationEmail; immediate where harm is ongoing
TerminationSevere, repeated, or illegal conductEmail, with data-export window where lawful

Termination for cause does not entitle you to a refund of prepaid fees — see the Refund Policy. Where we are legally required to preserve or disclose data, or where a data-export window would frustrate a lawful investigation, we may withhold it.


11. Appeals

If you believe an enforcement action was mistaken, email legal@paymentrecoverysystem.com within 30 days with your account email and the facts you want reconsidered. We will review and respond within 10 business days. Access is restored where the action was made in error.


12. Reporting Abuse

If you received an email sent through the Service that you believe violates this policy, or you have evidence of misuse, report it. Include the full message headers where possible — they let us identify the sending account.

Payment Recovery System — Abuse