Acceptable Use Policy
Draft v1 — Last updated 2026-05-28. Pending counsel review.
StoreWiz is operated by its parent company, currently in formation. The operating entity, jurisdiction of incorporation, and governing-law clauses will be finalized prior to general availability. For current corporate status, contact
legal@storewiz.ai.
This Acceptable Use Policy ("AUP") governs your use of the StoreWiz Services. It is incorporated into and made part of the Terms of Service. Capitalized terms not defined here have the meaning given in the Terms or the Privacy Policy.
We keep the AUP intentionally short and concrete. Violation of any provision below is grounds for suspension or termination of your account (see Terms §16).
If you become aware of a violation, please report it to abuse@storewiz.ai with as much detail as you can share.
1. Who this applies to
This AUP applies to:
- You, the tenant business that subscribes to StoreWiz;
- Every User you authorize to access the Services on your behalf;
- Any third party acting on your instructions or with your credentials;
- Your end-customers when they interact with content generated, sent, or published by the Services (e.g., agent-drafted email replies, agent-published social posts).
You are responsible for the actions of every party in this list.
2. Prohibited use cases
You may not use the Services:
2.1 For illegal activity
- To violate any applicable law or regulation, including (without limitation) consumer-protection law, advertising law, data-protection law, tax law, sanctions, anti-corruption law, or intellectual-property law;
- To engage in or promote fraud, money laundering, terrorism financing, human trafficking, or other criminal activity;
- To process or transact in goods or services that are illegal to sell in the jurisdiction of the buyer or seller.
2.2 To harm people
- To send harassing, threatening, defamatory, libelous, or abusive content;
- To facilitate stalking, doxxing, swatting, or invasion of privacy;
- To send sexually explicit content (including in customer email replies generated by the support agent) without verified consent of the recipient and in jurisdictions where it is lawful;
- To target or exploit minors;
- To incite or promote violence against any individual or group.
2.3 To send spam or unwanted communications
- To send any commercial email, SMS, push notification, or social DM that does not comply with applicable anti-spam law (including CAN-SPAM in the US, CASL in Canada, ePrivacy Directive in the EU, PECR in the UK);
- To send communications to recipients who have not opted in where consent is required, or who have opted out;
- To use deceptive subject lines, sender addresses, or DKIM/SPF practices;
- To purchase or use scraped recipient lists;
- To bypass platform-level deliverability protections imposed by Klaviyo, Meta, Google, or other connected services.
2.4 To deceive
- To impersonate any person or entity (including StoreWiz, our employees, or your own customer service);
- To generate content falsely attributed to a real person without consent;
- To create deepfake imagery, video, or audio of real people;
- To manufacture fake reviews, ratings, testimonials, or social-proof signals;
- To engage in undisclosed astroturfing or covert influencer marketing in violation of FTC Endorsement Guides or local equivalents.
2.5 To attack the platform or third parties
- To probe, scan, or test the vulnerability of the Services without our written permission (this does not prohibit good-faith security research conducted under §7);
- To breach security or authentication measures (yours or other tenants');
- To attempt to access another tenant's data, account, or AI Output;
- To circumvent rate limits, autonomy-tier caps, spend caps, or other platform controls;
- To use the Services to launch denial-of-service attacks, distribute malware, host phishing pages, or serve botnet command-and-control infrastructure;
- To scrape, crawl, or otherwise extract data from third-party platforms in violation of those platforms' terms (you must comply with Shopify, Meta, Google, Klaviyo, and other third-party terms when using the Services).
2.6 To misuse AI
- To attempt prompt injection against StoreWiz agents (i.e., embedding instructions in content meant to override agent behavior);
- To attempt to extract our system prompts, model weights, training data, or internal reasoning beyond what is presented in your reasoning traces;
- To use the Services to develop, train, fine-tune, or evaluate a competing AI model;
- To use AI Output in ways that violate this AUP (e.g., to generate spam, deceptive content, or content harmful to others);
- To attempt to elicit content from agents outside their declared scope (e.g., medical, legal, political, or personal advice — agents are scope-limited by design; do not attempt to bypass).
2.7 To build competing products
- To benchmark the Services for competitive purposes without our prior written consent;
- To use the Services to create a substantially similar or competing AI ecommerce platform;
- To resell, sublicense, or repackage the Services without an explicit reseller agreement with us.
2.8 To exfiltrate IP
- To reverse-engineer, decompile, or disassemble any part of the Services, except to the extent applicable law expressly forbids restricting that activity;
- To extract or scrape the Services for use outside the Services;
- To remove proprietary notices.
2.9 To process restricted data
You may not use the Services to process:
- Health data subject to HIPAA (we are not a HIPAA-covered entity or business associate);
- Payment-card data subject to PCI-DSS beyond what flows through Lemon Squeezy as Merchant of Record;
- Government-classified or export-controlled information;
- Biometric identifiers regulated under BIPA / GDPR Article 9 / similar laws;
- Children's data subject to COPPA without your own COPPA compliance program in place.
If your use case requires processing any of the above, contact us at legal@storewiz.ai to discuss whether a custom arrangement is possible.
3. Tenant obligations under connected third-party platforms
The Services connect to platforms operated by third parties (Shopify, Klaviyo, Meta Ads, Google Ads, Plaid, Zendesk/Intercom, others). You must:
- Comply with each platform's own terms (Shopify Partner Program Agreement, Meta Platform Terms, Google Ads API Terms, Klaviyo Terms, etc.);
- Authorize only the OAuth scopes necessary for your intended use;
- Maintain your own accounts in good standing on each platform;
- Take responsibility for any platform-side consequences of your use of the Services (e.g., your Meta Ads account being flagged for policy violation due to ad creatives you approved).
If a third-party platform suspends or removes the StoreWiz app due to your use, we may suspend the affected Services for you and your account may bear the consequences of any contractual breaches.
4. Content you publish
You are responsible for all content you publish, send, or display externally through the Services, whether drafted by you, by Wizzy, by another agent, or by a third party acting on your instructions. This includes (without limitation):
- Email and SMS campaigns sent via Klaviyo;
- Ad creatives published via Meta or Google;
- Social posts published via your social channels;
- Support replies sent via Zendesk/Intercom;
- Public-facing content on your Shopify store (product descriptions, blog posts, etc.).
You must review AI Output before publishing or sending it externally unless you have explicitly configured an Auto-approve Autonomy Tier for the relevant skill, with full awareness of the consequences (see Privacy Policy §5.2). Even with Auto-approve, you remain legally responsible for the published content.
5. Safety guardrails you cannot disable
Certain safety controls always apply (see Terms §9). You may not:
- Exceed per-tenant spend caps, mass-send thresholds, or other safety thresholds we set;
- Configure agents to publish to platforms you have explicitly opted out of for those platforms' end-customers;
- Bypass the confidence-threshold gate on sensitive actions (financial, billing, customer PII, external publishing);
- Modify or remove brand-voice safeguards in ways that would cause agents to produce content harmful to your customers.
We may add or modify safety guardrails over time. We will document material changes in the public changelog.
6. Reporting and enforcement
6.1 Reporting violations
If you believe someone is violating this AUP, email abuse@storewiz.ai. Provide as much detail as possible. We treat reports with discretion; we may share necessary information with law-enforcement or platform partners where required.
6.2 How we investigate
When we receive a credible report, we may:
- Review the affected tenant's activity logs, audit records, and (with appropriate authorization) Customer Content;
- Contact the tenant for an explanation;
- Engage a third-party platform (e.g., Shopify, Meta) to coordinate remediation;
- Engage law-enforcement where the violation involves serious crime.
6.3 Consequences
For violations, we may:
- Issue a warning;
- Restrict specific features (e.g., disable Auto-approve on the affected skill);
- Suspend the account;
- Terminate the account (per Terms §16.3);
- Block IP ranges, devices, or domains associated with the violation;
- Withhold or revoke AI Output, brand assets, or other artifacts created in furtherance of the violation;
- Cooperate with third-party platforms in their own enforcement;
- Pursue legal remedies (including indemnification under Terms §14.2).
We aim to act proportionally. We may act immediately and without prior notice in cases that pose imminent harm to the platform, other tenants, or the public.
6.4 Appeals
You may appeal an enforcement action in writing to appeals@storewiz.ai within 30 days. We will review and respond in good faith. Appeals do not automatically stay enforcement.
7. Good-faith security research (safe harbor)
We welcome good-faith security research. If you discover a vulnerability:
- Report it to
security@storewiz.ai(or our coordinated disclosure address published at GA); - Provide enough detail to reproduce, plus reasonable time for us to fix before public disclosure (typically 90 days);
- Do not access, modify, exfiltrate, or destroy data beyond what is strictly necessary to demonstrate the issue;
- Do not exploit the vulnerability against other tenants;
- Do not extort or threaten public disclosure.
We will not pursue legal action against researchers acting in good faith under these conditions. We do not currently operate a paid bug-bounty program; if we launch one, terms will be published separately.
8. Changes to this AUP
We may update this AUP from time to time. For material changes, we will give at least 30 days' advance notice in the Admin Console and (for paid tenants) by email. Continued use after a material change takes effect constitutes acceptance.
Previous versions are archived at storewiz.ai/legal/archive.
9. Governing law
[TODO[entity-pending]: This AUP is governed by the laws of [JURISDICTION TBD]; disputes resolved in [VENUE TBD], subject to mandatory consumer-protection and data-protection law of your country of residence.]
Contact. Abuse reports: abuse@storewiz.ai. Security: security@storewiz.ai. Appeals: appeals@storewiz.ai. Legal: legal@storewiz.ai. Privacy: privacy@storewiz.ai. DPO: dpo@storewiz.ai. Support: support@storewiz.ai.