Template pending legal review. This policy is a draft template and has not yet been reviewed by qualified legal counsel or aligned with Stripe’s restricted businesses list. It is not in force. Bracketed text marks details to be confirmed.
1. Scope
This Acceptable Use Policy (“Policy”) applies to every business and user of Tuppence, including checkout and pay pages, payment links, subscriptions, metered billing, the API and SDKs, our MCP server and agent tools, the dashboard, the iPhone app and Tuppence cards. It forms part of our Terms of Service.
Card payments on Tuppence are processed by Stripe, so you must also follow Stripe’s restricted businesses list and the rules in the Stripe Services Agreement. Where Stripe’s rules are stricter than this Policy, Stripe’s rules apply.
2. Prohibited activities
You must not use Tuppence, or allow anyone else (including an agent) to use it, to:
- break any law or regulation, or help anyone else to do so;
- launder money, finance terrorism or evade sanctions, including dealing with persons or territories subject to UK, UN, EU or US sanctions [confirm applicable regimes];
- commit or facilitate fraud, including card testing, taking payments for goods or services you do not intend to provide, or impersonating another business;
- process payments for another business, or let others use your account to take their own payments (sometimes called factoring or aggregation), unless we have agreed in writing;
- provide false, misleading or incomplete information to us or to Stripe, including during verification;
- evade tax, pay or receive bribes, or disguise the true nature or beneficiary of a payment;
- infringe anyone’s intellectual property, privacy or other rights;
- send unlawful, harassing, defamatory or threatening content through payment pages, receipts or emails.
3. Prohibited businesses
We cannot provide services to businesses whose activities include:
- illegal goods or services, including illegal drugs and counterfeit goods;
- weapons, ammunition or explosives, other than [exceptions to be confirmed];
- unlicensed financial services, including unregulated investment schemes, pyramid or Ponzi schemes;
- businesses that cannot demonstrate a genuine trading purpose;
- adult content involving any non-consensual or illegal material;
- any business Stripe does not support, as set out in Stripe’s restricted businesses list;
- [other categories as determined by our risk appetite].
4. Restricted businesses
Some businesses carry higher risk. We may support them only with our prior written approval, Stripe’s approval, additional checks and, where relevant, evidence of the appropriate licence or registration. These include:
- gambling and gaming operators;
- cryptoasset businesses;
- money service businesses and other financial services;
- dealers in high-value goods, precious metals or stones;
- [further categories to be confirmed].
If your business changes in a way that could bring it within these categories, you must tell us before the change takes effect.
5. Treating payers fairly
- Describe what payers are buying clearly and accurately, including the price, and for subscriptions and metered billing, how and when they will be charged.
- Only save a payer’s card or charge it later (off-session) where they have agreed to it, and only within what they agreed to.
- Make it easy to cancel a subscription and honour your own refund policy.
- Use a business name and statement descriptor payers will recognise, so they do not dispute payments by mistake.
- Keep your dispute and refund rates low. Unusually high rates may lead to holds, reserves or suspension.
6. Using AI agents
You are responsible for everything your agents do. You must not:
- let an agent ask for, collect, see or store card numbers, CVCs or PINs. Payers must enter card details only on Stripe or Tuppence hosted pages or fields;
- try to bypass, disable or trick agent mandates, spend limits, approvals or other safeguards, including by splitting payments to avoid thresholds;
- give an agent more access than it needs — use restricted keys scoped to the task;
- let an agent carry out live actions that move money — charges, refunds, payouts or card spend — without a person approving them, unless you have set a mandate with limits appropriate to the risk;
- use agents to send misleading communications, or to impersonate another person or organisation;
- attempt to manipulate our systems or other businesses’ agents with crafted instructions (sometimes called prompt injection).
If an agent behaves unexpectedly, revoke its key or pause its mandate from the dashboard and tell us straight away.
7. API keys and technical use
- Keep secret keys and agent private keys secret, store them securely and rotate them if you suspect exposure. Never put them in client-side code or public repositories.
- Verify webhook signatures and keep your webhook endpoints secure.
- Stay within the rate limits in our documentation, and do not attempt to overload or disrupt the service.
- Do not use test mode to process real payments or to test stolen card details.
- Do not scrape, reverse engineer or decompile the service, except to the extent the law allows despite this restriction.
- Do not probe, scan or test the security of our systems without permission. Please report vulnerabilities responsibly as described on our security page.
8. Tuppence cards and cashback
- Tuppence cards are for business spending only. Do not use them for personal or household spending.
- Do not farm cashback or self-deal — for example, by paying your own Tuppence account with your own Tuppence card, or by spending far beyond your earnings to generate cashback. We may withhold or reclaim cashback earned this way.
- Do not use Tuppence cards for anything this Policy prohibits, or share card details with anyone who is not authorised to use them.
9. Reporting misuse
If you believe someone is misusing Tuppence — including a suspicious payment page or payment link, or a scam — contact us immediately at [fraud reporting email] or through our contact page. If you have paid a scammer by card, also contact your card issuer as soon as possible.
10. Enforcement
If we or Stripe reasonably believe this Policy has been breached, we may, without prior notice where the law or risk requires:
- ask you for information or evidence;
- block or refund payments, hold payouts or keep a reserve;
- revoke API keys, pause agents, freeze cards or restrict features;
- withhold cashback;
- suspend or close your account, as set out in our Terms of Service;
- report the matter to Stripe, card networks, law enforcement, regulators or other authorities.
We may be prevented by law from telling you why we have taken action.
11. Changes to this policy
We may update this Policy to reflect changes in law, risk, Stripe’s requirements or our services. We will give notice of material changes in line with our Terms of Service, unless an immediate change is needed to meet a legal requirement or prevent harm.