Acceptable Use Policy
IN FORCE. See 00-README. Incorporated into the Terms of Service and Merchant Agreement.
Legal basis. Every provision below rests on one of three things: a measured fact about the platform (cited to file and line), a rule of law (cited to the instrument and article in the Legal Basis Register), or a commercial choice CIQRA has made where the law leaves it open. Prepared and adopted by CIQRA OÜ.
🔴 §4.2 and §4.3 describe DSA mechanisms that do not exist. Both are written in the present tense ("CIQRA maintains…", "CIQRA collects and verifies…") and neither is implemented. See the notes in those sections.
Provider: CIQRA OÜ, Tallinn, Estonia · abuse/report: abuse@ciqra.com · appeals: appeals@ciqra.com · legal@ciqra.com In force from: 2026-08-09 · Version: 1.0 · Adopted by: CIQRA OÜ
This AUP defines what you may and may not do on CIQRA, and which business/product categories are prohibited or restricted. It applies to all Merchants, their users, and to content on Storefronts. Breach may lead to content removal, feature/payment suspension, reserve, account termination, fund holds, and referral to authorities (see ToS §7, Merchant Agreement §10).
1. General conduct rules
You must not:
- Break the law or facilitate others doing so; infringe intellectual-property, privacy, or publicity rights.
- Upload or sell content that is unlawful, fraudulent, deceptive, defamatory, or that misrepresents you, your products, prices, or affiliation.
- Distribute malware, run phishing, or attempt to breach, probe, or overload the Services or other tenants (no unauthorised scanning, scraping beyond permitted APIs, credential stuffing, or denial-of-service).
- Circumvent tenant isolation, security controls, rate limits, or access data of other Merchants/Customers.
- Use the Services to send unlawful spam or to process marketing without a valid lawful basis/consent (see §5).
- Use CIQRA Pay for payment aggregation/factoring, processing payments for third parties, money laundering, terrorist financing, sanctions evasion, or transactions unrelated to your own bona-fide sales.
CIQRA's determination: this prohibition is load-bearing for CIQRA's regulatory characterisation, not merely a conduct rule: a Merchant processing third-party payments through its connected account would undermine the technical-service-provider position in Payment Terms §1 as well as breaching Stripe's terms. No mechanism detects it — enforcement depends on Stripe's monitoring and manual review.
- Misuse AI features: submitting content you have no right to use; attempting to generate illegal, infringing, deceptive, or harmful content; using AI to impersonate or to produce unlabelled synthetic media where labelling is required; or attempting to extract, reverse-engineer, or exfiltrate models or other tenants' data.
CIQRA's determination: AI misuse rules are enforced by content-safety filtering and manual action, not by a verified control. One related mechanism does exist: generated images carry IPTC provenance marking, and §4.2 of the AI Terms records the code's own limitation — provenance is recorded but disclosure cannot be enforced, because surrounding merchant copy is editable. The obligation not to strip that marking therefore rests on this Policy.
- Post reviews/UGC that are fake, incentivised without disclosure, or manipulative (see §4).
2. Prohibited businesses and products
Stripe's Restricted Businesses list applies in full and is incorporated by reference (using CIQRA Pay requires compliance with Stripe's rules). In addition, the following are prohibited on CIQRA (CIQRA-specific bans):
- Adult / sexual content: pornography, adult content, escort or sexual services.
- Weapons & munitions: firearms, ammunition, explosives, certain weapon parts/accessories.
- Tobacco, vape & nicotine: tobacco products, e-cigarettes/vapes, nicotine products.
- CBD, cannabis & unregulated supplements: CBD, cannabis and derivatives, and unregulated dietary supplements / nootropics. (Jurisdiction-variable —; may be permitted later under specific controls and in permitted markets only.)
CIQRA's determination: these categories are jurisdiction-variable and CIQRA has not performed a per-market legality review. The current blanket prohibition is the conservative position and is safe; relaxing it later (as the 00-README §3 contemplates) would require that review first, market by market.
- Crypto & NFTs: cryptocurrency trading/exchange, tokens/ICOs, NFTs.
- Gambling & betting: gambling, betting, lotteries, games of chance.
These bans are in addition to, not instead of, all other legally-restricted or high-risk categories (e.g. drugs and drug paraphernalia, prescription-only items, counterfeit goods, stolen goods, endangered species, human/organ trade, hate/extremist material, CSAM — absolutely prohibited and reported — regulated financial/insurance services, pyramid/MLM schemes, and any product requiring a licence you do not hold).
Restricted (allowed only with conditions/approval): age-restricted goods (must enforce age verification), alcohol (where lawful and licensed), pharmacy/health items, high-chargeback categories, and pre-order/deposit/long-fulfilment models (may trigger a risk-based reserve).
CIQRA's determination: the restricted categories require conditions — notably age verification for age-restricted goods — that CIQRA does not implement or verify. No age-assurance mechanism was found. The condition is therefore imposed on the Merchant without a platform control behind it, and approval is a manual process.
CIQRA may update this list (including tightening or, with added controls, relaxing it) and may refuse or remove any business it considers high-risk or non-compliant, including where required by Stripe, a bank, card scheme, or authority.
3. Consumer protection & product safety
You must sell lawfully: accurate descriptions and pricing, mandatory pre-contract information, honouring the statutory right of withdrawal and legal guarantees, product-safety and labelling compliance, and no dark patterns or unfair commercial practices.
CIQRA's determination: these are Merchant obligations restated from EU consumer law. Note one dated item CIQRA itself must support: the Estonian "withdraw from contract" button required from 01.09.2026 is not implemented — see Refund/Chargeback/Reserve Policy A.2. A Merchant cannot comply with that requirement through a storefront that does not offer the control.
4. User-generated content, reviews & moderation (DSA)
4.1 Merchants are responsible for UGC on their Storefronts (reviews, ratings, Q&A, comments) and must moderate it; reviews must reflect genuine experience and comply with consumer-law rules on fake/incentivised reviews.
CIQRA's determination: allocation to the Merchant is the right starting point, but it does not displace CIQRA's own duties as a hosting service under the DSA — see §4.2, where the mechanism CIQRA needs for those duties is recorded as missing. Note also that the programme has a standing rule against fabricated review data, which this clause supports.
4.2 Notice-and-action (DSA Art. 16–17). As a hosting service / online platform, CIQRA receives reports of allegedly illegal content or policy breaches at abuse@ciqra.com. ⛔ The mechanism DSA Arts. 16–17 require is NOT YET BUILT (PA-0350) — an inbox without a structured record cannot satisfy Art. 17. What follows describes how a notice should be framed and what CIQRA does with it; it is not a claim that the statutory mechanism is in place. A valid notice should identify the content/URL, explain why it is illegal or infringing, and include the notifier's contact details (and, for IP/DMCA-style notices, a good-faith statement and, where required, a signature). We acknowledge receipt, act in a timely, diligent and non-arbitrary way, and provide a clear statement of reasons to the affected Merchant/user for any restriction (removal, disabling, demotion, suspension), together with information about redress — an internal complaint/appeal path (appeals@ciqra.com), out-of-court dispute settlement, and judicial remedies. We maintain a repeat-infringer policy and may suspend or terminate accounts that repeatedly post illegal/infringing content. We act on valid orders from competent authorities and preserve counter-notice rights where applicable.
🔴 CIQRA's determination: no notice-and-action mechanism exists. A repo-wide search for an abuse/illegal-content report endpoint, takedown flow, or statement-of-reasons record (
ReportAbuse,AbuseReport,Takedown,IllegalContentReport,StatementOfReasons,NoticeAndAction) returns zero implementations. The word "maintains" asserts a live facility to anyone reading this Policy — including a regulator — and there is nothing behind it.DSA Arts. 16–17 are not deferrable in the way a market overlay is. They apply to a hosting service / online platform serving EU users, which CIQRA is from day one; Art. 16 requires the notice mechanism to be easy to access and user-friendly, and Art. 17 requires a statement of reasons for each restriction imposed. Neither can be satisfied by a support inbox that keeps no structured record. Either the mechanism is built before launch or this clause is withdrawn — it must not be published as a description of an existing facility. Launch-blocking.
4.3 Trader traceability (DSA Art. 30 / "know your business customer"). Before a Merchant can offer products or services to consumers, CIQRA collects and makes best efforts to verify the Merchant's traceability information — name, address, telephone and email, identification/registration details, and the payment-account identifier — and may suspend a Merchant that fails to provide or correct this information.
🔴 CIQRA's determination: no trader-traceability mechanism exists beyond reliance on Stripe's KYC/KYB at CIQRA Pay onboarding (
Payments/Stripe/StripeConnectService.cs:60-72). DSA Art. 30 places the duty on the online platform, not on its payment provider (Legal Basis Register row 2.1). CIQRA's determination is therefore that Stripe's KYB does not by itself discharge Art. 30, and that CIQRA owes the obligation directly — Art. 30 places the duty on the online platform, specifies the data points, and requires best-efforts assessment of the information's reliability. Two gaps follow: a Merchant using a BYO gateway never passes through Stripe onboarding at all and is therefore subject to no identity verification by CIQRA; and no record exists that CIQRA could produce to evidence best efforts. Same finding: Payment Terms §3.1, Merchant Agreement §2.1.
5. Marketing & communications
Marketing (email/SMS) requires a valid lawful basis and, where consent-based, double opt-in with an easy unsubscribe in every message; you must maintain suppression lists and comply with ePrivacy and, for Türkiye, ETK/İYS (see TR overlay). No unlawful spam.
CIQRA's determination: double opt-in and suppression-list handling are stated as requirements on the Merchant. This reconciliation did not verify that the platform enforces double opt-in or maintains suppression lists, so the clause should be read as an obligation imposed, not a control provided.
6. Enforcement
Depending on severity we may: warn; remove content; disable a feature; suspend or terminate CIQRA Pay or the account; impose or increase a reserve; hold funds to cover exposure; and report to Stripe/banks/authorities. We aim to give notice and a chance to cure where practicable and lawful, but may act immediately for serious risk (fraud, security, illegal content, sanctions). Appeals/complaints: appeals@ciqra.com (illegal-content and account-restriction decisions follow the DSA statement-of-reasons and redress process in §4.2). See ToS §7 and Merchant Agreement §10.
Provision register (this document)
| Provision | Basis | Where |
|---|---|---|
| payment aggregation ban | (B) load-bearing for §1 characterisation; no detection mechanism | §1.6 |
| AI misuse | (B) filtering + manual; provenance recorded but not enforceable | §1.7 |
| CBD / cannabis / supplements | (B) jurisdiction-variable; blanket ban is the safe position | §2 |
| restricted categories / age verification | (B) no age-assurance mechanism; condition imposed without a control | §2 |
| lawful selling | (B) + flags the missing 01.09.2026 withdrawal button | §3 |
| UGC responsibility | (B) allocation does not displace CIQRA's own hosting duties | §4.1 |
| notice-and-action | 🔴 (A) measured ABSENT — "maintains" withdrawn, launch-blocking | §4.2 |
| — | 🔴 (A) measured ABSENT — Stripe KYB relied on; BYO-gateway merchants get no check at all | §4.3 |
| marketing double opt-in | (B) obligation imposed, enforcement unmeasured | §5 |
Composition: 2 measured absences · 7 declared positions. §§4.2–4.3 are the two clauses in the whole set that assert a live facility with nothing behind it.
End of Acceptable Use Policy . See: Terms of Service · Merchant Agreement · Refund/Chargeback/Reserve.