Acceptable Use Policy
Last updated: [TBD] · This is a working draft pending legal review.
1. Introduction and scope
This Acceptable Use Policy (the "Policy") sets out the rules for using the commerce platform and related services (together, the "Platform") operated by Coded B.V., a private limited company (besloten vennootschap) incorporated in the Netherlands and a subsidiary of Coded Holding B.V. ("Coded", "we", "us", "our"). Coded is an international company; the Platform is offered to merchants and their customers worldwide, with the Netherlands as our jurisdiction of registration and initial launch market.
The Platform lets a merchant operate one or more branded online projects through an Organization, using a curated product catalog, built-in payments, and built-in fulfilment. Payment transactions are processed by our payment partners, Stripe and Mollie.
This Policy applies to everyone who uses the Platform, including:
- Merchants — the businesses and individuals who operate Organizations and run projects on the Platform.
- Authorized users — anyone a merchant invites into an Organization (staff, collaborators, agents).
- End customers and visitors — people who browse, buy from, or otherwise interact with a project hosted on the Platform.
This Policy is part of, and incorporated by reference into, our Terms of Service. Where this Policy and the Terms of Service conflict on a question of acceptable use, this Policy controls. Capitalized terms not defined here have the meaning given in the Terms of Service.
A breach of this Policy is a material breach of the Terms of Service and may lead to the enforcement actions described in Section 9.
1.1 Relationship to the Prohibited & Restricted Businesses list
This Policy works alongside our Prohibited & Restricted Businesses list, which sets out the categories of business, goods, and services that may not be offered through the Platform at all, or that may be offered only under conditions. This Policy governs conduct and content; the Prohibited & Restricted Businesses list governs what you sell. You must comply with both. Nothing in this Policy narrows the Prohibited & Restricted Businesses list, and nothing in that list narrows this Policy.
Because payments run through Stripe and Mollie, you must also comply with the applicable acceptable-use and restricted-business rules of those payment partners. A use that is permitted under this Policy may still be prohibited by a payment partner, and we may act to keep our payment partner relationships in good standing.
2. General responsibilities
When you use the Platform, you must:
- Use it only for lawful purposes and in compliance with all laws that apply to you, your Organization, your projects, and your end customers — including in every jurisdiction where you sell or where your customers are located.
- Comply with the Terms of Service, this Policy, the Prohibited & Restricted Businesses list, our Privacy Policy, and any product-specific terms.
- Keep your account credentials confidential, use reasonable security measures, and remain responsible for all activity that occurs under your Organization and your authorized users.
- Provide accurate information about your business, your products, your prices, your shipping and return terms, and your identity, and keep that information current.
- Honour the commitments you make to your end customers, including order fulfilment, refunds, and the handling of their personal data.
You are responsible for the content you publish and the conduct of everyone you authorize. We do not pre-screen content, and we are not the seller of record for goods sold by merchants.
3. Prohibited content
You may not upload, publish, sell, link to, or otherwise make available through the Platform any content that:
- Is unlawful, or that promotes, facilitates, or provides instructions for unlawful activity.
- Depicts, promotes, or facilitates the sexual exploitation or abuse of minors. We have zero tolerance for child sexual abuse material (CSAM). Suspected CSAM is removed and reported to the appropriate authorities and hotlines, and the account is terminated.
- Is sexually explicit or pornographic where prohibited by law, by this Policy, or by our payment partners, or that is made available to minors.
- Is hateful, or that incites, promotes, or glorifies violence, terrorism, self-harm, or discrimination against a person or group on the basis of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability, age, or any other protected characteristic.
- Harasses, bullies, threatens, defames, or invades the privacy of any person, or discloses another person's private information without a lawful basis.
- Is deceptive, fraudulent, or misleading, including deceptive pricing, fake reviews or testimonials, counterfeit goods, impersonation, false claims of affiliation or endorsement, or misrepresentation of a product's origin, nature, or compliance.
- Infringes the intellectual property, publicity, or privacy rights of others (see Section 6).
- Constitutes, promotes, or facilitates the sale of goods or services prohibited or restricted by the Prohibited & Restricted Businesses list (for example, illegal drugs and controlled substances, regulated weapons and ammunition, stolen goods, endangered species, and other restricted categories set out in that list).
- Contains malware, or is designed to interfere with, disable, or compromise any system, device, or data (see Section 5).
Some categories above are restricted rather than absolutely prohibited (for example, age-restricted goods that are lawful where sold and offered with the required controls). Where a category is restricted, the conditions in the Prohibited & Restricted Businesses list and applicable law apply.
4. Prohibited conduct
You may not use the Platform to:
- Violate any law, regulation, court order, sanctions program, or third-party right, or to facilitate any of these by others.
- Engage in fraud or deception of any kind, including payment fraud, chargeback fraud, transaction laundering (processing payments that do not match the disclosed business), money laundering, terrorist financing, or sanctions evasion.
- Sell or offer goods or services that you are not legally able to provide, or that you do not intend to deliver.
- Misuse the built-in payments or fulfilment features — for example, by routing transactions for an undisclosed business, processing transactions on behalf of an unrelated third party, or using fulfilment to ship prohibited items.
- Deceive, defraud, or harm your end customers, including by failing to fulfil orders, refusing lawful refunds, or hiding material terms of sale.
- Impersonate any person or entity, or misrepresent your affiliation with any person or entity.
- Interfere with another user's use of the Platform, or with the operation, integrity, or security of the Platform (see Section 5).
- Reverse engineer, decompile, or disassemble any part of the Platform, or attempt to derive source code, except to the extent this restriction is prohibited by applicable mandatory law.
- Resell, sublicense, or commercially exploit the Platform itself in a way not permitted by the Terms of Service.
- Circumvent, attempt to circumvent, or assist others in circumventing any usage limit, access control, geographic restriction, suspension, or termination.
4.1 No platform transaction fee — fee integrity
Coded charges a 0% platform fee on a merchant's payment transactions: merchants pay only the pass-through processing cost charged by Stripe or Mollie. (Subscription fees for publishing a project are separate and are described in our Terms of Service and pricing.) You may not represent to your customers that Coded imposes a transaction or platform fee, and you may not structure transactions to misstate amounts, taxes, or who is being charged.
5. Security and integrity
The Platform's security depends on every user behaving responsibly. You may not:
- Probe, scan, or test the vulnerability of the Platform or any related system or network, or breach or circumvent any security or authentication measure, without our prior written authorization.
- Access, or attempt to access, any account, Organization, data, system, or network that you are not authorized to access, including other merchants' data or end-customer data.
- Introduce, transmit, or host malware, ransomware, spyware, or any other malicious or harmful code.
- Interfere with or disrupt the Platform, including through denial-of-service or distributed denial-of-service attacks, flooding, or any activity that imposes an unreasonable or disproportionate load on our infrastructure.
- Use automated means (bots, scrapers, crawlers) to access, scrape, or harvest data from the Platform except as expressly permitted by us in writing or by a published, machine-readable access mechanism we provide.
- Use the API in a way that exceeds documented rate limits or is designed to evade them.
- Falsify, forge, or manipulate identifiers, headers, or any part of a transmission to disguise the origin of content or traffic.
5.1 Responsible disclosure
If you discover a security vulnerability, report it to security@coded.co and give us a reasonable opportunity to investigate and remediate before any public disclosure. Good-faith security research that follows our responsible-disclosure process and does not access, modify, or exfiltrate other users' data will not be treated as a violation of this Policy. Do not access more data than is strictly necessary to demonstrate a vulnerability, and do not degrade the experience of other users.
5.2 Our security posture
We design the Platform with privacy and security by default. Customer and merchant data is hosted in the European Union (Frankfurt, Germany). We do not currently claim any specific third-party security certification, and you should not rely on the existence of one; we describe our actual practices in our security documentation and update them over time.
6. Intellectual property and content rights
You must respect the intellectual property and other rights of others. You may not upload, publish, or sell content that you do not have the right to use, including content that infringes another party's copyright, trademark, patent, trade secret, design right, database right, or right of publicity.
You are responsible for ensuring that everything in your projects — product images, descriptions, branding, logos, text, and media — either belongs to you or is used with permission and in compliance with applicable law.
6.1 Notice-and-takedown
We operate a notice-and-takedown process. If you believe content on the Platform infringes your rights, send a notice to legal@coded.eu that includes:
- Identification of the protected work or right, and of the allegedly infringing content (with enough detail and a URL or other locator for us to find it).
- Your contact details.
- A statement of your good-faith belief that the use is not authorized by the rights holder, an agent, or the law.
- A statement that the information in your notice is accurate, and that you are the rights holder or authorized to act on the rights holder's behalf.
On receipt of a valid notice we may remove or disable access to the content and notify the merchant. The affected merchant may submit a counter-notice if they believe the content was removed in error. We may reinstate content following a valid counter-notice unless the original notifier pursues the matter through the appropriate legal channel. We maintain a policy of acting against repeat infringers, up to and including termination.
This process is intended to meet applicable intermediary, hosting, and platform-liability obligations across the jurisdictions in which we operate. It does not create rights beyond those provided by applicable law, and it does not waive any defence available to us as a hosting provider.
7. Spam, communications, and marketing
You may not use the Platform, or content or data obtained through it, to:
- Send unsolicited bulk or commercial messages ("spam") by email, SMS, push, or any other channel, in violation of applicable anti-spam and electronic-communications laws.
- Send marketing or transactional messages without a lawful basis or, where required, without valid consent, or without a clear and working way to opt out or unsubscribe.
- Harvest, scrape, or collect contact details or personal data of end customers or other users for purposes those people have not agreed to, or in violation of applicable privacy law.
- Misrepresent the sender, subject, or origin of any message, or disguise the commercial nature of a communication.
You are responsible for the lawful basis and consent records for any communications you send to your end customers, and for honouring their opt-out and data-subject requests. Coded does not sell or share personal data for cross-context behavioural advertising, and you must not use the Platform to do so on our infrastructure in a way that misrepresents our role or our analytics.
8. Privacy and end-customer data
If you collect or process personal data of your end customers through the Platform, you must:
- Comply with all applicable data-protection and privacy laws in every jurisdiction where you operate or where your customers are located — including the EU/EEA and UK GDPR, applicable US state privacy laws (such as the CCPA/CPRA and comparable state statutes), and other applicable international and local regimes.
- Maintain your own accurate, accessible privacy notice and any required cookie or tracking disclosures for your projects.
- Have a lawful basis for your processing, honour data-subject and consumer privacy requests (such as access, deletion, correction, and opt-out of sale/sharing), and only use end-customer data for the purposes disclosed.
- Not use the Platform to sell or share personal data for cross-context behavioural advertising in violation of applicable law, and not misuse the analytics or customer data the Platform makes available to you.
Our own processing of personal data is described in our Privacy Policy, and our respective roles and obligations as controller and processor are set out in our Data Processing Agreement. Hosting of personal data in the EU (Frankfurt) is a feature of the Platform, not a limitation on who may use it.
9. Enforcement, suspension, and termination
We would rather work with you to fix a problem than shut you down. Where it is reasonable and lawful to do so, we will give notice and an opportunity to cure a violation before taking more serious action. The action we take will be proportionate to the seriousness of the violation, taking into account the risk to other users, to end customers, to our payment partners, and to Coded.
9.1 Actions we may take
Depending on the nature and severity of a violation, we may:
- Issue a warning and request that you cure the violation within a stated period.
- Remove, disable, or restrict access to specific content, products, or projects.
- Limit features, throttle usage, or restrict access to payments or fulfilment.
- Suspend an Organization, project, or user account.
- Withhold, hold, or reverse funds where required by law, by our payment partners, or to protect against fraud, chargebacks, or unfunded refunds, as set out in the Terms of Service.
- Terminate an Organization, project, or user account and the related agreements.
- Report conduct to law-enforcement, regulators, payment partners, or other authorities where we are required or permitted to do so.
9.2 Immediate action without prior notice
We may act immediately and without prior notice — including by removing content or suspending or terminating access — where we reasonably believe a violation: involves CSAM or other clearly illegal content; presents a risk to the security, integrity, or availability of the Platform; exposes Coded, our payment partners, other users, or end customers to legal liability, fraud, or significant harm; or is required by law, by court or regulatory order, or by a sanctions program. We will give notice afterwards where it is lawful and appropriate to do so.
9.3 Effect of termination and appeals
The consequences of suspension and termination, including data export, retention, and deletion, and the treatment of outstanding funds and fulfilment obligations, are governed by the Terms of Service. Where required by applicable law, you may contest an enforcement action by contacting us at legal@coded.eu, and we will review the matter and respond within a reasonable time.
10. Reporting violations
If you become aware of content or conduct on the Platform that may violate this Policy, report it to legal@coded.eu. For suspected illegal content, fraud, or harm to end customers, include enough detail (such as a URL or order reference) for us to locate and investigate the issue. For security vulnerabilities, use the responsible-disclosure process in Section 5.1.
11. Changes to this Policy
We may update this Policy from time to time to reflect changes in the Platform, our payment partners' requirements, legal developments, or operational needs. When we make material changes, we will take reasonable steps to notify affected users, for example by posting the updated Policy with a new effective date or by notice through the Platform. Your continued use of the Platform after an update takes effect means you accept the updated Policy. The current version is always available on our website.
12. Governing law and jurisdiction
This Policy is governed by the laws of the Netherlands. The courts of Amsterdam, the Netherlands, have jurisdiction over any dispute arising out of or relating to this Policy, subject to the following: nothing in this Policy deprives a consumer or a data subject of the protection of mandatory laws of their own country or jurisdiction, and the mandatory consumer-protection, data-protection, and other laws of the user's jurisdiction may also apply where applicable law so requires. This reflects that Coded operates internationally and that users and end customers are located around the world.
Contact
Questions about this Policy, reports of violations, and intellectual-property notices:
- General and legal / takedown: legal@coded.eu
- Privacy and data-protection: privacy@coded.eu
- Security and responsible disclosure: security@coded.co
Coded B.V. De Taling 15, 2761 SL Zevenhuizen, The Netherlands KvK (Netherlands Chamber of Commerce) number: 42027097 VAT number: NL869368795B01 Effective date: 11 June 2026
<!-- OPEN ITEMS FOR COUNSEL: 1. Confirm contact domain (coded.eu (legal/privacy) · coded.co (ops)) for legal@ / privacy@ / security@ and whether a dedicated abuse@ / dmca@ alias is required. 2. Confirm the formal notice-and-takedown mechanism per jurisdiction: EU Digital Services Act (DSA) trusted-flagger / illegal-content notice obligations, statement-of-reasons requirements, and internal complaint-handling; US DMCA §512 designated-agent registration (and whether Coded needs a registered DMCA agent given international footprint); UK and other regimes. Verify whether the current process satisfies DSA Art. 16/17 and DMCA safe-harbour conditions. 3. Confirm CSAM reporting obligations and the correct authorities/hotlines per region (e.g. NCMEC for US-linked content, EU CSAM reporting, NL hotlines) and any mandatory-reporting timelines. 4. Confirm repeat-infringer policy specifics and record-keeping needed for safe-harbour eligibility. 5. Align prohibited/restricted categories precisely with Stripe Restricted Businesses and Mollie prohibited/restricted lists, and with the separate Coded Prohibited & Restricted Businesses document, so the three do not diverge. 6. Verify enforcement / fund-holding / reserve language against the Terms of Service and the payment-partner agreements (Stripe Connect platform obligations, Mollie) — ensure consistency on chargebacks, reserves, and clawbacks. 7. Confirm scope of "security research" carve-out and whether a formal bug-bounty / safe-harbour statement should be linked. 8. Validate the international governing-law / mandatory-local-law carve-out with counsel for enforceability vs. EU consumer (Rome I/Brussels I bis) and US state-law contexts; confirm the Amsterdam forum-selection survives consumer-protection mandatory rules. 9. Confirm anti-spam compliance references (GDPR/ePrivacy, CAN-SPAM, CASL, and others) match the markets actually targeted. 10. Decide whether to incorporate this Policy by reference into the Terms of Service or as a standalone binding document, and confirm the conflict-precedence clause (Section 1) is mirrored in the Terms. 11. Confirm "material breach" framing and cure-period language is consistent across Terms, this Policy, and any DPA. 12. Verify the EU-hosting (Frankfurt) statement remains accurate and that no certification claim (SOC 2 / ISO 27001 / PCI-DSS) is implied anywhere. -->