Skip to main content

Acceptable Use Policy

What the service may not be used for, and when we may suspend an account.

Version 1.0 · In effect since


This policy forms part of the Terms of Service. It is short because the rules are few, and each one is here because breaking it would put another customer’s payroll data at risk.

Do not

  • Upload information you have no authority to upload. Every person whose Social Insurance Number, banking details or home address you enter must be someone your firm or your client is entitled to hold that information about.
  • Use the service unlawfully, including to process payroll you know to be fraudulent or to produce records intended to mislead a tax authority.
  • Probe, scan or test the security of the service, attempt to reach another organisation’s data, or work around the access controls. Responsible disclosure is welcome — write to us first.
  • Share credentials. Each person who needs access gets their own account. Shared logins make the audit trail meaningless, which is the one thing that protects your firm when a client asks who looked at a record.
  • Resell or white-label the service as your own product without a written agreement with us. Using it to serve your own clients is exactly what it is for; passing it off as software you built is not.
  • Send messages through the service to people who have not consented to receive them, or use it to send anything unrelated to the engagement.
  • Overload it — automated bulk requests, scraping, or anything that degrades the service for others.

If this is breached

We will normally tell you and give you a chance to put it right. Where the breach is causing active harm — another customer’s data is exposed, or the service is being degraded — we may suspend access first and explain afterwards. Repeated or deliberate breaches are grounds for terminating the agreement.

Reporting a problem

If you find a security vulnerability, or believe someone is misusing the service, tell us through the contact page. We will not pursue a researcher who reports a genuine vulnerability to us in good faith and gives us a reasonable chance to fix it before disclosing it.