Acceptable use policy Version 0.2 — effective 2026-09-02, last updated 2026-09-02 Draft — pending legal review What Popfinch may not be used for, how a report is made, and what happens after one — including how to challenge a decision. Why this exists Popfinch puts content you write onto other people's screens, and lets that content carry your own JavaScript. That is useful and it is also the shape of a phishing kit, so the line has to be written down rather than assumed. This policy is part of the terms of service. The rules - Install the script only on websites you own or are authorised to change. - Ask only for personal data you have a lawful basis to collect, and be plain about what a form is for. A form that pretends to be something else is not permitted however it is worded. - Do not imitate another company, product or person — in a widget's design, its wording, or a domain it links to. - Do not collect passwords, card numbers or other payment credentials through a widget. Popfinch is not built to hold them and must not be used to. - Do not serve malware, run cryptocurrency miners, or use custom JavaScript to take over, redirect or deface the page a widget sits on. - Do not publish content that is illegal where the visitor is, or that sexualises children, incites violence, or harasses a specific person. - Do not deliberately overload the ingest endpoints, evade the rate limits, or use somebody else's site key. - Do not resell access to Popfinch as though it were your own product. Running widgets for your clients under your own account is fine and expected. Reporting something Anyone can report a widget served by Popfinch, whether or not they are a customer: the person whose website it appeared on, a visitor who saw it, or a company being imitated. The form at /report takes no account and asks for the page, what was shown and when. Writing to abuse@popfinch.com works too. A weakness in Popfinch itself is a different report: the security page at /security says what is in scope and what to send. Test against your own account, never against another customer's, and do not run denial-of-service tests against the live service. Reports about content go to abuse@popfinch.com and reports about a weakness in Popfinch itself to security@popfinch.com. No response time is promised anywhere in these documents, because none has been measured over a period long enough to keep — what is promised is that a person reads it. What happens after a report A report is looked at by a person. Popfinch does not monitor customer content in advance, and does not claim to. Where something breaks this policy, the narrowest thing that fixes it is done first: a single widget is taken off-line rather than an account suspended, unless the account itself is the problem. The customer is told what was removed, which rule it broke, and who decided. Where the law requires immediate removal without prior notice, the notice follows as soon as it is permitted. You can reply to that notice and ask for the decision to be reviewed. A review is done by a person, not by re-running whatever flagged it, and content restored after a review is restored with an explanation of what was got wrong. Suspension and termination Repeated or serious breaches end the account. Your data remains exportable during any suspension: losing access to the dashboard must not mean losing the leads you already collected. --- Operator: Vielendark s. r. o., Cyprichova 2477/24, 831 53 Bratislava - mestská časť Rača, Slovakia. Registration number 55121250, tax number 2121872962, VAT number SK2121872962, registered in the Commercial Register of the Municipal Court Bratislava III, Section Sro, Insert No. 167007/B. Contact: hello@popfinch.com. Privacy: privacy@popfinch.com. Security: security@popfinch.com. Abuse: abuse@popfinch.com. Owner verification outstanding: these register details have not yet been checked against a current extract from the Commercial Register.