Acceptable use policy

Last updated

What you may not do with Crypto Gate, and what happens if you do it.

1. Scope

This policy applies to everyone who uses Crypto Gate — through the dashboard, the mobile app, the API, or a hosted payment page — and to anyone you give access to your account or issue an API key to. It forms part of the terms of service, and breaching it breaches those terms.

The service is custodial: we hold funds on your behalf and we broadcast transactions on your instruction. That means what you do with the service is something we are involved in, not something we merely observe. It is why this policy is stricter than it would be for a self-hosted wallet.

The lists below give examples. They are not exhaustive, and something not named here can still breach this policy.

2. Financial crime

You must not use Crypto Gate for, or in connection with:

  • Money laundering — layering, structuring, or moving the proceeds of crime through the service in any form, including breaking a sum into smaller payments to avoid attention.
  • Terrorist financing or the financing of proliferation.
  • Fraud of any kind — including obtaining payment by deception, phishing, business email compromise, romance and investment scams, fake merchant storefronts, and refund or chargeback fraud against another payment provider.
  • Handling stolen funds — knowingly receiving, holding or moving crypto obtained through theft, hacking, ransomware or extortion.
  • Ransomware or extortion payments, whether collecting or forwarding them.
  • Mixing, tumbling, or deliberately obscuring the origin of funds, including using the service as a hop to break a traceable chain.
  • Tax evasion, or helping anyone else evade tax.
  • Bribery or corruption.

3. Sanctions and restricted persons

You must not use the service if you are, or if you are acting for or on behalf of, any person or entity that is:

  • subject to any sanctions regime applicable to you or to us, whether as a designated person, an entity owned or controlled by one, or otherwise;
  • located in, resident in, or organised under the laws of a comprehensively sanctioned territory;
  • otherwise barred by applicable law from receiving financial services.

You must not use the service to evade or circumvent sanctions, and you must not disguise the origin, destination or beneficial ownership of funds in order to do so.

You are responsible for knowing whether sanctions apply to you and to the parties you transact with.

[PLACEHOLDER — APPLICABLE SANCTIONS REGIMES AND SCREENING. Counsel to name the specific sanctions lists Crypto Gate is bound by given its jurisdiction and customer base, and to specify what screening is performed on customers, counterparties and on-chain addresses, and at what frequency. The current software does not implement automated sanctions screening; this clause must match what is actually built before the service accepts real funds.]

4. Illegal goods, services and content

You must not use Crypto Gate to take payment for, or fund:

  • controlled drugs, precursors, or drug paraphernalia sold unlawfully;
  • weapons, ammunition, explosives or their components sold unlawfully;
  • child sexual abuse material — this is reported, without exception and without notice to you;
  • human trafficking, forced labour, or any form of sexual exploitation;
  • stolen goods, stolen data, stolen credentials, or hacked accounts;
  • counterfeit goods, or goods infringing someone else's trade marks or copyright;
  • malware, exploit kits, botnets, or services for attacking other systems;
  • trade in endangered species or protected cultural property;
  • anything else illegal where you are, where your customer is, or where we are.

5. Harmful and deceptive business practices

You must not use the service to operate:

  • Ponzi schemes, pyramid schemes, matrix schemes, HYIPs, or any “guaranteed return” programme;
  • fake investment platforms, cloud-mining scams, or fraudulent token sales;
  • unlicensed gambling, lotteries or prize draws where a license is required;
  • unlicensed money transmission, remittance or currency exchange conducted through your account for third parties;
  • a business that takes payment for goods or services you do not intend to deliver;
  • a business that misrepresents who it is, what it sells, or where it is based, to its customers or to us.

You must describe your business to us honestly. Materially misrepresenting what you do in order to obtain or keep an account is itself a breach of this policy.

6. Technical abuse

You must not:

  • attempt to access accounts, data or systems that are not yours;
  • probe, scan or test the security of the service without our prior written permission — report findings to [email protected] instead;
  • attempt to bypass authentication, rate limits, approval steps, spending holds or the second factor on withdrawals;
  • exploit a bug, a race condition, a pricing error or a ledger inconsistency rather than reporting it — funds obtained that way are not yours, and we will reverse the entries and pursue recovery;
  • flood the API with requests, or use it in a way that degrades the service for others;
  • scrape, mirror or resell the service, or use automation to create accounts;
  • introduce malware, or use the service to distribute it;
  • reverse engineer the service except to the extent that right cannot lawfully be excluded.

7. Account and identity abuse

You must not:

  • open an account in a false name, or in someone else's name without authority;
  • open a new account after we have blocked or closed one of yours, unless we have agreed to it in writing;
  • operate an account on behalf of an undisclosed third party — an account is for you or for a business you are authorised to act for, not a front for someone else;
  • sell, rent or transfer your account, or let someone else use your credentials;
  • use the service to process payments belonging to another business as though they were your own.

8. Restricted activities

Some activity is not prohibited outright but requires our written agreement before you start, because it carries regulatory or fraud risk we need to understand:

  • licensed gambling and gaming;
  • adult content and services that are lawful where they are provided;
  • crowdfunding and donation collection on behalf of others;
  • trading, brokerage, OTC desks and other financial services;
  • high-value or high-volume payouts to third parties.

If your business is on this list, tell us before you start processing. Discovering it afterwards is a far worse outcome for both of us.

9. How we enforce this

Where we reasonably believe this policy has been breached, or that an account is being used unlawfully, we may — depending on what we find and what the law requires of us:

  • ask you for an explanation or for supporting documentation;
  • hold, delay or refuse a specific withdrawal or payout;
  • limit what the account can do;
  • block the account, which takes effect immediately;
  • close the account and end our relationship with you;
  • report the matter to law enforcement, a regulator, or another authority.

We do not need to prove a breach to a criminal standard before acting. We do try to act proportionately, and to ask before we block where asking is safe and lawful — but where we are legally prohibited from telling you why we have acted, we will not tell you.

10. What blocking actually does

Being specific about this, because it is abrupt:

  • Blocking takes effect immediately, not at your next sign-in. Active sessions stop working at once.
  • API keys stop working immediately too. A token issued before the block does not keep functioning — the check runs on every request, not only at login.
  • You will not be able to sign in to the dashboard or the app.
  • Any balance stays recorded in the ledger. It does not disappear, and it is not forfeited by the act of blocking.
  • Deposits already in flight are still recorded against your account.

[PLACEHOLDER — TREATMENT OF FUNDS DURING AND AFTER A BLOCK. How long funds may be held while a matter is investigated, what triggers their release, and what happens to a balance on an account closed for a policy breach — including whether release requires a court order or a regulator's direction. Counsel to set this; it must not be left to case-by-case discretion.]

11. Appealing a decision

If your account has been limited, blocked or closed and you believe we have it wrong, write to [email protected] with your account email and anything that helps explain the activity. A human will look at it.

[PLACEHOLDER — APPEAL PROCEDURE AND TIMEFRAME. The committed response time, who reviews an appeal, whether review is independent of the person who made the original decision, and any external escalation route available to you.]

12. Reporting abuse

If you believe someone is using Crypto Gate in breach of this policy — a scam collecting payments through us, a fraudulent merchant, or an account you think is compromised — tell us at [email protected]. Include transaction hashes, payment links or addresses where you have them; they make a report far easier to act on.

Security vulnerabilities go to [email protected], not to the support address.

We may change this policy as new forms of abuse appear. Continued use of the service after a change means you accept it.

Before this document goes live

Have counsel qualified in the relevant jurisdiction review the whole of it, fill every bracketed placeholder, and confirm what licensing or registration holding customer funds requires where Crypto Gate operates and where its customers are. Until that is done this page is a draft, not a contract.