This policy forms part of the Terms of Service and lists what may not be done with the Service. Terms defined there have the same meaning here.
It applies to the Customer and to everyone who operates under its Workspace. The Customer is responsible for the conduct of anyone who accesses the Service with its credentials or API keys, whether or not they belong to its organization.
01Lawful use and Third-Party Platform policies
You may not use the Service to:
- Carry out any activity that is illegal in your country or in the country where you sell, or that is contrary to good faith and fair trading.
- Breach the terms, policies or rules of Mercado Libre, Shopify, WooCommerce, Tiendanube, Odoo, Producteca, any AI provider or any other Third-Party Platform you connect — including their rules on listings, prices, buyer communications, data use and API usage.
- Evade sanctions, restrictions or suspensions that a Third-Party Platform has applied to you or to someone else, for example by moving a suspended catalog to another account.
- Operate accounts, stores or systems of third parties without their express authorization.
Compliance with the rules of each Third-Party Platform is the Customer's sole responsibility. NexxoSync does not interpret those rules for you or validate what you publish.
02Products, listings and content
You may not use the Service to publish, synchronize or offer:
- Goods or services whose sale is prohibited or restricted by applicable law, or by the policies of the destination platform, without meeting the conditions required — including weapons, controlled substances, counterfeit goods, stolen goods, and products subject to recalls or health authorizations you do not hold.
- Content that infringes intellectual property or other rights of third parties, including trademarks, photographs, texts and product descriptions you are not authorized to use.
- False, misleading or deceptive information about the characteristics, origin, price, availability, delivery or conditions of a product.
- Content that is defamatory, discriminatory, harassing, violent, sexually explicit involving minors, or that promotes hatred or illegal acts.
03AI Assistants
You may not use Assistants, or configure them, to:
- Send spam or unsolicited commercial messages, or contact people who have not engaged with you first, through any channel.
- Impersonate a person, a business or a Third-Party Platform, or hide from people that they are interacting with an automated system where the law or the platform requires disclosure.
- Generate deceptive answers — for example, fake reviews, false urgency, invented stock or false statements about warranties or consumer rights.
- Make or support decisions that produce legal effects on individuals or similarly significantly affect them, such as decisions on credit, employment, insurance or access to essential services.
- Collect from buyers or visitors data that is not needed for the conversation — in particular payment card numbers, passwords or sensitive personal data.
- Give professional advice (medical, legal, financial or similar) presented as such.
- Produce content that is illegal or that breaches the usage policies of the AI provider configured.
Nobody — Customers, Users or the people who talk to an Assistant — may:
- Attempt to manipulate an Assistant (for example, through prompt injection) to reveal its instructions, credentials, data of other buyers or orders that do not belong to the person asking, or data of another Workspace.
- Use an Assistant to bypass the order-lookup verification, or to automate queries against it.
04Personal data
You may not use the Service to process personal data without a legal basis, or to extract, compile or reuse data of buyers, customers or visitors for purposes other than managing your own sales and customer service.
- Do not use data obtained through Integrations or Assistants — including buyers' contact details from orders — to send marketing they have not consented to, or to sell, rent or transfer it to third parties.
- Do not synchronize sensitive personal data (health, biometric, religious beliefs, political opinions and similar categories) unless it is strictly necessary and you have the legal basis the law requires.
- Respect the data-protection rules of the Third-Party Platforms, including their restrictions on protected customer data and their deletion requests.
The obligations of each party on personal data are set out in the Data Processing Agreement.
05Technical integrity of the Service
You may not:
- Circumvent, alter or force the limits of your Plan — Connections, Assistants, runs, AI tokens, Users — or the rate limits the Service applies, including to Third-Party Platforms.
- Create multiple accounts or Workspaces to split a single operation and avoid the limits or price of the Plan that would apply.
- Access or attempt to access data, Workspaces or areas of the Service that do not belong to you.
- Scrape, crawl or extract data from the application or the website by automated means, or access the application by robots or scripts other than through the API and API keys we offer, used as documented.
- Decompile, reverse engineer or attempt to extract the source code, models or logic of the Service, except to the extent the law expressly allows it despite this restriction.
- Introduce malicious code, or interfere with the availability, integrity or performance of the Service, for example by generating a disproportionate volume of requests.
- Share API keys outside your organization or embed them where third parties can read them.
- Use the Service to build or train a competing product, or to benchmark it for publication without our prior written consent.
Third-Party Platforms often apply rate limits per application rather than per seller, so capacity is shared among all customers. Forcing those limits does not just affect us — it immediately affects other customers. This is the breach we act on most urgently.
06Security testing and responsible disclosure
Penetration tests, vulnerability scans, load tests or other security testing of the Service require our prior written authorization. To request it, or to report a vulnerability, write to [email protected].
If you discover a vulnerability in good faith, we ask you to:
- Report it to [email protected] as soon as possible, with enough detail to reproduce it.
- Not access, modify or delete data that is not yours beyond what is strictly needed to demonstrate the issue, and not disrupt the Service.
- Give us a reasonable time to fix it before disclosing it publicly.
We will not take action against research carried out in good faith and in line with these rules. We do not currently offer monetary rewards for reports.
07Resale and use on behalf of third parties
You may use the Service to manage stores and accounts of your own clients — for example, as an agency — provided you have each owner's authorization and your Plan allows the number of Connections and Workspaces needed. You remain responsible for them under these rules.
Without our prior written authorization, you may not:
- Resell, sublicense or transfer access to the Service.
- Offer the Service under another brand, or present it as your own.
- Share a single Workspace among independent organizations.
08Communications with support
Support is provided by people. We expect respectful treatment: abuse, threats or insults allow us to end that conversation, without affecting the rest of the contractual obligations.
09Consequences
Depending on the seriousness, repetition and harm caused, we may:
- Ask the Customer to stop the conduct and remedy it within a reasonable time.
- Temporarily limit the rate of the Workspace, or disable a specific Integration, Assistant or API key.
- Suspend access, as provided in the Terms of Service.
- Terminate the agreement immediately, without refund, in case of a serious or repeated breach.
- Inform the affected Third-Party Platform, or report the facts to the competent authorities when appropriate or legally required.
We will apply the least severe measure that is effective, and tell the Customer the reason and scope of the measure we take. When there is an imminent risk of harm to the Service, to other customers or to third parties, we may act without prior notice and will inform the Customer within twenty-four (24) hours.
10Reporting abuse
If you detect a use of the Service contrary to this policy, report it to [email protected], and security issues to [email protected]. Reports are handled confidentially.