Acceptable Use Policy
Cold outreach done properly is a legitimate, valuable way to grow a business. Done badly it is a nuisance, and in many places it is unlawful. This policy draws the line between the two, and explains what happens when someone crosses it.
The short version
- Contact businesses with a genuine commercial reason, under a lawful basis, using accurate sender details.
- Honour every opt-out immediately and permanently, across your whole workspace.
- No purchased or unlawfully obtained lists, no deception, no impersonation, no malware or phishing.
- Do not attempt to evade limits, suspensions or shared-network protections with extra accounts or identities.
- Serious or ongoing breaches can lead to immediate suspension, with no refund.
This summary is for convenience only. The numbered sections below are the binding text.
01Why this policy exists
Outreach platforms live or die on the behaviour of the people using them. One customer sending unlawful or reckless messages damages every other customer: shared sending reputation suffers, providers tighten their filters, and honest businesses stop reaching real inboxes.
So this policy is short on ceremony and firm on substance. It forms part of the Terms & Conditions and applies to everyone who uses the Service, including your team and anyone acting under your Account.
02The three rules that matter most
- 1Have a reason to be in someone’s inbox. Contact businesses where there is a genuine, relevant commercial fit, and where the law where you and they are located permits the contact.
- 2Be who you say you are. Real sender name, real business, real reply address, honest subject lines, honest claims.
- 3Let people leave, instantly and permanently. Every opt-out is honoured, everywhere in your workspace, forever.
A good test
If you would be uncomfortable showing a recipient exactly how they ended up on your list, they should not be on it.
03Consent, lawful basis and lists
- You must have a lawful basis for contacting every recipient, and a valid consent wherever consent is required by the law that applies to them. The standard differs by country, by channel and by whether the recipient is a business or an individual. Knowing which rules apply to your programme is your responsibility.
- You must not use purchased, rented, harvested-in-breach, leaked, or otherwise unlawfully obtained lists.
- You must not upload data obtained in breach of another platform’s terms of service.
- Business-to-consumer messaging carries materially stricter consent rules than business-to-business messaging in most jurisdictions. Take advice before running consumer campaigns.
- Messaging channels such as WhatsApp impose their own consent and content rules on top of the law. Those rules bind you, and breaking them can cost you the channel.
- You must not upload special-category personal data, government identifiers, financial account or payment card data, health information, or data about anyone under 18.
04Content standards
Content sent through the Service, and content stored in it, must not:
- be unlawful, or promote, facilitate or advertise unlawful activity;
- be deceptive, fraudulent, or misleading about who you are, what you sell, what it costs, or what results it produces;
- use forged, disguised or misleading sender information, header information, reply paths or domains;
- impersonate any person, business, brand or public body, or imply an endorsement, partnership or affiliation that does not exist;
- promote, or purport to promote, any of the following high-risk categories without our prior written approval: adult content, gambling, cryptocurrency or token offerings, high-yield or "get rich" investment schemes, payday or predatory lending, debt relief, multi-level marketing, essay mills, illicit pharmaceuticals or supplements with medical claims, weapons, tobacco, vaping or controlled substances;
- be defamatory, obscene, hateful, harassing, threatening, or designed to intimidate, or target anyone on the basis of a protected characteristic;
- infringe intellectual property, privacy, publicity or confidentiality rights;
- contain malware, ransomware, spyware, or links to any of them;
- constitute phishing, credential harvesting, business email compromise, invoice fraud or any other social engineering attack;
- consist of chain messages, pyramid schemes, or bulk untargeted messaging with no commercial relevance to the recipient.
05Opt-outs and suppression
- Every commercial message must give the recipient a clear and functioning way to opt out, and the Service adds standard unsubscribe handling to help you meet that requirement.
- Opt-outs must be honoured promptly across your entire workspace, not just in the sequence that produced them, and permanently.
- You must not remove, obscure, disable or otherwise interfere with unsubscribe mechanisms, suppression handling or the records that support them.
- You must not re-import, re-enrich or re-add a contact in order to defeat a suppression record.
- A recipient who asks to be removed by reply, by phone or by any other means counts as an opt-out. Record it.
- Do not continue messaging a recipient who has told you to stop, in any channel.
07Platform and security conduct
- Do not attempt to gain unauthorised access to any part of the Service, another customer’s workspace, or any system or network connected to it.
- Do not probe, scan, stress test or attempt to bypass any security or access control, except under a written testing agreement with us.
- Do not reverse engineer, decompile, disassemble or attempt to derive source code or underlying ideas, except to the extent applicable law expressly permits despite this restriction.
- Do not access the Service through automated means other than the interfaces and APIs we provide, and do not exceed documented rate limits.
- Do not interfere with, disrupt or place a disproportionate load on the Service or the infrastructure behind it.
- Do not use the Service to build, train or benchmark a competing product.
Found a vulnerability?
Please tell us before you tell anyone else. Write to support@leadsranger.com with "Security" in the subject line. We answer responsible disclosures, we fix what is real, and we credit the reporter where they want the credit. Do not access, alter or exfiltrate data that is not yours while investigating.
08Reporting abuse
If you received a message you believe was sent through our platform in breach of this policy, write to support@leadsranger.com with "Abuse" in the subject line. Include the message with its full headers where you can, because that is what lets us identify the sender.
Please note that the sender of the message is our customer and is the controller of your data, not us. We will act on breaches of this policy, and we will pass your request on to the sender so they can honour it directly.
09How we enforce this policy
We investigate credible reports and abnormal signals. Depending on severity, history and risk, we may:
- contact you and ask you to fix the problem;
- require changes to a campaign, a list or a sending configuration;
- reduce sending limits, pause a sequence, or restrict a feature;
- remove content or suspend a connected channel;
- suspend the Account;
- terminate the agreement and close the Account.
We prefer the first option. We will normally contact you before acting. Where a breach is serious, unlawful, ongoing, or presents an immediate risk to other customers, to third parties or to the integrity of the Service, we may act immediately and without prior notice.
Enforcement action taken for a breach does not entitle you to a refund, and does not limit any other remedy available to us, including our right to be indemnified under the Terms & Conditions.
This list is not exhaustive. New forms of abuse appear constantly, and we reserve the right to act against conduct that clearly offends the spirit of this policy even if it is not written down here yet.
