Legal

Acceptable Use Policy

Rules governing how FoodTruck POS may be used and the consequences for violations.

Last updated: June 25, 2026
5 minute read
Applies to: All accounts
01

Overview

This Acceptable Use Policy ("AUP") governs your use of FoodTruck POS ("Service"), operated by FoodTruck POS ("we," "us," or "our"). By accessing or using the Service, you agree to comply with this AUP in addition to our Terms of Service and Privacy Policy.

FoodTruck POS is designed for lawful commercial use by food service businesses. Misuse of the platform — whether through abuse of features, harmful data practices, security violations, or illegal activity — undermines the reliability and safety of the Service for all users.

Scope: This AUP applies to all users of the FoodTruck POS iOS app, Android app, web dashboard, API, and any other services we provide, regardless of subscription tier.
02

Permitted Use

FoodTruck POS may be used for lawful commercial food service operations, including but not limited to:

  • Processing customer orders and payments at food trucks, stalls, carts, and pop-up events
  • Managing menus, inventory, and business data for your own operation
  • Generating sales reports and analytics for your own business
  • Processing customer refunds and managing order history
  • Sending transactional SMS notifications to customers who have consented (Enterprise plan)
  • Integrating with approved third-party services for your own business purposes
Business use only: FoodTruck POS is a business tool intended for commercial food service operations. Personal, non-commercial use is not a supported use case and may result in account suspension.
03

Prohibited Conduct

The following activities are strictly prohibited when using FoodTruck POS:

🚫
Resale & Sublicensing
Reselling, sublicensing, or providing access to the Service to third parties not covered by your account.
🔓
Reverse Engineering
Decompiling, disassembling, reverse engineering, or attempting to derive source code from the Service.
🤖
Automated Scraping
Using bots, scrapers, or automated tools to extract data from the Service beyond permitted API use.
💥
System Overloading
Sending excessive requests that stress or degrade performance of the Service for other users.
🧪
Fraudulent Transactions
Processing fraudulent, fictitious, or unauthorized payment transactions through the Service.
🔐
Credential Sharing
Sharing account credentials with unauthorized persons or operating the Service under another's identity.
📧
Unsolicited Messaging
Sending spam, unsolicited commercial messages, or violating CASL using any messaging feature.
⚖️
Illegal Activities
Using the Service in connection with illegal activity, money laundering, or tax evasion.

Additional Prohibitions

  • Uploading malicious code, viruses, or malware through any Service input
  • Attempting to gain unauthorized access to other accounts, databases, or network resources
  • Using the Service to process payment card data in violation of PCI-DSS standards (all card processing must occur through Stripe)
  • Impersonating FoodTruck POS, its employees, or other users
  • Removing, obscuring, or altering any copyright, trademark, or proprietary rights notices
  • Using the Service in a way that violates any applicable Canadian federal, provincial, or local law or regulation
  • Interfering with or disrupting the integrity or performance of the Service or related systems
  • Collecting or harvesting any personally identifiable information from the Service without explicit consent
04

Data Integrity

You are responsible for the accuracy and integrity of data you enter into FoodTruck POS. Specifically, you must not:

  • Enter false, misleading, or fabricated business data
  • Manipulate sales records or reports to misrepresent your business's financial position
  • Enter customer data without the customer's knowledge or consent
  • Use customer data collected through the Service for any purpose other than operating your food service business
  • Retain customer data beyond the periods required for legitimate business operations
You are the data controller: For customer data you collect through FoodTruck POS (such as customer phone numbers for SMS notifications), you are acting as the data controller under PIPEDA. You are responsible for obtaining appropriate consent, handling data requests, and complying with applicable privacy law.

We reserve the right to investigate and take action if we detect data manipulation or fraudulent record-keeping that violates applicable law or could expose us to legal liability.

05

Security

You are responsible for maintaining the security of your account. Your obligations include:

  • Using a strong, unique password for your FoodTruck POS account
  • Logging out of devices when no longer in use, particularly shared or public devices
  • Not sharing your credentials with employees or staff — each staff member should have their own access if multi-user access is available on your plan
  • Immediately notifying us at security@foodtruckpos.app if you suspect unauthorized access to your account
  • Not attempting to bypass, disable, or circumvent any security controls in the Service
Security testing: Penetration testing, vulnerability scanning, or any other security testing of our infrastructure without prior written authorization is strictly prohibited and may constitute a criminal offence under the Criminal Code of Canada.

We take security seriously. If you discover a potential security vulnerability, please report it responsibly to security@foodtruckpos.app rather than exploiting it. We will acknowledge legitimate reports and work to address them promptly.

06

Messaging & CASL

The SMS messaging feature (available on the Enterprise plan via Twilio) is subject to Canada's Anti-Spam Legislation (CASL) and must be used as follows:

Express Consent Required

Before sending any commercial electronic message to a customer phone number, you must obtain the customer's express consent. Consent must be:

  • Freely given — not bundled with other terms or made a condition of service
  • Informed — the customer must know what they are consenting to receive and from whom
  • Specific — consent for order confirmations does not imply consent for marketing messages
  • Documented — you must retain records of when and how consent was obtained

Transactional vs. Marketing Messages

The messaging feature is designed for transactional messages only — for example, order ready notifications, receipt confirmations, or status updates. Using it to send unsolicited marketing, promotions, or bulk campaigns is a violation of this AUP and may constitute a CASL violation carrying fines of up to $1,000,000 per day.

Unsubscribe

  • All commercial messages must include a simple, functional unsubscribe mechanism
  • Unsubscribe requests must be honoured within 10 business days
  • You must not send further messages to contacts who have unsubscribed
CASL compliance is your responsibility: FoodTruck POS provides the messaging infrastructure, but you are solely responsible for complying with CASL and all applicable messaging laws. We reserve the right to suspend messaging access for accounts we have reason to believe are violating CASL.
07

Third-Party Integrations

FoodTruck POS integrates with third-party services including Stripe (payments), Resend (email), and Twilio (SMS). When using these integrations, you must:

  • Comply with the terms of service of each third-party provider
  • Not use Stripe to process payments for prohibited businesses or products under Stripe's Restricted Businesses policy
  • Not attempt to circumvent Stripe's fraud detection, chargeback process, or dispute resolution
  • Ensure your business category and product descriptions accurately represent what you sell
Payment processing: All payment card data is handled directly by Stripe. FoodTruck POS does not store raw card numbers. Attempting to capture, store, or transmit cardholder data outside of Stripe's secure systems is a serious PCI-DSS violation and is strictly prohibited.
08

Enforcement & Consequences

We reserve the right to investigate any suspected violation of this AUP. When we detect or receive reports of potential violations, we will take appropriate action proportional to the severity and nature of the violation.

Severity Examples Possible Actions
Minor Accidental policy violation, minor data entry issues Written warning, guidance provided
Moderate Repeated violations, credential sharing, excessive API requests Feature restriction, temporary suspension, formal notice
Severe Fraudulent transactions, illegal activity, security attacks, CASL spam Immediate account termination, data deletion, referral to law enforcement

No Refund on Termination for Cause

If your account is terminated for violation of this AUP, you will not be entitled to a refund of any prepaid subscription fees. This is in addition to any other remedies available to us at law or in equity.

Cooperation with Authorities

We will cooperate fully with law enforcement agencies and regulators investigating violations of applicable law, including by disclosing account information in response to lawful requests, warrants, or court orders.

Right to terminate: We reserve the right to terminate any account at our sole discretion if we determine that continued operation poses an unacceptable risk to the Service, other users, or the public, even in cases not expressly covered by this AUP.
09

Reporting Violations

If you become aware of a violation of this AUP — whether by another user or by us — please report it promptly so we can investigate.

Please include as much detail as possible in your report, including the nature of the violation, relevant account information (if known), and any supporting evidence.

Good-faith reporters: We will not take adverse action against users who report violations in good faith, even if the reported activity turns out not to violate this AUP.
10

Changes to This Policy

We may update this Acceptable Use Policy from time to time to reflect changes to our practices, legal requirements, or the features of the Service. When we make material changes, we will:

  • Post the updated policy at this URL
  • Update the "Last updated" date at the top of this page
  • Send an email notice to the primary account holder at least 14 days before material changes take effect

Continued use of the Service after the effective date of any changes constitutes your acceptance of the revised AUP. If you disagree with material changes, you may cancel your subscription before the effective date.

11

Contact

Questions about this Acceptable Use Policy can be directed to:

FoodTruck POS
Edmonton, Alberta, Canada
Email: legal@foodtruckpos.app
Support: support@foodtruckpos.app

This AUP is governed by the laws of the Province of Alberta and the applicable federal laws of Canada. Any disputes arising from this AUP will be subject to the exclusive jurisdiction of the courts of Alberta.


This Acceptable Use Policy was last updated on June 25, 2026.
It forms part of the FoodTruck POS Terms of Service.