Acceptable Use Policy
This Policy explains how clauses 4 and 4a of the Terms of Service apply to what you do with BookIQ.ai, and in particular to the messages you send to your clients through it. It is not a separate agreement and it does not add an obligation the Terms and the law do not already impose: everything below is either already prohibited by clause 4 (“for any unlawful purpose”), already prohibited by clause 4a (content that “is or contains spam or a scam”), or already required of you as the sender by the law of the place you are sending to. It is published so that you can read those obligations in one place and so that we can point at them when we act on a breach.
1. Who this applies to
It applies to every BookIQ.ai account holder, to their staff, and to anyone using an account. Under clause 1a of the Terms, where an account is a business account “you” means both the person who accepted the Terms and the business they accepted for, and both are bound.
2. What BookIQ.ai is for
BookIQ.ai is a booking and business-operations platform for a business and its own clients: appointments, client records, messages about those appointments, invoices and payments. It is not a bulk-mail platform, a lead-generation tool, or a way to reach people who have no relationship with your business.
3. Things you must not do
Clause 4 of the Terms lists the prohibited uses of the service and clause 4a lists the content you may not post. Both apply in full and are not repeated here. In addition, you must not:
- use BookIQ.ai to send anything that breaks section 4 of this Policy;
- probe, scan or test the security of BookIQ.ai, or of the services it runs on, without our written permission — if you think you have found a security problem, tell us at privacy@bookiq.ai and give us a reasonable chance to fix it before you publish it;
- work around an access control, a rate limit, a plan limit or a feature that is turned off for your account;
- scrape, harvest or bulk-extract data from BookIQ.ai other than through an interface we publish, or use an automated tool to create accounts;
- resell, sublicense or provide BookIQ.ai to someone else as your own service;
- impersonate another business, another person, or BookIQ.ai itself, in the product or in a message you send through it;
- upload anything designed to damage or interfere with the service or with the people who use it.
4. Messages you send through BookIQ.ai
This section is the heart of this Policy. When BookIQ.ai sends an email, an SMS or a message on a channel you have connected, you are the sender. The obligations below are yours, and they are yours whether or not we are able to enforce them for you.
4.1 Consent, and being able to prove it
You must have the recipient’s consent before you send them a commercial or promotional message. In Australia the Spam Act 2003 (Cth) allows consent to be express or, in narrow circumstances, inferred from an existing relationship; an existing customer relationship is not by itself consent for every kind of message, and a consent given for booking reminders is not a consent for marketing. In the United States, CAN-SPAM and, for text messages, the TCPA impose their own consent and disclosure rules. Whichever applies to you, you must be able to show, for each recipient, how and when you got their consent, and what they were told at the time.
What BookIQ.ai does on its side: a client can give or refuse marketing consent on the public booking form and can change it in the client portal, and both records are kept against the client. A refusal in either place suppresses marketing to that client and cannot be overwritten by a later “yes” recorded elsewhere. A marketing send that cannot be tied to an identified client with a consent record is refused rather than sent.
4.2 No purchased, rented, scraped or harvested lists
Do not import into BookIQ.ai, or send to, a list of addresses or numbers you did not collect yourself from the people on it. That includes purchased and rented lists, lists supplied by a lead vendor, addresses harvested from a website or a directory, and addresses generated by guessing. Sections 21 and 22 of the Spam Act 2003 (Cth) prohibit address-harvesting software and harvested-address lists outright; they are also a breach of this Policy in their own right.
4.3 Say who you are
Every commercial message must clearly identify the business sending it and give a way to contact that business that stays accurate for at least 30 days after the message is sent (Spam Act 2003 s 17). If you send to recipients in the United States, CAN-SPAM also requires your valid physical postal address in the message itself. BookIQ.ai does not add a postal address to your messages for you, so if that requirement applies to you, put it in the message.
4.4 Unsubscribe
Every marketing email BookIQ.ai sends carries an unsubscribe link in both the HTML and the plain-text part of the message, and a one-click unsubscribe header that a mail provider can act on without the recipient opening anything. If a compliant unsubscribe cannot be built for a marketing message, we refuse to send that message rather than sending it without one. You must not remove it, disable it, or send in a way that routes around it.
An unsubscribe takes effect straight away. Where it comes through the unsubscribe link or the one-click header BookIQ.ai puts on the message, it is written to both of the places we keep a client’s marketing preference, and the next marketing send drops that recipient. Where a campaign carries its own unsubscribe link as well, that link suppresses the address on the campaign list it was sent from. Either route stops the marketing; if you ever see the two disagree about a recipient, tell us. The Spam Act allows five working days to act on an unsubscribe; we do not use them. Once someone has unsubscribed, do not add them back, and do not ask them to opt in again by sending them another marketing message.
Messages about something the recipient has actually booked or bought — a confirmation, a reschedule, a reminder, a receipt, a one-time code, a password reset — are not marketing and are not stopped by an unsubscribe. Do not disguise a marketing message as one of these.
4.5 SMS and WhatsApp
Marketing SMS is switched off across BookIQ.ai. Any SMS send marked as marketing is refused before a message is composed and before any carrier credential is read, on every SMS path in the product, and there is no setting available to you that turns it back on. SMS through BookIQ.ai is for messages about a booking or the security of an account.
If a recipient replies STOP, that is recorded. We check that record before every SMS we send on your behalf, and before every WhatsApp message we send through BookIQ.ai’s own messaging, and we drop a recipient who is on it whatever the message is about — a texted STOP is a revocation at the carrier, not a preference.
Two limits, stated rather than left for you to assume. First, if the opt-out lookup itself fails — an error reaching the record, not a match against it — the message is allowed through, because losing a booking reminder silently is the worse failure. Second, the record is ours: it does not reach a channel you connected under your own account with the provider. See 4.6. Either way, do not try to reach someone who has stopped by texting them from a different number or on a different channel — that is your obligation under 4.1 whatever our systems do.
4.6 Channels you connect yourself
If you connect WhatsApp Business, LINE, Facebook, Instagram, Telegram, Viber, WeChat or Kakao to BookIQ.ai, you are the sender on that channel under your own account with that provider. That provider’s rules — its consent requirements, its template approval, its opt-out handling, its 24-hour and session windows — apply on top of this Policy, and where they are stricter, they win. The platform-wide marketing refusal described in 4.5 is specific to SMS and does not apply to a channel you connect. Neither does our STOP record: a client who texts STOP to your BookIQ.ai number is not thereby suppressed on a WhatsApp Business or LINE broadcast you send from a channel you connected — that channel keeps its own opt-in and opt-out list, and honouring an opt-out across every channel you use to reach that person is your obligation, not something our systems do for you. Broadcasting to a list on one of those channels is subject to every rule in this section 4, including consent and unsubscribe.
4.7 Frequency, timing and content
- Send at a reasonable hour for where the recipient is, and no more often than the relationship you have with them justifies.
- Do not use a misleading sender name, a misleading subject line, or a link that goes somewhere other than where it says.
- Do not send anything in section 4a of the Terms — a scam, harassment, hate speech, sexual content, threats, information you know to be false, or the promotion of illegal activity.
- Do not use BookIQ.ai to send a message on behalf of a business that is not yours.
5. Your clients’ information
Clause 4a of the Terms already requires that where the content you put into BookIQ.ai contains someone else’s personal information, you have a lawful basis to hold it and to put it into the service. In addition:
- Put in what you need to run the booking and no more. A free-text note is not a good place for information you would not want to have to explain.
- Do not use BookIQ.ai to hold information whose handling requires an agreement we do not offer. In particular we are not a HIPAA business associate and we do not offer a business associate agreement, and BookIQ.ai is not a card-data environment. Where a card payment is taken through BookIQ.ai the number is typed into Stripe’s own hosted fields and goes to Stripe; we do not receive or store a full card number. One older screen — the payment box on a shared invoice link — still draws card fields of its own. It takes no payment: a card or PayPal attempt there is refused in the browser and nothing is submitted. Do not ask a client to enter a card number there; give them the bank details on the invoice instead. It is on our list to remove.
- How we handle your clients’ information on your behalf, and what you can ask us to do about it, is set out in the Data Processing Agreement.
6. The AI features
Where you use an AI feature, the content you submit is sent to the provider named in section 3a of the Privacy Policy so that it can produce the result you asked for. Do not submit content you have no right to submit, and do not present an AI-generated draft to a client as something it is not. Clause 6b of the Terms already says that we do not warrant the accuracy of anything the AI features produce; check it before you send it.
7. Telling us about a breach
If you believe someone is using BookIQ.ai in breach of this Policy, email support@bookiq.ai. In the BookIQ mobile apps, every surface that carries someone else’s content — reviews, service listings and each message thread — has a Report control on it, and Safety & support lists the reports you have filed and the people you have blocked. Security problems go to privacy@bookiq.ai.
8. What we may do about a breach
We do not screen the messages you send before they go out, and nothing here obliges us to look for a breach. When we do act, we choose from the following according to what the breach requires:
- remove or hide the content, as clause 4a of the Terms describes;
- take your business out of the public directory, search and discovery surfaces on BookIQ.ai;
- refuse to send a message, or a class of messages, on your behalf;
- restrict or turn off a feature for your account;
- suspend your account, or close it, under clause 3 of the Terms.
Where we can tell you first, we will, and we will tell you the reason as soon as we reasonably can. Where the breach is serious, unlawful, or is causing harm to someone, we may act without telling you first. We are not obliged to act, and acting once does not oblige us to act the same way again. None of this displaces any right you have under clause 6a of the Terms or under a law that cannot be excluded.
Suspending or closing an account does not, by itself, refund anything: the Refund & Cancellation Policy governs that, and Schedule 1 of the Terms governs money you have taken from your own clients.
9. Changes to this Policy
This Policy is republished at this address whenever it changes, and each version carries the date it was published above. It describes obligations that clause 4 of the Terms of Service and the law already impose, so a change here restates the position more clearly rather than widening it. If we ever need to impose an obligation that the Terms do not already carry, we will do it by changing the Terms of Service, which carries the notice we promise in clause 7 of the Terms.
10. Contact
Questions about this Policy: legal@bookiq.ai. Privacy questions: privacy@bookiq.ai. Everything else: support@bookiq.ai.