This Acceptable Use Policy (the "AUP" or "Policy") governs your access to and use of the HundredFold platform, including the marketing site at gohundredfold.com and the application at app.gohundredfold.com (together, the "Service"). HundredFold is operated by Heem Megacorp LLC, 8500 Blazyk Drive, Austin, Texas 78737 ("HundredFold," "we," "us," or "our").
HundredFold is a multi-tenant business-intelligence and action platform for direct-to-consumer ecommerce brands. The Service connects a merchant's store, advertising, email, and inventory data, surfaces AI-prioritized insights, and lets authorized users take action on connected platforms.
This Policy is incorporated into and forms part of your agreement with HundredFold (the "Terms of Service" or "Agreement"). Capitalized terms not defined here have the meaning given in the Agreement. If there is a conflict between this Policy and the Agreement, the Agreement controls unless it expressly states otherwise.
By accessing or using the Service, you agree to this Policy. If you use the Service on behalf of an organization (a "merchant" or "tenant"), you agree to it on that organization's behalf and represent that you are authorized to do so. The organization is responsible for the acts and omissions of every person who accesses the Service through its account, including its owners, admins, members, and viewers.
1. Who this Policy applies to
This Policy applies to everyone who accesses the Service, including:
- Merchants (tenants) — the organizations whose data is connected to the Service.
- Users — the individual team members a merchant invites to its account, in any role (owner, admin, member, or viewer). Access today is invite-only via an owner-managed allowlist; there is no public self-serve signup.
- Anyone who otherwise interacts with or attempts to interact with the Service.
You are responsible for your own conduct on the Service and for any content, data, prompts, or instructions you submit.
2. Your responsibilities for connected accounts and data
The Service works by connecting to third-party platforms that you authorize, including Shopify, Meta (Facebook/Instagram), Google (Search Console, Google Analytics 4, Google Ads), Amazon Selling Partner API, and Klaviyo. You are responsible for:
- Having all rights, consents, and authority necessary to connect each account and to grant HundredFold the access described at connection time.
- Ensuring your use of each connected platform through the Service complies with that platform's terms, developer policies, and advertising or messaging policies (see Section 4).
- The accuracy and lawfulness of any data you bring into the Service, and of any content you generate, push, or export through it.
- Maintaining the confidentiality of your login method and account, and the conduct of every user you invite.
You must not connect an account, or upload or process data, that you are not authorized to connect, upload, or process.
3. Prohibited uses
You may not use the Service, and may not permit anyone to use the Service through your account, to do any of the following.
3.1 Illegal, harmful, or rights-violating use
- Violate any applicable law, regulation, or governmental order, or use the Service for any unlawful purpose.
- Infringe, misappropriate, or violate the intellectual property, privacy, publicity, contractual, or other rights of any person or entity.
- Upload, store, generate, transmit, or export any content that is unlawful, infringing, defamatory, fraudulent, deceptive, or that you do not have the right to use.
- Use the Service to harass, defraud, or harm others, or to facilitate any of the above.
3.2 Misuse of personal data
- Submit, connect, or process personal data you are not lawfully permitted to process, or use the Service to process personal data in violation of applicable privacy or data-protection law.
- Attempt to use the Service to collect, derive, or store categories of personal data beyond what the Service is designed to handle. (The Service processes a deliberately minimal set of end-customer personal data — an order's customer email address and shipping city/state/country — and is not intended for collecting customer names, street addresses, phone numbers, payment or card data, or building customer profiles.)
- Re-identify, enrich, sell, or otherwise misuse end-customer data accessed through the Service in violation of law or the merchant's obligations to its own customers.
3.3 Spam, unsolicited messaging, and email law
- Use the Service to send, schedule, or facilitate spam or unsolicited bulk or commercial messages.
- Export customer emails, build audiences (including win-back lists pushed to Klaviyo), or create draft campaigns or templates for recipients who have not provided the consent required by applicable law, or who have unsubscribed or opted out.
- Violate any anti-spam or email-marketing law, including the U.S. CAN-SPAM Act and other applicable email, SMS, and electronic-communications laws, or Klaviyo's policies, when using any email-related capability of the Service.
3.4 Violating connected-platform policies
Because the Service reads from and (where you enable it) writes to third-party platforms, you may not use the Service to do anything that violates those platforms' rules, including:
| Platform | What HundredFold does | You must not use the Service to |
|---|---|---|
| Meta (Facebook/Instagram) | Reads aggregate ad metrics; optionally creates paused draft ads for your review (never publishes live) | Create, prepare, or push ad content that violates Meta's Advertising Standards, Platform Terms, or policies; attempt to publish prohibited or deceptive advertising |
| Google (Search Console, GA4, Google Ads) | Read-only aggregate metrics | Violate Google Ads policies, the Google API Services User Data Policy (including Limited Use requirements), or any Google platform terms |
| Shopify | Read-only store, inventory, order, and fulfillment data | Violate Shopify's terms, API license terms, or partner/app policies |
| Amazon (Selling Partner API) | Reads FBA inventory and aggregate sales/traffic data (no customer data) | Violate Amazon's Selling Partner / Marketplace policies or data-use terms |
| Klaviyo | Reads email metrics; pushes draft templates and campaigns; exports customer emails for win-back lists | Violate Klaviyo's terms or acceptable-use policy, or applicable email-marketing law |
You remain solely responsible for any content you publish, send, or activate on a connected platform, including content that originated as a draft generated or pushed by the Service.
3.5 Tenant isolation and security controls
The Service is multi-tenant. Every record is scoped to the owning organization, enforced in application code and backstopped by PostgreSQL Row-Level Security. You may not:
- Access, attempt to access, or attempt to derive any other tenant's, merchant's, or user's data or credentials.
- Circumvent, disable, probe, or attempt to defeat any authentication, authorization, isolation, rate-limiting, or other security control of the Service.
- Exploit, or attempt to exploit, any vulnerability, misconfiguration, or bug to gain access you are not authorized to have.
- Test or scan the Service for vulnerabilities without our prior written authorization (see Section 6 for reporting genuine security issues).
3.6 Integrity and availability of the Service
- Reverse-engineer, decompile, disassemble, or attempt to discover the source code, models, or underlying structure of the Service, except to the extent this restriction is prohibited by applicable law.
- Scrape, crawl, harvest, or use automated means to extract data from the Service outside of functionality and interfaces we provide for that purpose.
- Introduce malware, or any code or mechanism intended to disrupt, damage, or gain unauthorized access to the Service or its infrastructure.
- Overload, flood, or otherwise impair the Service or its sub-processor infrastructure, or interfere with any other user's use of the Service.
- Use the Service to build or train a competing product or service, or to benchmark it for a competitor, without our prior written consent.
3.7 Account and credential abuse
- Share, sell, or transfer your login credentials or account access to anyone, or allow access by anyone not properly invited to the account.
- Misrepresent your identity or your authority to act for a merchant, or impersonate any person or entity.
- Circumvent the invite-only, role-based access model, including attempting to escalate your role or grant yourself permissions you were not given.
3.8 Misuse of AI features and outputs
The Service uses AI (Anthropic Claude) to produce briefings, analysis, and draft ad and email copy from your business aggregates and your own written context. You may not:
- Use AI-generated outputs in any way that violates applicable law or the policies of any platform on which you publish or send them (including Meta and Google advertising policies and email-marketing law).
- Attempt to use AI features to extract, infer, or surface other tenants' data, secrets, API keys, or tokens, or to manipulate the Service into producing content that violates this Policy.
- Represent AI-generated output as independent professional (e.g., legal, financial, or medical) advice, or rely on it without your own review. You are responsible for reviewing AI outputs before publishing, sending, or acting on them.
4. Your compliance with platform and marketing rules
Using HundredFold does not relieve you of your own obligations to the platforms you connect or to your customers. You remain independently responsible for complying with the terms and policies of Shopify, Meta, Google, Amazon, Klaviyo, and any other connected platform, and with all advertising, email, privacy, and consumer-protection laws that apply to your business. If a connected platform restricts or revokes access because of your conduct, that is your responsibility, not HundredFold's.
5. Enforcement and consequences
We may investigate any suspected violation of this Policy and cooperate with law enforcement where appropriate. If we determine, in our reasonable judgment, that you have violated this Policy — or to protect the Service, our other tenants, or any third party — we may, with or without prior notice depending on the severity and urgency:
- Issue a warning and request that you correct the violation;
- Throttle, restrict, suspend, or disable specific features, integrations, or a connected account;
- Suspend or restrict your or your users' access to the Service;
- Remove, disable, or quarantine offending content, data, or connections; and/or
- Terminate your account or the merchant's account in accordance with the Agreement.
For severe violations — including attempts to access other tenants' data, circumvent security controls, conduct illegal activity, or cause a security or integrity risk — we may suspend or terminate access immediately and without prior notice. We are not liable for any action taken in good faith to enforce this Policy, and enforcement action does not entitle you to a refund except as expressly stated in the Agreement. Suspension or termination does not limit any other rights or remedies available to us.
We may update this Policy from time to time. Material changes will be communicated as described in the Agreement, and your continued use of the Service after an update constitutes acceptance of the updated Policy.
6. Reporting abuse or security issues
If you become aware of any violation of this Policy, suspected abuse, or a potential security vulnerability, please report it to us promptly at admin@gohundredfold.com. Please include enough detail for us to investigate, and do not exploit, publicize, or further access any issue you discover while we work to resolve it.
This Policy should be read together with the HundredFold Terms of Service and Privacy Policy. Questions about this Policy may be directed to admin@gohundredfold.com.