legal: publish an Acceptable Use Policy, required by the payment provider's merchant review #267

Stängd
öppnade 2026-09-29 19:39:59 +00:00 av supernaut · 1 kommentar
Ägare

Problem

The payment provider's merchant review (Mollie) classifies Bitborg as a hosting service. That category requires an Acceptable Use Policy (AUP) on the website. The review is on hold until one is published. Mollie accepts either a separate document linked from the site or a section of the Terms.

Section 4 of the Terms ("Acceptable use", src/content/en/terms.md:36 and the Swedish twin) already covers prohibited content and resource abuse, but not everything Mollie lists.

Required content

Mollie's list, with what the current Terms already have:

  1. Scope: which services and which users the policy covers. Missing. State it: git hosting, package registry, LFS, CI runners and the web portal, for every account holder, organisation member and anyone acting through their access.
  2. Permitted and prohibited use, including restricted or high-risk activities. Partly there (section 4 list). Add: no use to sell or facilitate goods or services that are illegal, regulated without licence, or high-risk (weapons, drugs, gambling, adult content, financial services without authorisation), and no use of the service as infrastructure for such activity.
  3. Compliance with applicable law, including sanctions. Missing. Add: users confirm they comply with Swedish and EU law and that they are not, and do not act for, a person or entity subject to EU or UN sanctions or resident in a sanctioned territory.
  4. Rules preventing misuse, fraud and harmful content. Partly there. Add fraud explicitly: no payment with a card or identity you are not entitled to, no chargeback abuse, no fake accounts to gain trial or free-tier resources.
  5. Responsibility for third parties and sub-users. Missing. Add: the account holder answers for everyone they add to an organisation and for anything pushed through their credentials, tokens or CI.
  6. Monitoring and enforcement rights. Partly there ("we may remove content or suspend accounts"). Add: we may review content and usage when we have reason to, remove content, rate-limit, suspend or terminate accounts and organisations, refuse or cancel payments, and report unlawful activity to authorities.

Proposal

Keep it inside the Terms. Expand section 4 into the full policy and retitle it "Acceptable Use Policy". Add a footer link labelled "Acceptable use" that points at the section anchor, so the reviewer finds a URL that names the policy. One document in two languages to keep in sync, and #266 is already rewriting the Terms.

If the reviewer rejects an in-Terms section, split it into src/content/{en,sv}/acceptable-use.md with its own route, and have Terms section 4 refer to it.

Coordinate with #266: the enforcement and termination wording must stay consistent with the consumer-law fixes there (notice before suspension of a paid account, no refund only where the law allows).

Done when

  • The policy covers all six points above, in English and Swedish, with "Last updated" set and package.json bumped.
  • A footer link named "Acceptable use" reaches it in both languages.
  • Wording checked against docs/content-style.md.
  • Ticked on bitborg/bitborg-docs#106 once merged.
## Problem The payment provider's merchant review (Mollie) classifies Bitborg as a hosting service. That category requires an Acceptable Use Policy (AUP) on the website. The review is on hold until one is published. Mollie accepts either a separate document linked from the site or a section of the Terms. Section 4 of the Terms ("Acceptable use", `src/content/en/terms.md:36` and the Swedish twin) already covers prohibited content and resource abuse, but not everything Mollie lists. ## Required content Mollie's list, with what the current Terms already have: 1. **Scope: which services and which users the policy covers.** Missing. State it: git hosting, package registry, LFS, CI runners and the web portal, for every account holder, organisation member and anyone acting through their access. 2. **Permitted and prohibited use, including restricted or high-risk activities.** Partly there (section 4 list). Add: no use to sell or facilitate goods or services that are illegal, regulated without licence, or high-risk (weapons, drugs, gambling, adult content, financial services without authorisation), and no use of the service as infrastructure for such activity. 3. **Compliance with applicable law, including sanctions.** Missing. Add: users confirm they comply with Swedish and EU law and that they are not, and do not act for, a person or entity subject to EU or UN sanctions or resident in a sanctioned territory. 4. **Rules preventing misuse, fraud and harmful content.** Partly there. Add fraud explicitly: no payment with a card or identity you are not entitled to, no chargeback abuse, no fake accounts to gain trial or free-tier resources. 5. **Responsibility for third parties and sub-users.** Missing. Add: the account holder answers for everyone they add to an organisation and for anything pushed through their credentials, tokens or CI. 6. **Monitoring and enforcement rights.** Partly there ("we may remove content or suspend accounts"). Add: we may review content and usage when we have reason to, remove content, rate-limit, suspend or terminate accounts and organisations, refuse or cancel payments, and report unlawful activity to authorities. ## Proposal Keep it inside the Terms. Expand section 4 into the full policy and retitle it "Acceptable Use Policy". Add a footer link labelled "Acceptable use" that points at the section anchor, so the reviewer finds a URL that names the policy. One document in two languages to keep in sync, and #266 is already rewriting the Terms. If the reviewer rejects an in-Terms section, split it into `src/content/{en,sv}/acceptable-use.md` with its own route, and have Terms section 4 refer to it. Coordinate with #266: the enforcement and termination wording must stay consistent with the consumer-law fixes there (notice before suspension of a paid account, no refund only where the law allows). ## Done when - The policy covers all six points above, in English and Swedish, with "Last updated" set and `package.json` bumped. - A footer link named "Acceptable use" reaches it in both languages. - Wording checked against `docs/content-style.md`. - Ticked on bitborg/bitborg-docs#106 once merged.
supernaut lade till detta till projektet Bitborg Web 2026-09-29 19:41:59 +00:00
Upphovsperson
Ägare

Decision 2026-09-30: keep the policy inside the Terms. Section 4 becomes the Acceptable Use Policy and the footer links to its anchor. Standalone page only if the payment provider's reviewer rejects that.

Decision 2026-09-30: keep the policy inside the Terms. Section 4 becomes the Acceptable Use Policy and the footer links to its anchor. Standalone page only if the payment provider's reviewer rejects that.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web#267
Ingen beskrivning angiven.