Acceptable Use Policy
This Policy is part of the Terms of Service and binds every workspace. It sets the consent standards for the messages you send, the content and businesses we do not support, and what happens when a rule is broken.
1. What this Policy is and who it binds
1.1 This Acceptable Use Policy (the "Policy" or "AUP") is part of the DailyBuilt Terms of Service at https://dailybuilt.co/terms (the "Terms") and is incorporated into the Agreement between you and DailyBuilt, Inc., a Delaware corporation ("DailyBuilt", "we", "us"). Capitalized terms used but not defined here have the meanings given in the Terms.
1.2 This Policy applies to:
(a) Customer, the business that maintains a DailyBuilt workspace and is party to the Agreement;
(b) every person Customer permits to access the Service through Customer's workspace, including Customer's employees, contractors, agents, and any other authorized user (together, "Authorized Users"); and
(c) End Users, meaning the individuals who interact with DailyBuilt-hosted surfaces that Customer operates, including booking pages, signing pages, payment pages, hosted forms, and email and SMS messages sent through the Service.
1.3 Customer is responsible for compliance with this Policy by its Authorized Users and, to the extent Customer controls or directs the relevant activity, by its End Users. An act or omission by an Authorized User is treated as an act or omission by Customer. Customer must communicate the relevant parts of this Policy to its Authorized Users and must not configure, instruct, or permit any person to do through the Service what Customer could not do itself.
1.4 This Policy is not exhaustive. It describes categories of prohibited conduct. Conduct that is not listed but is unlawful, abusive, deceptive, or that exposes DailyBuilt, its vendors, its shared sending infrastructure, or other customers to harm is prohibited whether or not this Policy names it.
1.5 Order of precedence. If this Policy conflicts with an executed Order Form, a BAA (as to Protected Health Information), or the DPA, those documents control in the order stated in the Terms. Otherwise this Policy controls over other incorporated policies as to the subject matter it addresses.
1.6 Upstream vendor policies flow down. DailyBuilt delivers the Service using third-party providers whose own acceptable-use, messaging, advertising, and restricted-business rules bind DailyBuilt and, through this Policy, bind Customer. Those rules are incorporated by reference to the extent they apply to Customer's use of the corresponding feature. Where a vendor policy is stricter than this Policy, the stricter rule applies. Where a vendor instructs DailyBuilt to stop or restrict an activity, DailyBuilt will comply and may act under Section 15 without prior notice.
2. General prohibitions
You must not use the Service to:
(a) violate any applicable law, regulation, court order, or the rights of any person, including privacy, publicity, contract, and intellectual property rights;
(b) engage in fraud, deception, phishing, pretexting, social engineering, or any scheme designed to obtain money, credentials, or personal information under false pretenses;
(c) impersonate any person or entity, or misrepresent your identity, affiliation, or authority, including by misstating the business on whose behalf a message, invoice, document, or booking page is presented;
(d) harass, threaten, stalk, defame, or incite violence against any person, or promote self-harm, or engage in conduct that constitutes abuse or exploitation of a minor;
(e) distribute malware, ransomware, spyware, or any code designed to disrupt, damage, or gain unauthorized access to a system;
(f) interfere with, degrade, or place an unreasonable load on the Service or on any system or network connected to it; or
(g) facilitate, encourage, or provide the means for any other person to do any of the above.
3. Email messaging
DailyBuilt transmits Customer's email through shared sending infrastructure operated by DailyBuilt and its email provider. One sender's abuse degrades deliverability for every other customer on that infrastructure. The rules in this Section are therefore enforced strictly.
3.1 Consent and list sourcing
(a) Every recipient must have given consent, or you must have an established business relationship with that recipient that is sufficient under applicable law, before you send that recipient a commercial message through the Service.
(b) Purchased, rented, scraped, harvested, appended, co-registered, and "list broker" data is prohibited. You must not upload, import, or send to any address obtained by:
- purchase, rental, lease, barter, or exchange from any third party;
- automated harvesting, scraping, or crawling of websites, directories, social platforms, or public records;
- dictionary attacks, permutation, or guessing of addresses;
- "email appending" of addresses onto records you hold for a different identifier; or
- any third-party list where you cannot identify, for each individual recipient, when and how that recipient consented to hear from you.
(c) Consent records are mandatory. For each recipient of a marketing or promotional email, you must create and retain a record that identifies, at minimum: the date and time of consent, the source or web form through which it was captured, the exact disclosure text the recipient was shown, and the identifier consented (email address). You must retain these records for at least the longer of (i) four (4) years after the consent is given and (ii) four (4) years after the last message sent in reliance on it.
(d) You must produce consent records to DailyBuilt on request, within five (5) business days. DailyBuilt may request them following a complaint, a spam-trap hit, a rise in complaint or bounce rates, a vendor inquiry, or a regulatory or third-party demand. Failure to produce records for a challenged recipient list is itself a violation of this Policy and is grounds for suspension of email sending under Section 15.
3.2 CAN-SPAM and message content
For every commercial email you send through the Service, you must:
(a) use accurate and non-deceptive header information, including the "From", "Reply-To", sender name, and originating domain, and must not use a third party's domain or brand without that party's authorization;
(b) use a subject line that is not deceptive and that accurately reflects the content of the message;
(c) identify the message as an advertisement where it is one and where the law requires that identification;
(d) include a valid physical postal address for the sender in every commercial message;
(e) include a clear and conspicuous mechanism allowing the recipient to opt out of future commercial email, and keep that mechanism operable for at least thirty (30) days after the message is sent;
(f) honor an opt-out promptly and in any event within ten (10) business days, and never charge a fee, require any information beyond an email address and opt-out preference, or require the recipient to log in, visit more than a single page, or take any step beyond sending a reply or visiting a single web page in order to opt out; and
(g) not sell, exchange, or transfer an address of a recipient who has opted out, other than for compliance purposes.
3.3 Suppression and unsubscribes
(a) You must not send to any address on a suppression list applicable to your workspace, whether the suppression arose from an unsubscribe, a bounce, a spam complaint, or a manual entry.
(b) You must not attempt to circumvent, remove, disable, obscure, or re-import a suppressed address, and must not move a suppressed recipient to a different address, workspace, sending domain, or channel in order to keep messaging them.
(c) You must not disable, alter, or hide the unsubscribe mechanism, the sender identification, or the postal address in any message template.
(d) DailyBuilt operates a suppression list and blocks sends to suppressed destinations. DailyBuilt may add an address or number to that list, may expand a suppression to cover additional message types, and may make a suppression global across the platform, at its discretion. Suppression is a compliance control, not a deliverability setting. Suppression by DailyBuilt does not discharge your own obligation to maintain and honor your opt-out records, and you must not rely on DailyBuilt's suppression list as your compliance mechanism.
(e) DailyBuilt does not undertake to detect every non-compliant recipient, and nothing in this Section shifts responsibility for consent, opt-outs, or list hygiene from Customer to DailyBuilt.
3.4 Deliverability
(a) You must not send at a volume, cadence, or complaint rate that materially harms the reputation of a shared sending domain or IP. DailyBuilt may impose sending limits, require warm-up schedules, require a dedicated or Customer-controlled sending domain, throttle, or pause sending in order to protect shared infrastructure.
(b) Sustained spam-complaint rates above 0.1%, hard-bounce rates above 2%, or any spam-trap hit may trigger immediate action under Section 15. These figures are indicators DailyBuilt uses to protect shared infrastructure. They are not thresholds DailyBuilt is required to reach before acting, they are not a permission to send at any rate below them, and they are not a representation about deliverability. DailyBuilt may act at any level of complaints, bounces, or blocklisting where shared infrastructure is at risk.
4. SMS and text messaging
SMS carries statutory-damages exposure under the Telephone Consumer Protection Act (47 U.S.C. § 227) and analogous state statutes, and is governed by carrier and industry rules that apply on top of the law. The rules in this Section are conditions of access to SMS features.
4.1 Two consent standards
(a) Transactional and relationship messages. You must have the recipient's prior express consent. Consent is ordinarily established when the recipient provides their mobile number to you or through a DailyBuilt-hosted surface in connection with the transaction the message is about, after being shown the applicable disclosures. Transactional messages must relate to the specific transaction or relationship the recipient initiated, such as a booking confirmation, a change or reminder for a scheduled appointment, a document or payment request the recipient is a party to, or a reply from the business to the recipient's own inquiry.
(b) Marketing and promotional messages. Marketing text messaging is not enabled on DailyBuilt's currently registered messaging program, which is registered for transactional and customer-care traffic only. Any marketing tier DailyBuilt makes available in the future will run on a separately registered number and campaign. Where DailyBuilt makes marketing messaging available to you, you must have the recipient's prior express written consent as defined at 47 C.F.R. § 64.1200(f)(9) before sending any message that advertises or promotes goods or services. That means, at minimum, a written agreement signed by the recipient (including by a compliant electronic signature) that:
- bears the signature of the person called;
- clearly authorizes you, identified by name, to deliver advertisements or telemarketing messages using an automatic telephone dialing system or prerecorded or artificial voice;
- includes the telephone number to which the person authorizes messages to be delivered;
- contains a clear and conspicuous disclosure that the person is authorizing you to deliver such messages using an automatic telephone dialing system, and that the person is not required to sign the agreement or agree to receive the messages as a condition of purchasing any property, goods, or services; and
- is obtained without pre-checked boxes and without bundling the consent into unrelated terms in a way that defeats the clear and conspicuous requirement.
(c) Consent to marketing messages must never be a condition of purchase, booking, payment, or service. A booking form, intake form, checkout, or signing flow must remain fully completable by a person who declines marketing messages.
(d) Consent is channel-specific and sender-specific. Consent to email is not consent to SMS. Consent to receive transactional messages is not consent to marketing. Consent given to one business is not consent for an affiliate, a successor location, a franchisee, or any other business to message that recipient.
4.2 Consent records for SMS
(a) You must create and retain, for each mobile number and each consent standard, a record containing: the mobile number; the date and time of consent; the source (the specific form, page, document, or process); the exact disclosure text presented; the method of capture; and, where captured online, the IP address and user agent.
(b) You must retain these records for at least five (5) years after the later of the date of consent and the date of the last message sent in reliance on it.
(c) DailyBuilt may require documentary proof of opt-in before enabling, and at any time after enabling, SMS campaign features for your workspace, a specific sending number, or a specific audience. DailyBuilt may refuse to enable, may pause, and may revoke SMS features where proof is not produced within five (5) business days of request, is incomplete, or does not on its face satisfy Section 4.1. DailyBuilt has no obligation to enable SMS marketing for any Customer.
4.3 Prohibited SMS practices
You must not:
(a) send to any number obtained by purchase, rental, lease, exchange, scraping, harvesting, appending, skip-tracing, or from any third-party list, under any circumstances and regardless of what that third party represents about consent;
(b) send to a number for which you cannot produce the consent record required by Section 4.2;
(c) circumvent, ignore, delay, filter, or defeat an opt-out. "STOP" and every recognized opt-out keyword must always work. You must not require a recipient to call, email, log in, confirm twice, explain themselves, or take any other step in order to stop messages; you must not move an opted-out number to a different sending number, brand, campaign, workspace, or channel; and you must not re-obtain consent by messaging the number after opt-out;
(d) suppress, alter, or omit the "HELP" response or the identification of the sending business;
(e) send messages containing content prohibited by carrier or industry rules, including messages relating to cannabis, cannabidiol, illegal substances, firearms, unregulated lending or high-risk financial services, debt collection outside applicable rules, gambling, adult content, or any category the carriers or the messaging provider designate as prohibited or restricted;
(f) use "snowshoeing" (spreading similar traffic across numbers to evade filtering), number rotation to evade blocking, URL shorteners on shared or public domains, or any other technique intended to obscure the sender or evade carrier filtering;
(g) register or maintain a 10DLC brand or campaign containing false, incomplete, or misleading information about the sending business, the message content, the opt-in method, or the sample messages, or use a registered campaign for a use case other than the one registered;
(h) send marketing messages outside the hours permitted by applicable federal and state law in the recipient's time zone (as a platform default, before 8:00 a.m. or after 8:00 p.m. local time for the recipient — DailyBuilt applies the stricter of the federal 8:00 a.m. to 9:00 p.m. limit and the Florida 8:00 a.m. to 8:00 p.m. limit as its baseline, and you remain responsible for any state rule that is stricter still), or in violation of any applicable state telemarketing statute, including registration and disclosure requirements; or
(i) send SMS to any number in a jurisdiction where you are not authorized to do so, or to any number on an applicable do-not-call registry where the message requires do-not-call scrubbing.
4.4 Industry rules
You must comply with the CTIA Messaging Principles and Best Practices, the requirements of The Campaign Registry and the applicable A2P 10DLC program, and the acceptable-use, code-of-conduct, and messaging policies of DailyBuilt's messaging provider, each as amended. Where those rules require a specific disclosure, opt-in flow, or content restriction, that requirement is part of this Policy.
4.5 The published SMS Program Terms
Messages sent through DailyBuilt-hosted surfaces are subject to the SMS Program Terms at https://dailybuilt.co/sms-terms. You must not present opt-in language that contradicts those terms, and you must not remove or obscure the disclosures DailyBuilt presents on hosted surfaces.
5. Prohibited and restricted businesses
5.1 The Service includes payment functionality provided through Stripe. The Stripe list of restricted businesses at https://stripe.com/restricted-businesses is incorporated into this Policy by reference. You must not use the Service, and in particular must not use the payments, invoicing, or checkout features, in connection with any business, product, service, or activity on that list, as it is amended from time to time.
5.2 You must also comply with the Stripe Services Agreement and the Stripe Connected Account Agreement applicable to your connected account, including their restricted-business and prohibited-use provisions.
5.3 DailyBuilt will act on vendor instruction. If Stripe, DailyBuilt's email provider, DailyBuilt's messaging provider, Meta, Google, DailyBuilt's hosting or infrastructure providers, or any other vendor instructs DailyBuilt to suspend, restrict, or terminate an account, a feature, a sending identity, a connected account, or a specific activity, DailyBuilt will comply. DailyBuilt may take that action immediately and without prior notice, and, acting in good faith and after giving Customer notice as promptly as the circumstances and the provider's instructions permit, is not liable to Customer for doing so. Customer's remedy in that situation, if any, lies with the vendor under the vendor's own agreement with Customer. Where a suspension under this Section is not attributable to Customer's breach of this Policy or the Agreement, DailyBuilt will credit Customer a pro-rata portion of the fees for the suspended period.
5.4 Independently of the vendor lists, you must not use the Service in connection with: unlicensed practice of a licensed profession; sale of controlled substances, prescription pharmaceuticals, or medical devices without required authorization; deceptive health, weight-loss, or income claims; multi-level marketing recruitment; payday, title, or advance-fee lending; credit repair, debt relief, or student-loan relief services outside the applicable rules; sale of personal data; or any activity for which you lack a required license, registration, or permit.
6. Protected Health Information
6.1 No PHI without Healthcare Edition and an active BAA. You must not submit, store, transmit, or cause to be submitted through the Service any Protected Health Information ("PHI") as defined by HIPAA (45 C.F.R. § 160.103) unless (a) Healthcare Edition is enabled on your workspace and (b) a Business Associate Agreement between you and DailyBuilt is in effect and has been accepted by an authorized representative of your organization. Submitting PHI outside those conditions is a material breach of the Agreement.
6.2 Do not put PHI into channels that are not covered. Even where Healthcare Edition and a BAA are in effect, PHI must not be placed in the following, because they are delivered by, or exposed to, providers that are not covered by a BAA or are not designed to hold PHI:
(a) SMS message bodies, including appointment reminders, campaign content, custom message templates, and any free-text field that becomes an SMS body. Appointment messages must be limited to non-clinical logistics such as the name of the business, date, time, and location, and must not include diagnosis, treatment, procedure, clinician specialty, medication, test, or any similar clinical detail;
(b) advertising audiences, custom audiences, customer lists, conversion payloads, pixel or conversions-API events, ad creative, ad targeting parameters, or any data transmitted to Meta, Google, or any other advertising platform;
(c) calendar event titles, descriptions, locations, attendee fields, or any other field synchronized to an external calendar provider;
(d) web analytics, page titles, URL paths, query parameters, and form field names on public pages;
(e) subject lines of email, and any email sent to an address the individual has not confirmed;
(f) support requests, chat messages, screenshots, or sample data sent to DailyBuilt outside the Service, unless DailyBuilt has directed you to a channel it has designated for PHI; and
(g) any integration, export, webhook, or third-party connection that you enable and that DailyBuilt has not identified as covered for PHI.
6.3 You are responsible for determining whether information you submit is PHI, for your own compliance with HIPAA as a covered entity or business associate, and for obtaining any authorization required from an individual before using the Service in a way that requires one, including for any marketing communication that requires authorization under 45 C.F.R. § 164.508.
6.4 If you discover that PHI has been submitted in violation of this Section, you must notify DailyBuilt at hello@dailybuilt.co without unreasonable delay. DailyBuilt may, without notice, disable the affected feature, quarantine or delete the affected data, and suspend the workspace in order to limit exposure.
6.5 Sensitive information that is not PHI, including consumer health data regulated by state law, information about mental health, reproductive health, substance use, immigration status, sexual orientation, or gender identity, must be handled in accordance with applicable law and must not be used for advertising, audience building, or profiling through the Service.
7. Advertising, Business Profile, and search integrations
7.1 Platform policies apply. Where you use the Service to create, manage, or publish advertising, you must comply with the Meta Advertising Standards and Meta Platform Terms, the Google Ads policies and the Google Ads API terms, and the policies of any other advertising platform you connect, each as amended. Where you use the Business Profile or Search Console integrations, you must comply with the Google Business Profile guidelines and Google Search Essentials.
7.2 Special ad categories. If your advertising relates to credit, employment, housing, or social issues, elections, or politics, you must correctly declare the applicable special ad category before the campaign runs, and you must accept the resulting targeting restrictions. Declaring the category is your responsibility. DailyBuilt passes your declaration to the platform and does not verify it.
7.3 No discriminatory targeting. You must not use targeting, exclusion, audience, placement, or creative features to discriminate against a person or class of persons on the basis of race, color, national origin, religion, sex, sexual orientation, gender identity, familial status, disability, age, veteran status, source of income, or any other characteristic protected by federal, state, or local law.
7.4 You own your advertising. As between you and DailyBuilt, you are solely responsible for your ad creative, copy, claims, substantiation of those claims, offers, disclosures, landing pages, and the products or services advertised, and for compliance with the FTC Act, the FTC Endorsement Guides, state consumer-protection law, and any industry-specific advertising rules that apply to you. DailyBuilt does not review, approve, or substantiate your advertising.
7.5 Audiences. You must not upload to any advertising platform any audience, customer list, or identifier that you obtained without the required consent or notice, that you do not have the right to disclose to that platform, that includes PHI or the sensitive information described in Section 6.5, or that includes individuals who have opted out of your marketing.
7.6 Business Profile and Search Console. You must not connect, claim, verify, or manage a business location, listing, or web property that you do not own or are not authorized to manage. You must not publish reviews or review responses that are fake, incentivized without disclosure, or written by a person other than the reviewer they purport to be, and you must not solicit, filter, gate, or suppress reviews in a way that violates the platform's policy, the FTC's rules on consumer reviews, or applicable law.
7.7 If an advertising or listing platform suspends, restricts, or penalizes an account, asset, listing, or property in connection with your activity, that is a matter between you and that platform. Section 5.3 applies.
7.8 No geofencing of health care locations. You must not implement, or ask DailyBuilt to implement, a geofence around a hospital, clinic, pharmacy, or any other location where in-person health care services are provided, for the purpose of identifying or tracking consumers, collecting consumer health data, or delivering health-related messages or advertisements.
8. AI features
8.1 Status. As of the Effective Date, DailyBuilt does not make generative artificial intelligence features generally available in the Service. This Section governs AI Features if and when DailyBuilt makes them available, and applies from the moment a given AI Feature is enabled for your workspace.
8.2 Model-provider terms flow down. AI Features are delivered using one or more third-party model providers. The acceptable-use policy and usage policy of the applicable model provider are incorporated by reference and bind Customer with respect to AI Features. Where the model provider's policy is stricter, it controls.
8.3 No fully automated high-risk decisions. You must not use AI Features to make, or as the sole or determinative basis for, a decision that produces a legal or similarly significant effect on an individual, including decisions about medical diagnosis or treatment, eligibility for or denial of health services, credit, insurance, employment, housing, education, or access to essential services, or any decision in a legal or law-enforcement context.
8.4 Human review before End User output. You must review AI-generated content before it is sent to, presented to, or relied on by an End User, and before it is placed into a clinical record, a legal instrument, an invoice, or an advertisement. You remain responsible for the accuracy and legality of everything your workspace publishes or transmits, regardless of how it was generated.
8.5 Disclosure. Where law requires disclosure that a person is interacting with, or receiving content generated by, an automated system, you must make that disclosure. You must not represent AI-generated content as having been reviewed, authored, or approved by a licensed professional unless a licensed professional has in fact reviewed and approved it.
8.6 Data. You must not submit PHI or the sensitive information described in Section 6.5 to an AI Feature unless DailyBuilt has stated in writing that the applicable model provider is covered for that data. You must not use AI Features to generate content that this Policy otherwise prohibits, to attempt to extract another customer's data, or to circumvent any safety control.
9. Content
9.1 You must not upload, store, publish, transmit, or link to content that:
(a) infringes or misappropriates a copyright, trademark, patent, trade secret, right of publicity, or other proprietary right;
(b) is defamatory, libelous, or trade-libelous;
(c) is obscene, or that constitutes or promotes child sexual abuse material, non-consensual intimate imagery, or the sexual exploitation of any person;
(d) is unlawful, or that facilitates an unlawful act, including the sale of prohibited goods; or
(e) you do not have the right to upload, store, publish, or transmit.
9.2 Copyright. You must not use the Service to infringe copyright. DailyBuilt responds to notifications of claimed infringement under the Digital Millennium Copyright Act and terminates the accounts of repeat infringers in appropriate circumstances, as described in the Copyright and DMCA Policy. Notifications must be sent to the designated agent identified in that Policy and must contain the elements required by 17 U.S.C. § 512(c)(3). Trademark, right-of-publicity, defamation, privacy, and impersonation complaints are handled under this Policy and go to hello@dailybuilt.co.
9.3 Document templates are samples, not legal advice. Any document, agreement, consent, policy, or clinical form template made available through the Service is provided as a starting sample only. It is not legal, medical, tax, or professional advice, has not been prepared for your jurisdiction or your circumstances, and must be reviewed by your own qualified professional before use. You are solely responsible for the content, enforceability, and regulatory adequacy of every document you send, publish, or execute through the Service.
9.4 E-signature. You must not use the e-signature features to obtain a signature by deception, from a person who lacks capacity or authority, or on a document type for which electronic signature is not legally effective. You must not alter a document after signature except through the Service's own re-issuance process.
10. Platform integrity and security
You must not, and must not permit any person to:
(a) scrape, crawl, spider, or use any automated means to extract data from the Service, other than through the documented API within its published limits;
(b) reverse engineer, decompile, disassemble, or attempt to derive the source code, underlying structure, or algorithms of the Service, except to the extent that restriction is unenforceable under applicable law;
(c) circumvent, disable, or evade authentication, authorization, tenancy isolation, rate limits, quotas, entitlement checks, usage metering, or any other technical control, or use the Service in a manner designed to exceed a plan limit without paying for it;
(d) share, resell, or transfer login credentials or API keys; each Authorized User must use their own individual credentials, and API keys must be scoped, stored securely, and rotated when a person with access leaves;
(e) probe, scan, or test the vulnerability of the Service or any DailyBuilt or vendor system, conduct penetration testing, denial-of-service testing, load testing, or automated vulnerability scanning, or attempt to breach any security or authentication measure, without DailyBuilt's prior written authorization, except for good-faith security research conducted within the scope of, and in compliance with, the vulnerability disclosure policy published at https://dailybuilt.co/security. To request authorization, or to report a vulnerability you discover incidentally, contact hello@dailybuilt.co and do not access, alter, download, or disclose any data you encounter;
(f) access or attempt to access data belonging to another workspace, another customer, or any individual you are not authorized to access;
(g) introduce malware or any code intended to disrupt, damage, or gain unauthorized access to the Service or to a recipient's system;
(h) use the Service to operate a proxy, relay, VPN, mail relay, or bulk-sending service for third parties, or to send on behalf of any business other than the business identified on your workspace, except where DailyBuilt has approved that arrangement in writing;
(i) resell, sublicense, or make the Service available to a third party as a standalone service, or use the Service to build or benchmark a competing product; or
(j) remove, obscure, or alter the DailyBuilt attribution, the Terms and Privacy links, or the payment-processing disclosure presented on DailyBuilt-hosted End User surfaces.
11. Data you may put into the Service
11.1 Rights. You may submit only data that you have the right to collect, use, disclose to DailyBuilt, and process through the Service for the purposes for which you use it, and for which you have given every required notice and obtained every required consent. This applies to contacts you import in bulk, to lists you upload as an advertising audience, and to any record you create on another person's behalf.
11.2 Contact imports. When you import contacts, you represent that you obtained each contact lawfully, that you have a relationship with or consent from that contact sufficient for how you intend to use the record, and that no contact in the import was purchased, rented, scraped, or appended. An import is not consent; importing a contact does not create permission to send marketing email or SMS to that contact.
11.3 Minors. You may process data about a minor only where you have a lawful basis to do so and only where you have obtained the verifiable consent or authorization of a parent or legal guardian to the extent required by law, including the Children's Online Privacy Protection Act and applicable state law. You must not use a minor's data for marketing, advertising, audience building, profiling, or targeted messaging through the Service, and you must not direct a booking, signing, payment, or marketing surface at children under 13.
11.4 Categories you must not collect through the Service's intake surfaces. You must not configure a booking question, intake form, custom field, document field, note, or any other DailyBuilt-hosted collection surface to collect:
(a) biometric identifiers or biometric information, including fingerprints, voiceprints, face geometry or face templates, retina or iris scans, or any identifier regulated by the Illinois Biometric Information Privacy Act, Texas Bus. & Com. Code Ch. 503, Wash. Rev. Code Ch. 19.375, or a comparable statute;
(b) Social Security numbers, taxpayer identification numbers, driver's license numbers, passport numbers, state or military identification numbers, or images of any government-issued identification document;
(c) full payment card numbers, card verification values, magnetic stripe or chip data, bank account and routing numbers, or any other cardholder data. Payments must be taken only through the Service's integrated payment flow, which routes card data to the payment processor; and
(d) genetic data, precise geolocation, or account credentials for any third-party service.
11.5 If you have a genuine business need to collect a category listed in Section 11.4, contact DailyBuilt before configuring it. DailyBuilt may decline, and may require additional contractual terms, technical controls, or both.
11.6 Legal process. DailyBuilt's handling of subpoenas, warrants, and other legal demands is described at https://dailybuilt.co/legal-process. You must not use the Service in a manner that requires DailyBuilt to disclose data in violation of law or of a BAA.
12. End User conduct
12.1 End Users must not submit unlawful, infringing, threatening, or fraudulent content through a booking, signing, payment, or inquiry surface; must not submit another person's information without authority; must not use those surfaces to send unsolicited commercial messages to the Customer or to any other person; and must not attempt to interfere with the Service.
12.2 Customer is responsible for the surfaces it operates, including the questions it asks, the disclosures it presents, the content it publishes, and its handling of what End Users submit.
12.3 DailyBuilt may remove content, block a submitter, or disable a surface where the surface or its content violates this Policy or applicable law.
13. No obligation to monitor; right to investigate
13.1 DailyBuilt does not undertake to monitor Customer Data, messages, documents, or advertising, and no provision of this Policy creates a duty to do so. DailyBuilt's decision not to act in one instance does not waive its right to act in another.
13.2 DailyBuilt may, without becoming obligated to, investigate suspected violations, review message content and metadata, review sending patterns and complaint data, request consent records and other documentation, and disclose information as required by law, as permitted by the Terms and the Privacy Policy, and as required by a vendor's compliance process. Where PHI is involved, DailyBuilt will handle the investigation consistently with the BAA.
13.3 Customer must cooperate promptly and in good faith with a DailyBuilt investigation, must preserve records relevant to it, and must not delete or alter records after receiving a request from DailyBuilt about them.
14. Reporting abuse
14.1 To report a violation of this Policy, including spam, unwanted text messages, fraud, a deceptive booking or payment page, or a security concern, contact hello@dailybuilt.co.
14.2 Copyright complaints are handled under the Copyright and DMCA Policy and must be sent to the designated agent identified there, as described in Section 9.2. Non-copyright intellectual-property and content complaints go to hello@dailybuilt.co. Requests concerning personal information should follow the Privacy Policy at https://dailybuilt.co/privacy.
14.3 A useful report identifies: the DailyBuilt-hosted page, message, sending number, or sending address involved; the date and time; the recipient address or number; and, where available, the full message with headers. DailyBuilt will not necessarily report back on the outcome of an investigation, and does not commit to any particular remedy in response to a report.
15. Enforcement
15.1 Graduated response. Where circumstances permit, DailyBuilt will address a violation through a graduated response:
- Warning. Written notice of the violation and a period to cure, which DailyBuilt will set based on the severity of the violation.
- Feature suspension. Suspension of the specific feature involved, such as email sending, SMS sending, campaigns, advertising integrations, or payments.
- Account suspension. Suspension of access to the workspace.
- Termination. Termination of the Agreement for cause under the Terms.
DailyBuilt is not required to proceed through these steps in order or to use any of them before another.
15.2 Immediate action without prior notice. DailyBuilt may suspend or restrict any feature, workspace, sending identity, or account, remove or quarantine content, and disconnect an integration, immediately and without prior notice, where DailyBuilt reasonably determines that:
(a) the activity presents a security risk to the Service, to DailyBuilt, to a vendor, or to any person;
(b) DailyBuilt has received a subpoena, court order, regulatory inquiry, law-enforcement request, or other legal demand relating to the activity, or reasonably believes the activity is unlawful;
(c) a vendor, including DailyBuilt's payment, email, messaging, hosting, advertising, or infrastructure providers, has demanded or instructed the action, or has itself restricted DailyBuilt's account or capability in connection with the activity;
(d) the activity is harming or is likely to harm the deliverability, sender reputation, carrier standing, or 10DLC registration status of shared infrastructure;
(e) PHI has been or is likely to be exposed outside a covered channel or outside an active BAA;
(f) the activity involves fraud, chargeback abuse, money laundering, or a prohibited or restricted business; or
(g) continued operation would cause DailyBuilt to breach a law, a court order, a vendor agreement, or a BAA.
15.3 Scope and duration. DailyBuilt will use reasonable efforts to limit a suspension to the offending activity, workspace, or feature, and to restore service promptly once the violation is cured and DailyBuilt is reasonably satisfied it will not recur. DailyBuilt may condition restoration on documentation, a remediation plan, list hygiene, a dedicated sending domain, reduced limits, or a change to how a feature is used.
15.4 Effect on fees. Fees continue to accrue during a suspension caused by a violation of this Policy or of the Agreement, and no credit, refund, service credit, or extension is due for that period. Suspension does not relieve Customer of its payment obligations, and amounts already paid are not refundable on account of a suspension or a termination for cause.
15.5 Notice. Where DailyBuilt suspends without prior notice, it will notify Customer's workspace owner promptly afterward, unless prohibited by law or by the terms of a legal demand, or unless doing so would compromise an investigation or the security of the Service.
15.6 Effect on End Users. A suspension may make Customer's booking, signing, payment, and hosted pages unavailable to End Users, and may stop scheduled messages. Customer is responsible for communicating with its End Users about any resulting disruption. DailyBuilt is not liable to Customer or to any End User for that disruption.
15.7 Other remedies. Enforcement under this Section is in addition to, and not instead of, DailyBuilt's other rights and remedies under the Agreement and at law, including indemnification. Nothing in this Section limits Customer's indemnification obligations under the Terms, which expressly cover claims arising from Customer's messaging, advertising, content, documents, and handling of End User data.
16. Changes to this Policy
16.1 DailyBuilt may update this Policy. DailyBuilt will post the updated Policy at https://dailybuilt.co/acceptable-use and update the effective date. For a change that materially expands Customer's obligations, DailyBuilt will provide at least thirty (30) days' notice by email to the workspace owner or by in-product notice before the change takes effect, except where a shorter period is required to comply with law, a payment-network, carrier, or other vendor requirement, or an urgent security or abuse need.
16.2 Continued use of the Service after the effective date of an updated Policy constitutes acceptance of it.
16.3 Prior versions of this document are archived by date and are available on request to hello@dailybuilt.co.
17. Contact
DailyBuilt, Inc. c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, DE 19808 Abuse reports and general contact: hello@dailybuilt.co
Related documents: Terms of Service · Privacy Policy · SMS Program Terms · Data Processing Addendum · Subprocessors · Copyright and DMCA Policy · Legal Process Guidelines