1. Scope and customer control
This policy forms part of the Terms of Service and applies to every customer, administrator, employee, invited user, device, API or integration credential, imported record, message, upload, and other activity performed through or directed at Bibeno.
A customer business is responsible for configuring roles, stores, devices, workflows, integrations, customer notices, and employee access so that authorised users can perform only lawful business activity. A customer may impose stricter internal rules but may not permit conduct prohibited here.
2. Illegal, harmful, and deceptive use
- Committing, facilitating, promoting, concealing, or profiting from illegal, fraudulent, deceptive, corrupt, abusive, exploitative, discriminatory, threatening, or harmful activity.
- Creating false sales, refunds, expenses, stock, time, attendance, identity, tax, consent, invoice, loyalty, payment, delivery, support, or audit records.
- Using Bibeno to sell prohibited or unlawfully sourced goods or services, misrepresent price or availability, evade tax or reporting obligations, or conceal proceeds or beneficial ownership.
- Publishing a merchant storefront or accepting an online order without accurate supplier identity, contact, price, fee, tax, availability, fulfilment, acceptance, cancellation, refund, privacy, complaint, product-safety, allergen, age, and licence information that applies to that branch and order.
- Uploading or distributing material that unlawfully infringes privacy, confidentiality, copyright, trade marks, publicity rights, contractual rights, or another person's rights.
- Attempting to use an account, feature, export, support channel, or integration after authority has been withdrawn or for a purpose materially different from the authorised business purpose.
3. Security and platform integrity
- Do not probe, scan, exploit, bypass, disable, or interfere with authentication, authorisation, tenant or branch isolation, rate limits, signatures, audit controls, legal gates, payment controls, retention safeguards, or monitoring without written authorisation.
- Do not introduce malware, ransomware, destructive code, credential stealers, hidden miners, unsafe files, malicious links, or commands intended to damage, surveil, exfiltrate, or disrupt.
- Do not use stolen, shared, default, recycled, or exposed credentials; impersonate another user; defeat multi-factor authentication; or enrol an unauthorised device.
- Do not access another tenant, branch, customer, employee, support case, object, backup, export, provider record, or environment even if a technical error appears to make it reachable.
- Do not erase, falsify, reorder, replay, forge, or circumvent append-only evidence, transaction records, device authority, offline signatures, reconciliation, legal acceptance, or security-incident records.
4. Privacy, workforce, and sensitive data
Do not collect, import, infer, combine, monitor, disclose, or retain personal information without authority, a defined purpose, required notice, a lawful processing ground, suitable access controls, and an approved retention rule.
- Do not upload passwords, full payment-card data, CVV values, private cryptographic keys, identity-document copies, health information, biometric templates, criminal-allegation records, or children's information unless a specifically approved feature and lawful instruction requires it.
- Do not ask an online-order customer to place payment-card details, identity documents, medical histories, or other unnecessary sensitive information in an order-notes, address, delivery-instruction, support, or free-text field.
- Do not use workforce tools for covert or disproportionate surveillance, unlawful discrimination, retaliation, automated dismissal, or an unauthorised payroll deduction.
- Do not export customer, employee, supplier, support, or transaction data to a personal account, unmanaged device, public link, or unapproved foreign or third-party service.
- Do not re-identify de-identified or aggregated information, combine it to infer protected traits, or use it for an undisclosed incompatible purpose.
- Do not ignore an access objection, correction, deletion, suppression, STOP, unsubscribe, legal hold, or security-compromise instruction.
5. Communications, marketing, and loyalty
- Do not send spam, purchased-list campaigns, misleading promotions, impersonation messages, or electronic direct marketing without the evidence and route permitted by applicable law.
- Do not suppress the sender identity, physical or electronic contact route, required commercial disclosure, unsubscribe mechanism, SMS STOP route, or material promotion terms.
- Do not continue sending after an objection, unsubscribe, STOP request, complaint, internal suppression, or relevant National Consumer Commission Opt-Out Registry block.
- Do not manipulate loyalty balances, fabricate enrolment or consent, apply undisclosed expiry or forfeiture, discriminate unlawfully, or use loyalty data for an incompatible purpose.
- Do not use service, security, billing, or legal messages as a pretext for promotional content that would otherwise require consent or an opt-out.
6. Payments, credit, stored value, and finance
Bibeno records operational and payment-related information but is not approved to act as a bank, deposit taker, payment intermediary, escrow service, cross-merchant stored-value issuer, lender, debt collector, payroll bureau, tax adviser, or financial-services provider unless a written, gated product approval expressly says otherwise.
- Do not use Bibeno to hold or pool customer funds, route a payment outside an approved provider, conceal the true merchant, launder proceeds, split transactions to evade controls, or process a prohibited card transaction.
- Do not present a catalogue view, quote, basket, payment initiation, pending provider event, or unaccepted order as a completed sale, confirmed order, settled payment, delivered item, completed refund, or supplier acceptance.
- Do not issue gift cards outside the approved merchant programme, shorten the statutory minimum validity, divert unredeemed value, or treat bearer value as ordinary merchant revenue before lawful redemption.
- Do not create employee advances, loans, deductions, service charges, tips, consignments, supplier liabilities, or journal entries without the required agreement, authority, classification, and immutable evidence.
- Do not describe a document as a tax invoice or charge VAT unless the supplier's verified tax status and required invoice facts support it.
7. Service resources and automation
- Do not scrape, crawl, mirror, bulk extract, benchmark publicly, load test, denial-of-service test, or automate interaction outside documented limits without written permission.
- Do not bypass storage, user, branch, store, device, message, API, export, feature, or plan limits, or create duplicate accounts to avoid a commercial or safety control.
- Do not resell, sublicense, timeshare, white-label, clone, frame, or expose Bibeno as a service to an unauthorised third party.
- Do not use generated reports, recommendations, forecasts, rankings, or automation as a substitute for legally required human review, professional advice, or verification of source records.
8. Reporting and authorised testing
Report a suspected vulnerability, cross-tenant exposure, compromised credential, unlawful message, infringing content, or other credible abuse promptly to the verified security or support channel. Include the minimum information needed to reproduce or locate the issue and do not access additional data to prove impact.
Security research, penetration testing, performance testing, disclosure, and publication require Bibeno's prior written scope, dates, targets, test accounts, data restrictions, contact route, stop conditions, and disclosure rules. Good-faith reporting does not authorise access beyond that scope.
9. Investigation and enforcement
Bibeno may investigate credible misuse, preserve evidence, restrict affected access, and cooperate with lawful process. Proportionate notice and an opportunity to respond are provided where safety, law, fraud, or urgent security needs do not prevent it.
A response may include rate limiting, content or message quarantine, credential or device revocation, feature restriction, suspension, lawful removal, provider notification, refund or transaction review, preservation order, contract termination, or referral to a customer administrator, affected person, regulator, payment provider, hosting provider, law-enforcement body, or court.
Bibeno applies the least disruptive response reasonably available, preserves safe cancellation, export, privacy, complaint, repayment, and other exit rights, and documents the reason, scope, evidence, authoriser, review date, and restoration or appeal route. Urgent containment may occur before notice.
10. Changes and contact
A material change to prohibited conduct, monitoring, enforcement, suspension, or customer responsibility follows the legal change-classification and notice process and requires re-acceptance where the Terms of Service or applicable law requires it.
Questions, abuse reports, and requests for authorised testing may be sent to support@bibeno.co.za. Do not include passwords, payment-card data, identity documents, provider secrets, or unnecessary personal information.