Acceptable use policy
This policy sets out how Signedup may and may not be used. It applies to every customer and to everyone a customer allows to use its account. It forms part of our terms of service, and words defined there have the same meaning here. If you break it, we may take the steps described in section 8.
1. Building your lists
1.1 Every person on your lists should have expected to be there. You must not:
- add, import or keep anybody on a list without a lawful basis for doing so, recorded in a way you can show us if we ask;
- use purchased, rented, borrowed, shared, scraped, harvested or co-registration lists;
- add people who would not reasonably expect to be on the list, or who have asked not to be;
- re-add a person who has unsubscribed, or an address the Service has suppressed after a bounce or complaint, unless that person has asked to rejoin; or
- where you rely on consent, bundle it with something else, make it a condition of something that does not need it, or record it for purposes the person was not told about.
2. Your forms
2.1 Every form you publish must:
- make clear which organisation is asking for the information, and what it will be used for; and
- make your organisation's privacy notice available, for example by linking to it in the form's introductory text.
2.2 Unless we have agreed otherwise in writing, a form or import must not be used to collect:
- special category personal data, such as information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation;
- information about criminal convictions or offences;
- personal data about anyone under the age of 18;
- payment card or bank account details;
- national insurance, passport, driving licence or other government identification numbers;
- passwords, security questions or other credentials; or
- health records.
2.3 Where the purpose of a list could itself reveal something sensitive about the people on it, such as a staff network for people who share a religion, a health condition or a sexual orientation, clause 7.3(g) of our terms applies and you must make the assessment it describes before using the Service for that list.
2.4 A form must not impersonate another person or organisation, pretend to come from somebody it does not, or be used for phishing or to obtain information by deception.
3. Content
3.1 You must not use the Service to publish, collect or store content that:
- is unlawful, or encourages or facilitates unlawful activity;
- is defamatory, threatening, harassing, abusive or hateful, or discriminates unlawfully;
- is sexually explicit, or promotes terrorism or violent extremism;
- infringes anybody's intellectual property, privacy or other rights;
- is false or misleading in a way likely to cause harm; or
- contains malicious code, or links to it.
4. Messages
4.1 The Service sends only the messages it needs in order to work, such as sign-in and confirmation links, and the requests to check details that you choose to send. A request to check details must be used only for that purpose. You must not use it, or any other message the Service sends, to advertise, to promote anything, or to contact people who are not properly on the list.
4.2 You must not use the Service in a way that causes messages to be sent to people who did not ask for them, or in a volume intended to flood an inbox.
4.3 Anything you send yourself, using data held in the Service, must comply with the law on electronic marketing and unsolicited messages, as clause 7.3(k) of our terms requires.
5. Security and fair use
5.1 You must not, and must not attempt to:
- access another customer's account or data, or any part of the Service you are not authorised to use;
- probe, scan or test the vulnerability of the Service, or run load tests or automated security scans against it;
- get round rate limits, checks against automated abuse, or any other security or usage control;
- interfere with or disrupt the Service, or the networks and systems it relies on;
- access the Service by automated means other than the features we provide for that purpose, or scrape it; or
- use a sign-in link, or any link sent to another person, that was not intended for you.
5.2 Security testing of the Service is permitted only with our prior written permission. To ask for it, or to report a vulnerability you have found, write to security@signedup.io. Our contact details for security reports are also published at /.well-known/security.txt.
6. Commercial use
6.1 You must not:
- resell or sublicense the Service, provide it under another brand, or run it as a service for other organisations, without our written agreement;
- create more than one account or trial for the same organisation in order to avoid paying;
- share a login between more than one person; or
- give false information when creating an account or subscribing.
7. Reporting abuse
7.1 If you believe the Service is being used in breach of this policy, for example because you have been added to a list you did not expect to be on, please tell us at abuse@signedup.io, with as much detail as you can, such as the address of the form or a copy of the message you received.
7.2 If your concern is about how an organisation uses your details, you may also contact that organisation directly, because it is responsible for its list.
8. Enforcement
8.1 If we reasonably believe that this policy has been breached, we may take any of the following steps, choosing those that are proportionate to the breach:
- investigate, including by asking you for information;
- ask you for evidence of your lawful basis, of consent, or of how a list was obtained, which you must provide within the time clause 7.5 of our terms allows;
- remove or disable content, a form, a list, or a feature such as imports or requests to check details;
- suspend all or part of the Service under clause 11 of our terms;
- terminate the agreement under clause 12.2 of our terms; and
- report the matter to the police, a regulator or another authority where the law requires it or we reasonably consider it appropriate.
8.2 We will tell you what we have done and why, before we act where that is practicable and afterwards where it is not, unless the law prevents us or telling you would undermine the reason for acting.
8.3 Where we terminate for a serious or repeated breach of this policy, fees already paid are not refunded, except where the law requires. Nothing in this policy obliges us to monitor how the Service is used, and our not acting on a breach does not mean we accept it.
Changes to this document
We may update this policy as clause 17 of our terms describes, and the date at the top shows when it last changed. This version was published on 15 September 2026.