Legal

Acceptable Use Policy

Last updated: April 25, 2026

1. Scope

This Acceptable Use Policy ("AUP") applies to everyone who uses the BudStacks platform, including operators, their staff, end-customers, and visitors. It is incorporated by reference into the Terms of Service. Breach of this AUP may result in immediate suspension or termination.

2. Regulatory compliance

You may not use the platform to:

  • Sell, advertise, supply, or facilitate the sale of cannabis or cannabis products to consumers in jurisdictions where such activity is illegal.
  • Make therapeutic, curative, or medical-treatment claims about products that are not authorised medicines in the relevant jurisdiction. This includes claims that specific strains "treat", "cure", or "relieve" specific medical conditions, in breach of UK Human Medicines Regulations 2012 Regulation 279 and the MHRA Blue Guide.
  • Operate a storefront without a valid local operating licence.
  • Bypass age verification, prescription validation, KYC, or any other regulatory control required by local law.
  • Pay for or run advertising on Meta, LinkedIn, Google, TikTok or any other channel in breach of those platforms' policies on cannabis or restricted goods.

3. Content rules for operator storefronts

Storefronts hosted on BudStacks must:

  • Implement an age gate (18+ or 21+ per local law) before product browsing or checkout.
  • Display the operator's licence number, registered address, and complaints contact.
  • Avoid promotional language that markets cannabis to consumers in non-compliant ways (e.g. "buy now", "best high", "limited stock — order today!").
  • Not use imagery of cannabis flower, smoking, or recreational consumption in marketing copy where prohibited by local rules or platform policies.
  • Not promote discounts, sales, or special offers in ways that breach local cannabis advertising restrictions.

4. Security and integrity

You may not:

  • Probe, scan, or attempt to penetrate platform security.
  • Bypass authentication, rate limits, or feature gates.
  • Upload malware, viruses, or any code intended to disrupt the platform.
  • Access data belonging to other tenants without authorisation.
  • Reverse-engineer or copy proprietary parts of the platform.
  • Scrape data at volumes or rates that degrade service for others.

5. Lawful and ethical use

You may not use the platform to:

  • Send spam or unsolicited bulk communications.
  • Infringe intellectual property, privacy, or publicity rights.
  • Defame, harass, or threaten others.
  • Distribute illegal content (CSAM, terrorist content, etc.).
  • Engage in fraud, money-laundering, or other financial crime.
  • Trade with sanctioned individuals or jurisdictions.

6. Data handling

Operators are controllers of patient and customer data and must comply with the GDPR / UK GDPR. Operators must not upload special-category data (Article 9) without a lawful basis. Operators must respond to data-subject requests in line with statutory deadlines. Sharing of patient data with unauthorised third parties is strictly prohibited.

7. Reporting violations

To report suspected AUP violations, email [email protected]. Security vulnerabilities should be reported to [email protected].

8. Enforcement

BudStacks may, at its sole discretion: warn the operator, request remediation, suspend accounts or storefronts, remove content, terminate the agreement, cooperate with law-enforcement, and report suspected criminal conduct to the appropriate authorities. Where a breach is also a breach of the Terms of Service, BudStacks reserves all rights and remedies under those Terms and applicable law.