Acceptable Use Policy (AUP)

Last Updated: 29. 03. 2026

Welcome to the small-pms Acceptable Use Policy, also known as the "Please Don't Ruin It For Everyone Else" agreement.

Because small-pms provides you with powerful tools—like automated email pipelines and custom public-facing forms—we have strict rules about how those tools can be used. If you violate these rules, we reserve the right to suspend or permanently delete your account immediately, without notice and without a refund.

1. The Golden Rule of Email (Anti-Spam)

We use a shared infrastructure to send automated emails to your guests. If you send spam, our email provider will blacklist our entire domain, which breaks the software for every other host.

  • Transactional Only: You may only use our email features to send transactional messages related to an actual, specific short-term rental reservation (e.g., check-in instructions, house rules, checkout reminders).

  • No Marketing: You may not use small-pms to send mass marketing blasts, newsletters, or promotional offers.

  • No Purchased Lists: You may only email guests who have actively booked with you or explicitly consented to be contacted regarding a booking.

2. Public Forms and Data Collection

small-pms allows you to create custom forms and surveys (/guest/, /survey/) to collect information from your guests.

  • No Sensitive Data (Phishing): You absolutely may not use our forms to ask guests for raw credit card numbers, bank details, passwords, government IDs (like Social Security Numbers), or highly sensitive medical information.

  • No Impersonation: You may not use our forms to impersonate other businesses, booking channels (like Airbnb or Booking.com), or individuals.

3. System Abuse and Integrity

We are building a fast, lightweight system. Do not try to break it.

  • No Scraping or Botting: You may not use automated scripts, scrapers, or bots to extract data from small-pms or repeatedly hit our API endpoints outside of normal browser usage.

  • No Hacking: You may not attempt to bypass our authentication middleware, probe our Supabase database for vulnerabilities, or attempt to access the tenant_id or data of another host.

  • No Load Testing: Please do not run artificial load tests or penetration tests against our Netlify servers without our explicit, written permission.

4. Illegal and Harmful Activity

You may not use small-pms to facilitate any business that is illegal in your jurisdiction or ours. This includes, but is not limited to:

  • Managing properties you do not have the legal right to rent.

  • Processing fraudulent reservations.

  • Harassing, threatening, or discriminating against guests.

5. Enforcement and "Dropping the Hammer"

We actively monitor our system logs (event_logs) and email bounce rates. If we determine, in our sole discretion, that you are violating this policy, we will act immediately to protect the platform. This may include disabling your automated pipelines, blocking your public forms, or permanently terminating your account.