Acceptable Use Policy
Version: 2026-09-28.v1. Effective date: 28 September 2026. Operator: ABSOLUTE SERVICES (UEN 53464936W), a sole proprietorship registered in Singapore and owned by LEE KOK WAN. "Hail Pilot" is the name of the product and service operated by ABSOLUTE SERVICES ("Hail Pilot", "we", "us"). Registered address: 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051.
This Policy forms part of the Terms of Service at /legal/terms (the "Terms"). Capitalised words have the meaning given in the Terms. It applies to you (the Merchant), to every Merchant User, and to anyone who uses the Service, its API or its browser extension on your behalf. You are responsible for their compliance.
1. Purpose and scope
1.1 This Policy says what you may not do with the Service, what you are responsible for when you use AI Features, what you promise about data you upload, how to report misuse, and what we do when this Policy is broken.
1.2 The Service exists to help you manage refunds, returns, disputes, chargebacks and post-purchase abuse for your own business. Use outside that purpose, or in a way that harms Buyers, other Merchants, a Platform or us, is not permitted.
1.3 The Terms state the order of precedence between the documents that make up the Agreement. Where this Policy adds detail to a rule in the Terms, both apply.
2. Prohibited uses
You will not, and will not allow any Merchant User or third party to, use the Service to do any of the following.
2.1 Falsify or alter evidence. You will not upload, generate, edit or submit any photograph, screenshot, chat transcript, tracking record, delivery record, invoice, document or statement that is fabricated, altered (other than by lawful redaction), misdated, or that presents an AI-generated image or document as a record of a real event. This repeats the warranty in the Terms on evidence authenticity. AI-drafted narrative text is permitted only where the Terms allow it.
2.2 Harass, threaten or abuse Buyers. You will not send, or configure the Service to send, messages that are harassing, threatening, abusive, discriminatory, sexually explicit or intended to intimidate. Sending an AI-drafted message unedited after the Service has flagged it does not reduce your responsibility for it.
2.3 Defame or accuse without basis. You will not use the Service to publish statements that defame a Buyer, accuse a Buyer of a crime without reasonable basis, or share a Buyer's personal data in any public forum, group chat or review.
2.4 Defeat tenant isolation or infer other Merchants' data. You will not attempt to access, enumerate, reconstruct or infer the data of any other Merchant or of any Buyer outside your own workspace, whether directly, through the API, through the browser extension, or by reasoning from Network Signals. This includes attempts to reverse the pseudonymised tokens used for Network Signals.
2.5 Resell or republish Network Signals. You will not extract, export, resell, redistribute, sublicense, scrape or publish Network Signals, risk scores or any summary of them, including by screenshot. You may use them only inside the Service for decisions about your own orders and Buyers.
2.6 Breach Platform Terms. You will not use the Service in a way that breaches the Platform Terms of every Platform you connect, including their rules on automated messaging, seller-performance metrics, data use and rate limits. You are responsible for knowing those rules. If you use the browser extension, you will use it only on Seller Centre accounts you own or are authorised to operate, and you will satisfy yourself that your Platform permits its use. We give no warranty that any Platform permits it.
2.7 Bulk or unsupervised automated replies. You will not configure automated replies to flood Buyers, to send marketing or unsolicited messages, to evade the human-review default, to bypass the automated moderation check on outbound drafts, or to send at a rate or in a manner a Platform does not permit. Auto-Send may be used only after you have given the attestation described in the Terms and the AI Transparency Notice, and only while that attestation remains true.
2.8 Circumvent billing or limits. You will not create multiple accounts to evade Plan limits or the Trial, share credentials or API keys between separate businesses, misstate your business identity, or otherwise avoid Fees or metering.
2.9 Upload special-category data without necessity. You will not upload data about a person's health, biometrics, race or ethnicity, religion, political opinions, sexual life or criminal record unless it is strictly necessary for a specific dispute and you have the legal basis to process it. See clause 5.
2.10 Send refund or remedy statements without approval. You will not configure the Service, or edit its templates, so that a message stating refund rights, return windows, warranties, remedies or authority to settle is sent to a Buyer without a Merchant User approving it.
2.11 Market automation as indistinguishable from a person. You will not advertise or represent to Buyers, Platforms or anyone else that messages produced by an AI Feature are written by a person, or promote your use of the Service on the basis that Buyers will not know that automation is used.
2.12 Impersonate. You will not use the Service to pose as a Platform, a bank, a card network, a courier, a regulator, a government body, another Merchant or Hail Pilot.
2.13 Act unlawfully. You will not use the Service for any purpose that is unlawful in Singapore, in Malaysia, or in the place where a Buyer is located, including breaches of data-protection, consumer-protection, spam-control and anti-harassment laws.
3. Computer misuse
3.1 You will not do, attempt, or help anyone else to do, any of the following in relation to the Service, our systems, or any program or data held on them:
(a) access any account, workspace, program or data that you are not authorised to access, or continue to access anything after your authorisation has ended;
(b) access any part of the Service in order to commit or help commit any other offence, including fraud or theft;
(c) add, alter, delete, encrypt or corrupt any program or data without authority, or introduce malware or any code designed to do so;
(d) use any computer service, or intercept any communication or data, without authority, including by capturing other users' sessions, traffic or credentials;
(e) obstruct or interfere with the lawful use of the Service by others, including by denial-of-service, flooding, resource exhaustion or deliberately triggering rate limits; or
(f) disclose, share or sell any password, API key, session token, access code or other means of access to anyone who is not authorised to use it. Sharing a login between people is a breach of this clause.
3.2 You will not probe, scan, penetration-test, fuzz, reverse-engineer or otherwise test the security of the Service except as expressly authorised by the Vulnerability Disclosure Policy at /legal/vdp. You will not run credential-stuffing or brute-force attacks, and you will not use prompt injection or similar techniques to extract system prompts, model configuration, other users' data or internal heuristics from AI Features.
3.3 The conduct in clause 3.1 is an offence under the Computer Misuse Act 1993 (Singapore), which applies to persons outside Singapore as well as inside it, and under equivalent laws in Malaysia and elsewhere. We report suspected offences to the police and other relevant authorities, we preserve and hand over evidence when lawfully required, and we may inform affected Merchants, Buyers and Platforms.
3.4 Nothing in this clause 3 restricts good-faith security research carried out within the scope of, and in compliance with, the Vulnerability Disclosure Policy.
4. AI content: your responsibility
4.1 AI Output is a draft or a recommendation. When you send, publish or submit AI Output, or configure the Service to send it, you are its author and publisher.
4.2 Human review is the default. AI-drafted Buyer replies are sent only after a Merchant User approves each one, unless you have switched on Auto-Send. You will keep enough trained Merchant Users to review AI Output for the volume you handle.
4.3 Auto-Send. When you use an AI Feature to communicate with Buyers, including under Auto-Send, you are the Deployer of that AI Feature toward Buyers, as the Terms and the AI Transparency Notice describe. You are responsible for the accuracy of every message sent in your name, for deciding whether and how to tell Buyers that automation is used, and for checking that each Platform or messaging channel permits it. You will switch Auto-Send off if any part of your attestation stops being true.
4.4 No bypassing safety controls. You will not prompt, configure or manipulate an AI Feature so as to bypass the automated moderation check, the restricted-content controls in clause 2.10, or any other safeguard.
4.5 Reporting problems. If you see an AI Feature produce content that is false, harmful, discriminatory or that contains another person's data, stop using that output and tell us at business@hailpilot.com.
5. Data you upload or connect
5.1 You warrant that, for all Buyer Data and other personal data you upload to or connect to the Service, you have given the notices and obtained the consents required by the Personal Data Protection Act 2012 (Singapore), the Personal Data Protection Act 2010 (Malaysia) and any other law that applies to you, for the purposes described in the Privacy Policy and the Data Processing Agreement.
5.2 You will upload only data you are entitled to process, and only for managing post-purchase matters of your own business. You will not upload data obtained from a source that prohibits its use for that purpose.
5.3 You will not upload full payment card numbers, card security codes, or bank account credentials. The Service is not designed to hold them. If we find them we may delete them without notice.
5.4 You will not upload special-category data (clause 2.9) unless strictly necessary for a specific dispute and lawful. Where you do, you will limit it to what the dispute requires.
5.5 You are responsible for the accuracy of the data you upload and for correcting it when a Buyer or a Platform tells you it is wrong.
5.6 You will not upload malware, or files that you know or should know are unsafe.
6. Reporting misuse
6.1 Report a suspected breach of this Policy, including a complaint from a Buyer about a message sent through the Service, to business@hailpilot.com.
6.2 Report a suspected security vulnerability to business@hailpilot.com under the Vulnerability Disclosure Policy. Report suspected unauthorised access to your own account to business@hailpilot.com without delay.
6.3 Report a concern about personal data to business@hailpilot.com. Buyers can find their options in the Notice to Buyers at /legal/buyers.
6.4 We acknowledge every report, investigate it, and tell the reporter what action we took where the law and the interests of others allow.
7. Investigation
7.1 We may investigate any suspected breach of this Policy. In an investigation we access Merchant Data only to the extent necessary to establish what happened and to protect the Service, other Merchants, Buyers or a Platform.
7.2 You will cooperate with an investigation, preserve relevant records, and not delete or alter evidence after we have told you we are investigating.
7.3 We may share the results with the Platform, payment provider, acquirer or authority concerned where the conduct affects them or where we are required to.
8. Enforcement
8.1 We respond to a breach in proportion to its seriousness, its effect on others, and whether it was deliberate. The steps we may take are:
(a) Warning. We send you a written notice describing the breach and the corrective action required. Unless clause 8.2 applies, you have the cure period stated in the Terms for termination for cause to fix it, or a shorter period where necessary to protect Buyers, other Merchants, a Platform or the Service.
(b) Restriction. We may switch off Auto-Send, revoke extension or API keys, suspend paid features, or remove access to a feature for as long as the risk continues.
(c) Suspension. We may suspend all or part of your access under the suspension clause of the Terms, giving as much notice as is reasonable in the circumstances. We lift the suspension when its cause is resolved.
(d) Termination. We may terminate the Agreement under the termination-for-cause clause of the Terms if a breach is not cured within the cure period, or at once under clause 8.2.
8.2 Immediate action. For a wilful breach, we may restrict, suspend and terminate immediately on notice, without a cure period. Wilful breaches include falsified or altered evidence; harassment or threats; attempts to defeat tenant isolation or infer other Merchants' data; conduct described in clause 3; resale of Network Signals; impersonation; use of the Service for an unlawful purpose; and a repeat of any breach after a warning. Any refund on termination is governed by the Refund & Cancellation Policy at /legal/refund-policy.
8.3 Other action. We may also report the conduct to the Platform concerned, to the Personal Data Protection Commission (Singapore) or the Personal Data Protection Department (Malaysia) where required, and to the police under clause 3.3, and we may bring a civil claim for loss caused to us, to other Merchants or to Buyers.
8.4 Notice. When we take action we tell you what we did and why, unless the law, an authority's request or an ongoing investigation prevents it.
8.5 Review. If you believe an enforcement decision is wrong, write to business@hailpilot.com with your reasons. We reconsider in good faith and confirm the outcome to you in writing.
9. Changes
We may change this Policy as the Terms describe. Every version is listed on the legal changelog page at /legal/changelog.
10. Contact
All reports go to business@hailpilot.com. Put "Abuse", "Security", "Personal data" or "Legal" at the start of the subject line so the report reaches the right person first.