Acceptable Use Policy.
This policy is designed to protect service stability, customer data, and lawful, responsible use of the platform.
Purpose
This acceptable use policy protects SHIFTFM, customer data, and users from use that creates operational, security, or legal risk.
Prohibited Use
Access, identity, and permission abuse
- Accessing or attempting to access another organization’s account or data.
- Sharing login credentials in a way that allows unauthorized persons to use an account.
- Bypassing permission systems or technical or commercial limits.
- Impersonating another user or organization.
- Attempting to disable or bypass customer-data isolation.
Security testing, harmful code, and risky content
- Performing penetration testing or vulnerability scanning without prior written approval.
- Uploading, storing, or sharing malware, malicious code, or files intended to disrupt the service, devices, or users.
- Uploading executable files, scripts, or executable content that is not tied to a supported and authorized SHIFTFM function.
- Uploading links or files used for phishing, fraud, or credential theft.
- Using the platform for activities that violate applicable laws or regulations.
- Entering personal data obtained unlawfully.
- Entering categories of data that SHIFTFM does not support or that the technical infrastructure prohibits.
- Entering plaintext passwords, access tokens, API keys, or technical secrets inside operational fields or attachments.
- Entering payment-card numbers, bank-account numbers, or sensitive financial information inside records or attachments outside a dedicated function expressly approved for that data type within the service.
- Entering health, biometric, or other highly sensitive data categories unless SHIFTFM confirms express contractual and technical support.
Platform abuse, scraping, and misuse of resources
- Attempting to extract, copy, or reverse-engineer platform components.
- Flooding the platform with automated requests, records, or attachments in a way that affects performance.
- Using scraping, automation, or API activity beyond authorized limits.
- Manipulating records deliberately to create false operational reports.
- Using trial access repeatedly to avoid subscription.
Commercial misuse and third-party rights
- Reselling or renting access to SHIFTFM without approval.
- Uploading content that infringes intellectual-property rights or the rights of others.
Fair Use, Capacity, and Abuse
Each plan includes defined commercial capacity for the relevant facilities, users, records, storage, or other operational categories.
Legitimate use up to the included plan capacity is normal use. As a relevant limit approaches, SHIFTFM may notify the customer that the included capacity is nearing its limit.
When the included capacity is reached through legitimate operational use, that is a capacity event rather than abuse. SHIFTFM may stop additional creation in that category and direct the customer to request expansion, a service-scope adjustment, or an appropriate plan change.
Abuse includes circumvention of limits, creation of fake or meaningless records, deliberate duplicate records intended to consume resources, unauthorized automation or scripts, mass uploads unrelated to facility operations, unauthorized stress or load testing, repeated trial creation to avoid subscription, and deliberate infrastructure consumption outside genuine operational use.
Attachments and Harmful Files
SHIFTFM is an operating platform and not a general-purpose file repository.
Attachments must be directly related to the operational purpose of the record to which they are added.
Expected facility-related documents may include licenses, permits, engineering drawings, site plans, inspection or safety certificates, facility and maintenance contracts, warranty certificates, operation and maintenance manuals, equipment certificates, inspection or maintenance reports, handover records, recurring-work documentation, and other documents with a legitimate operational relationship to the facility.
Malware, harmful executable files, and any file designed to disrupt the service, users, or devices are prohibited.
Files and attachments are subject to SHIFTFM’s acceptable-use and security controls. SHIFTFM may restrict, reject, suspend processing of, or remove a file where its type, content, or behavior creates a security or operational risk or violates the applicable terms.
The presence of upload functionality does not mean every file type is permitted or suitable for processing.
Excessive Use and Large Data Loads
Record and attachment creation must remain proportionate to the customer’s genuine operational use.
Reasonable controls may be applied to the number of records created during a period, the number or size of attachments, import activity, automated requests, and API or automation usage.
Any permanent commercial limit should align with the agreed plan or quotation.
Reaching a disclosed plan or trial limit during legitimate evaluation or legitimate operational use is not itself abuse.
Measures for Breach
Depending on severity, SHIFTFM may respond with escalating protective measures.
- Warn the user.
- Restrict a specific permission.
- Restrict creation of data or attachments.
- Suspend the user.
- Suspend part of the service.
- Suspend the account.
- Terminate the service in serious breaches.
SHIFTFM may move directly to the protective measure it considers appropriate if continued activity presents a security, legal, or third-party data risk.
Policy Updates
SHIFTFM may update this Acceptable Use Policy from time to time without obtaining a new individual approval from every customer or user where the change is non-material. Non-material changes may include, without limitation, clarifications of wording, formatting or structural updates, contact-information updates, correction of errors, clarification of an existing process, operational or technical descriptions that do not materially reduce customer or user rights or materially increase their obligations, and changes needed to reflect existing platform functionality without materially changing the legal relationship.
Non-material updates become effective when the updated policy is published, and the Last updated date on this page is revised accordingly. If a change is material and materially affects customer rights, user rights, data-processing practices, material customer obligations, material service restrictions, payment or subscription obligations, or another substantial element of the legal relationship, SHIFTFM will provide notice through the platform and/or another appropriate communication channel.
Where applicable law or the nature of the change requires renewed acceptance, SHIFTFM may require the affected customer or user to accept the updated policy before continuing normal use. For changes that do not legally require renewed explicit acceptance, continued use of the service after the effective date may constitute acceptance of the updated policy, subject always to the laws and regulations applicable in the Kingdom of Saudi Arabia.