ACCEPTABLE USE POLICY

Last updated: 20 June 2026
Effective from: 20 June 2026
Version: 1.0

1. About This Policy

This Acceptable Use Policy governs access to and use of NibbleKit websites, mobile applications, web applications, ordering flows, customer account features, Merchant and administration portals, APIs, verification and reset pages, support services, demo workspaces and related platform services that link to this policy, together referred to as the Services.

The Services are operated by Paul Hepple, a sole trader trading as DarkByte Creations. In this policy, DarkByte, NibbleKit, we, us and our refer to Paul Hepple trading as DarkByte Creations.

For the purposes of this policy:

This policy applies differently according to the capacity in which you use the Services. Customer use is also governed by the NibbleKit Terms and Conditions and, where applicable, the End User Licence Agreement. Merchant and Merchant User access is also governed by the applicable Merchant agreement, authorised-user terms and any written security or data-processing requirements agreed with the Merchant.

This public policy does not replace the Merchant agreement. Where there is a conflict concerning a Merchant's business account or its authorised users, the Merchant agreement will take priority to the extent permitted by law.

2. General Standard of Use

You must use the Services only:

You must follow reasonable security and operational instructions displayed in the Services or communicated to you by DarkByte or, where relevant, the Merchant that authorised your access.

Nothing in this policy prevents a Customer from making a genuine complaint, exercising a statutory right, disputing an unauthorised transaction or reporting a security or safety concern in good faith.

3. Unlawful, Fraudulent or Abusive Use

You must not use or attempt to use the Services:

A genuine complaint, statutory claim or payment dispute is not prohibited merely because DarkByte or a Merchant disagrees with it.

4. Security and Technical Misuse

You must not:

You must not reverse engineer, decompile, disassemble or otherwise attempt to derive the source code, non-public structure or internal operation of the Services, except to the extent that applicable law grants a right that cannot lawfully be excluded.

5. Personal Data and Confidential Information

You must not use the Services to:

Where a feature permits allergy, dietary or other health-related information to be entered, you must use that feature only for its stated purpose and must not copy the information into unrelated tools or fields.

6. Content and Communications

You must not upload, publish, transmit or communicate content that:

You must not use the Services to send unsolicited marketing or other electronic communications unless you have authority to do so and the communication complies with applicable privacy and electronic-marketing rules.

7. Customer and Visitor Responsibilities

Customers and Visitors must:

A Customer is not responsible for unauthorised account activity to the extent that it resulted from DarkByte's or a Merchant's failure to use reasonable security measures.

8. Merchant and Merchant User Responsibilities

A Merchant User may access Merchant functions only where the Merchant has authorised that access. Merchant Users must use individual accounts where the Services provide them and must not share a common password or account merely for convenience.

Merchants and Merchant Users must:

A Merchant must not treat an automated validation, warning, classification or platform check as confirmation that its content is legally compliant, complete or safe.

9. Artificial Intelligence and Automated Tools

Where the Services provide or integrate artificial-intelligence, image, nutrition, mapping, categorisation or other automated tools, those tools must be used only for their intended purpose.

You must not:

Merchants remain responsible for reviewing and approving content published on their behalf, including content initially created or suggested by an automated tool.

10. Intellectual Property and Commercial Use

Unless applicable law provides otherwise or we give prior written permission, you must not:

Nothing in this section prevents an individual from expressing an honest opinion or publishing a genuine review based on ordinary lawful use of a customer-facing service.

11. Demo, Test and Trial Workspaces

A workspace or service identified as a demo, test, preview, development or trial environment is for evaluation and authorised testing only.

Unless DarkByte expressly confirms otherwise in writing, you must not use a demo, test or trial environment for:

Demo and test data may be changed, reset or deleted without notice. Information shown in a demo environment may be fictitious, incomplete or unsuitable for use in a real transaction.

12. Security Research and Vulnerability Reporting

You must not conduct security testing against the Services unless:

If you believe you have discovered a vulnerability without carrying out prohibited testing, report it promptly to support@nibblekit.com with the subject line Security report.

When reporting a vulnerability:

Reporting a vulnerability does not by itself authorise further testing. Our Security Overview and any published vulnerability-disclosure terms provide additional information.

13. Enforcement

If we reasonably believe that this policy has been breached, we may take proportionate action to protect the Services, Customers, Merchants, third parties or the public.

Depending on the circumstances, that action may include:

We may act without prior notice where we reasonably consider that there is an urgent security, fraud, privacy, food-safety, legal or operational risk. In other cases, we will normally provide notice and an opportunity to correct the breach where reasonably practicable.

Where reasonably possible, we will provide the affected account holder or Merchant with a general explanation of a material suspension or termination. We may withhold information where disclosure could compromise security, another person's rights, a confidential investigation or a legal obligation.

A Merchant may request a review of an enforcement decision by contacting support@nibblekit.com and providing the relevant account, workspace and decision details. A review does not require us to restore access while an urgent risk remains.

Account suspension or termination does not determine how long associated personal data or transaction records are retained. Those records are handled under the Privacy Policy, Data Retention Policy, applicable Merchant agreement and legal requirements.

14. Reporting Misuse

To report suspected misuse of the Services, contact:

Paul Hepple trading as DarkByte Creations Email: support@nibblekit.com

For an urgent security issue, contact:

support@nibblekit.com with the subject line Security report

For an order-specific complaint, contact the Merchant identified in the checkout, order confirmation or receipt unless the Services direct you to a different support route.

Do not include passwords, full payment card details, unnecessary identity documents or unrelated health information in an ordinary email.

15. Changes to This Policy

We may update this policy to reflect changes in law, security risks, technology, platform functions or operational practice.

The current version will show its last-updated date and version number. Where a change materially affects existing account use, we will take reasonable steps to provide notice before or when the change takes effect.

Changes apply prospectively. They do not retrospectively alter the terms governing an order that was completed before the revised policy took effect.

Previous material versions are available on reasonable request from support@nibblekit.com.

16. Contact Details

NibbleKit is operated by:

Paul Hepple, a sole trader trading as DarkByte Creations 152 Lindhurst Road, Barnsley, S71 3DG Email: support@nibblekit.com