ACCEPTABLE USE POLICY
Last updated: 20 June 2026
Effective from: 20 June 2026
Version: 1.0
1. About This Policy
This Acceptable Use Policy governs access to and use of NibbleKit websites, mobile applications, web applications, ordering flows, customer account features, Merchant and administration portals, APIs, verification and reset pages, support services, demo workspaces and related platform services that link to this policy, together referred to as the Services.
The Services are operated by Paul Hepple, a sole trader trading as DarkByte Creations. In this policy, DarkByte, NibbleKit, we, us and our refer to Paul Hepple trading as DarkByte Creations.
For the purposes of this policy:
- a Customer is an individual who browses, creates an account, places or manages an order, submits a support request or otherwise uses a customer-facing part of the Services;
- a Merchant is the food business or other seller that uses NibbleKit to offer products or services;
- a Merchant User is an owner, employee, contractor or other individual whom a Merchant authorises to use a Merchant, staff, support or administration account;
- a Visitor is anyone who accesses a public NibbleKit page without signing in; and
- you means the Customer, Merchant User, Visitor or other person accessing the Services.
This policy applies differently according to the capacity in which you use the Services. Customer use is also governed by the NibbleKit Terms and Conditions and, where applicable, the End User Licence Agreement. Merchant and Merchant User access is also governed by the applicable Merchant agreement, authorised-user terms and any written security or data-processing requirements agreed with the Merchant.
This public policy does not replace the Merchant agreement. Where there is a conflict concerning a Merchant's business account or its authorised users, the Merchant agreement will take priority to the extent permitted by law.
2. General Standard of Use
You must use the Services only:
- for their intended and authorised purposes;
- in a lawful, honest and responsible manner;
- in accordance with the access permissions assigned to you;
- without harming or unreasonably disrupting DarkByte, a Merchant, another user or any third party; and
- without creating an avoidable security, privacy, food-safety, operational or legal risk.
You must follow reasonable security and operational instructions displayed in the Services or communicated to you by DarkByte or, where relevant, the Merchant that authorised your access.
Nothing in this policy prevents a Customer from making a genuine complaint, exercising a statutory right, disputing an unauthorised transaction or reporting a security or safety concern in good faith.
3. Unlawful, Fraudulent or Abusive Use
You must not use or attempt to use the Services:
- in breach of any applicable law, regulation, court order or binding regulatory requirement;
- to commit, facilitate, encourage or conceal fraud, theft, money laundering, identity misuse or other dishonest conduct;
- to create false accounts, impersonate another person or falsely claim to act for a Merchant, Customer or organisation;
- to place false or malicious orders;
- to manipulate promotions, referral schemes, loyalty balances, vouchers, credits, discounts or pricing;
- to obtain a refund, credit, replacement, payment reversal or chargeback by knowingly providing false or misleading information;
- to seek duplicate recovery, such as knowingly retaining both a refund and an overlapping chargeback for the same amount;
- to use payment credentials, accounts, personal data or identity information without proper authority;
- to bypass an age, location, eligibility, payment, verification or access control;
- to offer, advertise or facilitate products or services that are illegal or that the relevant Merchant is not legally authorised to supply;
- to threaten, intimidate, exploit, harass, stalk or abuse another person;
- to incite violence, hatred or unlawful discrimination;
- to exploit, endanger or sexually abuse a child or other vulnerable person;
- to submit content intended to cause panic, material distress or physical harm; or
- to obstruct a lawful investigation, complaint, privacy request, recall, food-safety response or security investigation.
A genuine complaint, statutory claim or payment dispute is not prohibited merely because DarkByte or a Merchant disagrees with it.
4. Security and Technical Misuse
You must not:
- gain or attempt to gain access to an account, role, order, record, system, database, API, payment flow, Merchant workspace or administrative function that you are not authorised to access;
- use another person's login credentials or allow another person to use credentials assigned personally to you;
- perform credential stuffing, password spraying, session hijacking, token theft, enumeration or similar account attacks;
- introduce malware, ransomware, spyware, credential-stealing software, destructive code, corrupted data or any other harmful material;
- interfere with the availability, integrity, security or performance of the Services;
- overload the Services or carry out a denial-of-service or distributed denial-of-service attack;
- circumvent rate limits, authentication controls, audit logging, fraud controls, feature restrictions or technical safeguards;
- probe, scan or test the vulnerability of the Services except under prior written authorisation or an applicable published vulnerability-disclosure process;
- intercept, monitor or modify communications or data without authority;
- alter an order status, payment status, refund status, delivery status, collection record, audit entry or other operational record dishonestly or without authority;
- use bots, scripts, crawlers, scraping tools or other automated systems in a way that places an unreasonable load on the Services or exceeds documented permissions;
- use an API other than in accordance with its documentation, assigned credentials and agreed limits; or
- attempt to conceal the source, identity or nature of prohibited activity.
You must not reverse engineer, decompile, disassemble or otherwise attempt to derive the source code, non-public structure or internal operation of the Services, except to the extent that applicable law grants a right that cannot lawfully be excluded.
You must not use the Services to:
- collect, upload, access, disclose, export or otherwise process personal data without proper authority and a lawful purpose;
- access Customer, Merchant, staff, order, delivery, payment, allergy or support information for personal curiosity or any purpose unrelated to your authorised role;
- upload more personal data than is reasonably necessary for the relevant feature or request;
- enter passwords, full payment card details, identity documents or unnecessary health information into an ordinary support form, free-text field or other unapproved location;
- disclose personal data or confidential information to an unauthorised person;
- send Customer or Merchant data to a personal email account, personal cloud-storage account, unapproved messaging service or unapproved artificial-intelligence service;
- use Customer data for independent marketing, profiling, sale, enrichment or advertising without proper authority and a lawful basis;
- combine NibbleKit data with other datasets in a way that is unlawful, unexpected or outside your authorised purpose;
- attempt to identify a person from anonymised or aggregated information;
- use screenshots, exports or reports containing personal data for training, demonstrations, publicity or social media without proper authority and appropriate protection; or
- retain an export or local copy after it is no longer needed.
Where a feature permits allergy, dietary or other health-related information to be entered, you must use that feature only for its stated purpose and must not copy the information into unrelated tools or fields.
6. Content and Communications
You must not upload, publish, transmit or communicate content that:
- is unlawful, fraudulent, defamatory or knowingly false;
- infringes intellectual property, confidentiality, privacy, publicity or other legal rights;
- contains malware, hidden tracking or deceptive links;
- contains personal data that you have no authority to disclose;
- is threatening, harassing, discriminatory or abusive;
- falsely presents an opinion, endorsement or communication as having come from DarkByte, NibbleKit, a Merchant or another person;
- misrepresents the identity, legal status, location or contact details of a Merchant;
- misrepresents a product's price, quantity, availability, ingredients, allergens, nutrition, dietary suitability, preparation, origin, safety or legal status;
- makes an unsupported medical, health, "free-from", nutrition or therapeutic claim;
- conceals or understates a known allergen, food-safety, product-safety or recall issue; or
- is designed to deceive a Customer about the seller, payment recipient, refund responsibility, fulfilment provider or delivery provider.
You must not use the Services to send unsolicited marketing or other electronic communications unless you have authority to do so and the communication complies with applicable privacy and electronic-marketing rules.
7. Customer and Visitor Responsibilities
Customers and Visitors must:
- provide information that is accurate to the best of their knowledge;
- provide a valid delivery or collection contact where required;
- use only payment methods and accounts that they are authorised to use;
- protect their login credentials and tell us promptly if they believe an account has been compromised;
- avoid knowingly submitting false allergy, delivery, support, refund or privacy-request information;
- communicate respectfully with Merchant staff, delivery personnel and support personnel;
- use any cancellation, complaint, refund and payment-dispute process honestly; and
- avoid uploading unnecessary sensitive information.
A Customer is not responsible for unauthorised account activity to the extent that it resulted from DarkByte's or a Merchant's failure to use reasonable security measures.
8. Merchant and Merchant User Responsibilities
A Merchant User may access Merchant functions only where the Merchant has authorised that access. Merchant Users must use individual accounts where the Services provide them and must not share a common password or account merely for convenience.
Merchants and Merchant Users must:
- provide complete and accurate information about the Merchant's legal identity, trading name, geographic address and customer-service contact details;
- ensure that Customers can identify the seller before placing an order;
- maintain accurate and current menus, prices, taxes, compulsory fees, availability, delivery or collection settings and ordering restrictions;
- maintain accurate, current and item-specific ingredient, allergen, dietary, nutrition, preparation and food-safety information;
- ensure that required product and allergen information is reviewed before publication;
- make only claims that the Merchant can substantiate;
- correct or withdraw materially inaccurate content without undue delay;
- ensure that substitutions, recipe changes and supplier changes do not make published safety information inaccurate;
- grant access only to people who need it for their work;
- apply the least level of access reasonably required;
- remove or amend access promptly when a person changes role or stops working for the Merchant;
- protect Customer and staff information after it has been exported from the Services;
- keep devices used for Merchant administration reasonably secure;
- use multifactor authentication where it is made available or required;
- review warnings and audit information made available through the Services;
- report suspected unauthorised access, data exposure, fraud or food-safety issues promptly; and
- comply with the Merchant's contract with DarkByte and all laws applicable to the Merchant's business.
A Merchant must not treat an automated validation, warning, classification or platform check as confirmation that its content is legally compliant, complete or safe.
Where the Services provide or integrate artificial-intelligence, image, nutrition, mapping, categorisation or other automated tools, those tools must be used only for their intended purpose.
You must not:
- represent an automated output as independently verified when it has not been checked;
- use an automated output as the sole basis for a final allergen, ingredient, food-safety, medical or legal statement;
- use an automated tool to fabricate a product image, ingredient list, review, order record or other information in a misleading way;
- submit Customer personal data, allergy information, confidential information or payment information to an unapproved AI service;
- attempt to manipulate an automated feature through malicious prompts, hidden instructions or deliberately corrupted inputs;
- use automated outputs to discriminate unlawfully or make an unfair decision about a person; or
- enable or publish an AI-generated safety claim without appropriate human review by the responsible Merchant.
Merchants remain responsible for reviewing and approving content published on their behalf, including content initially created or suggested by an automated tool.
10. Intellectual Property and Commercial Use
Unless applicable law provides otherwise or we give prior written permission, you must not:
- copy or reproduce a material part of the Services;
- resell, sublicense, rent or commercially exploit access to the Services;
- create an unauthorised competing service using non-public NibbleKit materials;
- remove or alter proprietary, copyright, trade-mark or attribution notices;
- systematically extract Merchant or Customer data;
- use NibbleKit branding in a way that suggests an unauthorised partnership or endorsement; or
- conduct intrusive or systematic performance, security or comparative benchmarking for commercial publication.
Nothing in this section prevents an individual from expressing an honest opinion or publishing a genuine review based on ordinary lawful use of a customer-facing service.
11. Demo, Test and Trial Workspaces
A workspace or service identified as a demo, test, preview, development or trial environment is for evaluation and authorised testing only.
Unless DarkByte expressly confirms otherwise in writing, you must not use a demo, test or trial environment for:
- real food or product orders;
- live payments or refunds;
- real Customer fulfilment;
- real delivery or collection operations;
- personal data relating to an identifiable Customer or member of staff;
- allergy or health information;
- payment card information;
- confidential business information; or
- records that the Merchant is legally required to preserve.
Demo and test data may be changed, reset or deleted without notice. Information shown in a demo environment may be fictitious, incomplete or unsuitable for use in a real transaction.
12. Security Research and Vulnerability Reporting
You must not conduct security testing against the Services unless:
- DarkByte has given you prior written authorisation; or
- the testing falls clearly within the scope of a vulnerability-disclosure process published by DarkByte.
If you believe you have discovered a vulnerability without carrying out prohibited testing, report it promptly to support@nibblekit.com with the subject line Security report.
When reporting a vulnerability:
- do not access more information than is reasonably necessary to describe the issue;
- do not modify, download, retain or disclose information belonging to another person;
- stop testing if you encounter personal data, payment information or confidential records;
- do not use social engineering, physical intrusion, denial-of-service testing or destructive testing;
- give us a reasonable opportunity to investigate and address the issue before making it public; and
- include enough information for us to reproduce and assess the issue safely.
Reporting a vulnerability does not by itself authorise further testing. Our Security Overview and any published vulnerability-disclosure terms provide additional information.
13. Enforcement
If we reasonably believe that this policy has been breached, we may take proportionate action to protect the Services, Customers, Merchants, third parties or the public.
Depending on the circumstances, that action may include:
- asking you to explain or correct the activity;
- issuing a warning;
- requiring content to be corrected, removed or reapproved;
- removing, hiding or restricting content;
- restricting a feature, integration, token, device or network address;
- resetting credentials or requiring additional verification;
- temporarily suspending an account or role;
- terminating access for a serious or repeated breach;
- preserving relevant records;
- informing the Merchant that authorised your access;
- reversing or referring a fraudulent platform action where technically and legally appropriate;
- notifying a payment provider, app store, service provider, regulator or law-enforcement body where appropriate and lawful; or
- taking legal action.
We may act without prior notice where we reasonably consider that there is an urgent security, fraud, privacy, food-safety, legal or operational risk. In other cases, we will normally provide notice and an opportunity to correct the breach where reasonably practicable.
Where reasonably possible, we will provide the affected account holder or Merchant with a general explanation of a material suspension or termination. We may withhold information where disclosure could compromise security, another person's rights, a confidential investigation or a legal obligation.
A Merchant may request a review of an enforcement decision by contacting support@nibblekit.com and providing the relevant account, workspace and decision details. A review does not require us to restore access while an urgent risk remains.
Account suspension or termination does not determine how long associated personal data or transaction records are retained. Those records are handled under the Privacy Policy, Data Retention Policy, applicable Merchant agreement and legal requirements.
14. Reporting Misuse
To report suspected misuse of the Services, contact:
Paul Hepple trading as DarkByte Creations Email: support@nibblekit.com
For an urgent security issue, contact:
support@nibblekit.com with the subject line Security report
For an order-specific complaint, contact the Merchant identified in the checkout, order confirmation or receipt unless the Services direct you to a different support route.
Do not include passwords, full payment card details, unnecessary identity documents or unrelated health information in an ordinary email.
15. Changes to This Policy
We may update this policy to reflect changes in law, security risks, technology, platform functions or operational practice.
The current version will show its last-updated date and version number. Where a change materially affects existing account use, we will take reasonable steps to provide notice before or when the change takes effect.
Changes apply prospectively. They do not retrospectively alter the terms governing an order that was completed before the revised policy took effect.
Previous material versions are available on reasonable request from support@nibblekit.com.
NibbleKit is operated by:
Paul Hepple, a sole trader trading as DarkByte Creations 152 Lindhurst Road, Barnsley, S71 3DG Email: support@nibblekit.com