Document information
- Owner / operator
- Mugpire, LLC, a Wyoming limited liability company, doing business as OppAction
- Document status
- Effective
- Revision date
- September 8, 2026
- Intended users
- Businesses and authorized business users only
- Policy URL
- View the published Acceptable Use Policy
1. Scope, Definitions, and Relationship to the Terms
This Acceptable Use Policy (the “AUP”) applies to each Customer and Authorized User that accesses or uses the Services. Capitalized terms not defined here have the meanings given in the OppAction Terms of Service (the “Terms”).
OppAction currently provides Shopify-focused ecommerce listing analysis, scoring, optimization drafts, catalog workflows, and related review tools. References in this AUP to APIs, automation, synchronization, publishing, AI agents, or other functionality apply only if OppAction actually makes that functionality available to Customer and Customer enables or uses it.
This AUP is incorporated into the Terms. If this AUP conflicts with another Agreement document, the order of precedence in the Terms controls: (a) a separately signed enterprise agreement; (b) the applicable Order, including a Shopify charge-approval screen; (c) an applicable Data Processing Addendum (the “DPA”); (d) an accepted Feature Addendum; (e) the Terms; and (f) incorporated policies, including this AUP. Each document controls only within its stated scope. The Privacy Policy provides notice about Personal Information, the DPA controls OppAction’s processor or service-provider processing, and the AI & Automation Disclaimer at https://oppaction.com/ai-policy provides additional disclosures concerning AI, recommendations, automation, and Marketplace activity.
2. Baseline Responsibilities
Customer must use the Services lawfully, in good faith, and only for authorized business purposes. Customer is responsible for its Authorized Users and for the content, products, listings, claims, settings, permissions, and connected Marketplace accounts used with the Services.
- Follow applicable laws, the Agreement, Documentation, Marketplace rules, and provider policies presented as applicable to a feature.
- Use only permissions, access scopes, data, accounts, and systems that Customer is authorized to use.
- Review and substantiate AI Outputs and merchant-facing claims before publishing, applying, or relying on them.
- Promptly address known misuse, unauthorized access, credential compromise, or material policy violations involving the Account.
3. Illegal, Harmful, Abusive, or Deceptive Conduct
Customer may not use the Services to create, facilitate, promote, transact in, or materially assist:
- illegal activity, illicit goods or services, fraud, scams, phishing, spam, impersonation, deceptive advertising, or evasion of legal or regulatory requirements;
- threats, intimidation, harassment, defamation, hate-based abuse, terrorism, violence, sexual violence, non-consensual intimate content, or promotion or facilitation of self-harm;
- weapons development, procurement, or use, including chemical, biological, radiological, nuclear, or explosive weapons;
- child sexual abuse material, grooming, sexualization or exploitation of a minor, age-inappropriate sexual or violent content directed to minors, or access by minors to age-restricted goods or activities;
- real-money gambling or another use prohibited by an applicable provider policy or Marketplace rule; or
- conduct intended to bypass safeguards, conceal prohibited activity, or induce OppAction or a provider to violate law or binding policy.
4. Ecommerce and Marketplace Integrity
Customer may not use the Services to manipulate a Marketplace, mislead merchants or buyers, or interfere with fair commerce. Prohibited conduct includes:
- fake, purchased, coordinated, or incentivized reviews; fabricated testimonials, endorsements, purchase notifications, engagement, rankings, traffic, or conversion signals;
- counterfeit, stolen, infringing, unsafe, unlawfully marketed, or prohibited products or listings;
- false, unsubstantiated, or misleading product, health, safety, environmental, pricing, scarcity, comparison, origin, certification, or performance claims;
- click fraud, ranking manipulation, bot-network activity, traffic laundering, account farming, or coordinated abuse;
- bypassing Shopify checkout, billing, approval, permission, privacy, or other core platform controls where those controls apply; or
- using a Marketplace connection outside the permissions and workflows deliberately authorized by the applicable merchant.
5. Privacy, Personal Information, and Sensitive Data
Customer may not use the Services to compromise another person’s privacy or to collect, infer, aggregate, monitor, profile, disclose, sell, or distribute Personal Information without a lawful basis and required authorization.
- Do not submit passwords or authentication secrets. Customer must not submit health information, full payment-card data, government identifiers, biometric data, precise geolocation, children’s Personal Data, GDPR special-category data, or comparable sensitive or regulated data (collectively, “Prohibited Sensitive Data”). No exception is permitted unless an authorized OppAction representative gives prior written Legal approval in a signed Order or supplemental agreement that documents the lawful basis, required security measures, and an approved secure technical workflow.
- Do not build facial-recognition databases without data-subject consent; perform real-time remote biometric identification in public spaces; or use a person’s likeness or voice deceptively without authorization.
- Do not use social scoring; prohibited sensitive-trait inference; unauthorized surveillance; emotion inference in workplace or educational settings except where necessary for medical or safety reasons; assessment or prediction of criminal risk based solely on personal traits or profiling; or other profiling that violates law or materially affects a person’s rights or access to opportunities.
- Do not circumvent consent, access-scope, data-minimization, deletion, redaction, or privacy controls imposed by OppAction, Shopify, another Marketplace, or applicable law.
These personal-data restrictions are separate from the product-claim requirements in Sections 4 and 7. Because free-form inputs cannot guarantee technical prevention of accidental receipt, OppAction may restrict access, suspend affected processing, contain and delete Prohibited Sensitive Data, invoke incident-response procedures, and notify Customer as appropriate. Customer will reasonably cooperate with containment and remediation.
6. Security, Technical Abuse, and Service Integrity
Customer may not interfere with, compromise, or place unreasonable load on the Services, a Marketplace, a provider, or another person’s systems or data.
- No malware, ransomware, malicious code, denial-of-service activity, credential attacks, unauthorized access, destructive cyber activity, or exploitation of vulnerabilities.
- No scraping, harvesting, crawling, bulk extraction, or automated access except through functionality and limits OppAction expressly supports.
- No bypassing rate limits, usage limits, authentication, permissions, safety filters, moderation, or other technical safeguards.
- No reverse engineering, decompiling, disassembling, prompt extraction, or discovery of non-public source code, models, or system components, except to the extent a restriction is prohibited by law.
- No unsolicited penetration testing, vulnerability scanning, red teaming, or safety testing. Authorized research must follow written scope and testing rules supplied by OppAction.
- No resale, sublicensing, time-sharing, credential pooling, or making the Services available as an unauthorized standalone service.
7. AI-Assisted Uses and High-Stakes Decisions
Customer must not use AI-assisted functionality in a manner prohibited by applicable AI-provider policies. Without limiting Sections 3 through 6, Customer may not use AI-assisted functionality for:
- tailored legal, medical, financial, or other licensed professional advice without appropriate involvement by a qualified professional and disclosure of material AI limitations where required;
- academic dishonesty;
- fully automated high-stakes decisions affecting a person in employment, housing, education, credit, insurance, healthcare, legal services, essential government services, migration, law enforcement, critical infrastructure, or product-safety functions without meaningful human review and legally required safeguards;
- political campaigning, lobbying, election interference, voter suppression or demobilization, or deceptive political persuasion;
- national-security or intelligence uses without required provider review and approval; or
- circumventing AI safety controls, concealing prohibited prompts or content, or attempting to cause a provider to generate or process prohibited material.
AI Outputs are probabilistic and may be inaccurate, incomplete, non-original, or unsuitable. Customer must review, verify, and approve outputs and claims before publication or material reliance.
8. Automation, Batch Actions, and Connected Workflows
If OppAction makes an automated, batch, API, synchronization, publishing, or agentic feature available, OppAction will identify the disclosed function and available controls before Customer enables batch auto-apply or another automated action. Customer must deliberately configure its scope, test it in an appropriate environment, supervise its operation, maintain appropriate backups, and use available review and approval controls.
Customer is responsible for instructions, permissions, settings, and workflows that its authorized personnel deliberately enable. Platform records may be relevant evidence of activity but do not create an irrebuttable presumption that every action was authorized, accurate, or lawful.
Customer may not use automation to perform conduct prohibited by this AUP, evade rate or usage limits, generate excessive or abusive requests, or continue an action after notice that it creates a material security, legal, provider, or Marketplace risk.
9. Content, Intellectual Property, and Competitive Conduct
- Customer must have all rights and permissions necessary for Customer Content, prompts, product information, images, listings, claims, connected accounts, and requested processing.
- Customer may not infringe, misappropriate, or violate intellectual-property, publicity, confidentiality, privacy, or other third-party rights.
- Customer may not use non-public OppAction Materials, Confidential Information, extracted prompts, or restricted technical information to develop or train a competing product or model.
- Customer may not publish a benchmark intended to mislead or disclose non-public performance, security, pricing, or technical information without authorization and reasonable context.
Nothing in this Section prohibits lawful independent development, good-faith comparative evaluation using publicly available information, protected reporting, or activity that cannot lawfully be restricted.
10. Credentials, Tokens, and Connected Accounts
Customer must protect credentials, OAuth tokens, access keys, and connected-account permissions; restrict them to personnel and service providers with a legitimate need; and promptly revoke or rotate them after suspected compromise.
Credential sharing outside supported team features, token pooling, public exposure, sale or transfer of credentials, API sublicensing, and use of another person’s or merchant’s account without authorization are prohibited.
11. Export Controls, Sanctions, and Restricted Access
Customer may not access or use the Services in violation of applicable export-control, sanctions, embargo, or trade laws or permit access by a prohibited person or from a prohibited territory. OppAction may restrict access or cooperate with providers, Marketplaces, or authorities as reasonably necessary for compliance with law and binding obligations.
12. Monitoring, Investigation, and Preservation
OppAction may use automated and manual methods to detect, investigate, and respond to suspected violations, fraud, abuse, security threats, provider notices, or legal requirements. To the extent reasonably necessary and permitted by law, this may include reviewing available Account records, Customer Content implicated in a report, AI inputs and outputs, authentication events, technical logs, Usage Data, and connected-workflow activity.
OppAction’s collection, use, disclosure, and retention of information remains subject to the Privacy Policy, the Agreement, applicable law, and any applicable DPA. OppAction may preserve relevant records when reasonably necessary for security, fraud prevention, legal compliance, dispute preservation, or enforcement.
OppAction does not undertake a duty to monitor every user, workflow, output, listing, or transaction or to detect or prevent every violation.
13. Enforcement, Emergency Action, and Review
When OppAction reasonably believes that activity violates this AUP or creates a material legal, security, provider, Marketplace, or service-integrity risk, OppAction may take proportionate action, including warning the Customer, blocking content or requests, limiting functionality, throttling activity, disconnecting an integration, invalidating a token, suspending access, preserving relevant evidence, or terminating affected Services as permitted by the Terms.
Emergency action may be immediate and may be automated where reasonably necessary to address suspected compromise, ongoing abuse, imminent harm, provider requirements, or unlawful activity. Where practicable and legally permitted, OppAction will provide notice and an opportunity to cure a remediable violation.
Automated or provider-generated signals may be incomplete or produce false positives. Customer may request review of an enforcement decision by contacting legal@oppaction.com with the Account, relevant event, and reasons the decision should be reconsidered. Failure to enforce a provision once does not waive future enforcement.
14. Reporting Violations and Security Concerns
Suspected AUP violations, illegal content, or abuse may be reported to legal@oppaction.com. Security vulnerabilities, credential compromise, or suspected unauthorized access should be reported to security@oppaction.com. Reports should include enough information to identify the Account, content, event, and risk without unnecessarily transmitting sensitive data.
15. Updates, Governing Terms, and Contact
OppAction may update this AUP prospectively as described in the Terms. OppAction will provide notice or obtain affirmative reacceptance when required by the Terms, an applicable DPA, or applicable law. Passive publication does not override a required notice, acceptance, or consent. Provider and Marketplace rules may also change and apply to the connected functionality they govern.
The Terms—including their disclaimers, liability limitations, indemnification provisions, dispute-resolution framework, and order of precedence—govern this AUP. This AUP does not expand OppAction’s processing rights beyond the Privacy Policy, the Agreement, applicable law, or an applicable DPA.
Mugpire, LLC d/b/a OppAction · PO Box 2869 · Jackson, WY 83001 · legal@oppaction.com · OppAction website