1. Scope and responsibilities
Version: September 23, 2026. This Acceptable Use Policy describes the permitted use of Soffyt’s workspaces, customer portals, files, integrations, and other service features. It forms part of the agreement when incorporated into the Terms of Service or another agreement accepted by your organization and Soffyt LLC. Your organization is responsible for making these rules available to its authorized users and for their use of its workspace. The Terms of Service govern suspension, termination, fees, refunds, and liability and control any conflict with this policy.
Read the Terms of Service2. Lawful and honest business activity
Use Soffyt for legitimate business operations and only where you have authority to act. Do not use the service to commit fraud, impersonate another person or business, misrepresent authorization, or facilitate unlawful activity. Do not create or distribute content that unlawfully threatens, harasses, exploits, or discriminates against others, or that infringes their privacy or intellectual property rights.
- Do not fabricate customer approval, signatures, payment receipts, inspection results, or other evidence of work or payment. Correct an inaccurate record through the appropriate correction process rather than using the service to conceal fraud.
- Use clear sender and company identities. Do not mislead customers about who is providing the work, what has been agreed, or whether a payment has settled.
- Your organization remains responsible for its contractor licenses, customer agreements, required notices, workplace practices, taxes, and other obligations. A template or product feature does not establish compliance on its own.
3. Authorized access and account security
Access only the accounts, organizations, records, and connections you are permitted to use. Keep login credentials and access links secure, use individual user accounts, and follow your organization’s access procedures. Do not bypass permissions, impersonate users, share seats to avoid subscription limits, or retain access after your authorization ends.
- Do not obtain, guess, steal, publish, or misuse another person’s password, session, access token, or customer portal link.
- Do not use a configuration mistake or software flaw to open another organization’s records, change its data, or test how much information you can retrieve.
- If you encounter unexpected access, stop the affected activity and report the location and what you observed. Do not collect additional records to demonstrate the issue.
4. Customer information, files, and sharing
Upload, import, connect, or share information only when you have the necessary rights and a lawful business purpose. Use the minimum information needed for the work. Review the recipient, organization, and visibility settings before sharing quotes, documents, photos, messages, or portal access. Respect confidentiality commitments and the rights of customers, workers, and other people whose information you handle.
- Do not upload stolen records, unlawfully obtained contact lists, or files you are not entitled to use. Respect licenses for templates, images, maps, and other third-party material.
- Do not put full payment-card numbers, card security codes, passwords, or access tokens in notes, files, messages, or support requests. Use the designated provider’s secure payment or authorization flow where available.
- Do not submit information requiring specialized regulated processing that Soffyt has not expressly agreed to provide, or use the service for emergency response or safety-critical decisions.
- Do not use location sharing for covert surveillance, unauthorized tracking, or off-duty monitoring. Do not bypass a worker’s sharing controls or falsify location, mileage, or time records. Use the applicable correction process and retain required attribution.
- Provide required notices and obtain any necessary permissions before collecting or using worker, customer, location, or communication information. A device permission or an integration connection does not replace those responsibilities.
5. Messages and connected services
Use communication features and connected accounts only for purposes you are authorized to carry out. Do not send phishing messages, deceptive payment requests, unlawful spam, or messages with misleading identities or subject lines. For commercial messages, provide required sender information, disclosures, and opt-out methods, and honor applicable consent, preference, and unsubscribe requirements. Do not disguise advertising as a necessary service message to evade those requirements.
- Do not use purchased or harvested recipient lists without a lawful basis and any required permissions. Do not reconnect an account, change senders, or use another feature to evade an opt-out, provider restriction, or suspension.
- Connect only accounts your organization is authorized to use. Respect the connected provider’s terms, permitted purposes, access scopes, and sending or usage limits.
- Do not use an integration to access or transfer information beyond the authorization granted. Disconnect access when it is no longer authorized and separately request any necessary deletion of retained records.
6. Protecting the service
Do not introduce malware, ransomware, malicious scripts, or files intended to compromise the service or another person’s device. Do not disrupt availability, damage records, overload the service, defeat file checks, or evade rate, storage, seat, or other plan limits. Do not use the service as a general-purpose file distribution network or resell access without Soffyt’s written agreement.
- Use supported import, export, and integration functions within their intended scope. Do not use scripts, scraping, or repeated requests to bypass authorization or usage controls.
- Do not perform intrusive security scans, exploitation, denial-of-service tests, or load tests against Soffyt without prior written authorization identifying the permitted scope. Ordinary authorized use and reporting a problem encountered during that use are allowed.
- Do not reverse engineer the service except to the extent applicable law permits it despite a contractual restriction. This policy does not limit rights that cannot lawfully be restricted.
7. Reporting misuse or a security concern
Report suspected misuse to support@soffyt.com. Include the affected page or record location, your organization if relevant, the approximate time, a brief description, and a way to contact you. For a suspected security issue, share only enough detail to locate and understand it; do not include credentials or copies of unrelated customer information. If sensitive evidence is needed, ask how to provide it securely.
- If you believe material infringes your rights, identify the material and its location, describe your rights and concern, and provide contact details for follow-up. Do not attach an entire customer file when a description or record reference is sufficient.
- For a privacy, access, or deletion request, contact privacy@soffyt.com so it can be routed through the appropriate verification and organization process.
8. Investigation and proportionate action
Soffyt may investigate a credible report and take action reasonably necessary to stop misuse, protect people and information, or comply with law. Depending on the circumstances, action may include requesting a correction, restricting a file or connection, disabling affected access, or applying the suspension or termination provisions in the Terms of Service. We will limit the action to affected content, users, or functions where reasonably practicable.
- Where lawful and practicable, we will explain the issue and provide an opportunity to correct it. Immediate restrictions may be necessary for a serious security threat, ongoing harm, or a legal requirement. Repeated or serious violations may result in termination under the agreement.
- Investigation and any retention or disclosure of information remain subject to the agreement, privacy policy, and applicable law. A report does not give another customer permission to access the affected records.
- This policy does not guarantee that every file, message, or activity is reviewed or that every misuse will be detected. A restriction does not automatically erase organization records or determine a refund; those matters follow the agreement and applicable law.
9. Requesting a review
If you believe an action was taken in error or have corrected the issue, reply to the notice or contact support@soffyt.com. Identify your organization, the affected account or content, and the facts supporting your request. Soffyt will consider the information and explain the outcome where lawful. We may need to verify your authority before discussing organization records. Do not create another account or use someone else’s access to bypass a restriction while a review is pending.
Request a review10. Policy changes and questions
Material changes to this policy follow the notice and acceptance process in the Terms of Service or the separate agreement that incorporates it. The version accepted for a subscription remains the applicable version until changed through that process. An update does not retroactively change how an existing dispute is handled. Contact hello@soffyt.com if you need to discuss whether a planned workflow is supported before using it with customer or worker information.
Ask about a planned use