Acceptable Use Policy
A plain set of rules for using Mtrix responsibly. It governs what you may collect, build and send through the platform, and the conduct we prohibit because our script runs on real, live storefronts.
1. Introduction & scope
This is a conduct policy. It tells you what you can and cannot do with Mtrix and with the data the platform handles. It is part of your agreement with us, it binds you and everyone you let into your account, and breaking it can lead to enforcement up to suspension or termination.
This Acceptable Use Policy (the AUP) sets out the rules for using Mtrix, the analytics and experimentation platform operated by Mtrix Inc. (Mtrix, we, us). It applies to you (the Customer), to every Authorized User you provision, and to anyone who accesses the Services through your account or your credentials. You are responsible for their conduct as if it were your own.
This AUP is incorporated by reference into our Terms of Service and works alongside our Data Processing Addendum (the DPA). Using the Services means you accept it. In the rare event of a direct conflict, the order of precedence in the Terms applies: an Order Form controls over product-specific terms, which control over the DPA, which controls over the Terms on any personal-data-processing question, which control over this AUP. The AUP overrides the Terms only to the narrow extent needed to resolve a direct conflict about acceptable use.
This policy is written in plain language on purpose. It is not an exhaustive list of everything that is unacceptable; it describes the categories of misuse we care about most. We may treat conduct that is clearly abusive, unlawful, or harmful to other customers or to end users as a violation even if it is not spelled out below.
Capitalized terms not defined here have the meaning given in our Terms of Service or DPA.
2. Compliance with laws
You must use Mtrix legally. That means following the privacy, electronic-communications, consumer-protection, anti-spam and trade-control laws that apply to you, your store and your end users — not just the ones in your own country.
You must comply with all laws, regulations and codes that apply to your use of the Services and to the data you process through them. Depending on where you and your end users are located, that includes, without limitation:
- Data protection and privacy law — the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act, the Swiss Federal Act on Data Protection (FADP), and US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), together with comparable laws in other states and countries.
- Electronic-communications and cookie law — the EU ePrivacy Directive and its national implementations, and equivalent rules governing cookies, tracking technologies and access to information stored on an end user's device. You are responsible for the consent that law requires before our SDK reads or writes anything on a visitor's browser on your site.
- Consumer-protection and advertising law — rules against unfair, deceptive or misleading commercial practices, including pricing, claims, reviews and disclosure requirements.
- Anti-spam law — the US CAN-SPAM Act, Canada's Anti-Spam Legislation (CASL), the ePrivacy rules on electronic marketing, and similar regimes, for any messaging you create or send with the platform.
- Export controls and sanctions — applicable export, re-export and economic sanctions laws. You may not use the Services if you are located in, ordinarily resident in, or organised under the laws of an embargoed jurisdiction, or if you are a restricted or sanctioned party, and you may not provide access to anyone who is.
Where more than one rule could apply, follow the stricter one. Compliance with this AUP does not relieve you of any obligation under law, and nothing in it grants you permission to do something the law forbids.
3. Your responsibility for end-user data, consent & lawful basis
For the data Mtrix captures from your visitors, you are the controller and we are your processor. That means the legal basis, the privacy notices, the consent and the opt-outs are yours to get right. We give you the tooling; you make the calls.
Mtrix processes Customer End-User Data — analytics and clickstream events, masked session recordings, A/B experiment-exposure metadata, performance and error telemetry, device and browser information, IP address and derived location, timestamps and URLs — on your behalf and on your documented instructions. For that data you act as the Controller (or as a processor for your own clients) and Mtrix acts as your Processor (or Sub-processor). The full allocation of roles and obligations is set out in our DPA.
Because you are the controller, the following are your responsibility, not ours:
- establishing a valid lawful basis under the GDPR, the UK GDPR, the FADP or applicable US law for every kind of processing you carry out through the Services, including analytics, session recording, heatmaps, experimentation and performance and error monitoring;
- providing your end users with clear, accurate and complete privacy notices that disclose your use of Mtrix and of session recording, and that name Mtrix as a processor where required;
- obtaining and recording any consent the law requires — including consent for cookies, similar technologies and recording — before our SDK begins capturing on your site, and configuring the Services so capture only starts once that consent exists;
- honouring opt-outs and preference signals, including the Global Privacy Control (GPC) and any consent withdrawal, and reflecting them in how you configure the SDK;
- responding to Data Subject Requests from your end users as the controller. Mtrix provides tooling to help you find, export and delete an individual's data across modules, and forwards to you any request it receives directly, but Mtrix does not decide the outcome of those requests.
Mtrix supplies the controls — default masking, configurable retention, consent-gated initialisation, GPC handling, and per-user export and deletion tooling — but you decide how to use them. You must not instruct or configure the Services to process end-user data without the lawful basis, notice and consent that the law requires.
4. Sensitive & prohibited data
Some categories of data must never flow into Mtrix unless we have agreed to it in writing. The biggest risk is that this data leaks in indirectly — through a recording, an error payload or an event property — so keep it out at the source.
The Services are general-purpose analytics and experimentation tools. They are not designed or cleared for high-risk categories of data. Except where we have expressly agreed otherwise in writing (for example under a Business Associate Agreement or a specific written authorisation), you must not collect, transmit, store or otherwise process any of the following through the Services (Prohibited Data):
- Protected health information (PHI) regulated by HIPAA or comparable health-privacy laws. Mtrix will act as a HIPAA Business Associate only under a signed BAA, which is available to eligible customers; without one, PHI must stay off the platform.
- Full payment-card data in scope of the PCI DSS — primary account numbers, card verification values, magnetic-stripe or chip data, or full track data.
- Financial-account information regulated under laws such as the US Gramm-Leach-Bliley Act (GLBA), including non-public personal financial information.
- Biometric identifiers and templates regulated by laws such as the Illinois BIPA and comparable regimes.
- Children's personal data regulated by COPPA, the GDPR rules on children, or similar laws, and any data from services directed to children below the applicable age.
- Special-category or sensitive personal data under Article 9 of the GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data processed to identify a person, health, sex life or sexual orientation — and equivalent “sensitive” categories under US state law.
- Government-issued classified information, national identifiers used as the primary content of records (for example social-security or passport numbers), and similar high-sensitivity identifiers.
- Authentication credentials and secrets — passwords, API keys, tokens, security answers and the like.
Because Mtrix captures behaviour, the highest risk is that Prohibited Data enters the platform indirectly: inside a session recording of a form, inside an error or performance payload such as a stack trace or a request or response body, or inside the properties you attach to events. You must design your instrumentation so that Prohibited Data never reaches us — by relying on our default masking and scrubbing, by extending masking to cover any field that might contain it, and by not passing it as event properties or custom metadata. Our default protections, described next, are a floor and not a substitute for your own data minimisation.
5. Session replay, masking & recording hygiene
Mtrix masks sensitive inputs by default and suppresses the most sensitive fields on the visitor's device before anything is sent. Do not turn that protection off to capture data you should not have, and do not record where the law does not allow it.
Session recording is one of the most powerful and most sensitive things Mtrix does, so we ship it locked down by default and ask you to keep it that way:
- Default masking. By default, Mtrix masks the contents of text inputs, form fields and payment fields, so the characters a visitor types are not captured.
-
Never captured. Passwords and fields carrying standard sensitive attributes — for
example
type=passwordandautocomplete=cc-*— are never captured at all. - Suppressed on-device. These sensitive inputs are suppressed on the end user's device before any data leaves the browser, so Mtrix never receives them. There is no copy to leak on our side.
- Telemetry scrubbing. Error and performance payloads — stack traces, request and response bodies, and URLs — are scrubbed for personal data by default.
-
Your controls. You can tighten or loosen what is captured using CSS-selector
blocklists and allowlists and the
data-mtrix-maskanddata-mtrix-unmaskattributes. With that control comes responsibility.
Recording hygiene rules you must follow:
-
Do not weaken masking to harvest sensitive data. You must not disable, bypass or
narrow the default masking, or use
data-mtrix-unmaskor an allowlist, in order to capture Prohibited Data or any other data you have no lawful basis to collect. - Extend masking where you should. Where your own forms collect data that is sensitive in context — even if it does not carry a standard sensitive attribute — you are responsible for adding masking to cover it.
- Only record where it is lawful. You must not record sessions where recording is unlawful, or without the notice and consent the law requires, or in a way that captures private spaces or communications you have no right to capture.
Anything you do choose to capture as sensitive is held in isolated, access-restricted storage, and Mtrix never sells personal data and never shares it for cross-context behavioural advertising. The detailed processing commitments behind these protections are set out in our DPA.
6. Prohibited uses (platform & security)
Do not attack, probe, overload or abuse the platform, and do not use it to host or distribute illegal or harmful content. Some categories — like child sexual abuse material — we report to the authorities.
You must not, and must not permit anyone else to:
Security and integrity
- probe, scan, penetration-test or otherwise test the vulnerability of the Services or our infrastructure, except under a written authorisation we have agreed in advance;
- circumvent, disable or interfere with authentication, authorisation, rate limits, usage metering, quotas or any other security or access-control mechanism;
- access any account, data, tenant or part of the Services you are not authorised to access, or attempt to read, modify or delete another customer's data;
- introduce or transmit malware, ransomware, worms, time bombs or any other malicious or harmful code;
- launch a denial-of-service or distributed-denial-of-service attack, flood, or otherwise deliberately overload or impair the Services;
- scrape, crawl, harvest or extract data from the Services other than through our published APIs and within their documented limits;
- reverse engineer, decompile or disassemble the Services or our SDK except to the extent that restriction is prohibited by applicable law.
Content and conduct
- impersonate any person or entity, or misrepresent your affiliation with a person or entity, including by forging headers or manipulating identifiers;
- infringe the intellectual-property, privacy, publicity or other rights of any person;
- harass, threaten, defame or stalk any person, or engage in conduct that is abusive, hateful or intended to harm;
- store, transmit or distribute content that is unlawful, or that depicts or promotes serious harm.
Some illegal content carries a mandatory response. If we become aware of child sexual abuse material (CSAM) or other content we are legally required to report, we will preserve and report it to the competent authorities and cooperate with them, and we will take immediate action on the account involved.
7. Honest experimentation & no manipulation
Use A/B testing and personalisation to learn what works, not to trick people. Do not use the platform to run dark patterns, fake urgency, or fully automated high-stakes decisions about people without a human in the loop.
Experimentation, personalisation and audience targeting exist to help you understand your customers and improve your store honestly. You must not use them to deceive or manipulate. In particular, you must not use the Services to:
- deploy dark patterns — interface or copy designs engineered to trick, coerce or confuse a person into a decision they would not otherwise make, such as disguised ads, forced continuity, hidden costs, confirm-shaming or obstructed cancellation;
- present fake scarcity or false urgency — fabricated countdowns, invented “only N left” counters, or other false claims about availability, demand or pricing;
- use subliminal or deceptive techniques that materially distort behaviour in a way that impairs a person's ability to make an informed choice.
You must also not use the Services to make, or to materially drive, solely automated decisions that produce legal or similarly significant effects on a person — for example decisions about employment, housing, credit or lending, insurance, education, or access to essential public or private services — without meaningful human review and the disclosures the law requires. This reflects obligations under the GDPR on automated decision-making and the EU AI Act on high-risk uses. Mtrix's experimentation tools are designed to keep a human in the loop; do not repurpose them to remove one.
8. Website builder & CMS content standards
Anything you build and publish with the Mtrix website builder, content models and email creator has to be lawful, honest and safe. No phishing, no malware, no infringing or deceptive content, and no restricted goods you are not allowed to sell.
When you use the visual website builder, content models, CMS or email creator to publish pages, content or messages, that content must meet the same standards as the rest of your use of the Services. You must not create, host, publish or distribute content that:
- is unlawful, infringes a third party's intellectual-property or other rights, or violates a person's privacy or publicity rights;
- is deceptive, fraudulent or misleading, including false claims, fake endorsements or counterfeit goods;
- is malicious — for example pages or messages used for phishing, credential harvesting, scams, or the distribution of malware or unwanted software;
- promotes or facilitates the sale of restricted or prohibited goods and services that you are not lawfully permitted to offer — for example illegal drugs, weapons and explosives, regulated pharmaceuticals sold without authorisation, counterfeits, stolen goods, or other items restricted in the markets you serve;
- contains Prohibited Data. Builder pages, content entries and email templates must not embed PHI, full payment-card data, credentials or any of the other categories listed in section 4.
You are solely responsible for the content you create and publish through the Services and for ensuring it is accurate, lawful and properly licensed.
9. Messaging & marketing communications
If you use Mtrix to send marketing, do it by the book: only message people who have agreed to hear from you, tell the truth about who is sending, and make unsubscribing easy and immediate.
If you use the email creator or any other messaging feature of the Services to send marketing or commercial communications, you must comply with all applicable anti-spam and electronic-marketing laws, including the US CAN-SPAM Act, Canada's CASL, and the ePrivacy rules in the EU, UK and Switzerland. At a minimum, you must:
- have a lawful basis to message each recipient, including any prior consent or permitted relationship the law requires, and keep records that demonstrate it;
- use accurate sender and routing information — truthful “from”, “to” and reply-to fields, accurate headers, and subject lines that are not deceptive;
- identify the message as a commercial communication where the law requires and include a valid physical postal address for the sender;
- provide a clear, working unsubscribe mechanism in every marketing message and honour opt-out requests promptly, within the time the law allows;
- not send unsolicited bulk messages (spam), and not use purchased, scraped or harvested contact lists.
You are the sender of every message you create and dispatch through the Services and are responsible for its content and for compliance.
10. Platform integrity, rate limits & fair use
Use the platform within fair, normal limits. Do not interfere with how usage is measured, do not hammer the ingestion endpoints, and do not split activity across accounts to dodge plan limits. We may throttle or rate-limit traffic that threatens stability.
The Services are shared infrastructure, and our pricing depends on accurate metering of usage such as events, experiment participants, recorded sessions and API calls. To keep the platform stable and fair for everyone, you must not:
- tamper with, obstruct or attempt to falsify usage metering or billing measurement, or otherwise misrepresent your usage;
- send traffic — including synthetic, automated or artificially inflated event volume — that is designed to evade limits, distort analytics, or place an unreasonable load on the Services;
- create multiple accounts, or split a single workload across accounts, in order to circumvent plan limits, free-tier limits, quotas or suspensions;
- use the Services in a way that degrades performance or availability for other customers.
To protect platform integrity, Mtrix may apply rate limits, throttle or shape excessive or abnormal ingestion or API traffic, queue or shed load, and take other reasonable measures. We will aim to apply these in the least disruptive way consistent with protecting the Services and other customers. Specific, published limits in the Documentation form part of this fair-use expectation.
11. Third-party infrastructure & AI sub-processor flow-down
Mtrix runs on third-party infrastructure and AI providers, and they have their own acceptable-use rules. Those rules flow down to you. Where a provider's policy is stricter, the stricter one wins.
The Services rely on third-party infrastructure providers and, for certain features, third-party AI and machine-learning providers, all of which act as Sub-processors. Those providers impose their own acceptable-use and prohibited-use policies, and those policies flow down to your use of the Services. You must:
- comply with the acceptable-use policies of our infrastructure and AI Sub-processors as they apply to the way you use the Services. Where any such policy is more restrictive than this AUP, the more restrictive policy applies;
- not use any AI or machine-learning feature of the Services, or any output of it, to train, fine-tune or otherwise build a product or model that competes with Mtrix;
- not attempt to jailbreak, prompt-inject, or otherwise manipulate any AI feature or its underlying model to bypass safety controls, exfiltrate data, or produce prohibited output;
- not submit to any AI feature content you are not permitted to submit, including Prohibited Data.
For clarity, and as set out in our DPA, Mtrix does not use Customer End-User Data to train foundation models, and our AI Sub-processors are bound by no-training and no-retention commitments.
12. Reporting & enforcement
Tell us if you spot abuse. When we have to enforce, we use the smallest effective step first — because our script runs on live storefronts and we do not want to take down a working store unless we have to. We move faster when there is real danger or a legal requirement.
If you become aware of a violation of this AUP, a security issue, or abusive or illegal use of the Services, please report it to security@mtrix.io. Security vulnerabilities can be reported to the same address under our responsible-disclosure approach described on our Security page; legal and abuse questions can also go to legal@mtrix.io.
Our enforcement is graduated and proportionate. The Mtrix SDK runs on your live store, so a heavy-handed response can break a working business. Wherever we reasonably can, we will choose the narrowest effective measure and give you the chance to fix the problem. Depending on the severity and the risk, our response may include:
- notifying you of the issue and asking you to remediate within a reasonable time;
- restricting, throttling or disabling the specific feature, configuration or data flow that is causing the problem, rather than the whole account;
- removing or disabling offending content;
- suspending the affected account or Authorized User;
- terminating the Services in accordance with the Terms of Service for serious or repeated violations.
We reserve the right to take immediate action, including suspension or content removal without prior notice, where conduct is clearly illegal, presents a risk of imminent harm to people, the platform, or other customers, exposes Prohibited Data, or where we are legally compelled to act. Where we act without prior notice, we will tell you as soon as we reasonably can, unless the law or an investigation prevents it. Enforcement under this AUP is in addition to, and does not limit, our other rights and remedies under the Terms and at law.
13. Relationship to the Terms & DPA
This page is the conduct rulebook. The detailed legal machinery lives elsewhere: how we handle and protect data is in the DPA, the commercial and liability terms are in the Terms, and what we do with your own account data is in the Privacy Policy.
This AUP is intentionally narrow. It governs conduct, and it points you to the documents that carry the rest of the relationship:
- Our Data Processing Addendum covers how we process Customer End-User Data on your behalf — international data transfers (EU/EEA hosting, the EU Standard Contractual Clauses, the UK IDTA and the Swiss adaptation), data retention and deletion windows, our personal-data breach notification commitment (without undue delay and within 72 hours of confirming a breach), our technical and organisational security measures, and our use of Sub-processors (with the named list in Annex III).
- Our Terms of Service cover the commercial relationship — limitation of liability, intellectual-property ownership and licences, fees, warranties, and the governing law and venue (the laws of Estonia and the courts of Harju County, Tallinn).
- Our Privacy Policy covers the data for which Mtrix is itself an independent controller — your Customer Account Data and a narrow set of Service Operations Data — and the privacy rights you have over it.
If anything in this AUP appears to conflict with those documents, the order of precedence in the Terms resolves it, and the DPA prevails on any question about the processing of personal data.
14. Changes to this policy
We can update this policy, and updates take effect when posted. We will not quietly make it materially worse for you mid-term, except where the law, security, abuse or a provider's rules require it — and we will give reasonable notice of significant changes.
We may update this AUP from time to time to reflect new features, new risks, or changes in law. The current version is always the one posted on this page, and changes take effect when posted unless we state a later date. The “Last updated” date at the top of the page shows when it was last revised.
We will not make changes that materially reduce your rights or materially expand the restrictions on your existing use during a paid Subscription Term, except where a change is reasonably necessary to comply with law or regulation, to protect the security or integrity of the Services or their users, to respond to abuse or illegal use, or to reflect a requirement imposed by an infrastructure or AI Sub-processor. For material changes, we will give reasonable advance notice through the Services or by email, consistent with the change-notice commitments in our Terms of Service. Continuing to use the Services after a change takes effect means you accept the updated policy. If you do not agree to a material change, your remedy is to stop using the Services in accordance with the Terms.
Questions about this policy can be sent to legal@mtrix.io, or by post to Mtrix Inc., Tornimäe tn 5, Kesklinna linnaosa, Tallinn, Harju maakond, 10145, Estonia.