← All policies

Current published policy. Auto Expert is the former brand name; legal wording is preserved.

Acceptable Use Policy

Last updated Jun 26, 2026 · 10 min read

At a Glance

This Acceptable Use Policy (the "AUP") sets the rules for how the Auto Expert software-as-a-service application (the "Service") may and may not be used. In plain terms:

  • Use the Service to run your dealership. Do not use it to harm others, abuse systems, or break the law.
  • Treat your dealership's customer data the way you would want yours treated.
  • Do not try to break, copy, or out-engineer the Service.
  • Send communications (email, SMS) only to people you have a lawful right to contact, with required consents and opt-outs.
  • Violations may result in suspension, termination, or referral to law enforcement.

1. Scope

This AUP applies to all access to and use of the Service, including by Customer (the dealership or other entity on the Order Form), Authorized Users (employees, contractors, or agents granted access by Customer), and anyone using credentials or APIs associated with Customer's account.

This AUP is incorporated by reference into the Auto Expert Terms of Service available at https://theautoexpert.io/legal (the "Terms"). Capitalized terms used and not defined in this AUP have the meanings given in the Terms. In the event of any conflict between this AUP and the Terms, the Terms control.

2. Prohibited Uses

Customer agrees not to, and not to permit any Authorized User or third party to, do any of the following in connection with the Service. The categories below expand on the prohibitions in Section 6 of the Terms; they are not intended to limit those prohibitions.

2.1 Security and System Integrity

  • attempt to gain unauthorized access to the Service, related systems, infrastructure, source code, or other users' accounts;
  • probe, scan, or test the vulnerability of the Service or related infrastructure without prior written permission, except as part of a published responsible disclosure program;
  • interfere with, disrupt, or impose an unreasonable load on the Service or its supporting systems (for example, denial-of-service attempts, intentional retry storms, or runaway scripts);
  • circumvent or attempt to circumvent authentication, rate limiting, access controls, audit logging, billing controls, or other technical or contractual restrictions;
  • introduce malware, ransomware, worms, viruses, or any other malicious code into the Service or transmit any such code through the Service;
  • use the Service to attack, compromise, or interfere with any other system, including those of third parties;
  • share, sell, lend, or otherwise transfer login credentials, multi-factor authentication tokens, or session cookies to any unauthorized person;
  • use a single named user account for what is effectively multiple people (account sharing).

2.2 Content and Data

  • upload, store, transmit, or process any content that is unlawful, infringes intellectual property or privacy rights, is defamatory, harassing, or otherwise objectionable;
  • use the Service to store or process information that the user does not have the right to store or process (including, for example, customer records obtained without consent or in violation of contract);
  • upload or process special categories of sensitive personal information that the Service is not designed to handle — including government identifiers (e.g., Social Security numbers), full payment card numbers (PCI scope is handled by the dealership's payment processor, not Auto Expert), health information beyond what is incidental to vehicle service, biometric identifiers, or precise geolocation outside of standard dealership operational use;
  • use the Service to process or store any information about individuals under the age of 16 except as incidental to a parent or guardian relationship recorded in the ordinary course of dealership business;
  • upload content that contains malicious code, exploit payloads, or content designed to evade security controls.

2.3 Communications (Email, SMS, Voice)

Where the Service supports outbound communications to Customer's own customers — including email, SMS, voice, or any future channel — Customer is solely responsible for ensuring all communications comply with applicable law and platform requirements.

  • Send messages only to recipients from whom Customer has obtained any consent required by law (including TCPA, CAN-SPAM, state-level consent statutes, and equivalent laws applicable to the recipient).
  • Honor opt-out requests promptly. STOP, UNSUBSCRIBE, and equivalent opt-out keywords must be respected as required by carrier and regulator rules.
  • Do not send unsolicited commercial messages, marketing to recipients who have not consented, or messages of a deceptive nature.
  • Do not use spoofed sender identities, misleading subject lines, or impersonate other senders.
  • Do not send content that is prohibited by carriers or messaging providers (for example, content related to high-risk financial offers, illegal substances, or adult content where prohibited).
  • Maintain accurate sender information, business identification, and physical address as required by CAN-SPAM and similar statutes.

2.4 Customer Data Handling Within the Service

  • Limit access to Customer Data within the Service to Authorized Users with a legitimate business need.
  • Promptly disable accounts of employees or contractors who no longer require access (terminations, role changes, contract end).
  • Do not export Customer Data to systems that lack equivalent protections (for example, exporting customer lists into a personal email account or unsecured spreadsheet).
  • Do not use Customer Data accessed through the Service for any purpose unrelated to the dealership's ordinary business operations.
  • Comply with the dealership's own privacy policy and applicable privacy laws (including CCPA/CPRA and analogous state laws) with respect to Customer Data.

2.5 AI Features

Where the Service includes AI-powered features (for example, communication drafting, call summarization, voice-to-RO, advisor coaching, or similar), the following additional rules apply:

  • Do not submit content to AI features that the user does not have a lawful right to process (including, for example, recordings made in violation of two-party consent recording laws).
  • Do not rely on AI-generated output as the sole basis for any binding customer-facing commitment, repair commitment, or safety-critical decision. AI output is a draft, not the final answer — a human is responsible for review.
  • Do not use AI features to generate content that is deceptive, defamatory, fraudulent, or impersonates a real person without that person's consent.
  • Do not use AI features to attempt to extract training data, model parameters, system prompts, or other internal information from the underlying AI providers.
  • Do not use AI output to make decisions that produce legal or similarly significant effects on individuals without appropriate human review and any required disclosures under applicable law.

2.6 Competitive and Reverse Engineering

  • Do not use the Service, the Documentation, or any output from the Service to develop, train, improve, or benchmark a competing product or service.
  • Do not reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, models, or trade secrets of the Service, except to the extent expressly permitted by applicable law.
  • Do not scrape, harvest, or use any automated means to access the Service except via APIs that Auto Expert expressly makes available, and only within the limits documented for those APIs.
  • Do not copy, modify, translate, or create derivative works of the Service or the Documentation, except as expressly permitted by the Terms.
  • Do not remove or obscure any proprietary notices on the Service or Documentation.

2.7 Legal Compliance

  • Do not use the Service to engage in or facilitate any unlawful activity.
  • Do not use the Service in a manner that violates any applicable law, regulation, or order, including consumer protection, advertising, lending, financing, employment, anti-discrimination, dealer franchise, recordkeeping, or licensing laws.
  • Do not use the Service in a manner that violates trade-control laws, including U.S. export controls and sanctions administered by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), or to provide the Service or its output to any person located in a sanctioned jurisdiction or on a restricted-party list.

3. Reporting Violations

Suspected violations of this AUP, vulnerabilities in the Service, or abuse originating from a Customer account should be reported to:

Email: [SECURITY EMAIL — e.g., support@theautoexpert.io]

Subject line: "AUP Violation Report" or "Security Report"

Reports made in good faith and through this channel will be acknowledged within five (5) business days. Good-faith security research is not pursued legally; see Section 6.4 of the Auto Expert Incident Response Plan for the responsible disclosure handling.

4. Enforcement

Auto Expert may take any of the following actions in response to an actual or suspected violation of this AUP, depending on the severity of the violation, the risk it poses to the Service or other users, and Customer's responsiveness:

  • Investigation, including review of audit logs, communication content, and account activity to the extent permitted by Customer's contract and applicable law.
  • Notice to Customer requesting that the violation be cured within a stated period.
  • Throttling, restriction, or removal of specific features or content where necessary to mitigate harm.
  • Suspension of an Authorized User's access, where the violation is associated with a specific user.
  • Suspension of the entire Customer account, where necessary to protect the Service or other users.
  • Termination of Customer's subscription for material or repeated violation, in accordance with the Terms.
  • Cooperation with law enforcement and regulators, including in response to lawful requests.

Where reasonably practicable and not prohibited by law or legal process, Auto Expert will provide Customer with notice before suspending or terminating the entire account and an opportunity to cure. In urgent situations (for example, an active security incident, ongoing harm to third parties, or legal compulsion), Auto Expert may act first and notify Customer as soon as reasonably practicable thereafter.

5. Suspension and Termination

Suspension and termination rights, notice requirements, cure periods, and effects (including return or export of Customer Data) are governed by the Terms and any applicable Order Form. This AUP does not expand or restrict those rights except as expressly set forth above.

6. Changes to This AUP

Auto Expert may update this AUP from time to time to reflect changes in the Service, in applicable law, or in security and abuse patterns. Material changes will be communicated to Customer in accordance with the Terms and will become effective on the date specified in the notice or, if no date is specified, thirty (30) days after posting. Continued use of the Service after the effective date constitutes acceptance of the updated AUP.

The most current version of this AUP is always published at https://theautoexpert.io/legal.

7. Contact

Questions about this AUP can be directed to:

Axiom Technologies, LLC

Lincoln, Nebraska, USA

Email: [LEGAL EMAIL — e.g., support@theautoexpert.io]