1. Purpose & Scope
This Acceptable Use Policy (“AUP”) governs your access to and use of the polling, survey,
and form ingestion services operated by Leatra Technologies LTD (“ZapPoll”,
“we”, “us”, or “our”) across zappoll.com, app.zappoll.com,
and api.zappoll.com.
This policy applies to all creators, workspace members, API consumers, and respondents. By using ZapPoll, you agree to adhere strictly to these rules. Any violation of this policy constitutes a material breach of our Terms of Service and will result in immediate service suspension, termination, and potential referral to statutory law enforcement authorities.
2. Absolute Ban on Credential Harvesting
ZapPoll endpoints and polls must NEVER be used to collect, harvest, or solicit authentication credentials, payment card numbers, private keys, or government-issued national identity numbers.
You must not configure any form field, question, or survey input to collect:
- Account Credentials: Passwords, password hints, PIN numbers, or authentication secrets;
- Financial Instrument Data: Full payment card primary account numbers (PAN), credit card security codes (CVV/CVC), or bank account PINs;
- Cryptographic Secrets: Private encryption keys, seed phrases, hardware wallet backup phrases, or API secret tokens;
- Government Identifiers: Social Security Numbers (SSN), National Identification Numbers (NIN), Bank Verification Numbers (BVN), passport numbers, or driver license numbers, unless explicitly authorized by a separate, signed enterprise compliance agreement.
3. Phishing, Social Engineering & Malware
You must not use ZapPoll to facilitate any form of cybercrime or deceptive practices:
- Phishing & Brand Impersonation: Crafting polls, forms, or notification emails that mimic financial institutions, government agencies, social networks, or other commercial brands to deceive respondents;
- Malicious Payloads: Distributing, linking to, or embedding malware, spyware, ransomware, trojan horses, worms, or weaponized document attachments;
- Exploitation: Submitting Cross-Site Scripting (XSS) vectors, SQL injection payloads, or command execution strings into form fields or poll questions.
4. Unlawful, Defamatory & Harmful Content
You may not host, distribute, or solicit responses regarding content that violates applicable law in Nigeria, the United States, the European Union, or your local jurisdiction:
- Child Exploitation (CSAM): Child sexual abuse material or any form of child exploitation is strictly prohibited. Any occurrence will be reported immediately to the National Center for Missing & Exploited Children (NCMEC) and relevant domestic and international law enforcement bodies;
- Terrorism & Violent Extremism: Content that promotes, incites, or coordinates terrorism, violence, or unlawful physical harm against individuals or groups;
- Hate Speech & Harassment: Severe, pervasive harassment, cyberstalking, doxxing, or content promoting discrimination based on race, ethnicity, religion, disability, gender, or sexual orientation;
- Illegal Trade & Narcotics: Facilitating the unlicensed sale of controlled substances, illicit narcotics, firearms, or contraband.
5. Platform & Network Abuse
To safeguard the availability and integrity of the ZapPoll infrastructure for all users, the following activities are strictly banned:
- Automated Ballot Stuffing: Deploying bots, headless browsers, automated scripts, or click farms to artificially inflate vote tallies or distort poll outcomes;
- Denial of Service (DoS/DDoS): Flooding endpoints, attempting to exhaust server memory, or conducting stress testing without prior written authorization from Leatra Technologies LTD;
- Rate-Limit Circumvention: Rotating IP addresses, proxy networks, or header spoofing to evade configured admission and capacity controls;
- Spam & Unsolicited Bulk Communications: Using ZapPoll email notification features or targeted invitation systems to send unsolicited marketing spam in violation of the CAN-SPAM Act, CASL, or NDPA.
6. External Forms Ingestion Obligations
When utilizing our headless Forms Ingestion API (`api.zappoll.com/f/{form_id}`):
- Lawful Consent: You must ensure that your external website provides a clear, compliant privacy notice and obtains valid legal consent before transmitting respondent data to ZapPoll;
- No Misrepresentation: You must not misrepresent ZapPoll's security guarantees. In particular, external forms must not be described to respondents as “Anonymous” when your external website scripts, cookies, or analytics track respondent identities;
- Single-Domain Hygiene: You must configure endpoint origin restrictions and ensure submission endpoints are not exposed to open cross-origin scraping.
7. Monitoring & Abuse Detection
Leatra Technologies LTD maintains automated edge heuristics, rate-limiting algorithms, and pattern matching to detect abuse, phishing patterns, and denial-of-service attempts.
While we do not actively monitor the content of private encrypted form responses, we reserve the right to inspect unencrypted form field schemas, public poll titles, and traffic metrics upon receipt of abuse reports or automated system anomalies.
8. Enforcement & Grant Forfeiture
Violating this policy results in immediate administrative action without liability to Leatra Technologies LTD.
If you violate this Acceptable Use Policy, Leatra Technologies LTD may take any of the following actions at its sole discretion:
- Immediate Endpoint Deactivation: Instantly disabling the offending poll, form endpoint, or workspace;
- Permanent Forfeiture of Capability Grants: Any purchased response capacity, advanced analytics, or add-on grants associated with the offending workspace or poll are permanently forfeited without refund;
- Network & Domain Blacklisting: Permanently banning the associated email domain, IP address range, and API keys;
- Law Enforcement Referral: Forwarding evidence, access logs, and creator identity records to relevant law enforcement agencies, including the Nigeria Police Force Cybercrime Unit, INTERPOL, and domestic regulatory bodies.
9. Reporting Violations & Contact
If you discover a poll, form, or endpoint hosted on or communicating with ZapPoll that violates this Acceptable Use Policy, please report it immediately to our security and trust team: