Accounts and credentials
Users must provide accurate account information, keep credentials confidential, use available security controls and promptly report suspected compromise.
Users must not share accounts, impersonate another person, reuse a former employee’s access, bypass multi-factor authentication or allow an unauthorised person to use the service.
Operator and depot isolation
Users must not attempt to access another operator’s, company’s, depot’s or customer’s users, drivers, vehicles, jobs, messages, documents, audit records, billing information or configuration.
Users must not alter identifiers, requests, URLs, application state or permissions to test or defeat tenant separation. Any accidental cross-customer visibility must be reported immediately and must not be copied, shared or further inspected.
Security abuse
Without prior written authorisation, users must not:
- probe, scan, penetration test or attempt to exploit the service;
- bypass authentication, rate limits, permissions or billing controls;
- introduce malware, ransomware, malicious scripts or harmful files;
- interfere with availability, performance, logs or monitoring;
- use automated scraping, bulk extraction or credential-stuffing tools;
- reverse engineer the service except where applicable law expressly permits it; or
- help another person carry out prohibited activity.
Operational, compliance and audit records
Users must not create, alter, conceal or delete records for a fraudulent, misleading or unlawful purpose. This includes driver hours, walkaround checks, defect records, roadworthiness decisions, workshop sign-offs, invoices, expenses, job records and audit events.
Users must not falsely record that an inspection, repair, approval, duty or compliance action took place.
Location and workforce information
Driver location and workforce information may be used only for lawful, disclosed and proportionate operational purposes.
Customers and users must not use location data for covert monitoring, harassment, discrimination, personal tracking, unauthorised surveillance or a purpose incompatible with the information provided to the affected person.
Access must be limited to authorised roles and off-duty tracking must not be enabled or pursued without a lawful, necessary and properly disclosed basis.
Messages, uploads and content
Users must not upload or send unlawful, threatening, discriminatory, harassing, defamatory, obscene, fraudulent or infringing material.
Users must not upload information they have no right to process, unnecessary special-category data, payment-card details, passwords, malicious files or content that could compromise another person or system.
Operational messages must not be used to intimidate staff, conceal misconduct or bypass the Customer’s required safeguarding and incident procedures.
Third-party services
Users must comply with the lawful terms of mapping, messaging, payment, email, SMS, app-store and other connected providers.
Users must not use an integration to send spam, unlawful marketing, abusive messages, deceptive payment requests or content that breaches third-party rights.
Fair use and platform capacity
Users must not place an excessive, abusive or unreasonable load on the service, create artificial traffic, run unsupported high-volume automation or consume resources in a way that materially affects other customers.
Where unusually high usage is legitimate, the Customer should contact North Route Systems Ltd so appropriate capacity or commercial arrangements can be agreed.
Investigation and enforcement
We may investigate suspected misuse, preserve relevant evidence, restrict functionality, suspend accounts or terminate access where reasonably necessary to protect customers, data, security, legal compliance or the platform.
Where appropriate, we will notify the Customer and allow a reasonable opportunity to explain or remedy the issue. Immediate action may be taken for serious security threats, illegality, fraud, cross-customer access or risk of harm.
We may report suspected criminal activity or comply with lawful requests from regulators, courts and law-enforcement bodies.
Reporting concerns
Suspected security issues, cross-customer visibility, unlawful use or policy breaches should be reported promptly to Jay@northroutesystems.com.
Do not publicly disclose a suspected vulnerability before North Route Systems Ltd has had a reasonable opportunity to investigate and address it.