North Route OperationsNorth Route Systems Ltd
Platform protection

Acceptable Use Policy

This policy protects North Route Operations, customer information and the separation between operators. It applies to customers, authorised users, demonstration users and anyone accessing a North Route Systems service.

It forms part of the Commercial Terms & Conditions where incorporated into a Customer agreement.

Lawful and authorised use

Users may access the service only for legitimate business purposes authorised by the Customer and within the permissions assigned to them.

Users must comply with applicable law, the Customer’s internal policies, transport and employment obligations, privacy requirements and any reasonable North Route Systems security instruction.

Accounts and credentials

Users must provide accurate account information, keep credentials confidential, use available security controls and promptly report suspected compromise.

Users must not share accounts, impersonate another person, reuse a former employee’s access, bypass multi-factor authentication or allow an unauthorised person to use the service.

Operator and depot isolation

Users must not attempt to access another operator’s, company’s, depot’s or customer’s users, drivers, vehicles, jobs, messages, documents, audit records, billing information or configuration.

Users must not alter identifiers, requests, URLs, application state or permissions to test or defeat tenant separation. Any accidental cross-customer visibility must be reported immediately and must not be copied, shared or further inspected.

Security abuse

Without prior written authorisation, users must not:

  • probe, scan, penetration test or attempt to exploit the service;
  • bypass authentication, rate limits, permissions or billing controls;
  • introduce malware, ransomware, malicious scripts or harmful files;
  • interfere with availability, performance, logs or monitoring;
  • use automated scraping, bulk extraction or credential-stuffing tools;
  • reverse engineer the service except where applicable law expressly permits it; or
  • help another person carry out prohibited activity.

Operational, compliance and audit records

Users must not create, alter, conceal or delete records for a fraudulent, misleading or unlawful purpose. This includes driver hours, walkaround checks, defect records, roadworthiness decisions, workshop sign-offs, invoices, expenses, job records and audit events.

Users must not falsely record that an inspection, repair, approval, duty or compliance action took place.

Location and workforce information

Driver location and workforce information may be used only for lawful, disclosed and proportionate operational purposes.

Customers and users must not use location data for covert monitoring, harassment, discrimination, personal tracking, unauthorised surveillance or a purpose incompatible with the information provided to the affected person.

Access must be limited to authorised roles and off-duty tracking must not be enabled or pursued without a lawful, necessary and properly disclosed basis.

Messages, uploads and content

Users must not upload or send unlawful, threatening, discriminatory, harassing, defamatory, obscene, fraudulent or infringing material.

Users must not upload information they have no right to process, unnecessary special-category data, payment-card details, passwords, malicious files or content that could compromise another person or system.

Operational messages must not be used to intimidate staff, conceal misconduct or bypass the Customer’s required safeguarding and incident procedures.

Third-party services

Users must comply with the lawful terms of mapping, messaging, payment, email, SMS, app-store and other connected providers.

Users must not use an integration to send spam, unlawful marketing, abusive messages, deceptive payment requests or content that breaches third-party rights.

Fair use and platform capacity

Users must not place an excessive, abusive or unreasonable load on the service, create artificial traffic, run unsupported high-volume automation or consume resources in a way that materially affects other customers.

Where unusually high usage is legitimate, the Customer should contact North Route Systems Ltd so appropriate capacity or commercial arrangements can be agreed.

Investigation and enforcement

We may investigate suspected misuse, preserve relevant evidence, restrict functionality, suspend accounts or terminate access where reasonably necessary to protect customers, data, security, legal compliance or the platform.

Where appropriate, we will notify the Customer and allow a reasonable opportunity to explain or remedy the issue. Immediate action may be taken for serious security threats, illegality, fraud, cross-customer access or risk of harm.

We may report suspected criminal activity or comply with lawful requests from regulators, courts and law-enforcement bodies.

Reporting concerns

Suspected security issues, cross-customer visibility, unlawful use or policy breaches should be reported promptly to Jay@northroutesystems.com.

Do not publicly disclose a suspected vulnerability before North Route Systems Ltd has had a reasonable opportunity to investigate and address it.