Overview
This Acceptable Use Policy ("AUP") governs your use of all SIPSTACK products and services, including Nova PBX, Flare SMS, Aura AI, SARA AI, Pulse, and Switchboard (collectively, the "Services"). This AUP is incorporated by reference into the SIPSTACK Terms of Service.
Violations of this AUP may result in immediate suspension or termination of your account without refund. SIPSTACK reserves the right to update this AUP at any time with notice.
Permitted Use
SIPSTACK services are designed for legitimate business telecommunications, messaging, and AI-powered automation. You may use our platform to:
- Make and receive voice calls for legitimate business purposes
- Send and receive business SMS and MMS messages with proper recipient consent
- Build voice applications and automated call flows using Nova PBX features
- Automate customer support communications using SARA AI and Aura AI
- Integrate SIPSTACK capabilities into your products via our API
- Conduct marketing campaigns with properly opted-in recipients
- Send transactional notifications, appointment reminders, and two-factor authentication messages
Prohibited Activities
General Prohibitions
You may not use SIPSTACK services for any activity that:
- Violates any applicable local, provincial, state, national, or international law or regulation
- Constitutes fraud, harassment, stalking, or threats against any person
- Infringes or misappropriates the intellectual property rights of any third party
- Involves the transmission of material that is defamatory, obscene, or unlawfully harmful
- Promotes violence, illegal discrimination, or illegal activity
- Facilitates unauthorized access to systems, networks, or accounts
Caller ID and Identity
- Caller ID spoofing for fraudulent purposes is prohibited. Legitimate caller ID customization (e.g., displaying a business main number or DID) is permitted where technically supported and legally compliant.
- You must not manipulate caller ID with intent to defraud, cause harm, or wrongfully obtain anything of value.
- Under the Truth in Caller ID Act and similar laws, false or misleading caller ID information used to defraud is illegal.
Network Abuse
- You may not engage in activity that disrupts, degrades, or interferes with SIPSTACK's network, infrastructure, or other customers' service quality.
- Denial-of-service attacks, traffic flooding, deliberate packet corruption, or attempts to overwhelm systems with excessive requests are prohibited.
- Unauthorized probing, scanning, or vulnerability testing of SIPSTACK systems without prior written authorization is prohibited.
- Cryptocurrency mining, unauthorized resource consumption, or running automated scripts that exceed published rate limits without authorization is prohibited.
Resale and Redistribution
You may not resell, redistribute, or provide SIPSTACK services to third parties without an executed channel partner or reseller agreement. Unauthorized commercial resale of SIPSTACK network infrastructure or API endpoints is prohibited.
Nova PBX — Specific Requirements
Call Recording
- You are solely responsible for complying with all applicable call recording consent laws in your jurisdiction and the jurisdictions of all parties you record. Requirements vary by jurisdiction:
- One-party consent (federal US, most US states): Recording permitted with consent of one party (typically you)
- Two-party / all-party consent (California, other US states, Canada under some circumstances): Recording requires consent of all parties
- SIPSTACK provides configurable recording announcement features. Use of recording features without legally required consent disclosures is a violation of this AUP.
- Nova PBX recording does not substitute for your legal obligation to consult qualified legal counsel about call recording requirements in the jurisdictions where you operate.
Robocalling and Auto-Dialing
- Automated or pre-recorded outbound calls to consumers (robocalling) are prohibited unless you have obtained express prior written consent from each called party as required by the Telephone Consumer Protection Act (TCPA) and equivalent laws in other jurisdictions.
- Emergency notification systems, informational messages to parties with established business relationships, and calls with express consent are permitted subject to applicable law.
- You must maintain records of consent for all automated call recipients and make such records available to SIPSTACK upon request.
Emergency Services (E911)
- You must keep registered E911 service addresses current and accurate for all users.
- Misuse of E911 services is illegal and subject to immediate account termination and referral to law enforcement.
Flare SMS — Specific Requirements
Consent and Opt-In
- All recipients of marketing, promotional, or recurring informational SMS/MMS messages must have provided explicit prior written consent to receive such messages (opt-in).
- Transactional messages (order confirmations, appointment reminders, 2FA codes) require prior business relationship or transaction, not explicit SMS opt-in, but must still include an opt-out mechanism.
- You must maintain auditable records of opt-in consent, including the date, method, and exact consent language displayed to the recipient.
10DLC Registration
- All business messaging (A2P) in the United States must be registered under the 10-Digit Long Code (10DLC) framework with The Campaign Registry (TCR).
- You are responsible for registering your brand and campaigns prior to sending A2P traffic. Unregistered traffic may be filtered or blocked by US mobile carriers without liability to SIPSTACK.
- Campaign registration must accurately describe your messaging use case. Misrepresenting your campaign type or content is a violation of this AUP and carrier terms.
Opt-Out Compliance
- You must honor opt-out requests immediately. Replying STOP (or equivalent) to any message must result in immediate suppression from future sends to that number.
- SIPSTACK automatically maintains opt-out suppression lists. You must not attempt to override, circumvent, or re-add opted-out recipients.
- Required keywords (STOP, HELP, UNSUBSCRIBE, CANCEL, QUIT, END) must produce legally compliant responses.
Prohibited Message Content
The following message content is prohibited regardless of recipient consent:
- Sexually explicit content (SHAFT: Sex)
- Hate speech, harassment, or threats (SHAFT: Hate)
- Alcohol or firearms promotions to unverified audiences
- Controlled substances, cannabis (in jurisdictions where not permitted)
- Phishing, fraud, or deceptive content
- Loan shark or predatory lending solicitations
- Affiliate marketing or "get rich quick" schemes
- Multi-level marketing or pyramid scheme recruitment
- Unsolicited bulk messaging (spam)
TCPA and CASL Compliance
- TCPA (USA): You are solely responsible for compliance with the Telephone Consumer Protection Act, including consent requirements, calling hour restrictions, and Do Not Call Registry scrubbing.
- CASL (Canada): You are solely responsible for compliance with Canada's Anti-Spam Legislation, including express or implied consent requirements for commercial electronic messages and the mandatory unsubscribe mechanism.
Links and URL Shorteners
- Public URL shorteners are prohibited in Flare SMS campaigns on every plan — including (without limitation) bit.ly, TinyURL, ow.ly, t.co, goo.gl, rebrand.ly, is.gd, cutt.ly, and similar services. US and Canadian carriers filter or outright block messages containing public/shared shorteners (AT&T blocks them entirely), which harms deliverability for you and for the platform.
- Use instead: a full destination URL on a domain that matches your registered brand, or — on the Ultra plan — link tracking on your own branded link domain (e.g.
go.yourbrand.com), provisioned in Switchboard under Account settings. Branded domains are carrier-trusted and keep each sender's reputation isolated. - Link cloaking is prohibited: a shortened or tracked link must resolve to the destination a reasonable recipient would expect from the message; misrepresenting a link's destination violates this AUP and carrier rules.
Aura AI and SARA AI — Specific Requirements
Disclosure of AI Nature
- Where required by law, you must disclose that a communication is AI-generated or that a caller is interacting with an AI agent, not a human.
- You must not deploy Aura AI voice agents in a manner that impersonates a named real person without that person's explicit consent.
- You must comply with the FTC Endorsement Guides, relevant state laws, and emerging AI disclosure requirements applicable to your jurisdiction.
Prohibited AI Uses
You must not use Aura AI or SARA AI to:
- Generate content that violates this AUP or applicable law
- Impersonate any real individual without disclosure that the communication is AI-generated
- Circumvent or attempt to reverse-engineer SIPSTACK's AI safety measures, model guardrails, or content filters
- Attempt to extract, replicate, or reproduce SIPSTACK's AI model weights, training data, or inference pipeline
- Process personal data of individuals under 13 years of age (or under 16 in jurisdictions with stricter requirements)
- Produce content designed to discriminate unlawfully based on protected characteristics
- Conduct mass or targeted harassment campaigns using automated voice or messaging
AI Output Responsibility
You are solely responsible for reviewing, validating, and taking responsibility for AI-generated outputs before acting on them or delivering them to third parties. SIPSTACK makes no warranty as to the accuracy, completeness, or fitness of AI outputs. Do not rely on AI outputs as a substitute for professional legal, medical, financial, or other licensed advice.
Rate Limits and Fair Use
SIPSTACK enforces rate limits to protect network stability and ensure equitable service for all customers. Published rate limits are available in the Documentation at sipstack.com.
- API rate limits: Requests exceeding published limits will be throttled with HTTP 429 responses. Sustained rate limit violations may result in temporary suspension.
- Messaging throughput: Outbound SMS/MMS is subject to per-second throughput limits based on your registered 10DLC campaign type and subscription tier. Exceeding throughput limits may result in queuing or rejection by downstream carriers.
- Bulk calling: Automated outbound calling campaigns must conform to published concurrent call limits. Exceeding limits may result in call failure or rate throttling.
- Deliberate circumvention: Using multiple accounts, credential rotation, IP rotation, or other techniques to circumvent rate limits is a violation of this AUP and may result in permanent termination.
Contact [email protected] to discuss higher throughput requirements for legitimate high-volume use cases.
Trial Accounts
Free trial Subscriptions are subject to the usage allowances and fair-use caps shown at signup and on the pricing page, which are lower than the corresponding paid plan's allowances (for example, a flat messaging cap and a fixed Aura AI credit grant for the trial period). Trial allowances are provided for legitimate evaluation of the Services and are not a substitute for a paid Subscription.
The following are violations of this AUP when performed in connection with a trial:
- Creating multiple accounts, or using multiple email addresses, payment methods, or organizations, to obtain more than one trial of the same product. Trials are limited to one per organization per product unless we agree otherwise.
- Using a trial to carry production traffic, run commercial campaigns, or conduct load testing beyond the stated trial allowances, or to circumvent paid-plan rate limits or throughput tiers.
- Any activity prohibited elsewhere in this AUP. Trial accounts receive the same monitoring as paid accounts.
We may suspend or terminate a trial immediately, decline to convert it to a paid Subscription, and refuse future trials for any violation of this section.
Enforcement
SIPSTACK monitors network traffic and usage patterns to detect potential violations of this policy. We employ automated systems to identify suspicious activity, unusual calling patterns, spam indicators, and other signs of abuse.
Upon detecting a violation, we may take immediate action including:
- Implementing rate limiting or traffic shaping on affected services
- Suspending specific numbers, campaigns, or features
- Suspending or terminating your account
- Blocking specific destinations or routes
- Reporting illegal activity to relevant regulatory bodies or law enforcement
Account suspension or termination for policy violations does not relieve you of your obligation to pay for services rendered. Refunds are not provided for accounts terminated due to AUP violations.
We investigate all reported violations. If you believe another user is violating this policy, submit a report to our abuse team.
Reporting Abuse
Email: [email protected] Phone: 1-800-277-7578 Online: Submit a report through your Switchboard account dashboard
When reporting abuse, please include: phone numbers or accounts involved, dates and times of incidents, message content or call recordings (if available), and a description of the violation.
We take all abuse reports seriously and will acknowledge receipt promptly. For time-sensitive matters such as ongoing harassment or threats, contact local law enforcement. SIPSTACK will cooperate fully with law enforcement investigations involving illegal use of our services.
Contact
For questions about this Acceptable Use Policy:
Email: [email protected] Mail: SIPSTACK Inc., Legal Department, 575-3093 Bathurst St., Toronto, ON M6A 2A3, Canada