1. Scope
This Acceptable Use Policy ("AUP") governs use of the Tripkoz platform operated by Tripkoz Technologies. It expands clause 9 of the Terms & Conditions and forms part of them.
It applies to everyone who uses the Service — organisation administrators, drivers, guardians and independent drivers — and you are responsible for the conduct of every user on your account.
2. Lawful and honest use
You must use the Service lawfully, and consistently with the transport, labour, motor vehicle, privacy and data-protection laws that apply to you.
You must not:
- Use the Service for any unlawful purpose or to further any unlawful act;
- Misrepresent your identity, your organisation, or your authority to act for an organisation;
- Use the Service to harass, threaten, defame, stalk or intimidate any person;
- Upload content that is unlawful, obscene, or that infringes another party’s rights.
3. Safety and compliance records
The safety features of Tripkoz only mean something if what goes into them is true. You must not:
- Record a safety inspection, vehicle check or maintenance task that was not actually carried out;
- Complete a driver’s checklist on their behalf to make a trip appear compliant;
- Falsify boarding, attendance or absence records, or alter a trip log to misstate what happened;
- Upload a forged, altered or expired licence, permit, fitness certificate or insurance document, or present another person’s document as a driver’s own;
- Backdate a record, or use the Service to construct compliance evidence for an audit, inspection or insurance claim that does not reflect reality.
A falsified safety record can put a child in an unroadworthy vehicle. We treat it as the most serious breach of this policy, and it will normally lead to immediate suspension.
4. Tracking and surveillance limits
Tripkoz collects location data so that transport can be operated and supervised safely. It must not become a general surveillance tool. You must not:
- Track a driver, passenger or guardian outside the legitimate purposes of transport safety and operations;
- Continue to collect a driver’s location outside their working trips, or use trip history to monitor their personal movements;
- Use location, attendance or trip data for disciplinary, commercial or personal purposes unrelated to transport, without a lawful basis and proper notice;
- Share a live tracking link or a passenger’s location with anyone other than the guardians and staff authorised to receive it;
- Use the Service to profile, market to, or build behavioural records about children.
You must tell drivers, passengers and guardians that location data is collected, what it is used for, how long it is kept and who can see it, and you must obtain any consent the law requires — including verifiable parental consent for a child.
5. Accounts, access and permissions
You must not:
- Share a single login between multiple people — credentials are personal, and shared logins destroy the audit trail the Service depends on;
- Grant a user more permission than their role needs, or use an administrator account for routine driver or guardian tasks;
- Attempt to access data belonging to another organisation, or to any user whose records your role does not cover;
- Attempt to defeat, bypass or test the tenant separation, authentication, session or permission controls of the Service;
- Continue to hold an account for a person who has left your organisation.
6. Technical restrictions
Without our prior written consent, you must not:
- Probe, scan or penetration-test the Service, or run automated vulnerability tooling against it;
- Reverse-engineer, decompile or attempt to derive the source code of the Service, except to the extent the law expressly permits;
- Scrape, harvest or bulk-extract data from the Service other than through the export features provided;
- Use bots, scripts or automated clients against the interface, or drive the API at a rate that degrades the Service for others;
- Circumvent rate limits, plan limits or usage metering, or create multiple accounts to do so;
- Introduce malware, or use the Service to store or distribute it;
- Resell, sublicense, white-label, or provide the Service to third parties.
Security research is welcome under the Responsible Disclosure Policy, which sets out what testing is permitted and how to report what you find. Testing under that policy is not a breach of this section.
7. What you put into the Service
You must only upload personal data you are entitled to process, and only what the Service is designed to hold.
Do not upload financial account details, health records, biometric data, caste or religion, or government identity numbers of passengers. The Service is not built to protect them and they are not needed to run transport.
Keep records accurate and current — an out-of-date guardian phone number or a stale pickup point is a safety problem, not an administrative one.
8. Emergency features
SOS and incident features exist so that a real emergency reaches the right people quickly. You must not raise a test SOS on a live account outside an agreed drill, or use an emergency feature to get attention for a non-emergency.
Remember that these alerts do not reach the police, ambulance or fire services. Your own escalation procedure, not Tripkoz, is what answers an emergency.
9. How we enforce this policy
Where we believe this policy has been breached, our response is proportionate to what happened and to the risk involved. We may:
- Contact you and ask you to put it right, which is what we do in most cases;
- Restrict or remove a specific user’s access;
- Remove or quarantine offending content;
- Suspend the account, where there is an immediate risk to safety, security, or another customer;
- Terminate the subscription for a serious or repeated breach;
- Report the matter to the police or a regulator where the law requires it, or where a person appears to be in danger.
Except where there is an immediate risk or the law prevents it, we will tell you what we believe happened and give you a chance to respond before we suspend or terminate. Suspension or termination for breach is not refundable.
10. Reporting a breach of this policy
If you believe someone is misusing Tripkoz — falsified records, misuse of tracking, or an account that should have been closed — write to support@tripkoz.com. Security vulnerabilities should go to security@tripkoz.com under the Responsible Disclosure Policy instead.
We treat reports in confidence, and we do not disclose the reporter to the organisation reported except where the law requires it.
Related policies
This document sits alongside the rest of our published terms. Together they form the agreement that governs your use of Tripkoz.