Acceptable Use Policy
Version 1 · Effective 2 October 2026
This policy forms part of our Terms of Service. It applies to the web app, the API (including through RapidAPI and our WordPress plugin), and everything you get from them.
1. Scope
You are responsible for making sure that everyone who uses the Service through your account, your team seats or your API keys follows this policy.
2. Using our data
You must not:
- scrape, crawl or bulk-download the website, or use automated tools on the web app instead of the API;
- copy the data in bulk to resell, sublicense or republish it, or to build a database or service that competes with CompanyStack;
- present our outputs as your own data product without attribution, or remove attribution and source notices; or
- use the Service to train or build a dataset for resale.
Limited extracts in your own products and publications are fine with attribution, as set out in clause 17 of the Terms.
3. Accounts and API keys
- Do not share, sell or publish API keys, or let anyone outside your business use them.
- Do not share a team seat between several people, or share login details.
- Do not open more than one account to get extra free usage.
- Keep keys out of public code, browser code and shared documents.
4. Limits and security
You must not:
- try to get around rate limits or plan limits, for example by rotating keys or accounts;
- probe, scan or test the security of the Service without our written permission;
- access data or accounts that are not yours;
- send traffic designed to overload or disrupt the Service; or
- upload malicious code or use webhooks to attack other systems.
If you find a security weakness, please tell us at support@companystack.co.uk and give us a chance to fix it before you disclose it.
5. People in our data
Our data includes directors, secretaries and people with significant control. You must not use it:
- to harass, stalk, threaten or intimidate anyone, or to find where someone lives;
- to discriminate against anyone, for example because of nationality, age or any other protected characteristic;
- for unlawful profiling, or as the main basis for decisions about an individual's credit, employment, insurance or housing;
- to send unsolicited marketing by email, text or automated calls in breach of the Privacy and Electronic Communications Regulations (PECR), or to call numbers registered with the Telephone Preference Service; or
- in any other way that breaks the UK GDPR or the Data Protection Act 2018.
6. Unlawful use
You must not use the Service for fraud, money laundering, sanctions evasion, impersonation, or any other unlawful purpose, or to help anyone else do so.
7. Enforcement
If we reasonably believe this policy has been broken, we may:
- contact you and ask you to stop;
- throttle or block requests, or revoke API keys;
- suspend or close the account, under clause 13 of the Terms; and
- report the matter to the police, the ICO or another authority where appropriate.
Where we can, we will warn you first and give you a chance to put things right. We will act straight away where there is a risk to people, to the Service or to other customers. Fees are not refunded when an account is suspended or closed for a serious breach.
8. Reporting misuse
If you think someone is misusing CompanyStack or our data, email support@companystack.co.uk.