1. Purpose and Scope
This OktoRocket Acceptable Use Policy (“AUP” or “Policy”) governs use of all services provided by ShopRocket, LLC, a Tennessee limited liability company doing business as OktoRocket (“OktoRocket,” “we,” or “us”), including its SaaS platform, VoIP communications services, messaging services, and associated APIs and integrations (collectively, the “Services”). This Policy is incorporated by reference into OktoRocket’s online Terms and Conditions, signed Master Services Agreement, Subscription Agreement or other ordering document, and applies to all customers, users, and account holders regardless of which governing agreement applies to their account (each, a “Customer”).
Capitalized terms used but not defined in this Policy have the meanings given to them in Customer’s governing agreement. In the event of a conflict between this Policy and a signed Master Services Agreement, the order of precedence set forth in such signed Master Services Agreement applies.
Customer is responsible for compliance with this Policy by its authorized users and by any person accessing the Services through customer’s account or credentials, and for all activity occurring under its account. Non-compliance by an authorized user is deemed non-compliance by Customer. Customer is responsible for safeguarding its account credentials and for promptly notifying OktoRocket of any suspected unauthorized access to or use of its account.
The lists of prohibited conduct in this Policy are illustrative and not exhaustive. OktoRocket may suspend or terminate access for conduct it reasonably believes is harmful to the Services, OktoRocket, or other customers, whether or not specifically described in this Policy.
Violation of this Policy may result in suspension or termination of the Service as described in Section 8 below.
2. General Prohibited Conduct
Customers and their users may not directly or indirectly use the Services to:
- Violate any applicable federal, state, or local law or regulation, or any applicable foreign law;
- Infringe or misappropriate the intellectual property, privacy, or other rights of any third party;
- Transmit malware or attempt to gain unauthorized access to any system, account or network;
- Interfere with or disrupt the integrity or performance of the Services or the networks/systems connected to them;
- Reverse engineer, decompile, or attempt to derive source code from any of the Services;
- Resell, sublicense, or provide access to the Services to any third party without OktoRocket’s prior written consent, except as expressly permitted under Customer’s governing agreement;
- Misrepresent identity or affiliation in a way intended to deceive, including impersonating any person or entity or misrepresenting an affiliation with OktoRocket;
- Transmit, store, or make available content that is unlawful, defamatory, harassing, abusive, threatening, or that promotes violence or discrimination against any individual or group;
- Transmit, store, or make available any child sexual abuse material or any other content that sexually exploits or endangers a minor;
- Transmit unsolicited commercial email or other communications in violation of the CAN-SPAM Act or any applicable anti-spam law; or
- Use the Services in violation of applicable export control, economic sanctions (including those administered by OFAC), or anti-bribery and anti-corruption laws, or make the Services available to any person or entity designated on any U.S. government list of prohibited or restricted parties.
OktoRocket maintains a zero tolerance policy with respect to child sexual abuse material. Any such use constitutes grounds for immediate termination without notice, in addition to any other rights or remedies available under Customer’s governing agreement, and will result in preservation of relevant records and reporting to the National Center for Missing & Exploited Children and law enforcement as required by law.
3. VoIP-Specific Prohibited Conduct
In connection with OktoRocket’s VoIP and telephony Services, Customers and their users may not directly or indirectly:
- Originate robocalls, autodialed calls, prerecorded messages or any other outbound communication in violation of (a) the Telephone Consumer Protection Act (47 U.S.C. § 227) and its implementing Federal Communications Commission (“FCC”) regulations (47 C.F.R. § 64.1200), (b) the Telemarketing Consumer Fraud and Abuse Act (15 U.S.C. §§ 6101-6108) and its implementing regulations under the Federal Trade Commission’s Telemarketing Sales Rule (16 C.F.R. § 310), and (c) similar state laws governing telemarketing and/or outbound calling and texting (the “Applicable Outbound Calling Requirements”);
- Originate calls that do not fully comply with all applicable federal and state laws governing call recording-consent, including but not limited to the Federal Wiretap Act, and the Electronic Communications Privacy Act (the “Applicable Call Recording-Consent Requirements”);
- Falsify, spoof, or manipulate caller ID information with intent to defraud, cause harm, or wrongfully obtain anything of value, in violation of the Truth in Caller ID Act or other applicable federal or state laws;
- Engage in traffic pumping, access stimulation, or other artificial inflation of call volume or minutes;
- Commit or facilitate toll fraud;
- Disable, circumvent, or interfere with 911/E911 functionality, or misrepresent a Registered Location;
- Use the Services to transmit unlawful, harassing, or threatening communications;
- Originate calling traffic that would cause OktoRocket to be out of compliance with FCC rules, its Robocall Mitigation Database filing, or its STIR/SHAKEN caller ID authentication obligations; or
- Submit inaccurate information in connection with a number port request, request the port of a number Customer is not authorized to port, or otherwise misuse numbering resources assigned to the account.
4. Messaging-Specific Prohibited Conduct
In connection with SMS, MMS or other messaging features of the Services, Customers and their users may not directly or indirectly:
- Send messages that do not fully comply with Applicable Outbound Calling Requirements and Applicable Call Recording-Consent Requirements;
- Send messages without having obtained and documented the consent required by applicable law for the type of message sent, including prior express written consent where required;
- Fail to honor opt-out or revocation requests promptly and across all campaigns or programs using the same originating number;
- Send messages to any recipient following receipt of an opt-out or revocation request, or to any number Customer knows or should reasonably know has been reassigned or disconnected;
- Send messages through the Services without completing and maintaining accurate brand and campaign registration with The Campaign Registry and/or any applicable carrier or aggregator registration;
- Send message traffic under a campaign registration that does not match the actual content, use case, sender or opt-in method of the traffic being sent;
- Engage in snowshoeing, number rotation, grey-route messaging, URL cloaking, use of public URL shorteners, or any other practice intended to evade carrier filtering, throughput limits, registration requirements or attribution;
- Send messages concerning content prohibited or restricted by wireless carriers or applicable industry standards, including without limitation high-risk financial services, debt collection or debt forgiveness, illegal substances, cannabis, gambling, firearms, or sexually explicit content, except where expressly permitted by the applicable carriers and properly registered;
- Share, rent, sell or purchase opt-in lists, or send messages to any list of recipients acquired from a third party;
- Misrepresent the identity of the sender, the brand, or the nature of the messaging program in any call to action or in any message, or send messages using a brand name that does not match the registered brand or DBA; or
- Send messages to recipients outside the United States except where expressly permitted by OktoRocket in writing and in compliance with applicable law in the destination jurisdiction.
Customers are solely responsible for the content of their messages, for obtaining and maintaining records evidencing consent for each recipient, and for producing those records to OktoRocket promptly upon request. Customers are responsible for their own brand and campaign registrations and for all fees, penalties, filtering or blocking imposed by any carrier or registry in connection with their traffic.
In addition to any rights or remedies available under Customer’s governing agreement, OktoRocket may suspend or throttle messaging traffic immediately and without prior notice where OktoRocket reasonably believes that Customer’s traffic is unregistered, non-compliant, or creates a risk of carrier filtering, blocking, fines or reputational harm to OktoRocket, its numbering resources or its other customers.
5. SaaS Platform-Specific Prohibited Conduct
In connection with OktoRocket’s SaaS platform, Customers and their users may not directly or indirectly:
- Scrape, crawl, or extract data from the platform outside of documented, authorized interfaces;
- Circumvent usage limits, rate limits, or account-tier restrictions;
- Use automated means to create accounts or access OktoRocket’s SaaS platform in a manner not authorized by OktoRocket;
- Consume platform resources in a manner that degrades service for other customers; or
- Exceed the seats, usage volumes or capacity authorized under Customer’s applicable ordering document.
OktoRocket may establish, publish and update from time to time reasonable usage thresholds, fair-use limits and technical restrictions applicable to the Services, and may measure and verify Customer usage against the levels authorized under such Customer’s account.
6. API, MCP, and AI/LLM Integration Use
OktoRocket may provide access to its Services through an application programming interface (“API”), Model Context Protocol (“MCP”) server, or other machine/AI-facing integrations (collectively, “Programmatic Access”). Use of Programmatic Access is subject to the general provisions of this Policy, and additionally the following:
Scope of use
Programmatic Access may only be used in a reasonable manner consistent with Customer’s own account, its users, and its own legitimate business purposes. Customers may not use Programmatic Access to provide services to, or on behalf of, any third party or separate client of Customer, whether or not for a fee, without OktoRocket’s prior written consent or except under a written reseller, agency or partner arrangement with OktoRocket.
No resale or pass-through access
Customers may not resell, sublicense, rent, lease, or otherwise make Programmatic Access available to any third party, including by exposing OktoRocket’s API or MCP functionality through Customer’s own product, service, or integration in a manner that extends effective access beyond Customer’s own account.
Infrastructure impact
Customers must use Programmatic Access in a manner that does not impose an unreasonable or disproportionate burden on OktoRocket’s infrastructure, including through excessive call volume, request frequency, concurrency, or payload size. OktoRocket may impose, and update from time to time, rate limits, quotas, or throttling on Programmatic Access to protect platform performance and stability.
Artificial Intelligence (“AI”) agent and automated use
Where Programmatic Access is used by or through an AI agent, large language model, or other automated system acting on Customer’s behalf, Customer remains fully responsible for all activity conducted through that access, including ensuring the automated system operates within the bounds of this Policy and Customer’s own account permissions. Customers may not use the Services, or any data obtained through the Services, to train, fine-tune or develop any machine learning or artificial intelligence model without OktoRocket’s prior written consent, and may not input into any third-party AI system any data Customer is not authorized to disclose to that system.
Suspension for violations or performance impact
OktoRocket reserves the right to suspend or restrict Programmatic Access, in whole or in part, immediately and without prior notice, if OktoRocket determines in its reasonable judgment that a customer’s use (i) violates this Policy, (ii) exceeds the scope of rights granted under Customer’s account, or (iii) is causing or is reasonably likely to cause performance, stability, or security issues for OktoRocket’s platform or other customers. OktoRocket will provide notice of the suspension and, where practicable, may provide an opportunity to remediate before taking further action, except where the circumstances involve security, fraud or unlawful conduct.
7. Monitoring, Content Removal and Cooperation with Authorities
OktoRocket has no obligation to monitor use of the Services or the content transmitted or stored through them. OktoRocket may, however, monitor use of the Services and may access, review and preserve content and account records as reasonably necessary to investigate a suspected violation of this Policy or Customer’s governing agreement, to protect the security, integrity or availability of the Services, or to comply with applicable law or legal process. Any such monitoring, access, review or preservation will be conducted in accordance with applicable law, including rules governing Customer Proprietary Network Information and the privacy of communications, and in accordance with OktoRocket’s Privacy Policy and internal data retention policies.
Customer will cooperate reasonably with OktoRocket in the investigation of any suspected violation of this Policy, including by providing information, records and access reasonably requested by OktoRocket, and will take prompt action to remediate any violation and to prevent its recurrence.
OktoRocket may remove, disable access to, or quarantine any content that OktoRocket reasonably believes violates this Policy, Customer’s governing agreement or applicable law, or that creates a risk of liability to OktoRocket. Where practicable and not prohibited by law, OktoRocket will provide Customer notice of any such action.
OktoRocket may report suspected unlawful activity to law enforcement or other governmental authorities and may cooperate with, and disclose records in response to, any lawful request, subpoena, court order or other legal process.
Suspected violations of this Policy may be reported to OktoRocket at abuse@oktorocket.com.
8. Enforcement
OktoRocket reserves the right to investigate suspected violations of this Policy by Customers and their users. Depending on the severity and nature of the violation, OktoRocket may, in its sole discretion:
- Issue a warning and request remediation within a specified period;
- Suspend access to the affected Service(s) pending resolution;
- Throttle, filter or restrict the affected traffic or functionality; and/or
- Terminate the account, subject to the termination provisions of Customer’s governing agreement; provided that where Customer’s governing agreement permits termination without a cure period, including for conduct involving a threat to security or integrity, fraud, or unlawful conduct, OktoRocket may exercise that right.
Immediate suspension, without prior notice, may occur where OktoRocket reasonably believes the violation poses an imminent risk to OktoRocket’s platform security, stability, legal compliance, or the rights of third parties including violations under Sections 3, 4 and 6 above.
Any suspension, throttling or restriction under this Policy does not constitute downtime or unavailability for purposes of any service level agreement agreed to with Customer, does not constitute a breach by OktoRocket of Customer’s governing agreement, does not entitle Customer to any service credit, and does not relieve Customer of any payment obligation.
A violation of this Policy is a breach of Customer’s governing agreement, and any claim, loss, damage, liability or expense arising from such a violation shall be subject to Customer’s indemnification obligations under such agreement, if any.
Customer’s obligations under this Policy relating to consent records, indemnification and cooperation survive any expiration or termination of Customer’s governing agreement.
If any provision of this Policy is held unenforceable, the remaining provisions remain in full force.
9. Changes to this Policy
OktoRocket may – in its sole discretion – update this Policy from time to time to address new risks, technologies, or regulatory requirements. Material changes will be communicated in accordance with the notice provisions of Customer’s governing agreement. Where Customer has no signed agreement containing notice provisions, material changes will be posted at the published location of this Policy with an updated “Last Updated” date, and continued use of the Services after the changes take effect constitutes acceptance of the revised Policy.


