Acceptable Use Policy
This Acceptable Use Policy (the “Policy”) describes conduct that is not permitted when accessing or using the Stewardvine software, websites, applications, and related services (collectively, the “Service”). It is a plain-language template that must be finalized by counsel and read together with the [to be finalized], the Privacy Policy, and the Data Processing Addendum.
How Stewardvine fits in. Stewardvine provides software. The parish is the merchant of record; Square processes and settles donations directly and in full into the parish's own Square account; and Stewardvine never accepts, holds, escrows, or transmits donor funds. This Policy governs use of the software — it does not make Stewardvine a party to any payment.
1. Who this Policy binds
This Policy applies to everyone who interacts with the Service, including:
- Parishes and dioceses that subscribe to the Service (each, a “Parish” or “Customer”).
- Administrators, staff, clergy, and volunteers who are granted access to configure the software, present the device at Mass, or view reports (each, an “Admin” or “Authorized User”).
- Donors who make a contactless gift through an attended device operated by a Parish.
Each Parish is responsible for ensuring that its Admins, Authorized Users, and volunteers comply with this Policy. A donor's use of the Service to complete a gift is also subject to the prohibited-conduct rules below.
2. Prohibited conduct
You may not do any of the following, or attempt, enable, or assist any third party to do so:
2.1 Fraud, laundering & illicit funds
- Use the Service to commit or facilitate fraud, deception, or misrepresentation of any kind.
- Engage in money laundering, structuring, terrorist financing, sanctions evasion, or the movement of proceeds of unlawful activity.
- Run test, self-, or “card-testing” transactions to validate stolen or enumerated card numbers.
- Submit transactions using a payment method you are not authorized to use.
2.2 Non-donation & prohibited-purpose use
- Solicit or collect funds for anything other than the Parish's own lawful charitable and religious purposes.
- Use the Service to sell goods or services, process point-of-sale retail payments, collect tuition, dues, or fees, or otherwise run non-donation transactions unless expressly permitted in writing.
- Solicit for, or route funds to, any prohibited, regulated, or restricted category (for example [to be finalized]).
- Misrepresent where a gift is going, who is receiving it, or its tax treatment.
2.3 Security, integrity & the platform
- Gain or attempt to gain unauthorized access to the Service, other Parishes' accounts, or any system or data (including credential stuffing or privilege escalation).
- Scrape, harvest, crawl, or bulk-extract data from the Service except through features expressly provided for that purpose.
- Reverse engineer, decompile, disassemble, or otherwise attempt to derive source code, except to the extent this restriction is prohibited by law.
- Introduce or transmit malware, ransomware, or other malicious code; conduct a denial-of-service (DoS/DDoS) attack; or interfere with the integrity or performance of the Service.
- Circumvent, disable, or bypass rate limits, authentication, quotas, usage caps, or other technical protections.
- Probe, scan, or test the vulnerability of the Service except under an authorized program described in the [to be finalized].
2.4 Identity & accounts
- Impersonate any person, parish, diocese, or organization, or misstate your affiliation with one.
- Create fake, duplicate, or unauthorized accounts, or register a parish you are not authorized to represent.
- Share, sell, or transfer login credentials, or allow use of your access by anyone not authorized by the Parish.
2.5 Misuse of donor personal information
- Access, use, disclose, or retain donor personal information for any purpose other than administering the Parish's own giving program.
- Sell, rent, or trade donor personal information, or use it for unrelated marketing without a lawful basis and any required consent.
- Fail to apply reasonable safeguards to donor personal information within your control.
3. Square, Apple & card-network rules
Because donations are processed by Square and captured through Apple hardware and software, your use of the Service must also comply with the rules of those providers and the card networks.
- You must comply with the applicable Square (Block, Inc.) terms, seller agreement, and prohibited-use rules that govern the Parish's own Square account.
- You must comply with Apple's terms for the device and for Tap to Pay on iPhone.
- You must comply with the rules of the applicable card networks (for example [to be finalized]) and with applicable payments law.
A violation of a partner or network rule may independently result in suspension or termination of the Parish's Square account by Square, which is outside Stewardvine's control.
4. Donor data & privacy obligations
Authorized Users must handle donor personal information consistently with the Privacy Policy and the Data Processing Addendum, applicable U.S. state privacy laws, and the Parish's own commitments to its donors. Report any suspected data incident promptly through the channel in Section 6.
5. Enforcement & consequences
Stewardvine may investigate suspected violations and may take any action it considers appropriate, in its reasonable discretion and subject to the Terms / MSA, including:
- Warning or request to remediate a violation within a stated period.
- Suspension of a user, an Admin account, or the Parish's access to the Service.
- Termination of access or of the subscription in accordance with the Terms / MSA.
- Revocation of the OAuth connection / access tokens that link the Stewardvine software to the Parish's Square account. Revoking that connection stops Stewardvine's software from reading transaction metadata; it does not move, freeze, or withhold any funds, which remain in the Parish's own Square account under the Parish's control.
- Referral to Square, Apple, a card network, or law enforcement where appropriate.
Because Stewardvine never holds donor funds, no enforcement action by Stewardvine places donations at risk of loss. Enforcement affects access to Stewardvine's software features only — the Parish's money stays in the Parish's own Square account throughout.
Stewardvine's failure to enforce any part of this Policy is not a waiver of its right to do so later. Remedies here are in addition to any other rights in the [to be finalized].
6. Reporting abuse
If you become aware of a violation of this Policy — suspected fraud, a security vulnerability, misuse of donor data, or impersonation — please report it promptly:
- Abuse & security reports: abuse@stewardvine.com
- Suspected data incident: [to be finalized]
- General questions: privacy@stewardvine.com
Please include enough detail for us to locate and investigate the issue. Do not include full payment-card numbers or other sensitive data in your report.
7. Changes to this Policy
Stewardvine may update this Policy from time to time. Material changes will be communicated as described in the [to be finalized]. Continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.
Questions? Contact privacy@stewardvine.com. You can also return to the Legal hub.