We operate shared technical infrastructure serving many stores. What one subscriber does can affect the rest — so this document sets out what is permitted, what is not, and what we do when it is breached.
1. Who it applies to
It applies to everyone who uses our services or technical resources: the client, their staff, their contractors, and any party the client grants access to the service.
2. Prohibited uses
1. Breaking the law
- Offering or selling products or services prohibited in the Kingdom, or requiring a licence the client does not hold.
- Carrying on commercial activity without a valid commercial registration or freelance document, contrary to what the Ministry of Commerce requires of online stores.
- Commercial concealment, or trading under an identity other than that of the true owner of the business.
2. Harming systems and networks
- Attempting unlawful access to any system, account or network.
- Penetration testing or security scanning against our infrastructure without our prior written authorisation.
- Distributing malware, exploiting vulnerabilities, or denying service to others.
- Exceeding agreed consumption limits in a way that harms other subscribers, or running cryptocurrency mining.
3. Harming the consumer
- Misleading advertising, fictitious prices, or discounts that are not real.
- Concealing entity details or return terms from the buyer.
- Imposing terms that waive the consumer’s statutory rights.
4. Misusing data
- Processing personal data without a lawful basis or without a published privacy notice.
- Uploading purchased or leaked databases to our systems.
- Sending bulk commercial messages to people who have not consented to receive them.
5. Prohibited content
- Anything contrary to Sharia, public morals, or public order in the Kingdom.
- Anything infringing another party’s intellectual property.
- Anything inciting hatred or violence, or amounting to defamation or impersonation.
3. Security obligations on the client
- Enable two-step verification on administrative accounts.
- Grant each person the least privilege sufficient for their work, and withdraw it as soon as their role ends.
- Do not share a single set of credentials among several people.
- Notify us immediately on suspicion of compromise or leakage.
- Do not install extensions or scripts of unknown origin on the environment we operate without coordinating with us.
4. What we do on a breach
- Notice and a cure period — for breaches capable of correction, we notify you and allow a reasonable period.
- Restriction or temporary suspension — where the breach causes immediate harm to the infrastructure, to other subscribers, or to people’s data.
- Termination — on a serious breach, or repetition after notice.
- Reporting — where the law requires reporting to the competent authorities, we comply.
We always seek the lightest measure sufficient to stop the harm, and we tell you what we took and why, unless the law prevents it.
5. Reporting abuse or a vulnerability
If you observe misuse of our services or discover a security vulnerability, write to support@ezhalha.store with the subject “security report”. We undertake to reply within one business day, and to take no action against a security researcher who reports in good faith, does not exceed the access necessary to demonstrate the vulnerability, and does not publish it before it is remediated.
Not sure whether your activity needs an extra licence?
We help you read the technical and regulatory requirements for your activity before launch, not after.
