Skip to content

Legal

Acceptable Use Policy

Droppy is non-custodial software, so we cannot freeze or reverse a payment. What we can do is decline to provide the service to people using it to cause harm. This policy sets out where that line sits.

Prohibited activity

You may not use Droppy to request or receive payment in connection with:

  • Fraud, deception or impersonation, including requesting payment for goods or services you do not intend to provide.
  • Money laundering, terrorist financing, or evasion of sanctions or export controls.
  • Ransomware, extortion, blackmail, or payment for access to data or systems obtained without authorisation.
  • Sale of stolen goods, stolen credentials, stolen payment instruments or stolen personal data.
  • Child sexual abuse material, or any content produced through the sexual exploitation of any person.
  • Human trafficking, forced labour, or the exploitation of vulnerable people.
  • Sale of weapons, explosives or controlled substances where doing so is unlawful in the relevant jurisdiction.
  • Ponzi schemes, pyramid schemes, matrix schemes or other structures dependent on recruiting new participants to pay earlier ones.
  • Any other activity unlawful in your jurisdiction or the jurisdiction of the person paying you.

Impersonation and phishing

You may not present Droppy payment links in a way that implies endorsement by, or affiliation with, Droppy or any other organisation without authorisation.

You may not use Droppy as part of a phishing operation, including creating checkout pages designed to be mistaken for another brand's, or soliciting seed phrases or private keys. Droppy itself will never ask for these, and neither should anyone using it.

Technical abuse

You may not:

  • Attempt to circumvent rate limits, authentication or authorisation controls.
  • Access or attempt to access payment links, dashboards or data belonging to another merchant.
  • Automate link creation at a volume that degrades the service for others.
  • Probe, scan or test the security of the service except as described under responsible disclosure below.
  • Reverse engineer the service in order to build a competing product using our infrastructure.

Responsible security research

Good-faith security research is welcome and will not be treated as abuse, provided you avoid accessing other people's data, avoid degrading the service for others, do not exfiltrate data beyond what is needed to demonstrate an issue, and report what you find privately to security@droppy.app before disclosing it publicly.

We will confirm receipt of a report, keep you updated, and credit you if you would like to be credited.

How we enforce this

Droppy is non-custodial: we hold no funds, so enforcement never involves seizing or freezing money. It cannot, technically.

Where we find a clear violation, we may decline to serve a wallet address, disable specific payment links, or restrict access to the hosted service. Where required by law, we may report unlawful activity to the relevant authorities.

Because we cannot reverse a blockchain payment, enforcement is necessarily forward-looking. This is a reason to be careful about who you transact with, not a reason to rely on us to undo a bad one.

Reporting abuse

If you believe a Droppy payment link is being used for any of the activity above, report it to abuse@droppy.app. Include the link URL and any context you can share. If you have been defrauded, contact your local law enforcement as well — they, not we, have the authority to investigate.

Ready to accept crypto?

Create your first payment link in under a minute. No signup form, no API key.