Acceptable Use Policy
What is not allowed on TrustRating — fake reviews, manipulation, harassment, scraping, technical and commercial abuse.
_Last updated: 3 August 2026_
This Acceptable Use Policy ("AUP") sets out what you may not do on TrustRating. It applies to everyone — visitors, reviewers, businesses, team members, affiliates, API consumers — and to every part of the Service: the consumer site, the business panel, widgets, the API, webhooks, emails and support channels. It is part of the Terms of Service; breaching it is breaching your contract with us. Specialised rules for reviews live in the Reviewer Guidelines; for businesses in the Business Terms of Service; for developers and partners in the API, Webhooks & Affiliate Program Terms. Where several documents touch the same conduct, the strictest applicable rule governs — the overlap is deliberate, not an accident to be argued about.
The purpose of this document is simple: TrustRating only works if the information on it is honest and the platform is safe to use. Everything below serves that purpose.
1. Unlawful and harmful content
The content rules below apply to every field a user can fill — reviews, replies, usernames, profile text, company descriptions, news posts, ticket messages, application forms. You must not submit, publish or transmit content that: is illegal in your jurisdiction or ours; is defamatory, fraudulent or deliberately misleading; harasses, threatens, intimidates or incites hatred or violence against any person or group, including on the basis of race, ethnicity, religion, gender, sexual orientation, disability or nationality; is sexually explicit or exploits minors in any way (such content is reported to authorities); discloses another person's private information without their consent — home addresses, private phone numbers, financial details, health information, or the identity of private individuals who have not made themselves part of a public matter; infringes intellectual-property rights (see the takedown procedure in the Content Integrity, Scoring & IP Policy); or contains malware, phishing links or other technically harmful material.
Naming a company employee in a review is acceptable only when relevant to the experience and limited to their professional role (for example a first name and position). Campaigns targeting individual staff members are treated as harassment. The same balance applies in the other direction: a business reply must never expose a reviewer's identity or personal details beyond what the reviewer chose to publish, and "we will find out who you are" rhetoric in replies is a violation on its face.
2. Review and rating manipulation
The integrity of reviews and TrustScores is the platform's reason to exist. You must not, directly or through others: write or commission fake reviews — reviews of experiences that did not happen, or by people who did not have them; buy, sell or trade reviews, ratings, helpful votes or flags, or offer or accept any incentive (money, discounts, gifts, contest entries, refunds) in exchange for a review or for changing or deleting one; review your own business or your employer's without disclosure, or a direct competitor's business in order to harm it; operate or participate in review rings, bot networks or coordinated campaigns — positive or negative — including "review bombing" a business over news events rather than personal experiences; threaten a business with a negative review (or offer to remove one) to extract refunds, freebies or payments beyond what you are genuinely owed — this is extortion and results in immediate account termination; submit reviews generated wholesale by AI tools and presented as personal experience; or create multiple accounts to amplify any of the above, evade a ban, or fabricate consensus.
Businesses must not cherry-pick which customers are invited to review, gate negative feedback away from the platform, impersonate consumers, or retaliate against reviewers — the full rules are in the Business Terms of Service. Attempting to manipulate the AI analysis that feeds TrustScores — for example by publishing misleading content designed to game model assessments — is treated the same as review fraud.
Be aware that in most jurisdictions this is not merely a platform rule: publishing fake reviews, purchasing them, or suppressing genuine ones is illegal under consumer-protection law (unfair commercial practices rules in the EU, FTC endorsement rules in the US, and their equivalents elsewhere), and both the commissioning business and the paid reviewer can face regulatory penalties independent of anything we do. Our enforcement and the law's enforcement stack; they do not substitute for each other.
3. Misrepresentation and impersonation
You must not impersonate any person or organisation, claim a company you do not represent (see the Company Claims & Domain Verification Policy), misstate your affiliation with TrustRating, present our scores or badges in a false or misleading way (see the Widget & Embedding Terms), or use the platform to run scams, pyramid schemes or deceptive commercial practices.
Evading enforcement is itself a violation: creating new accounts after a suspension or ban, using another person's account to continue prohibited activity, laundering a banned business through a "new" profile for the same operation, or re-entering the affiliate program under a different identity after a fraud termination. Sanctions follow the person and the operation, not the account name, and evasion converts temporary measures into permanent ones.
4. Technical abuse
Technical rules protect two things at once: the stability of the Service for everyone using it right now, and the value of the database that honest reviewers spent years building. You must not: probe, scan or test the vulnerability of the Service, or breach or circumvent authentication and security controls; access data not intended for you, including other users' accounts or non-public company data; scrape, crawl, harvest or bulk-download content — including reviews, scores and company data — outside the documented API and our robots directives; extract or reuse a substantial part of our database in any medium, or build a competing dataset from our content; interfere with the Service's operation by flooding, rate-limit evasion, denial-of-service, or by imposing an unreasonable load; bypass, remove or defeat rate limits, paywalls, plan entitlements or moderation controls; introduce viruses, worms or other malicious code; send unsolicited bulk messages through any of our features (invitations, replies, tickets, webhooks); or use automated agents to register accounts or submit content. Good-faith security research is welcome through coordinated disclosure — contact us before testing anything, and never access other people's data.
5. Commercial misuse
You must not: resell, sublicense or white-label access to the Service except as expressly allowed by your plan; use consumer accounts for commercial solicitation, advertising or SEO link-building (reviews exist for experiences, not promotion); abuse free trials, courtesy features or promotional credits through repeated sign-ups; misuse the affiliate program through self-referrals, cookie stuffing, forced clicks, brand-keyword advertising or misleading promises (full list in the API, Webhooks & Affiliate Program Terms); or use TWallet credits or payment flows for money laundering, sanctions evasion or any purpose other than paying for the Service — see the Payments & Refunds Policy.
A specific warning for reputation-management vendors: services offering to "fix", "boost" or "clean up" a TrustRating profile through review posting, review removal, mass flagging or claimed inside contacts are selling violations of this AUP. A business that hires such a vendor is responsible for everything the vendor does in its name, under Section 3 of the Business Terms of Service — "our agency did it" has never once been a defence.
6. How the rules apply in practice
Abstract rules are easiest to follow through examples, so here is how common situations resolve. "My cousin had a terrible experience — can I write it up for her?" No; experiences belong to the person who had them. Help her create an account instead. "A company offered me a discount code to change my one-star review." The offer itself violates this AUP on the company's side; accepting it would violate it on yours. Report it, keep the review honest. "I run a marketing agency — can I post reviews for my clients' happy customers?" Never. Each customer writes their own review or there is no review; an agency posting on behalf of customers is a fake-review operation whatever the underlying sentiment. "Can I scrape scores for a university research project?" Not by scraping — but we like research; contact us about data access, and quoting published scores with attribution needs no permission at all. "A competitor is clearly review-bombing my company." Report it from your business panel; coordinated attacks are exactly what TrustGuard quarantines, and the moderation policy describes the process. "I found a security vulnerability." Thank you — report it privately through the contact page before telling anyone else, do not access other people's data while demonstrating it, and give us reasonable time to fix it. Good-faith reports handled this way will never be met with legal action from us.
7. Rules for specific surfaces
A few features carry their own sharpened rules. Support and tickets: support staff are people; abuse, threats and spam directed at them are treated exactly like abuse of users, and fraudulent tickets (fake billing claims, impersonation of other account holders) are treated as fraud. Company news and profile content: business-published content must be recognisable as company communication, truthful, and free of the prohibited content in Section 1 — a company profile is not a platform for attacks on competitors or reviewers. Review invitations: using invitation tools for anything but genuine post-transaction review requests — newsletters, promotions, harvesting — is spam and breaches the Business Terms of Service as well. Notifications and mentions: systematically triggering notifications to harass a person (flag-spamming their reviews, mass-reporting their account) is harassment even though each individual action looks procedural. Public profiles: usernames, display names and avatars are content too — impersonating names, slurs, and misleading "official"-sounding identities are prohibited and renamed or removed on discovery.
8. Reporting violations
Anyone can flag a review directly on the page; flags from independent users automatically escalate content to human moderation. For anything else — impersonation, security issues, harassment, fraud — use the contact page or the help center. Reports are confidential; we do not reveal reporter identities to the reported party except where the law requires. Knowingly false or abusive reports are themselves a violation of this AUP.
When we investigate a report we may preserve relevant records (content, logs, account signals) beyond their normal retention so the investigation and any appeal can be conducted fairly — this preservation is described in the Privacy Policy. Where conduct appears criminal — threats of violence, child-safety violations, large-scale fraud — we report to and cooperate with law enforcement, and we respond to valid legal orders as described in the moderation policy.
9. How we enforce
Enforcement is proportionate to the harm and the intent, and follows the process in the Review Verification, Moderation & Appeals Policy. Measures include, in escalating order: removing or hiding content; adding warning labels; restricting specific features (for example a review ban that leaves the rest of the account intact); temporary suspension; permanent termination of the account and all linked identities; forfeiture of affiliate commissions obtained through fraud; and, for grave cases — fraud, extortion, threats, child-safety violations — referral to law enforcement and civil action. Where the violation involves a business account, consequences can extend to the subscription (without refund, where the law permits) and to the verified badge. Every enforcement decision tells you what rule was breached and how to appeal.
Proportionality cuts both ways: we distinguish a heated review from a harassment campaign, a curious developer from a scraping operation, a misconfigured integration from deliberate rate-limit evasion — and we also refuse to be gamed by bad actors hiding behind "it was just a mistake" when the pattern says otherwise. History matters: a first borderline incident usually earns an explanation and a chance to fix it; the same incident from an account with prior warnings earns the next step on the ladder. Every substantive enforcement decision states the rule applied and carries the appeal route described in the Review Verification, Moderation & Appeals Policy.
10. Changes
We update this AUP as new abuse patterns emerge. Material changes are announced as described in the Terms of Service. Continued use after the effective date is acceptance of the updated policy.