Network Acceptable Use Policy
1. Purpose and Scope
This Acceptable Use Policy governs the use of all products, systems, infrastructure, networks, platforms, applications, equipment, connectivity, hosting, email, domain, DNS, storage, backup, security, monitoring, support, and related services supplied, operated, administered, leased, licensed, or arranged by Spark Rack.
This Policy applies to:
- Every Spark Rack customer;
- Every person or entity accessing Services through a customer;
- Customer employees, contractors, agents, representatives, and administrators;
- Resellers and their customers;
- End Users;
- Visitors, subscribers, members, or users of Customer-operated services;
- All Customer Content;
- All devices, systems, applications, domains, and accounts connected to the Services;
- All traffic transmitted through the Spark Rack Network; and
- Any activity that originates from, targets, passes through, is controlled through, or is materially supported by the Services.
This Policy is incorporated into and forms part of the Spark Rack Terms of Service. Capitalized terms not separately defined in this Policy have the meanings assigned to them in the Terms of Service.
By ordering, accessing, or using the Services, Customer agrees to comply with this Policy and to ensure that every End User complies with it.
2. Definitions
2.1 “Abuse”
Any activity that violates this Policy, Applicable Law, the rights of another person, the security or integrity of a system, or the intended operation of the Services or Spark Rack Network.
2.2 “Customer”
The individual or legal entity that creates an Account, submits an Order, receives an invoice, accepts the Terms of Service, or otherwise uses or controls the Services.
2.3 “Customer Content”
All files, websites, applications, software, databases, messages, media, records, configurations, credentials, domains, data, and other material uploaded, stored, processed, transmitted, displayed, distributed, or otherwise made available through the Services by or for Customer.
2.4 “End User”
Any person or entity that accesses, receives, or uses the Services through Customer, including employees, contractors, customers, subscribers, tenants, website visitors, application users, and reseller clients.
2.5 “Services”
All services supplied by Spark Rack, including hosting, servers, virtual machines, containers, infrastructure, networking, Internet connectivity, email, messaging, domain registration, DNS, databases, storage, backups, security, monitoring, managed services, support, licenses, and related products.
2.6 “Spark Rack Network”
All network infrastructure operated, administered, controlled, leased, licensed, or arranged by Spark Rack, including servers, routers, switches, firewalls, storage systems, transit, peering, Internet connections, IP address space, DNS systems, DDoS-mitigation systems, internal networks, management networks, data-center connectivity, and upstream or downstream provider relationships.
3. General Use Requirements
Customer may use the Services only:
- For lawful purposes;
- In accordance with this Policy and the Terms of Service;
- Within the technical and resource limits of the applicable Service;
- In a manner that does not interfere with other customers;
- In a manner that does not threaten the security, reputation, availability, or integrity of Spark Rack or any third party;
- Using accurate Account, billing, and contact information;
- With all required licenses, permissions, authorizations, notices, and consents; and
- In accordance with all applicable product descriptions, Documentation, Orders, and service-specific restrictions.
Customer may not use the Services to engage in, facilitate, support, conceal, advertise, promote, or materially contribute to prohibited activity.
Customer may not use a third party, intermediary, proxy, reseller, content-delivery network, tunnel, redirect, domain, or remote system to accomplish activity that would be prohibited if performed directly through the Services.
4. Customer Responsibility
Customer is responsible for:
- All activity conducted through the Account or Services;
- All Customer Content;
- All End User activity;
- All applications, software, scripts, and services installed by or for Customer;
- Securing credentials, private keys, tokens, recovery codes, and administrative access;
- Maintaining current security updates;
- Correcting compromised or vulnerable systems;
- Maintaining accurate abuse, administrative, and technical contacts;
- Responding promptly to Spark Rack notices;
- Maintaining independent backups;
- Monitoring Customer-operated services for Abuse;
- Obtaining all legally required consents and permissions;
- Ensuring that resellers and End Users are bound by appropriate acceptable-use requirements; and
- Preventing unauthorized persons from using the Services.
Customer is responsible for activity performed with compromised credentials unless the compromise was directly caused by Spark Rack’s legally actionable conduct.
Customer’s lack of knowledge does not excuse a violation when Customer knew, reasonably should have known, or failed to take reasonable measures to discover or prevent the activity.
5. Unlawful Activity
The Services may not be used for any activity that violates applicable federal, state, local, or foreign law.
Prohibited activity includes:
- Fraud;
- Theft;
- Identity theft;
- Trafficking;
- Extortion;
- Blackmail;
- Bribery;
- Money laundering;
- Racketeering;
- Criminal solicitation;
- Obstruction of justice;
- Tax fraud;
- Counterfeiting;
- Sanctions evasion;
- Illegal gambling;
- Sale or distribution of illegal goods or services;
- Unauthorized access to systems or data;
- Unlawful interception of communications;
- Violation of intellectual-property rights;
- Violation of privacy or data-protection rights;
- Conduct involving stolen property or stolen information;
- Material support of criminal activity; and
- Attempts, conspiracies, or assistance relating to prohibited conduct.
Spark Rack may restrict activity that creates a substantial legal, regulatory, security, or reputational risk even when the final legality of the activity has not yet been adjudicated.
6. Fraud, Deception, and Impersonation
Customer may not use the Services to commit, facilitate, or promote fraud or deception.
Prohibited conduct includes:
- Creating fraudulent websites, stores, marketplaces, charities, investment services, or support portals;
- Impersonating another person, company, government agency, financial institution, service provider, or brand without lawful authorization;
- Creating fake invoices, payment notices, account warnings, shipment notices, or legal demands;
- Using deceptive domains, subdomains, display names, sender identities, or website designs;
- Operating advance-fee, romance, employment, technical-support, refund, recovery, or investment scams;
- Misrepresenting the origin, ownership, purpose, or destination of funds;
- Using false reviews, testimonials, endorsements, credentials, or affiliations;
- Manipulating online marketplaces or payment systems;
- Creating fake identity-verification systems;
- Using synthetic media or artificial intelligence to impersonate another person deceptively;
- Registering domains primarily to deceive users about identity or affiliation;
- Using stolen or fabricated identification documents;
- Operating fraudulent customer-service telephone numbers, chat services, or email addresses;
- Submitting false information to Spark Rack or another provider; or
- Concealing the identity or location of a person engaged in prohibited activity.
7. Financial Crime and Payment Abuse
The Services may not be used for financial crime or payment-system abuse.
Prohibited activity includes:
- Carding;
- Testing stolen payment-card numbers;
- Trading payment-card data;
- Hosting carding forums or marketplaces;
- Account takeover;
- Credential stuffing against financial services;
- Payment laundering;
- Fraudulent chargebacks;
- Check fraud;
- Wire fraud;
- Cryptocurrency theft;
- Wallet-draining schemes;
- Fraudulent token offerings;
- Pyramid or Ponzi schemes;
- Market manipulation;
- Securities fraud;
- Money-mule recruitment;
- Sale or distribution of stolen financial information;
- Bypassing fraud-prevention or identity-verification systems; or
- Operating an unlicensed financial service where a license is legally required.
8. Child Safety and Exploitation
The Services may not be used for any activity that exploits, abuses, sexualizes, traffics, grooms, entices, threatens, or endangers a minor.
Strictly prohibited content and activity include:
- Child sexual abuse material;
- Material depicting or promoting the sexual exploitation of a minor;
- Computer-generated, altered, animated, illustrated, or synthetic material depicting the sexual abuse or sexual exploitation of a minor;
- Sexualized depictions of persons presented as minors;
- Grooming or online enticement;
- Sextortion;
- Child sex trafficking;
- Solicitation of sexual activity involving a minor;
- Instructions for locating, creating, concealing, trading, or accessing child sexual abuse material;
- Communities, forums, chat rooms, or services organized around sexual interest in minors;
- Sexualized roleplay involving minors;
- Requests for a minor to create or transmit sexually explicit material;
- Threats to publish intimate material involving a minor;
- Links, hashes, access credentials, indexes, archives, or directories facilitating access to prohibited material;
- Attempts to evade child-safety detection or reporting systems; and
- Any material or conduct that Spark Rack reasonably believes must be reported or preserved under applicable child-safety law.
Apparent child sexual exploitation may result in immediate suspension or termination without prior notice. Spark Rack may preserve relevant records and report apparent violations to the National Center for Missing & Exploited Children, law enforcement, or another appropriate authority.
Customer must not access, download, copy, transmit, or preserve suspected child sexual abuse material for the purpose of independently investigating it. Customer should immediately stop interacting with the material and report the matter through Spark Rack’s designated abuse channel or an appropriate law-enforcement or child-protection reporting channel.
9. Sexual Exploitation and Nonconsensual Intimate Content
The Services may not be used to create, distribute, threaten to distribute, solicit, advertise, sell, or facilitate:
- Nonconsensual intimate images or recordings;
- Sexual deepfakes or synthetic intimate media depicting an identifiable person without consent;
- Hidden-camera sexual content;
- Voyeuristic content created or distributed unlawfully;
- Sexual content obtained through coercion, trafficking, exploitation, or abuse;
- Threats to publish intimate content;
- Sextortion;
- Sexual services that violate Applicable Law;
- Content depicting sexual assault or abuse as an actual event;
- Content distributed in violation of a court order or legal restriction; or
- Services primarily designed to identify, expose, harass, or exploit sex workers, abuse survivors, or victims of intimate-image abuse.
Services primarily dedicated to lawful sexually explicit adult content require prior written approval from Spark Rack. Approval may be withheld or revoked based on payment-processor rules, data-center requirements, Applicable Law, security risk, resource usage, or abuse history.
Where approved, Customer must maintain appropriate age verification, consent records, content-review controls, abuse-reporting mechanisms, and procedures for promptly removing unlawful or nonconsensual content.
10. Human Trafficking and Exploitation
The Services may not be used to facilitate, advertise, recruit for, conceal, finance, or profit from human trafficking, forced labor, involuntary servitude, sexual exploitation, or coercive labor practices.
This prohibition includes:
- Trafficking advertisements;
- Recruitment through fraud or coercion;
- Sale or transfer of persons;
- Withholding identity documents to control another person;
- Threatening victims or witnesses;
- Transportation or lodging systems knowingly supporting trafficking;
- Payment systems knowingly supporting trafficking; and
- Directories or communications systems knowingly used to coordinate exploitation.
11. Violence, Threats, and Dangerous Activity
The Services may not be used to make, facilitate, or promote credible threats of violence or unlawful physical harm.
Prohibited conduct includes:
- Credible threats against an identifiable person or group;
- Soliciting murder, assault, kidnapping, arson, bombing, or another violent offense;
- Publishing personal information to facilitate imminent violence;
- Coordinating violent criminal activity;
- Providing operational support for an imminent violent attack;
- Threatening critical infrastructure;
- Extortion involving threats of physical harm;
- Promoting or facilitating terrorism in violation of Applicable Law;
- Material support for legally designated terrorist organizations;
- Instructions specifically intended to enable an imminent violent crime; or
- Glorification of actual violence when combined with recruitment, operational coordination, fundraising, or material support for unlawful violence.
This section is not intended to prohibit lawful news reporting, historical discussion, academic research, documentary material, fictional content, political advocacy, or other lawful expression that does not materially facilitate prohibited conduct.
12. Harassment, Stalking, and Doxxing
The Services may not be used for targeted harassment, stalking, intimidation, or unlawful disclosure of personal information.
Prohibited conduct includes:
- Publishing a person’s private home address, precise location, credentials, financial information, or sensitive identifying information to threaten or facilitate harm;
- Operating a campaign of targeted threats or intimidation;
- Cyberstalking;
- Coordinated harassment intended to cause substantial harm;
- Repeated unwanted communications after a clear request to stop where prohibited by law;
- Swatting or facilitating false emergency reports;
- Threatening family members, employers, customers, or associates to coerce a person;
- Publishing private information obtained through hacking, theft, coercion, or unlawful surveillance;
- Operating services designed primarily to facilitate stalking or intimate-partner abuse;
- Using tracking technology without required authority or consent; or
- Impersonating a victim to damage reputation, employment, finances, or personal safety.
This provision does not prohibit lawful criticism, consumer reviews, journalism, public-record reporting, whistleblowing, political speech, parody, satire, or advocacy merely because the subject finds the expression offensive.
13. Intellectual Property and Proprietary Rights
Customer may not use the Services to infringe, misappropriate, or violate:
- Copyrights;
- Trademarks;
- Patents;
- Trade secrets;
- Database rights;
- Publicity rights;
- Design rights;
- Software licenses;
- Contractual confidentiality rights; or
- Other proprietary rights.
Prohibited activity includes:
- Hosting pirated software, media, books, games, or subscription content;
- Operating unauthorized streaming or download services;
- Distributing license keys, cracks, key generators, or access-control bypass tools primarily intended for infringement;
- Hosting counterfeit-goods marketplaces;
- Using a domain or website to impersonate or confuse users regarding a protected brand;
- Distributing stolen source code or confidential commercial data;
- Operating services primarily intended to evade technological protection measures unlawfully;
- Ignoring valid infringement notices;
- Repeated infringement by Customer or End Users; or
- Assisting another person in concealing infringing activity.
Spark Rack may remove or disable access to allegedly infringing material, forward complaints to Customer, request a response, or terminate repeat infringers in appropriate circumstances.
14. Privacy and Personal Data
Customer may not use the Services to collect, process, sell, disclose, transmit, monitor, or retain personal information in violation of Applicable Law or enforceable privacy rights.
Prohibited activity includes:
- Hosting stolen personal-information databases;
- Trading credentials or identity information;
- Collecting personal information through deception;
- Unlawful surveillance;
- Unlawful interception of electronic communications;
- Installing spyware or stalkerware without lawful authority;
- Collecting biometric, health, financial, location, or children’s information without required notices or consent;
- Selling personal information where prohibited;
- Using unlawfully obtained data for identity theft, harassment, discrimination, or fraud;
- Operating data-broker services without required disclosures, registrations, or controls;
- Circumventing privacy settings or access controls;
- Publishing authentication secrets, private keys, or recovery codes;
- Failing to protect regulated data with legally required safeguards; or
- Retaining personal information longer than lawfully permitted.
Customer is responsible for providing required privacy notices, obtaining required consents, honoring applicable rights requests, implementing reasonable security controls, and entering any legally required data-processing agreements.
15. Unauthorized Access and Computer Misuse
Customer may not access or attempt to access any system, service, network, account, device, or data without authorization or in excess of granted authorization.
Prohibited activity includes:
- Hacking;
- Password cracking;
- Credential stuffing;
- Brute-force attacks;
- Account takeover;
- Session hijacking;
- Token theft;
- Exploiting vulnerabilities without authorization;
- Bypassing authentication or authorization controls;
- Privilege escalation without authorization;
- Accessing another customer’s files, databases, traffic, or systems;
- Breaking tenant-isolation or virtualization controls;
- Escaping a container, virtual machine, or sandbox without authorization;
- Intercepting passwords, tokens, cookies, messages, or network traffic unlawfully;
- Using stolen credentials;
- Installing unauthorized remote-access tools;
- Enumerating accounts for malicious purposes;
- Attempting to compromise Spark Rack personnel, vendors, or customers;
- Using social engineering to obtain unauthorized access;
- Maintaining unauthorized persistence in a system; or
- Concealing unauthorized access through log deletion, rootkits, proxies, or other evasion methods.
16. Malware, Botnets, and Harmful Code
Customer may not knowingly create, host, distribute, operate, control, sell, or facilitate malicious or destructive software.
Prohibited software and activity include:
- Viruses;
- Worms;
- Ransomware;
- Trojan horses;
- Keyloggers;
- Credential stealers;
- Rootkits;
- Bootkits;
- Web shells;
- Backdoors;
- Botnets;
- Command-and-control infrastructure;
- Malicious remote-access software;
- Cryptojacking software;
- Data-destruction tools;
- Wiper malware;
- Exploit kits;
- Malvertising;
- Drive-by download systems;
- Malicious browser extensions;
- Payload-hosting services;
- Dropper or loader infrastructure;
- Phishing kits;
- Traffic-distribution systems supporting malware;
- Domain-generation infrastructure supporting malware;
- Fast-flux networks supporting malicious activity;
- Services that sell or rent access to compromised systems;
- Malware obfuscation or crypter services intended to evade detection;
- Stolen-data exfiltration or collection systems; or
- Any software primarily designed to compromise, damage, disrupt, surveil, extort, or steal from another person without authorization.
Legitimate malware research, defensive analysis, reverse engineering, sandboxing, honeypots, and threat-intelligence activity require prior written approval when the activity could expose Spark Rack, other customers, or third parties to malicious code or harmful traffic.
17. Vulnerability Scanning and Security Research
Customer may perform security testing only against systems Customer owns or is expressly authorized to test.
Customer must obtain prior written approval from Spark Rack before conducting testing that:
- Targets Spark Rack systems or the Spark Rack Network;
- Could generate a material volume of scanning or attack-like traffic;
- Includes denial-of-service testing;
- Includes packet flooding;
- Attempts to escape a virtualized environment;
- Could affect another customer;
- Uses destructive payloads;
- Could trigger upstream abuse controls;
- Could impair network reputation; or
- Is otherwise likely to disrupt the Services.
Security testing must:
- Remain within the authorized scope;
- Use authorized source and destination systems;
- Occur during the approved period;
- Comply with any volume or rate limits;
- Avoid accessing unrelated data;
- Avoid persistent access unless expressly authorized;
- Avoid data destruction;
- Avoid social engineering unless expressly authorized;
- Stop immediately if unintended impact occurs; and
- Be supported by written evidence of authorization upon request.
Discovery of a vulnerability does not authorize Customer to access additional data, expand testing, publish sensitive information, demand payment, or retain unauthorized access.
18. Denial-of-Service Activity and Network Disruption
Customer may not initiate, facilitate, encourage, sell, rent, or coordinate denial-of-service activity.
Prohibited activity includes:
- Distributed denial-of-service attacks;
- Packet floods;
- Application-layer floods;
- Connection exhaustion;
- Reflection attacks;
- Amplification attacks;
- DNS amplification;
- NTP amplification;
- Memcached amplification;
- SSDP amplification;
- CLDAP amplification;
- CHARGEN amplification;
- SYN floods;
- UDP floods;
- ICMP floods;
- Slow-request attacks;
- Resource-exhaustion attacks;
- Booter or stresser services;
- Attack-for-hire services;
- Coordinating traffic intended to make a service unavailable;
- Testing denial-of-service tools without prior approval; or
- Maintaining systems configured as involuntary amplification or reflection sources after receiving notice.
Spark Rack may filter, rate-limit, divert, challenge, block, null-route, isolate, or suspend traffic or Services that are targeted by, participating in, or contributing to a denial-of-service event.
19. Network Integrity and Protocol Abuse
Customer may not interfere with the proper operation of the Spark Rack Network or another network.
Prohibited conduct includes:
- Source-address spoofing;
- MAC-address spoofing for unauthorized purposes;
- ARP poisoning;
- Neighbor-discovery abuse;
- Rogue DHCP services;
- Unauthorized router advertisements;
- Duplicate-address conflicts caused intentionally or through reckless configuration;
- VLAN hopping;
- Bypassing network segmentation;
- Unauthorized packet capture;
- Manipulating network-control protocols;
- Forging TCP/IP packet headers;
- Using addresses or prefixes not assigned to Customer;
- Creating open recursive DNS resolvers without appropriate access controls;
- Operating open SMTP relays;
- Operating insecure amplification services;
- Deliberately generating malformed traffic;
- Causing excessive broadcast or multicast traffic;
- Attempting to evade port, protocol, or traffic controls;
- Using the Services to measure, map, or attack internal Spark Rack infrastructure without authorization;
- Interfering with monitoring, logging, metering, or abuse-detection systems; or
- Conduct that materially degrades network stability, availability, or reputation.
20. Routing, BGP, and Address-Space Abuse
Customers using routing or Border Gateway Protocol services must:
- Advertise only prefixes they are authorized to announce;
- Provide valid letters of authorization when requested;
- Maintain accurate routing-registry records where applicable;
- Maintain valid route-origin authorizations where applicable;
- Use appropriate prefix filters;
- Use appropriate maximum-prefix limits;
- Maintain current technical and abuse contacts;
- Prevent route leaks;
- Prevent unauthorized route propagation;
- Promptly correct unstable or malformed announcements;
- Follow Spark Rack routing requirements; and
- Respond promptly to routing incidents.
Customer may not:
- Hijack an IP prefix;
- Announce address space without authorization;
- Originate false routing information;
- Manipulate route attributes to deceive another network;
- Operate a route leak knowingly or recklessly;
- Use Spark Rack-assigned address space after the assignment ends;
- Lease, sell, transfer, or announce assigned address space without authorization;
- Use address space to conceal prohibited activity; or
- Submit false routing, ownership, geolocation, or registry information.
Spark Rack may reject, filter, suppress, modify, or withdraw route announcements that appear invalid, unauthorized, unstable, dangerous, or inconsistent with Spark Rack routing requirements.
21. Scanning, Brute Force, and Automated Attacks
Customer may not use the Services to perform unauthorized or abusive scanning, enumeration, credential attacks, or automated exploitation.
Prohibited conduct includes:
- Port scanning without authorization;
- Vulnerability scanning without authorization;
- Mass scanning likely to trigger abuse or degrade network reputation;
- Password guessing;
- Credential stuffing;
- Username enumeration for malicious purposes;
- Directory or endpoint enumeration for unauthorized exploitation;
- Automated login attempts against third parties;
- Automated exploitation frameworks used without authorization;
- Mass exploitation of newly disclosed vulnerabilities;
- Scanning for exposed databases, storage buckets, remote-desktop services, or administrative panels for unauthorized access;
- Harvesting API keys, tokens, or credentials;
- Automated account creation intended to evade controls; or
- Distributed scanning intended to avoid detection or rate limits.
22. Phishing and Credential Theft
Customer may not create, host, transmit, redirect to, or otherwise support phishing or credential theft.
Prohibited conduct includes:
- Fake login pages;
- Credential-harvesting forms;
- Fraudulent multifactor-authentication prompts;
- Session-token interception;
- OAuth-consent phishing;
- QR-code phishing;
- Voice or SMS phishing supported by the Services;
- Business-email-compromise campaigns;
- Fraudulent password-reset messages;
- Malicious document-delivery systems;
- Reverse-proxy phishing kits;
- Domains registered primarily to imitate a trusted entity;
- Redirects intended to conceal a phishing destination;
- Hosting images, scripts, mailboxes, or tracking infrastructure supporting phishing;
- Selling phishing kits or stolen credentials;
- Testing stolen credentials;
- Providing bulletproof hosting for phishing operations; or
- Concealing phishing infrastructure through tunnels, proxies, content-delivery networks, or rotating domains.
23. Email and Electronic Messaging
Customer may not use the Services to send, relay, host, facilitate, or support Spam or abusive electronic messaging.
This section applies to:
- Email;
- SMS or MMS messaging;
- Instant messaging;
- Push notifications;
- Social-media messages;
- Voice messages;
- Automated calls;
- Chat systems;
- Contact forms;
- Forum messages;
- Application notifications; and
- Any substantially similar communications.
23.1 Consent and Recipient Lists
Customer must:
- Obtain all consent required by Applicable Law;
- Maintain reasonable evidence of consent;
- Use recipient lists acquired through lawful and transparent means;
- Honor withdrawal of consent;
- Maintain suppression lists;
- Remove invalid or persistently bouncing recipients;
- Prevent messaging to recipients who have opted out;
- Apply appropriate age-related consent requirements; and
- Review third-party list sources before use.
Customer may not use:
- Purchased recipient lists without documented lawful consent;
- Rented lists without documented lawful consent;
- Harvested email addresses;
- Scraped contact information for unsolicited campaigns;
- Guessed or generated addresses;
- Address-enumeration lists;
- Stolen contact databases;
- Lists obtained through malware or data breaches;
- Lists from persons who did not authorize the applicable communication; or
- List-washing or verification services intended to prepare unlawfully obtained lists for delivery.
23.2 Message Identification
Messages must:
- Use accurate sender information;
- Use accurate routing and header information;
- Identify the actual sender or responsible organization;
- Use a subject line that accurately describes the message;
- Clearly identify commercial or promotional content where required;
- Include a valid physical postal address where required;
- Include a functioning opt-out mechanism where required;
- Avoid deceptive display names;
- Avoid misleading reply-to addresses;
- Avoid forged message identifiers; and
- Comply with all legally required disclosures.
23.3 Opt-Out Requirements
Customer must:
- Provide a clear and conspicuous opt-out method for commercial or bulk messaging where required;
- Keep the opt-out mechanism operational for the legally required period;
- Honor valid opt-out requests within the legally required period and no later than ten business days for commercial email;
- Not charge a fee to opt out;
- Not require information beyond what is reasonably necessary to process the opt-out;
- Not require a recipient to log in merely to opt out unless legally permitted;
- Not sell, transfer, or use an opted-out address except to maintain a suppression list; and
- Apply the opt-out across campaigns where required.
23.4 Prohibited Messaging Practices
Customer may not engage in:
- Unsolicited bulk messaging;
- Snowshoe Spam;
- Rotating IP addresses or domains to evade reputation controls;
- Sending through compromised accounts;
- Using open relays or open proxies;
- Forging sender or routing information;
- Using deceptive subjects or sender names;
- Continuing to message recipients who opted out;
- Sending to harvested or generated recipients;
- Using transactional messages to conceal promotional content;
- Misrepresenting the origin of a campaign;
- Operating a messaging service without reasonable abuse controls;
- Sending messages that generate excessive complaints;
- Sending messages that generate excessive hard bounces;
- Using another provider to send messages promoted by or directing users to content hosted by Spark Rack when the campaign violates this Policy;
- Hosting landing pages, images, tracking pixels, unsubscribe pages, redirectors, or data-collection forms supporting prohibited messaging;
- Using URL shorteners to conceal prohibited destinations;
- Evading recipient, provider, or Spark Rack blocks; or
- Sending communications in violation of applicable telemarketing, privacy, consumer-protection, or messaging law.
23.5 Mailing and Messaging Services
Customers operating mailing-list, newsletter, notification, or messaging services must maintain:
- Documented permission standards;
- Automated unsubscribe processing;
- Bounce processing;
- Complaint processing;
- Suppression lists;
- Rate limits;
- Account-abuse controls;
- Compromised-account detection;
- Accurate sender identification;
- Abuse-reporting contacts;
- Reasonable customer verification; and
- Prompt termination of abusive users.
Spark Rack may impose sending limits, recipient limits, rate limits, port restrictions, authentication requirements, or other controls without publishing the precise thresholds used for abuse prevention.
24. Domain Name and DNS Abuse
Customer may not use domain, subdomain, hostname, DNS, or registration Services for:
- Phishing;
- Malware distribution;
- Botnet command and control;
- Fraud;
- Impersonation;
- Counterfeit-goods sales;
- Fast-flux hosting;
- Domain-generation systems supporting malicious activity;
- DNS tunneling for unauthorized access or data exfiltration;
- DNS amplification;
- Operating an unsecured open recursive resolver;
- Deceptive redirects;
- Typosquatting intended to deceive users;
- Homograph attacks;
- Domain shadowing;
- Abusive wildcard records;
- Concealing the destination of prohibited content;
- Bypassing suspension or enforcement;
- Infringing another person’s trademark or rights; or
- Any other activity prohibited by this Policy.
Customer must maintain accurate domain-registration information and must promptly respond to verification, ownership, abuse, or legal inquiries.
Spark Rack may disable DNS resolution, remove a DNS record, suspend domain-management access, place a domain on hold where authorized, or coordinate with a registrar or registry when reasonably necessary to address Abuse.
25. Proxy, VPN, Tor, Relay, and Tunneling Services
Private VPNs and encrypted tunnels used to secure Customer’s own authorized systems are generally permitted unless restricted by the applicable Service.
The following require prior written approval:
- Public proxy services;
- Commercial VPN services;
- Tor exit nodes;
- Public anonymization gateways;
- Traffic relays;
- Residential-proxy networks;
- Peer-to-peer proxy systems;
- Browser-based proxy services;
- Public SSH tunnels;
- Public remote-desktop gateways;
- Public port-forwarding services;
- Reverse-tunneling platforms;
- Content-unblocking services;
- Public DNS privacy gateways; and
- Services whose primary purpose is concealing the source or destination of third-party traffic.
Approval may be conditioned on:
- Customer verification;
- Abuse logging;
- Reasonable retention of security records;
- Rate limits;
- Restricted ports or destinations;
- Prompt abuse response;
- End User terms;
- Sanctions controls;
- Fraud controls;
- Prohibition of Spam and scanning;
- Payment of increased security or network costs; and
- Other reasonable risk controls.
Customer may not use a proxy, VPN, relay, or tunnel to evade Spark Rack enforcement, conceal prohibited activity, bypass legal restrictions, impersonate another user, or interfere with abuse attribution.
26. Scraping, Crawling, and Automated Collection
Customer may use automated collection tools only when authorized and lawful.
Prohibited activity includes:
- Scraping personal information unlawfully;
- Bypassing authentication or paywalls without authorization;
- Circumventing technical access controls;
- Ignoring legally enforceable access restrictions;
- Overloading a third-party service;
- Using distributed systems to evade rate limits;
- Collecting credentials, payment information, or private messages;
- Scraping data for identity theft, harassment, Spam, or fraud;
- Using stolen session cookies or tokens;
- Automating account creation to evade restrictions;
- Collecting copyrighted databases for unlawful redistribution;
- Using browser automation to commit fraud or abuse;
- Operating ticket-buying, purchasing, reservation, or marketplace bots in violation of Applicable Law;
- Creating unreasonable request volumes; or
- Continuing automated access after receiving a valid demand to stop.
Customer must use reasonable request rates, identify automated agents where appropriate, respect security controls, and maintain evidence of authorization when the activity could reasonably be interpreted as abusive.
27. Resource Abuse and Fair Use
Customer may not use resources in a manner that materially interferes with the Services, Spark Rack Network, or another customer.
Prohibited resource use includes:
- Sustained use materially beyond the intended product profile;
- Deliberately exhausting CPU, memory, storage, disk operations, database connections, processes, threads, or network capacity;
- Evading quotas or usage measurements;
- Splitting workloads across Accounts to avoid limits;
- Using shared hosting primarily as bulk storage;
- Using backup Services as general-purpose file distribution;
- Operating public mirrors without approval;
- Operating high-volume download services without approval;
- Generating excessive file or inode counts;
- Running defective software that repeatedly impairs shared systems;
- Creating excessive database load;
- Generating excessive logs or temporary files;
- Using excessive outbound connections;
- Operating public compute services on products not designed for that purpose;
- Consuming resources through compromised applications;
- Using excessive resources without responding to optimization requests;
- Attempting to bypass container, process, execution-time, or memory limits;
- Running persistent processes where the product does not permit them;
- Using shared resources for workloads requiring dedicated infrastructure; or
- Any activity that materially reduces availability or performance for others.
“Unlimited,” “unmetered,” or similar descriptions do not authorize abusive, unreasonable, or technically impossible usage. Such Services remain subject to physical capacity, product design, fair-use requirements, security controls, and protection of other customers.
Spark Rack may require Customer to optimize, reduce, schedule, relocate, or upgrade a workload.
28. Cryptocurrency, Blockchain, and Distributed Computing
Cryptocurrency mining and similarly intensive proof-of-work activity are prohibited unless Spark Rack provides prior written approval.
The following may also require prior written approval:
- Public blockchain nodes;
- Validators;
- Staking services;
- Cryptocurrency exchanges;
- Custodial wallet services;
- Mixers or tumblers;
- Mining pools;
- High-frequency trading systems;
- Token-issuance platforms;
- Cryptocurrency-payment processors;
- Distributed-computing networks;
- High-resource scientific-computing workloads; and
- Services that create elevated financial, sanctions, fraud, or abuse risk.
The Services may not be used for:
- Cryptojacking;
- Wallet theft;
- Seed-phrase theft;
- Fraudulent token sales;
- Money laundering;
- Sanctions evasion;
- Ransomware payments or infrastructure;
- Unlicensed financial activity where a license is required;
- Market manipulation;
- Ponzi or pyramid schemes;
- Operating a mixer or privacy service for unlawful purposes; or
- Any cryptocurrency activity prohibited by Applicable Law.
29. Gambling, Contests, and Wagering
Customer may not use the Services to operate, facilitate, advertise, or process payments for unlawful gambling, wagering, lotteries, sweepstakes, contests, prediction markets, or games of chance.
Services involving gambling or wagering require prior written approval and evidence of all required licenses, geographic controls, age controls, consumer disclosures, responsible-gaming measures, and payment authorization.
Customer may not:
- Accept unlawful wagers;
- Permit underage gambling;
- Evade geographic restrictions;
- Manipulate game outcomes;
- Operate rigged or deceptive games;
- Use stolen payment methods;
- Facilitate match fixing;
- Operate an unlicensed lottery;
- Misrepresent odds or prizes;
- Withhold lawful winnings fraudulently; or
- Use virtual items, tokens, or cryptocurrencies to conceal unlawful wagering.
30. Controlled Substances, Weapons, and Regulated Goods
The Services may not be used to advertise, sell, distribute, manufacture, traffic, or facilitate goods or services in violation of Applicable Law.
Prohibited activity includes:
- Illegal controlled substances;
- Counterfeit prescription drugs;
- Prescription drugs sold without required authorization;
- Drug-trafficking services;
- Instructions specifically intended to facilitate unlawful drug manufacturing;
- Illegal firearms or ammunition sales;
- Weapons trafficking;
- Explosives sold or distributed unlawfully;
- Unlawful suppressors, destructive devices, or regulated weapon components;
- Stolen goods;
- Counterfeit goods;
- Illegal wildlife products;
- Human organs or tissue sold unlawfully;
- Illegal pesticides, poisons, or hazardous chemicals;
- Sanctioned goods;
- Export-controlled goods transferred unlawfully; or
- Any regulated product sold without required licenses, notices, verification, or controls.
Lawful businesses involving regulated goods may be required to provide licensing, age-verification, geographic-control, compliance, or insurance information before approval.
31. Artificial Intelligence and Automated Systems
Artificial intelligence, machine learning, automation, and synthetic-media tools may not be used through the Services to violate this Policy.
Prohibited activity includes using automated or artificial-intelligence systems to:
- Create or facilitate child sexual abuse material;
- Create nonconsensual intimate images;
- Impersonate a person for fraud;
- Generate phishing campaigns;
- Create or improve malware for unauthorized use;
- Automate credential attacks;
- Operate Spam campaigns;
- Generate deceptive reviews or endorsements;
- Fabricate identity documents;
- Create fraudulent evidence;
- Facilitate unlawful discrimination;
- Perform unauthorized surveillance;
- Generate credible threats;
- Coordinate unlawful violence;
- Manipulate markets;
- Evade security, moderation, or abuse controls;
- Mass-create abusive Accounts or domains;
- Clone a person’s voice or likeness deceptively;
- Misrepresent synthetic content as authentic where doing so is fraudulent or unlawful; or
- Process data in violation of privacy, intellectual-property, or contractual rights.
Customer remains responsible for the output and operation of automated systems, including actions performed without direct human review.
32. High-Risk, Critical, and Life-Safety Uses
Unless expressly approved in a signed agreement, Customer may not rely on the Services as the sole or primary system for:
- Emergency dispatch;
- Emergency calling;
- Life-support systems;
- Medical-device control;
- Aircraft navigation or control;
- Vehicle control;
- Nuclear operations;
- Weapons control;
- Industrial safety systems;
- Public-warning systems;
- Critical-infrastructure control;
- Hazardous-material containment;
- Systems where failure could reasonably result in death or serious bodily injury; or
- Any application requiring fault tolerance beyond the capabilities expressly stated in the applicable Order.
Customer is responsible for redundancy, failover, emergency procedures, alternate communications, business continuity, and independent safety controls.
33. Export Controls and Economic Sanctions
Customer may not use the Services in violation of applicable export-control, import-control, trade-sanctions, anti-boycott, or restricted-party laws.
Customer may not:
- Provide Services to a prohibited person or entity;
- Use the Services for a prohibited destination or end use;
- Export controlled software, technical data, encryption, or services without required authorization;
- Use false identity or location information to evade sanctions;
- Use proxies, VPNs, intermediaries, or resellers to conceal a prohibited transaction;
- Facilitate transactions involving blocked property;
- Provide material support to a sanctioned organization;
- Use the Services for prohibited weapons proliferation;
- Use the Services to evade asset freezes or transaction restrictions; or
- Cause Spark Rack to violate an applicable sanctions or export-control requirement.
Spark Rack may screen Accounts, transactions, addresses, domains, payment methods, and other relevant information against sanctions or restricted-party information.
Spark Rack may reject, block, freeze where legally required, suspend, or terminate activity when reasonably necessary to comply with applicable restrictions.
34. Evasion and Concealment
Customer may not evade or attempt to evade this Policy, Spark Rack controls, or enforcement action.
Prohibited evasion includes:
- Creating additional Accounts after suspension or termination;
- Using another person’s Account;
- Providing false identity or contact information;
- Using resellers to conceal ownership;
- Rotating domains, IP addresses, or providers to continue prohibited activity;
- Using reverse proxies or content-delivery networks to conceal an origin involved in Abuse;
- Encrypting or obfuscating activity specifically to evade abuse detection;
- Deleting or altering logs to conceal prohibited activity;
- Using tunnels or relays to defeat traffic restrictions;
- Mislabeling traffic or applications;
- Splitting prohibited activity across multiple systems;
- Moving Content temporarily during an investigation and restoring it afterward;
- Using third-party storage to support prohibited content hosted through the Services;
- Changing sender identity to evade messaging blocks;
- Using domain-generation or fast-flux techniques;
- Providing misleading responses during an investigation;
- Interfering with monitoring or metering;
- Attempting to bypass a null route, firewall rule, rate limit, or suspension; or
- Retaliating against a complainant, investigator, or abuse reporter.
35. Resellers and Multi-Tenant Services
Customers reselling or providing Services to End Users must:
- Maintain enforceable terms consistent with this Policy;
- Provide an accessible abuse-reporting method;
- Maintain accurate End User records;
- Respond promptly to abuse complaints;
- Investigate apparent violations;
- Remove, restrict, or suspend abusive End Users where appropriate;
- Prevent terminated End Users from immediately returning;
- Maintain reasonable security and fraud controls;
- Cooperate with Spark Rack investigations;
- Provide relevant End User information when legally permitted and reasonably required;
- Flow down applicable messaging, privacy, sanctions, and security requirements;
- Monitor for repeated Abuse;
- Maintain a current administrative and abuse contact;
- Avoid representing that an End User is a direct Spark Rack customer; and
- Remain responsible for all activity under the reseller Account.
Spark Rack may take direct action against an End User’s workload when Customer fails to respond or when immediate action is reasonably necessary.
36. Compromised Systems and Accounts
Customer must promptly address any compromised system, application, mailbox, credential, domain, device, or Account.
Required remediation may include:
- Taking the affected system offline;
- Resetting passwords;
- Revoking tokens or API keys;
- Rotating private keys;
- Removing malicious files;
- Rebuilding the system from a trusted source;
- Installing security updates;
- Correcting vulnerable configurations;
- Reviewing logs;
- Notifying affected persons where required;
- Restoring from a verified clean backup;
- Implementing multifactor authentication;
- Restricting administrative access;
- Submitting a remediation summary;
- Allowing Spark Rack to verify remediation; or
- Completing another reasonable corrective measure.
Spark Rack may isolate, block, reset, suspend, or disable a compromised resource without prior notice when necessary to prevent continuing harm.
37. Abuse Reporting
Suspected Abuse involving the Services should be reported through the designated legal or abuse-reporting channel in the Spark Rack Customer Portal.
Reports may also be mailed to:
Spark RackAttn: Abuse and Legal Notices
PO Box 2215
Valdosta, GA 31604
United States
An Abuse report should include, where available:
- The reporting person’s name and contact information;
- The affected IP address, domain, URL, hostname, Account, or Service;
- The date, time, and applicable time zone;
- A clear description of the activity;
- Relevant logs, headers, screenshots, or evidence;
- The legal or policy basis for the complaint;
- Steps already taken;
- Whether immediate danger exists;
- Whether law enforcement has been contacted;
- Whether the report contains sensitive or confidential information; and
- A statement that the report is accurate to the reporter’s knowledge.
Reports should not include unnecessary passwords, private keys, complete payment-card numbers, child sexual abuse material, or other illegal material.
Submission of a report does not guarantee any particular outcome. Spark Rack may request additional information, decline incomplete or unsupported requests, forward relevant portions to Customer, or refer the matter to another provider or authority.
38. Customer Response to Abuse Notices
Customer must:
- Maintain a monitored abuse and administrative contact;
- Review Spark Rack notices promptly;
- Acknowledge critical notices without unreasonable delay;
- Investigate the reported activity;
- Stop continuing Abuse;
- Preserve relevant evidence where appropriate;
- Provide an accurate response;
- Describe corrective action;
- Identify the cause of the incident;
- Prevent recurrence;
- Meet any reasonable remediation deadline;
- Cooperate with necessary testing or verification; and
- Notify Spark Rack if the report appears mistaken and provide supporting information.
The response deadline may depend on the nature and severity of the issue. Immediate threats, active attacks, phishing, malware, child exploitation, Spam, compromised systems, and significant network disruption may require immediate action.
Failure to respond does not prevent Spark Rack from taking enforcement action.
39. Investigation and Monitoring
Spark Rack may investigate suspected violations of this Policy.
Investigative measures may include:
- Reviewing Account records;
- Reviewing authentication records;
- Reviewing system and application logs;
- Reviewing network-flow information;
- Reviewing message headers and delivery records;
- Reviewing resource usage;
- Reviewing configuration data;
- Conducting limited packet capture;
- Testing whether a Service is compromised or misconfigured;
- Reviewing publicly accessible Customer Content;
- Requesting information from Customer;
- Consulting upstream providers, registrars, registries, data centers, security vendors, or law enforcement;
- Preserving relevant records;
- Using automated abuse-detection systems; and
- Taking other reasonable measures necessary to assess or stop harm.
Spark Rack has no general obligation to monitor all Customer Content or activity and does not assume responsibility for detecting every violation.
Spark Rack’s failure to detect, investigate, or act on a violation does not constitute approval of the activity or waiver of the right to act later.
40. Enforcement
Spark Rack may take one or more enforcement actions when it reasonably believes this Policy has been violated or that action is necessary to protect people, systems, data, infrastructure, legal compliance, or network reputation.
Enforcement actions may include:
- Issuing a warning;
- Requesting information;
- Requiring remediation;
- Setting a remediation deadline;
- Resetting credentials;
- Revoking tokens, API keys, or certificates;
- Disabling a user or administrative Account;
- Removing or disabling access to Content;
- Quarantining files;
- Blocking a port, protocol, source, or destination;
- Applying rate limits;
- Filtering traffic;
- Rejecting or deferring messages;
- Disabling outbound email;
- Disabling DNS records or resolution;
- Null-routing an IP address;
- Withdrawing a route;
- Isolating a server or network interface;
- Suspending a Service;
- Suspending the entire Account;
- Refusing new Orders;
- Requiring a Service upgrade or migration;
- Requiring a security deposit or advance payment;
- Charging documented remediation or third-party costs where permitted;
- Terminating a Service or Account;
- Preserving relevant data;
- Notifying an upstream provider, registrar, registry, data center, payment processor, or affected third party;
- Reporting apparent criminal conduct to law enforcement or an appropriate reporting organization; or
- Taking another reasonable protective measure.
41. Immediate Action Without Notice
Spark Rack may act without prior notice when it reasonably believes immediate action is necessary to:
- Prevent death or serious physical harm;
- Address child exploitation;
- Stop an active cyberattack;
- Stop phishing or credential theft;
- Stop malware distribution;
- Stop a denial-of-service event;
- Prevent substantial network disruption;
- Protect another customer’s data;
- Comply with legal process;
- Comply with sanctions or export restrictions;
- Prevent substantial fraud;
- Address a compromised system;
- Protect IP address or domain reputation;
- Prevent evidence destruction;
- Protect Spark Rack personnel or infrastructure; or
- Address another urgent and material risk.
42. Enforcement Factors
When determining an appropriate response, Spark Rack may consider:
- The severity of the activity;
- Whether harm is ongoing;
- Whether the violation was intentional, reckless, negligent, or accidental;
- The risk to people, systems, data, or infrastructure;
- The volume and duration of the activity;
- The number of affected persons;
- Customer’s prior violation history;
- Customer’s response to notices;
- Customer’s remediation efforts;
- Whether Customer attempted to conceal the activity;
- Whether Customer profited from the activity;
- Whether the Account appears compromised;
- Whether a lesser measure can reasonably address the risk;
- Requirements imposed by law or third parties;
- Impact on Spark Rack’s network or reputation; and
- Other relevant facts and circumstances.
Spark Rack is not required to use progressive enforcement and may immediately suspend or terminate serious or repeated violations.
43. Repeat Violations
Repeated violations may result in escalating enforcement, including termination.
Spark Rack may treat the following as repeat violations:
- Multiple incidents involving the same Account;
- Violations by multiple End Users under the same Customer;
- Recurring compromised systems caused by inadequate security;
- Repeated failure to respond to notices;
- Repeated Spam complaints;
- Repeated infringement complaints;
- Repeated use of new domains or IP addresses for substantially similar Abuse;
- Return of a previously terminated person through another Account;
- Failure to implement promised corrective measures; or
- A pattern demonstrating inability or unwillingness to control Abuse.
44. Costs, Fees, Credits, and Refunds
Customer remains responsible for fees during a suspension unless Spark Rack agrees otherwise or Applicable Law requires otherwise.
Customer is not entitled to a Service credit, refund, or extension for downtime or loss of access resulting from good-faith enforcement of this Policy.
To the extent permitted by law, Customer may be responsible for reasonable costs resulting from Customer’s violation, including:
- Emergency engineering work;
- Malware cleanup;
- DDoS mitigation costs;
- Third-party provider charges;
- IP reputation remediation;
- Data recovery;
- Legal-response costs;
- Forensic investigation;
- Equipment replacement;
- Network restoration; and
- Other documented remediation expenses.
45. Appeals
Customer may request review of an enforcement action through the designated support, legal, or abuse channel in the Customer Portal.
An appeal should include:
- The affected Account or Service;
- The enforcement action being challenged;
- The reason Customer believes the action was mistaken or disproportionate;
- Relevant supporting evidence;
- A description of remediation already completed;
- A plan to prevent recurrence; and
- The requested resolution.
Submission of an appeal does not automatically stay an enforcement action or require Spark Rack to restore a Service while review is pending.
Spark Rack may deny an appeal that is incomplete, misleading, unsupported, repetitive, or inconsistent with legal or security requirements.
46. Cooperation with Authorities and Third Parties
Spark Rack may cooperate with:
- Law-enforcement agencies;
- Courts;
- Regulators;
- Child-protection organizations;
- Emergency services;
- Registrars and registries;
- Data centers;
- Network providers;
- Security researchers;
- Incident-response organizations;
- Payment processors;
- Intellectual-property owners;
- Victims of Abuse; and
- Other appropriate parties.
Spark Rack may disclose information when reasonably believed necessary to comply with law, respond to valid legal process, investigate Abuse, prevent imminent harm, protect rights or systems, or enforce the Terms of Service.
47. No Safe Harbor Created
Nothing in this Policy:
- Authorizes conduct that is otherwise unlawful;
- Creates a right to use any particular Service for high-risk activity;
- Requires Spark Rack to host any particular Content;
- Prevents Spark Rack from applying product-specific restrictions;
- Limits Spark Rack’s rights under the Terms of Service;
- Requires Spark Rack to disclose security thresholds or detection methods;
- Creates a duty to monitor Customer Content;
- Guarantees that Spark Rack will detect Abuse;
- Guarantees advance notice before enforcement; or
- Creates rights for a third party except where required by law.
48. Policy Changes
Spark Rack may update this Policy to reflect legal requirements, security threats, industry practices, service changes, network conditions, third-party requirements, or new forms of Abuse.
Spark Rack will provide reasonable notice of material changes when commercially practicable.
Changes required to address urgent legal, security, abuse, or operational risks may take effect immediately.
Continued use of the Services after an updated Policy takes effect constitutes acceptance of the updated Policy.
49. Contact Information
Questions regarding this Policy may be submitted through the appropriate Spark Rack Customer Portal channel or mailed to:
Spark RackPO Box 2215
Valdosta, GA 31604
United States
50. Customer Acknowledgment
By ordering, accessing, or using the Services, Customer acknowledges that Customer:
- Has read this Acceptable Use Policy;
- Understands this Acceptable Use Policy;
- Agrees to comply with this Acceptable Use Policy;
- Will ensure that End Users comply with this Acceptable Use Policy;
- Accepts responsibility for activity conducted through the Account and Services;
- Will respond promptly to Abuse and security notices;
- Understands that violations may result in restriction, suspension, or termination; and
- Understands that Spark Rack may take immediate action when reasonably necessary to protect people, systems, data, infrastructure, legal compliance, or network integrity.