Appearance
Acceptable Use Policy
Effective Date: 2026-07-09 · Document ID: AUP-MMA-001 · Contact: info@mapsted.com · Contact UsVersion: 1.0
Document ID: AUP-MMA-001 Contact: info@mapsted.com
1. Purpose
This Acceptable Use Policy ("AUP") describes permitted and prohibited uses of the Mapsted Maps JavaScript API (the "Service") and its supporting backend infrastructure. This AUP is expressly incorporated into and forms part of the Terms of Service (TOS-MMA-001) and every Commercial Agreement ("Commercial Agreement" means any signed, written agreement between you and Mapsted Corp. governing access to the Service) entered with Mapsted Corp. It must be read alongside the Licence Agreement and Terms of Service.
Violation of this AUP may result in suspension or termination of your access to the Service in accordance with Section 6.
2. Permitted Use
You may use the Service to:
- embed Mapsted indoor maps, wayfinding, floor navigation, and routing in your own web or kiosk applications, under a valid licence;
- display building data and navigation instructions to legitimate end users of your application;
- evaluate the Service on a non-production basis in accordance with §3 (Fair Use);
- integrate with Mapsted's public postMessage API as documented at this site, within the limits of your Commercial Agreement.
3. Fair Use and Reserved Right to Introduce Usage Limits
Use of the Service is subject to a general fair-use expectation. Licensees and evaluators are expected to use the Service only as reasonably necessary to develop, test, or operate an integration covered by a valid Commercial Agreement or a bona-fide non-production evaluation.
Reserved right to introduce usage limits. Mapsted Corp. reserves the right, at its sole discretion and with reasonable notice posted to this documentation site, to introduce tiered access (for example, anonymous evaluation, sandbox, and production tiers), per-session or per-day call quotas, fair-use limits, rate-limiting, required API keys, or other usage controls for the Service at any time. Any such controls, when introduced, will be published in this Acceptable Use Policy and enforced at Mapsted's infrastructure. Production use of the Service without a signed Commercial Agreement is not permitted regardless of whether any such usage control has been introduced, and regardless of whether any such control has been circumvented.
For anonymous and sandbox tier users, in the absence of a signed Commercial Agreement specifying otherwise, this AUP and any dispute relating to it shall be governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein.
4. Prohibited Conduct
The following conduct is prohibited regardless of whether a Commercial Agreement is in place, unless Mapsted Corp. has given prior written authorisation in each instance:
4.1 Technical abuse
- Circumvention of usage controls (reserved right) — where Mapsted Corp. has introduced tiered access, API key validation, rate-limiting, fair-use quotas, or any other usage control (see §3), you must not attempt to bypass such controls. Prohibited techniques include rotating or fabricating API keys, using multiple sandbox accounts, creating fake accounts or organisations, employing headless-browser or automated-browser tools (including Playwright, Puppeteer, or similar) to recycle anonymous sessions in order to exceed any fair-use limit, or employing any other mechanism intended to obtain more use of the Service than Mapsted has authorised for your tier or Commercial Agreement.
- API key misuse — sharing, publishing, or transferring API keys or sandbox credentials to unauthorised parties; using API keys obtained through credential stuffing or other unauthorised means.
- Reverse engineering — decompiling, disassembling, deobfuscating, or otherwise attempting to derive the source code,
postMessagewire protocol, routing algorithm (a Mapsted trade secret), positioning algorithm (a Mapsted trade secret), or other proprietary components of the Software or Mapsted's backend services. - Authentication and security circumvention — bypassing, disabling, or interfering with any authentication mechanism, API key validation, origin whitelist, rate limiter, or other security control in the Software or in Mapsted's backend infrastructure.
- postMessage manipulation — sending malformed, spoofed, or high-volume postMessage events to any Mapsted-hosted iframe or widget with intent to disrupt service, extract data, or probe internal state; replaying or intercepting postMessage communications between the Service and any iframe or host page.
- Man-in-the-middle and replay attacks — intercepting, modifying, or replaying TLS-protected communications between the Service and any Mapsted backend, including through TLS interception proxies or forged certificates.
- Scraping and bulk extraction — systematically crawling, scraping, or caching map tiles, building data (entity metadata, floor plans, coordinates), routing graphs, or any other data from any Mapsted backend hostname or API endpoint, whether or not publicly documented, beyond what is necessary to render a legitimate end-user map session. Extraction of building data not licensed to you is prohibited.
- Denial-of-service — submitting requests at a volume or rate that unreasonably degrades service quality for other customers, or launching any form of denial-of-service attack against Mapsted infrastructure.
- Automated probing — using automated tools to test, probe, or scan any Mapsted backend hostname or API endpoint, whether or not publicly documented, for vulnerabilities without prior written authorisation from Mapsted Corp. (see Security Policy for responsible disclosure). For clarity, good-faith security research conducted under the terms of the Security Policy is not prohibited by this section.
4.2 Intellectual property and branding abuse
- White-labelling — presenting the Software or the indoor maps it renders as your own technology, removing or obscuring Mapsted attribution or watermarks, or misrepresenting the origin of the mapping technology to end users.
- Trademark misuse — using Mapsted marks in a manner not permitted by the Trademark Policy, including implying partnership, endorsement, or sponsorship without a signed agreement.
- Competitive benchmarking — using the Service as the subject of a comparative test published for the commercial advantage of a direct competitor, where Mapsted's Confidential Information would be disclosed as part of the result, without Mapsted Corp.'s prior written authorisation.
4.3 Redistribution and sublicensing
- Redistribution — redistributing, reselling, or sublicensing the Software or access to it to third parties without express written authorisation from Mapsted Corp.
- Embedding in competing services — incorporating the Software into a product or service that provides indoor-mapping, indoor-routing, or indoor-positioning capabilities to third parties as a direct substitute using Mapsted's proprietary data or algorithms.
4.4 Unlawful and harmful use
- Illegal use — using the Service in any manner that violates applicable law, including but not limited to: data-protection and privacy law, export-control law, intellectual property law, and anti-spam law.
- Harmful content — using the Service to facilitate harassment, discrimination, threats of violence, illegal surveillance, or any other content or activity that causes or is intended to cause harm to individuals or groups.
- Infringing content — uploading or displaying content via the Service that infringes the copyright, trade mark, patent, or other intellectual property rights of any third party.
5. Compliance with Laws
You are solely responsible for ensuring that your application embedding the Software complies with all laws and regulations applicable to you, your application, and the jurisdictions in which your end users are located — including data-protection, accessibility, export-control, and consumer-protection law.
6. Enforcement
Mapsted Corp. reserves the right to investigate reasonably suspected violations of this AUP. Upon identifying a violation or reasonably suspected violation, Mapsted Corp. may, in its sole discretion:
- issue a written warning;
- temporarily reduce or suspend API quota;
- suspend access to the Service;
- terminate the Licence Agreement and Commercial Agreement;
- pursue legal remedies, including injunctive relief and damages.
For non-critical violations, Mapsted will ordinarily provide at least 5 business days' written notice and an opportunity to cure before proceeding to suspension or termination, except where immediate action is necessary to prevent harm, impede an ongoing security incident, or satisfy a legal obligation.
Where immediate suspension or termination is required (including for critical or ongoing security violations), Mapsted Corp. will use reasonable efforts to notify you as soon as practicable thereafter, unless doing so would impede an investigation or is not required by the applicable Commercial Agreement.
7. Reporting Abuse
To report suspected abuse of the Service by a third party, email info@mapsted.com. Include as much detail as possible: the nature of the abuse, any API keys or domains involved, and timestamps.
For security vulnerability reports, see the Security Policy.
Related documents
- Licence Agreement — LA-MMA-001
- Terms of Service — TOS-MMA-001
- Security Policy — SP-MMA-001
- Trademark Policy — TP-MMA-001
- Legal Hub