SS SiteminderStore

Legal · Platform rules

Acceptable Use Policy

Chính sách sử dụng hợp lý · Version 2.9, in force 12 August 2026

The Acceptable Use Policy defines the small number of activities that are not welcome on the Marketplace and inside the Modules it distributes. Its purpose is not to police creativity but to keep the platform safe, lawful, and pleasant to use for the thousands of Vietnamese hoteliers who rely on it. Whenever a doubt arises about whether a use case is permitted, the safest thing to do is to write to abuse@siteminderstore.org before you deploy; our team replies within one Vietnamese business day.

§ 01Who this policy applies to

This policy applies to every Customer, every seat inside a Customer's account, every guest of a hotel operated by a Customer whose data flows through a Module, and every developer who accesses the Marketplace API. It is incorporated by reference into the master Terms of Service and takes precedence, on the specific questions it addresses, over any softer language elsewhere in the contractual documentation.

§ 02Prohibited uses — the core list

You may not use the Marketplace or any Module to:

§ 03Scraping and automated access

The Marketplace welcomes programmatic access through the documented API. What it does not welcome is scraping — the unauthorised extraction of catalogue content, of Module documentation, or of editorial articles through mass HTTP requests that circumvent the API rate limits, rotate IP addresses, or falsify user agents. Scraping is trivially detected by our infrastructure and results in an immediate block at the ingress layer. If you have a legitimate need to consume Marketplace content in bulk — for example, to build a comparison directory or to feed a research paper — please contact api@siteminderstore.org and we will provision a purpose-built endpoint.

The rule is simple: if the API can do it, use the API. If the API cannot do it and you need it, ask us. Do not scrape.

§ 04Rate limits and their abuse

The Marketplace API applies per-account rate limits published in the developer documentation. The current defaults are three hundred requests per minute for the read endpoints and sixty requests per minute for the write endpoints, with per-endpoint variations documented individually. Rate limits exist to protect the shared infrastructure and, in particular, to protect the SiteMinder platform, which imposes its own rate limits on the connectors we build. Deliberate circumvention of the rate limits — parallel accounts, credential rotation, distributed request sources with the intent to aggregate throughput — is a breach of this policy and grounds for immediate suspension of every account we can attribute to the same beneficial owner.

§ 05Obligations of hotel operators uploading guest data

When a Customer installs a Module that reads guest data from its SiteMinder Workspace, it becomes responsible for ensuring that the underlying guests have consented to that processing in the terms required by Decree 13/2023/ND-CP. In practice this means: the Customer's booking flow must include a clear, opt-in consent statement covering the categories of data collected, the purposes for which they will be processed, and the identity of the processors that will handle them. SiteminderStore provides sample wording in the "Consent library" section of the Marketplace; the wording must be adapted to the specific circumstances of each Customer and approved by the Customer's own legal counsel.

§ 06Special categories of personal data

Modules are not designed to process special-category personal data such as health data, biometric data, religious beliefs, political opinions, or genetic data. Customers must not upload such data to a Module without a prior written impact assessment approved by our Data Protection Officer. Where a Module inadvertently captures such data — for example a guest volunteering a health condition in a special-request field — the Customer must apply the same safeguards it applies internally to such data and must instruct the Module to purge the field within a reasonable retention window.

§ 07Content moderation

Content published on the Marketplace by third parties — Module descriptions, screenshots, changelogs, customer testimonials — is moderated before it goes live. Content published on the Customer-facing surfaces of a Module (guest-facing landing pages, mailings) is the responsibility of the Customer. Where a third party reports content that appears to breach Vietnamese law, we investigate promptly and, where the report is substantiated, we take the content down within twenty-four hours in line with the timelines of the Law on Cybersecurity 2018.

§ 08Reporting abuse

Anyone who suspects a breach of this policy can report it to abuse@siteminderstore.org. Reports should include, at minimum, the URL of the offending content, a description of the alleged breach, and any evidence the reporter can share (screenshots, e-mail headers, log excerpts). We reply within one Vietnamese business day to acknowledge the report and within seven Vietnamese business days with the outcome of our investigation. Reports made in good faith are treated in confidence; retaliation against a reporter is itself a breach of this policy.

§ 09Enforcement — warning, suspension, termination

Enforcement follows a proportionate ladder:

StepTriggerAction
WarningFirst minor breach, cured on request within 48 hoursWritten notice by e-mail; no suspension
Temporary suspensionRepeat breach, or single breach the seriousness of which requires immediate interventionSuspension of the affected Module for up to 30 days; access to historical data preserved
TerminationBreach of the "core list" of Section 02, or failure to cure a suspended state within 30 daysTermination of the master Terms of Service; refunds handled under the Refund Policy
Emergency interventionOngoing distribution of malware, ongoing phishing campaign, imminent risk to third partiesImmediate suspension pending investigation; no prior notice

§ 10Appeals

A Customer whose subscription has been suspended or terminated may appeal to appeals@siteminderstore.org within fifteen calendar days of the enforcement action. The appeal is reviewed by the director, Nguyễn Minh Đức, and by an in-house counsel not involved in the initial enforcement decision. The outcome of the appeal is communicated in writing within thirty calendar days. Where the appeal is upheld, the subscription is reinstated and any pro-rated refund of consumed suspension days is credited to the next invoice.

§ 11Cooperation with authorities

SiteminderStore cooperates with the Ministry of Public Security (Bộ Công an) — in particular the Department of Cybersecurity and High-Tech Crime Prevention (A05) — and with any other competent Vietnamese authority acting within the scope of its jurisdiction. Where an authority requests information about a Customer or its content, we ask that the request be formulated in writing and be accompanied by the appropriate legal basis. We inform the affected Customer of the request unless the authority has explicitly prohibited us from doing so. Where we form the view that a request is disproportionate or unlawful, we may challenge it in the competent Vietnamese court before disclosing any information.

§ 12Fair-use guidance for connectors to the SiteMinder API

Modules that connect to the SiteMinder Application Programming Interface must respect the rate limits and use quotas that SiteMinder Limited publishes. In practice this means designing polling patterns that use webhooks in preference to long-polling, honouring HTTP 429 responses with an exponential back-off, and consolidating multiple small updates into batched calls where the API supports batching. Customers whose usage is causing SiteMinder to throttle the shared connector will be contacted by our team and asked to adjust their configuration; sustained excess usage may be subject to a fair-use overage charge documented on the Module's Marketplace page.

§ 13Independence from SiteMinder Limited

SiteminderStore Vietnam Company Limited is an independent Vietnamese company. It is not affiliated with, sponsored by, or endorsed by SiteMinder Limited. Modules integrate with the Customer's SiteMinder Workspace via the official SiteMinder API and work alongside the SiteMinder Workspace; they do not replace SiteMinder. Any use of the Marketplace that misrepresents this relationship — for example a Customer describing SiteminderStore as an official SiteMinder reseller in its own marketing material — is a breach of this policy and grounds for enforcement.

§ 14Amendments

We review this policy each time a new class of misuse appears or a Vietnamese law is updated, and at least once per calendar year. Material changes are announced by e-mail to account owners and in the Marketplace changelog at least thirty days before they take effect. Non-material changes may be published without prior notice.

§ 15Contact

For questions about this policy please write to legal@siteminderstore.org. To report a breach please use abuse@siteminderstore.org. For appeals please write to appeals@siteminderstore.org. All three inboxes are monitored by the SiteminderStore compliance team from 09:00 to 18:00 Indochina Time on business days.