Partner Acceptable Use Policy
Platform Conduct, Security, Data Integrity and Enforcement Framework
Effective Date: May 10, 2025
Operational Integrity Mandate: All kitchen partners, cloud culinary operators, and meal providers must adhere to this Acceptable Use Policy. Engaging in prohibited conduct, falsifying hygiene certifications, or abusing customer data results in immediate suspension.
Prohibited Conduct
Core platform safeguards & integrity requirements
All registered kitchen partners, cloud kitchen operators, prep managers, and authorized personnel must maintain fair, lawful, and secure use of Brocoly. Engaging directly or through automation in any of the following activities constitutes a material breach of the Master Commercial Agreement.
Strictly prohibits fictitious transactions, forged vouchers, phantom order dispatches, circular self-ordering to capture subsidies, or fabricated meal deliveries for fraudulent payouts.
Credential harvesting, deployment of malicious scripts, denial-of-service attempts, unauthorized API penetration testing, or automated port-scanning of Brocoly core routing endpoints.
Circumventing technical access barriers, scraping subscriber lists, copying competitor recipes, pricing matrices, diet-engine parameters, or bulk extraction of consumer culinary preferences.
Decompiling, disassembling, decoding, or reverse engineering any part of the Brocoly Merchant OS, kitchen allocation heuristics, or logistics dispatch dispatch models.
Selling, licensing, harvesting, external leaking, or running unauthorized offline promotional campaigns against Brocoly subscriber contact details or delivery addresses.
Unauthorized use of third-party trademarks, proprietary recipes, copyrighted photos, or unapproved commercial replication of the Brocoly green marks and visual trade dress.
Incentivizing false positive customer reviews, automated rating bot seeding, orchestrating coordinated negative review campaigns against neighboring kitchens, or payment chargeback manipulation.
Misrepresenting active FSSAI licensing certifications, operating from undisclosed kitchen premises, falsifying allergen warnings, or misrepresenting organic sourcing credentials.
Account & Access Security
Credential governance & privileged boundary protocols
Kitchen partners possess privileged administrative control over menu matrices, pricing logic, preparation queues, and subscriber dietary information. Strict operational security standards must be maintained at all operating terminals.
Mandatory multi-factor authentication for kitchen master admins. Shared generic credentials (e.g., kitchen@gmail.com) are strictly barred.
Restrict kitchen tablet screens and dispatch portals strictly to employees currently packaging dishes. Access must be revoked within 12 hours of staff exit.
Any suspected token leakage, stolen terminal device, or credential breach must be declared to security@brocoly.in within 24 hours.
Investigation & Enforcement
Monitoring telemetry, audit rights & graduated remedial action
Brocoly maintains algorithmic auditing, telemetry monitoring, and physical inspection powers over all connected meal providers. In the event of confirmed or reasonably suspected non-compliance, Brocoly implements progressive enforcement:
Notice & Capability Throttling
Immediate operational notification with temporary limits placed on maximum concurrent meal orders, custom dish publishing, or promotional placement.
Catalog & Content Moderation
Instant removal, delisting, or suppression of dishes containing unverified health claims, misleading allergen tags, or unauthorized trademarks.
Settlement Escrow & Payout Holds
Temporary freeze on weekly merchant disbursements while transactional integrity, food safety anomalies, or refund liabilities are audited.
Permanent Network Termination
Complete revocation of merchant OS access, permanent blacklisting across the Brocoly network, and formal referral to law enforcement or statutory regulators where applicable.
Emergency Protective Actions
Unilateral swift intervention without prior consultation
Brocoly reserves the non-negotiable right to take immediate, unilateral protective action without advance notification where delay creates material risk to subscriber wellbeing, physical food hygiene, platform infrastructure, or legal compliance.
bolt Recognized Emergency Triggers:
- Active or suspected customer data exfiltration
- Severe food poisoning or adulteration reports
- Malicious software / token compromise
- Statutory or government court mandate
Schedule Incorporated into Master Commercial Partner Agreement
Acceptance of this Acceptable Use Policy constitutes binding operational adherence alongside the Master Partner Agreement and Data Protection Schedule.