Acceptable use

What Nilstock may and may not be used for. Last updated 20 August 2026.

This sits alongside the terms of service. It is short because most of it is obvious, and the parts that are not obvious are the parts worth reading.

The one that is specific to us

Nilstock records what people take from a store, and it does that by name. That record exists so a business can account for its stock and its equipment. It is not a productivity monitor, and using it as one — to measure how often somebody visits the store, to build a picture of an individual’s working patterns, or to discipline on the basis of movement data taken out of context — is a use we do not support and will not help with.

More practically: the people whose names are in your account have rights over that data under UK GDPR, and you are their controller. Tell them the system exists and what it records. It is a one-paragraph notice and it removes almost every problem that would otherwise arrive later.

Do not

  • Upload anything unlawful, or anything you do not have the right to hold — including personal data about people you have no lawful basis to process.
  • Use the account to store special-category data. There is no field for health, biometric or similar data and there is no reason to force one; if you find yourself pasting it into a note, stop.
  • Probe, scan, load-test or otherwise attack the service. If you want to test it, ask — we would rather know, and we will usually say yes and give you a window.
  • Share one account between organisations that should not see each other’s data. Sites and per-site access exist precisely so you do not have to.
  • Resell or white-label the service without a written agreement. We are not against it, but it needs to be a conversation.
  • Use the API or the exports to build a competing product from our data. Your data is yours; the shape of ours is not.

Automated access

There is no public API yet. When there is, it will come with its own rate limits and its own terms. Until then, please do not script the web interface — not because we mind the ambition, but because a screen-scraper breaks on a deploy and then it is a support ticket for both of us.

If something is wrong

If you think an account is being used in breach of this policy — including one of ours — write to [email protected]. We will look at it and tell you what we did.

What we will do about a breach

Talk to you first, in almost every case. Suspension without warning is reserved for something actively harmful — an attack in progress, or content that has to come down immediately. We are a small company and you are a person with a store to run; the default should be a phone call, not a lockout.