Acceptable Use Policy

What PayBridgeNP prohibits across merchant accounts, hosted checkout, payment links and buttons, APIs, MCP tokens, notifications, webhooks, and embeds, and the conduct that can lead to review, restriction, or removal.

Last updated August 30, 2026

Prohibited businesses and transactions

  • Illegal goods, illegal services, or transactions that violate applicable laws, regulations, or provider rules.
  • Fraudulent schemes, deceptive offers, phishing, impersonation, or any activity intended to mislead customers or counterparties.
  • Sanctions evasion, money laundering, unauthorised remittance activity, or use of the platform to mask the true source or destination of funds.
  • High-risk categories we do not support, including adult exploitation, counterfeit goods, stolen items, and transactions involving abuse or violence.
  • Businesses that need a licence they do not hold, or that we do not support: gambling and betting, remittance and money transfer, foreign exchange, lending and investment schemes, virtual assets and crypto exchange, collecting donations or crowdfunding on behalf of others, weapons, controlled drugs, adult content and sexual services, multi-level marketing, and any activity restricted by sanctions.

Prohibited conduct

  • Using PayBridgeNP to process payments on behalf of another undisclosed business or to hide the true merchant of record.
  • Attempting to test stolen or unauthorised payment credentials, probe provider behaviour, evade rate limits, or automate abusive transaction patterns.
  • Interfering with the security or availability of the platform, including unauthorised access attempts, scraping that degrades service, or exploit activity.
  • Providing false business details, fake websites, misleading product descriptions, or inaccurate fulfilment information.

Integration and checkout integrity

Merchants must present customers with accurate order details, pricing, and business identity. You may not use misleading redirects, concealment, mismatched product descriptions, or fake support channels to influence payment completion.

API and webhook usage must stay within documented behaviour. Do not attempt to forge payment state, replay signed events, or misuse public tracking endpoints to enumerate transaction data.

SMS and email abuse

PayBridgeNP sends transactional notifications on your behalf to people who have a real payment relationship with you. We do not allow:

  • Marketing campaigns, promotional broadcasts, newsletters, or any non-transactional outreach via the SMS or email surface.
  • Sending to recipients who have not transacted with you (e.g. importing third-party lists into checkout sessions purely to trigger reminder messages).
  • Repeatedly sending the same transactional template to the same recipient in a way designed to bypass the platform's per-recipient cooldown.
  • Using the SMS history or email log as a mailing list for outbound communication outside the platform.

PayBridgeNP enforces per-merchant burst rate limits and per-recipient cooldowns at the dispatcher layer. Suppressed messages are still logged so you can see what would have gone out, and what was throttled.

MCP and AI-agent abuse

The Model Context Protocol surface lets AI assistants act on a merchant's behalf with a scoped token. Misuse can be costly to the merchant, the platform, and the customer. We do not allow:

  • Using AI agents for bulk or unauthorised money-related actions, including refunds and changes to subscriptions or invoices, that no authorised person initiated.
  • Embedding MCP tokens in shared or untrusted environments where third parties could trigger actions on the merchant's account.
  • Using AI agents to enumerate other merchants' data, attempt prompt-injection attacks against the platform, or extract internal IDs.
  • Bypassing the platform's confirmation prompts on money-moving actions through automated approval scripts.

The merchant remains responsible for every action taken by an authorised AI agent under their token. Revoke tokens immediately from /mcp on suspected misuse.

Buy Button and embed abuse

The PayBridgeNP Buy Button (script-tag embed) and Payment Links surface let you accept payments from any website. The same surface can be misused; we do not allow:

  • Embedding Buy Buttons or Payment Links on sites that do not match the business identity declared on the merchant account.
  • Using Buy Buttons to circumvent platform terms (e.g. reselling another business's goods through your account).
  • Modifying the embed script or hosted checkout markup to deceive customers about the destination, amount, or identity of the receiving merchant.
  • Iframing or proxying the hosted checkout in a way that hides the PayBridgeNP origin.

How enforcement works

We may ask for clarifying information, review account activity, disable features, or suspend an account where there is fraud, elevated operational risk, or a policy breach. Suspended accounts have API keys returning 403, hosted checkout and payment links blocked, and dashboard access locked, with the suspension reason shown at sign-in.

In severe cases we may terminate access immediately and preserve records for investigation or compliance purposes. Provider restrictions may also affect platform access - a merchant that is removed or restricted by eSewa, Khalti, or Fonepay may lose access to related PayBridgeNP functionality.

Where the law and the situation allow, we tell you the reason for a restriction and how to ask for a review. Where fraud, security, or legal risk is involved, we may restrict first and explain afterwards.