Acceptable Use Policy
Effective June 11, 2026 · Last updated June 11, 2026
What this means
Use the data lawfully and respectfully. You are the sender of your outreach, so anti-spam laws apply to you. No scraping, no reselling the database, no working around credits or rate limits.
What this policy covers
This policy sets the rules for using Clapleads Atlas — the website, the app, the API, and any data you export from it. It is part of our Terms of Use. If you use the service, you agree to follow these rules.
Use the data lawfully
When you contact people using data from the platform, you are the sender. That means the laws that govern marketing and outreach apply to you, not just to us. Depending on where you and your recipients are, these can include:
- CAN-SPAM in the United States,
- CASL in Canada,
- GDPR and PECR in the EU and the UK,
- and similar laws elsewhere.
In practice this means: say who you are, do not use misleading subject lines, give people a working way to unsubscribe, and honor it. Our GDPR Guide has practical tips, but it is not legal advice — checking your own obligations is your responsibility.
Respect opt-outs
When someone asks us to remove their data, we add them to a suppression list. Suppressed contacts are excluded from every export — automatically, every time.
You must do the same on your side: keep your own suppression list, honor unsubscribe requests quickly, and never re-import contacts who opted out.
No scraping or resale
You may not:
- scrape, crawl, or bulk-copy the database by any means other than the export features we provide;
- resell, sublicense, or redistribute the database or large parts of it, with or without charge;
- use exported data to build or improve a competing data product;
- share exports outside your own organization, except with service providers working on your behalf.
Exports are licensed for your own business use — lead generation, sales, marketing, and research. See the Terms of Use for the full license.
Account and access rules
- Keep your password and API keys secret.
- Do not share one seat between several people. Plans include a set number of seats — add seats instead.
- Do not open multiple accounts, rotate API keys, or use any other trick to get around credit limits or rate limits.
- Do not let anyone you have banned or removed use your access.
Security testing
Do not probe, scan, or test the security of the platform without our prior written permission. If you find a vulnerability by accident, stop, do not access other people's data, and report it through the support page. See our Security page for how we handle reports.
Prohibited conduct
You may not use the platform to:
- break any law, or help someone else break one;
- commit fraud, impersonate a person or company, or misrepresent who is sending a message;
- harass, threaten, or abuse anyone;
- send malware, phishing messages, or spam;
- violate anyone's privacy, publicity, or intellectual property rights;
- interfere with the service — for example by overloading it or disrupting other customers.
If you break these rules
Depending on how serious the problem is, we may warn you, limit features, suspend your account, or terminate it. For serious abuse — like spam runs, scraping, or fraud — we may suspend access immediately, without notice, and without refunding fees already paid. We may also report illegal activity to authorities where the law requires or allows it.
We try to be fair. If you think we got it wrong, contact us through the support page and we will review the decision.
Reporting abuse
If you receive unwanted messages from someone using our platform, or you see this policy being broken, please tell us through the support page. If the issue is about data we hold on you, use the data request portal.
Related policies
Questions or requests
If anything on this page is unclear, or you want to act on your rights, you can reach us through the support page. To ask about data we hold on you or your business, use the data request portal — no account is needed.
Data protection contact
For data-protection matters — access, correction, deletion, objection, portability, or “do not sell” requests under GDPR/CCPA — the fastest route is the data request portal, which is logged and tracked to completion. Identity is verified before any personal data is disclosed.