Acceptable Use Policy (AUP)
Last updated: March 3, 2026
Kavto provides digital wallet management and configuration services for companies. We promote ethical practices in the use of data. We are governed by Colombian Habeas Data regulations and impose standards on our "Business" clients. By using our gateway and online service, you agree to strictly comply with this Acceptable Use Policy.
1. General Prohibited Activities
You may not use Kavto's services for any of the following purposes:
- 1.1 Illegal activity, impersonation, evasion, or deceptive reward offers.
- 1.2 Violating or encouraging violations of Colombian law or the applicable terms of Google and Apple.
- 1.3 Sending unsolicited notifications or excessive spam.
- 1.4 Disrupting, tampering with, or attacking our SaaS infrastructure.
2. Prohibited Content on Cards/Passes
Discount cards, points programs, and stamp cards must not contain or link by QR code to content that is:
- Illegal, false, degrading, pornographic, or defamatory toward individuals or vulnerable groups.
- Promoting racism, discrimination, violence, or sectarianism based on identity, sexual orientation, or political views protected under Colombian law.
- Infringing trademarks, distribution rights, property rights, or trade secrets, or impersonating or defaming third parties, including franchises the participating business is not authorized to operate.
- Involving an invasion of privacy or covert collection of photographs.
3. Prohibited Goods and Services
Kavto may not be used to operate loyalty programs for businesses offering any of the following goods or services:
- Pornographic or sexual services, or unregulated adult products.
- Pirated, counterfeit, smuggled, or fraudulent goods or software.
- Restricted medicines, controlled substances, illegal drugs, or hazardous materials sold outside the oversight of INVIMA or another applicable health authority.
- Raffles, casinos, or other gambling activities operated without the required permits and Coljuegos approval.
- Weapons promotion.
4. Strict Capture of Sensitive Data (Law 1581)
Under Colombian data-protection and privacy law, storing “Sensitive Data” in Kavto custom fields is strictly prohibited unless expressly authorized and legally permitted.
The category covered requires that you (The Business), through our QR integrations or native forms, may not require or store health profiles (medical histories), racial or ethnic characteristics (religion/belief), direct interbank financial data and passwords and/or the buyer's static credit card number. If it is collected with the authorization of another, Kavto formally repudiates said operation without support or protection and will mediate by deleting such collection, thus preventing any wrongdoing of the End Users before the authorities.
5. Legal Application (Enforcement)
Kavto reserves the right to terminate a customer and revoke API access or credentials when its legal and technical teams find credible evidence of an AUP violation. We will provide information required by a valid legal request from the Colombian Attorney General's Office concerning suspected criminal activity on the platform.
Questions about this AUP may be submitted through: soporte@kavto.com