Purpose and binding nature of the Rules
These Usage Rules define permitted and prohibited conduct in the RichAnanas Service. They form part of the Terms of Use and apply to the organisation, account owner, administrators, team members, API clients, plugins and every person accessing the Service through their authorisation.
The Rules protect Customers, their buyers, connected platforms, VMTech and Service stability while enabling reasonable and predictable use. The organisation must inform its users of the Rules and is responsible for their conduct.
Accounts, roles and secrets
Each user must use their own account, protect passwords, tokens, API keys and integration secrets, and apply the least necessary privilege. Secrets must not be sent through unprotected email, published in support, entered in AI instructions or disclosed to unauthorised persons.
Owners and administrators must regularly review team membership, immediately revoke access when a person leaves the organisation and report suspicious activity to support@richananas.rs. Attempting to access another account, tenant, file, token or administrative area is prohibited.
Content accuracy and responsibility
Before publication, a user must verify names, descriptions, categories, EAN/SKU, prices, VAT treatment, stock, declarations, images, content rights, order data and every other business-significant item. Synchronisation or an automated suggestion is not confirmation that data is accurate, lawful or acceptable to a connected platform.
It is prohibited knowingly to publish false, misleading, outdated or incomplete data, manipulate prices or stock for fraud, conceal mandatory product characteristics or use the Service for goods and activities prohibited by law or sales-channel rules.
Personal and confidential data
A user may process personal data only where the organisation has an appropriate legal basis, notice and authority. Buyer and recipient data may be used only for orders, delivery, support, statutory records and other lawful purposes determined by the Customer.
Product fields, files and AI features must not contain special categories of personal data, health data, biometrics, political or religious beliefs, criminal-offence data, payment-card numbers, authentication data, state secrets or unnecessary third-party data. If such processing is exceptionally necessary, an appropriate written agreement with VMTech must be concluded before using the Service.
Use of automated features
Automated features are assistance tools, not substitutes for professional review. The user must review factual accuracy, language, safety, intellectual-property rights, marketplace-rule compliance and suitability for the relevant goods and market.
It is prohibited to use automated features for fraud, misleading reviews, impersonation, discrimination, unlawful profiling, malicious-code generation, content endangering persons, systems or rights, or processing secret and unnecessary personal data. A user must not claim that VMTech guarantees or endorses generated output.
Prohibited content and activities
It is prohibited to upload, store, generate, publish or transmit content that:
- violates law, a court or administrative decision, consumer rights or connected-platform rules;
- infringes copyright, trademark, trade secret, privacy, image rights or another third-party right;
- constitutes fraud, phishing, impersonation, hate speech, threats, harassment or incitement to violence;
- contains malicious code, unauthorised-access tools, stolen credentials or misuse instructions;
- concerns illegal goods, counterfeits or goods for which the organisation lacks a required permit;
- may unreasonably endanger a person, system, sales channel or another entity's reputation.
Technical misuse and security
Unauthorised scanning, penetration testing without prior written consent, exploitation of vulnerabilities, traffic interception, circumvention of authentication, rate limits, quotas, billing or tenant isolation, automated mass account creation, disruption and attempts to access source code or another party's data are prohibited.
It is prohibited to send a volume of requests that disproportionately burdens the Service, use bots or scraping outside the documented API, remove security markings, alter signed URLs or bypass file expiry. VMTech may apply technical limits, temporary throttling or blocking to protect stability.
Integrations, APIs and plugins
An integration may be connected only to a store or account the organisation is authorised to manage. The user must protect Client IDs, Secret Keys, plugin tokens and personal API tokens, grant only necessary scopes and revoke them when no longer needed. Tokens must not be embedded in public code, repositories, screenshots or documents available to third parties.
The user must follow documentation, rate limits, sales-channel rules and prohibitions on unauthorised automation. Requests must not be modified or repeated in a way that creates duplicate orders, incorrect prices, uncontrolled inventory or other harm. Test mode, where available, must remain separate from production data.
Relationship with connected platforms
The Customer remains directly responsible to a connected platform and its buyers for goods, catalogue, prices, inventory, delivery times, documents, complaints and compliance with platform rules. RichAnanas assists technical management but does not assume the Customer's contract with a platform or authority to make final business decisions for the Customer.
RichAnanas must not be used to circumvent a connected platform's controls, limits, fees or security requirements. Removing an integration need not delete historical information required for audit, security or legal duties.
Media and intellectual-property rights
A user may upload only images, video, fonts, text, logos and other materials created by the user, lawfully licensed or otherwise validly authorised for use and distribution. At VMTech's or a rights holder's request, the user must provide a reasonable explanation or evidence of rights.
It is prohibited to remove authorship or protection notices, use an individual's likeness without required permission, generate deceptive imitations of protected brands or publish infringing content. VMTech may temporarily remove or block disputed material while reviewing a properly reasoned notice.
Communications and support
Contact and support must be used in good faith. Spam, abuse, threats, malicious attachments, another party's secrets or repeated requests intended to disrupt work are prohibited. An issue report should contain only data required for diagnosis; passwords and complete secret keys must never be sent to support.
The user should cooperate in investigating an issue, provide steps and allow reasonable response time. Falsely reporting a security incident, attempted extortion or public disclosure of an active vulnerability before VMTech has a reasonable opportunity to remediate it constitutes a serious breach.
Usage monitoring and records
VMTech may automatically record authentication, API calls, data changes, integration events, errors, quota usage and security signals to provide the Service, maintain audit, prevent misuse and evidence actions. Records are not used to read business content without need; access is limited by role and purpose.
Security, audit, API and integration records may be kept for up to five years. A user must not attempt to alter or delete a system audit trail, falsify the actor's identity or conceal an event. Removing a business record from the user interface does not necessarily mean immediate removal of a protective or legally required trace.
Measures for breach of the Rules
Depending on severity, repetition, intent and risk, VMTech may warn a user, require remediation, restrict a feature, revoke a token, remove disputed content, temporarily suspend an account or terminate the contract. An urgent measure may be taken without prior notice to prevent immediate harm, unauthorised access, legal violation or danger to third parties.
Where appropriate, VMTech will state the reason and allow the organisation to provide an explanation. VMTech may preserve evidence, cooperate with competent authorities under a valid request and notify an affected platform or Customer where lawful and necessary. Suspension for breach does not release the Customer from accrued obligations.
Reporting misuse and final provisions
Suspected account compromise, data breach, unlawful content, vulnerability or other misuse should be reported without delay to support@richananas.rs with enough facts for review. Do not send more personal or confidential data than necessary.
VMTech may amend the Rules for new risks, features, integrations or legal requirements and will publish the date of the new version. The Serbian version is original and controlling in case of translation differences unless mandatory law provides otherwise. Undefined terms have the meanings given in the Terms of Use and Privacy Policy.