Acceptable Use Policy
What you may and may not do with the Cabica platform: prohibited uses, automation and rate limits, security testing, and what happens if this is broken.
- Last Updated
- 8 August 2026
- Effective
- 8 August 2026
Who this is for: Everyone using the platform — operator staff, drivers, passengers, and anyone using the API.
In Short
- Use it for licensed taxi and private-hire work. Do not use it to break the law or to harm anyone.
- Do not scrape, bulk-extract, or automate against the platform outside the documented API.
- Do not test our security without asking. Do report anything you find — we will thank you, not sue you.
- Rate limits exist and are enforced. Hitting them is a warning, not a punishment.
- Serious or repeated breaches mean suspension, and the worst mean immediate termination.
This summary is here to be read. It is not a substitute for the full text below, and where the two differ, the full text is what applies.
1. What the platform is for
The Cabica platform exists to run licensed taxi and private-hire operations: taking bookings, dispatching vehicles, managing drivers and fleets, taking payment, and meeting licensing obligations.
Anything else needs our written agreement. That is not us being difficult — dispatch data is personal data about people's movements, and the platform is built on the assumption that it is being used for the thing it was built for.
2. What you must not do
Unlawful and harmful use.
- Anything illegal under the law of the place where you operate.
- Operating without the licences your local authority requires, or in breach of their conditions.
- Harassing, threatening, stalking or endangering any person — passenger, driver, or member of staff.
- Using booking, tracking or location data to follow someone, or to build a picture of their movements for any purpose other than fulfilling a journey.
- Discriminating against a passenger or driver on any ground protected by the Equality Act 2010, including refusing an assistance dog.
Data and privacy.
- Extracting passenger or driver records for any purpose other than running the journeys they relate to.
- Selling, renting or sharing personal data from the platform with anyone who does not need it to do their job.
- Uploading personal data you have no lawful basis to hold.
- Retaining data after you have been told to delete it, or after the person has validly asked you to.
- Using the platform to send marketing to people who have not consented, where consent is required.
Technical.
- Reverse-engineering, decompiling or attempting to derive source code, beyond what the Copyright, Designs and Patents Act 1988 permits.
- Copying, reselling, sublicensing or white-labelling the platform as your own product.
- Circumventing any access control, rate limit, authentication or licence check.
- Interfering with the service or its infrastructure: denial of service, resource exhaustion, deliberate overload.
- Uploading malware, or content designed to exploit a browser or a device.
- Using automated tools to create accounts, submit bookings, or generate traffic.
Content.
- Uploading anything you have no right to upload — see the Copyright Policy.
- Uploading anything obscene, defamatory or unlawful.
- Impersonating another firm, driver or passenger.
3. Automation, scraping and rate limits
There is a documented API with keys and scopes. Use it. Anything that talks to the platform by pretending to be a browser or an app is outside this policy.
- No scraping the CRM, the driver app, the passenger app or the booking site.
- No headless browsers, no scripted clicking, no replaying app traffic.
- No bulk enumeration — walking ride ids, customer ids or booking references to see what comes back.
- No sharing API keys outside your organisation, and no embedding a key in a public client.
Rate limits. The platform enforces limits on how often a single account or address can call it. They are set well above ordinary use, and the endpoints that cost money — address lookup, routing — are limited more tightly than the rest.
4. Security testing and vulnerability reporting
Do not test the production platform without written permission. It is a live dispatch system: a test that looks harmless in a lab can strand a passenger or take a fleet offline.
Do report anything you find. If you come across a vulnerability in the course of ordinary use, or through research that did not involve attacking us, tell us:
- Where
- security@cabica.co.uk
- What to include
- What you found, how to reproduce it, and what you think the impact is. A screenshot beats a paragraph.
- What we will do
- Acknowledge within two business days, tell you what we found, and tell you when it is fixed.
- What we will not do
- Pursue you, threaten you, or report you — provided you acted in good faith, did not access or exfiltrate anyone else's data, did not degrade the service, and gave us reasonable time before publishing.
We do not currently run a paid bug bounty. We do credit reporters who want to be credited.
5. What happens when this policy is broken
We respond in proportion to what happened, and we tell you what we are doing and why.
- A limit hit, or an honest mistake
- Nothing. You get a 429, or an email if it keeps happening.
- A first, non-serious breach
- We contact you and ask you to stop.
- A repeated or serious breach
- Suspension of the account or API key, with notice, until it is resolved.
- Anything that endangers a person, the platform, or another operator's data
- Immediate suspension without notice. We tell you as soon as it is safe to, and explain what triggered it.
- Criminal conduct
- Suspension, and referral to the police or the licensing authority.
An IP address or range may be blocked where it is the source of abuse. Blocks applied by an operator to their own tenant always carry an expiry, because consumer addresses rotate and a permanent block set in anger eventually refuses somebody innocent. Blocks are recorded with a reason and can be lifted.
If you think we have got it wrong, write to legal@cabica.co.uk. We will look again, and we will lift a block that turns out to be a mistake.
6. Reporting misuse
If you see the platform being misused — a firm harvesting data, someone using tracking to follow a person, an account behaving as though it is compromised — tell us.
- Security and abuse
- security@cabica.co.uk
- Copyright
- See the Copyright Policy
- Anything else
- legal@cabica.co.uk
We treat reports confidentially. If someone is in immediate danger, call 999 first and tell us afterwards.
This document was last updated on 8 August 2026. See all legal documents.