Not production legal advice. Bracketed review notes have been turned into visible counsel notes so launch owners can see what remains unresolved.
1. Purpose
Waystone travel data is intended for lawful, ordinary personal or approved business connectivity. Use must also follow the terms attached to the selected plan and any rules that cannot be changed by Waystone.
2. Prohibited activity
Customers must not use Waystone to harm people, systems, or networks or to interfere with another person’s use of a service.
- Illegal, fraudulent, threatening, exploitative, or abusive activity.
- Malware, credential theft, unauthorized access, or security testing without permission.
- Spam, automated messaging abuse, or deliberate network disruption.
- Reselling or redistributing a plan unless an authorized partner agreement allows it.
- Circumventing plan controls, identity checks, security limits, or provider restrictions.
- Using another person’s account, activation code, or eSIM profile without authorization.
3. Network integrity and fair use
A plan may include provider-supplied traffic management or fair-use terms. Waystone should show those terms with the relevant product rather than inventing a universal threshold.
Activity that creates an unusual security or network risk may require investigation. High usage alone should not be labeled misuse when it remains within the verified plan terms.
4. Security and activation details
Treat QR codes, SM-DP+ details, activation codes, passwords, and account recovery links as sensitive. Do not publish or sell them. Report suspected compromise promptly.
5. Review and enforcement
Waystone may need to limit, suspend, or terminate access when reasonably necessary to address verified misuse, a security incident, a legal request, or a provider network restriction. Responses should be proportionate and documented.
Counsel must define notice, emergency action, appeals, preservation requests, and termination rights.
6. Reporting concerns
The production policy must provide a monitored channel for reporting abuse or security concerns. Reports should include useful technical context without unnecessary personal data.