Acceptable Use Policy
Introduction
This policy defines permitted and prohibited behavior when using BitcoinP2P services. It supplements, but does not replace, our Terms of Service. Breaches may result in restricted access, temporary suspension, or permanent account closure.
Account use and verification
- Accounts are personal and cannot be sold, transferred, or shared with others.
- Company profiles must complete company verification channels before business use.
- Users must comply with KYC/AML obligations and local law in their jurisdiction.
We may decline service for businesses in high-risk sectors such as gambling, weapons, and certain regulated intermediary services where platform risk is unacceptable.
Advertising and trading conduct
- Ad pricing must be commercially reasonable and not intended to manipulate market behavior.
- Duplicate ads in the same market lane are restricted unless there is meaningful differentiation.
- Misleading terms, false claims, or abusive verification requests are prohibited.
- Trade-related communication and sensitive proof should remain inside trade chat.
- Threatening language, harassment, malicious links, and spam are strictly prohibited.
Restricted payment and asset categories
For safety reasons, some payment instruments and non-Bitcoin asset arrangements are disallowed. Platform moderation may remove listings or block trade flow where risk signals are identified.
Wallet and financial crime restrictions
- Wallet support is limited to Bitcoin network assets explicitly supported by the platform.
- Services must not be used for money laundering, terrorism financing, fraud, scams, phishing, or mixer-like behavior.
- Transactions connected to criminal proceeds or predatory schemes are prohibited.
Cooperation during disputes and support reviews
- Users must provide accurate, complete evidence within dispute workflows.
- Deliberate obstruction, non-response, or fabricated proof may lead to sanctions.
- Support agents do not request passwords, 2FA codes, or payments to unlock funds.
Security contact and vulnerability reporting
We welcome responsible reports from security researchers who help improve platform safety.
Responsible disclosure principles
- Give us reasonable time to investigate and fix before public disclosure.
- Avoid exposing, altering, or destroying user data.
- Do not exploit findings to defraud users or the platform.
We aim not to pursue legal action against good-faith researchers who follow these principles.
Potential rewards
Reward decisions are discretionary and depend on impact, exploitability, and relevance.
Focus areas typically prioritized
- XSS (stored or reflected)
- RCE or command injection
- SQL injection and injection-class flaws
- Serious data exposure issues
- CSRF or session weaknesses with practical exploitability
- SSRF
- Authentication and authorization bypass defects
Examples often not reward-eligible
- Informational error messages and stack traces
- General hardening suggestions without exploit path
- Unexploitable browser-only legacy findings
- Pure availability spam/DoS reports without novel impact