Sb Sabee
Legal · AUP

Acceptable use policy.

This acceptable use policy sets out exactly how the Sabee platform may and may not be used. It forms part of the Sabee subscription agreement and applies to every user account created under a customer tenant. Last updated 15 May 2026.

1. Purpose

Sabee is provided to help hotels, hostels, aparthotels and multi-property groups run their day-to-day operations reliably and securely. This policy exists to protect the availability of the platform for every customer that relies on it, to protect guests whose personal data passes through it, and to give a clear, predictable account of what will trigger a warning, a suspension, or termination. It applies to every user account created under a customer tenant, and the customer is responsible for the conduct of every user it invites.

This policy is written to be specific rather than aspirational: every rule below exists because we have seen, in this industry or an adjacent one, a real pattern of misuse that it is designed to prevent, and every enforcement step is designed to be proportionate to the actual risk a violation creates for other customers, for guests, or for the platform. Nothing in this policy is intended to restrict ordinary, well-run hospitality operations — a property running at full occupancy with heavy guest messaging volume is not, by itself, a policy concern; a property using the messaging system to blast unsolicited offers to a purchased contact list is.

2. Prohibited content

Customers and their users must not use the platform to store, transmit, generate or process any of the following:

  • Illegal content — anything unlawful in the customer's jurisdiction, the jurisdiction of any affected guest, or the European Union
  • Spam — unsolicited commercial communications sent to guests, prospects or any third party who has not opted in, including bulk messages routed through the platform's guest-messaging tools
  • Malware — viruses, worms, trojans, ransomware or any other malicious code, whether uploaded as an attachment, embedded in a booking note, or delivered through an integration
  • Adult content — sexually explicit material unrelated to legitimate hospitality operations
  • Hateful content — content that attacks or demeans a person or group based on a protected characteristic
  • Intellectual property infringement — content that infringes a third party's copyright, trademark or other proprietary right
  • PII abuse — collecting, storing or using guest personal data for a purpose beyond operating the property, including reselling guest contact lists or using guest data to build a marketing audience outside the platform without a lawful basis and appropriate notice
  • Unsolicited marketing to guests — sending promotional messages to a guest who has not given marketing consent, regardless of whether the guest has an active or historical reservation
  • Phishing — impersonating Sabee, a payment provider, an OTA, or any other party in a communication sent through or referencing the platform in order to obtain credentials or payment details

This list is illustrative of the categories we act on most often, not an exhaustive catalogue of every possible violation; content that is clearly harmful in a way not explicitly enumerated above is still a violation of the spirit of this policy, and Sabee's trust and safety team retains discretion to act on it under the enforcement process in Section 7.

3. Prohibited technical activity

Customers and their users must not:

  • Interfere with or disrupt the platform's servers, networks, or the experience of other customers
  • Attempt to gain unauthorised access to any account, tenant, or system not belonging to them
  • Reverse-engineer, decompile, disassemble, or otherwise attempt to derive the source code, algorithms or underlying structure of the platform
  • Conduct load testing, stress testing, or automated scanning of the platform without at least five business days' prior written notice to security@sabee.esesun.com and Sabee's written acknowledgement
  • Run port scans, vulnerability scans, or penetration tests against Sabee infrastructure without the same prior written authorisation
  • Use the platform's compute resources, API access, or integrations to mine cryptocurrency or run any workload unrelated to hospitality operations
  • Exceed published API rate limits through excessive or abusive polling
  • Introduce automated scripts, bots or browser macros against the platform's user interface in a way that circumvents rate limits designed for human use
  • Share account credentials between individuals in a way that defeats per-user audit logging, rather than creating a separate account for each person who needs access

Where a customer or its integration partner genuinely needs sustained access above published limits — for example, a channel-management partner syncing inventory across a large multi-property portfolio — the correct path is to request a documented rate-limit exception through support@sabee.esesun.com rather than to route around the published limit technically. We generally approve reasonable exceptions quickly once we understand the legitimate use case.

4. Guest data duties

The customer is the controller of the guest personal data it uploads to or generates within the platform, and is responsible for having its own lawful basis for processing that data under GDPR and any other applicable data protection law, and for maintaining its own privacy notice to guests describing that processing, including Sabee's role as processor. Sabee's processing on the customer's behalf is governed by the Data Processing Addendum. The customer's duties to its own guests — including responding to guest data subject requests and maintaining its own record of processing activities — are the customer's alone and are not delegated to or assumed by Sabee merely by virtue of using the platform.

5. Fair use caps

Every plan includes generous soft limits designed to comfortably cover normal property operations. These are fair-use guidelines, not hard technical caps, and we contact a customer before restricting anything:

ActivityFair-use baseline
Booking events (create, modify, cancel) per room per monthUp to 40
Rate and availability updates per room per dayUp to 20
Guest messages sent per room per monthUp to 25
API calls per minute per tenantUp to 300
Concurrent channel manager syncs per propertyUp to 15

A customer that expects to exceed these baselines — for example, a hostel with high-frequency short-stay turnover, or a group running a large promotional campaign — should contact sales@sabee.esesun.com to discuss a higher-capacity plan rather than relying on sustained excess usage, which may otherwise trigger the review process described in Section 7.

6. Abuse reporting

If you become aware of a violation of this policy — by another customer, a third party, or someone within your own organisation — report it to abuse@sabee.esesun.com with as much detail as you can provide, including the tenant or account involved and any supporting evidence. Reports are triaged within one business day (1bd) of receipt, and the reporter is given an acknowledgement of receipt even where the outcome of the investigation cannot be shared for confidentiality reasons.

A report can come from anyone: a guest who received an unsolicited message, a competitor who noticed a scraping pattern against a public booking page, or a customer's own compliance team flagging an internal misuse of guest records. We do not require the reporter to prove a violation before we investigate — a good-faith description of what was observed, with dates and screenshots where available, is enough to open a case. Anonymous reports are accepted, though we cannot send an acknowledgement or follow-up in that case.

7. Enforcement

Enforcement follows a graduated process appropriate to the severity of the violation. For a first, low-severity violation, Sabee's trust and safety team issues a warning and a request for remediation within a reasonable timeframe, typically seven days. If the issue is not remediated, or for a moderate violation, the affected functionality may be restricted or the account placed under suspension pending investigation, during which the tenant retains read-only access to export its data. For a severe, repeated, or wilful violation — including anything in Section 2 involving illegal content, malware or phishing — Sabee may proceed directly to termination with immediate effect, without an intervening warning. Throughout this process, the customer is given notice of the specific provision at issue and an opportunity to respond, except where doing so would create an immediate risk to other customers, guests, or the platform itself, in which case notice is given as soon as reasonably practicable afterward. Sabee cooperates with law enforcement requests where legally required to do so.

8. Appeals

A customer that disagrees with an enforcement decision may appeal in writing to legal@sabee.esesun.com within 14 days of the decision, setting out the grounds for the appeal. Appeals are reviewed by a member of the trust and safety team who was not involved in the original decision, and a written response is provided within ten business days. Filing an appeal does not automatically pause a suspension or termination, but Sabee will consider a request to pause enforcement pending the appeal where the underlying risk is low.

8b. Enforcement examples

Because enforcement outcomes can look opaque when described only as "warning, suspension, termination," we publish rough guidance on how the trust and safety team categorises the most common patterns we encounter. A single accidental bulk message to a marketing list that hadn't been re-consented after import, self-reported by the customer within 24 hours, is typically resolved as a warning plus mandatory reconfirmation of the list before any further outbound send. A repeated pattern of using the guest CRM to send messages that a reasonable guest would consider marketing without an opt-in, continuing after a first warning, is typically resolved as a functional suspension of the CRM outbound-send capability for the tenant until the customer demonstrates a compliant opt-in workflow. Use of scraped or purchased guest email lists, discovered through a spam complaint that traces back to identifiers in the tenant's dataset, is typically resolved as immediate termination with data export offered under the standard timeline in the Terms of Service.

These examples are illustrative, not prescriptive: the trust and safety team weighs factors including whether the violation appears intentional, whether the customer self-reported, whether remediation has been proposed and executed, and whether guests or other customers have been materially harmed. A cooperative first-time customer who self-reports a genuine mistake and takes remediation seriously is treated very differently from a customer that ignores repeated notices or contests obvious violations.

9. Changes to this policy

Material changes to this policy are notified to customers at least 30 days before taking effect, by email to the tenant's registered administrator and by a note in the product changelog. The "last updated" date at the top of this page reflects the version currently in force.

10. Contact

General questions about this policy: legal@sabee.esesun.com. Abuse reports: abuse@sabee.esesun.com. Security disclosures and testing authorisation requests: security@sabee.esesun.com.

v2.1 Last updated 15 May 2026.