Last updated: 2026-05-10 · v1

Acceptable Use Policy

Effective Date: 2026-05-11 Last Updated: 2026-05-11 Version: 1.0

This Acceptable Use Policy ("AUP") governs your conduct on the Gvoya Service and is part of the Terms of Service. Violations may result in suspension, account termination, and legal action including injunction, damages claims, and criminal referral where applicable.

1. Permitted Use

You may use the Service to:

  • Discover, compare, and book voyages from Gvoya's Supplier network for personal use, family use, or — where you are a registered Partner — for your verified Clients
  • Engage with the AI Concierge in good faith conversations about your travel preferences
  • Access the Partner Portal or Supplier Portal under the corresponding agreement
  • Submit reviews and feedback in your own genuine voice
  • Exercise privacy rights under the Privacy Policy and applicable law

2. Prohibited Conduct

You must not:

2.1 Scraping, automation, and AI training

a. Scrape, mirror, crawl, or systematically extract data from the Service by any means, including but not limited to: manual extraction at industrial scale, scripted clients, headless browsers (Playwright, Puppeteer, Selenium), residential proxy networks, or distributed scraping services; b. Train, fine-tune, evaluate, or benchmark any artificial-intelligence or machine-learning model on Service content (including AI Concierge outputs, voyage descriptions, photographs, prices, itineraries) without prior written consent from Gvoya; c. Reverse-engineer Gvoya's AI prompts, system instructions, or model behavior; d. Probe rate limits, attempt to extract higher-than-allowed rate limits via header manipulation, or attempt to access internal/admin endpoints; e. Access endpoints flagged in robots.txt as Disallow: /voyages/honeypot- or any other honeypot path. Any access of a honeypot route is logged with severity=critical and triggers a 24-hour automatic IP blocklist; f. Use the Service or any AI conversation log to compete with Gvoya by building a substantially-similar AI voyage concierge.

2.2 Fraud, impersonation, and identity abuse

a. Misrepresent your identity, age, nationality, or credentials; b. Use false or stolen payment instruments; c. Create accounts using disposable, throwaway, or burner email addresses with intent to evade rate limits or identity verification; d. Impersonate another person, a Gvoya employee, a Supplier representative, or a public official; e. Attempt to phish, social-engineer, or otherwise extract credentials from staff, Partners, Suppliers, or other users.

2.3 Booking abuse

a. Make bookings without genuine intent to travel; b. Use the Service to circumvent visa, sanction, or immigration controls; c. Use the Service to evade tax reporting in any jurisdiction; d. Make repeated bookings and last-minute cancellations to manipulate Supplier inventory or commissions; e. Knowingly book on behalf of a sanctioned individual or entity.

2.4 Brand and IP

a. Use Gvoya brand assets ("Gvoya", logos, taglines, trade dress) outside the express licenses in Terms §7, Partner Agreement §2, or Supplier Content License; b. Register domains containing "gvoya", "g-voya", or visually-similar marks (e.g., "gvoyatravel.com", "gvoya-cruise.cn") for any purpose; c. Bid on the keyword "Gvoya" or close variants in paid-search platforms (Google Ads, Bing Ads, Baidu, Yandex) without our prior written authorization.

2.5 Content abuse

a. Submit content (reviews, names, descriptions) that is unlawful, defamatory, hateful, threatening, harassing, sexually explicit involving minors, infringing on third-party rights, or designed to deceive; b. Spam reviews — coordinated review manipulation, paid review schemes, or fake personas; c. Distribute malware, viruses, ransomware, cryptocurrency miners, or any harmful code through the Service.

2.6 Security and abuse

a. Probe, scan, or test the vulnerability of any Gvoya system; b. Attempt to bypass authentication or authorization; c. Conduct denial-of-service or distributed-denial-of-service attacks; d. Attempt brute-force credential stuffing on login endpoints; the platform rate-limits and logs all such attempts as DefenseEvent and may auto-block source IPs; e. Use the Service to launder data, financial value, or evade legal obligations.

2.7 Privacy abuse

a. Submit other people's personal data without lawful basis (e.g., booking for someone else without their consent); b. Attempt to access another user's account or data; c. Re-identify de-identified or aggregated data we publish; d. Misuse contact information collected through Partner or Supplier interactions.

2.8 Sanctions and legal compliance

a. Use the Service in violation of US, EU, UK, UN, Singapore, Australian, Canadian, or Chinese sanctions, embargoes, or export controls; b. Use the Service to facilitate money laundering, terrorism financing, or any other unlawful activity; c. Use the Service in jurisdictions where it is unlawful to do so.

3. Enforcement

Gvoya may, in its sole discretion and without prior notice when circumstances require:

a. Issue a warning or request remediation; b. Suspend access or specific features (e.g., AI Concierge access, booking capability); c. Terminate the account and any related Partner or Supplier accounts; d. Cancel pending bookings; e. Withhold commission payments or seek clawback of paid commissions; f. File a takedown notice with hosting providers, DNS registrars, or platform operators (using the Defense + Watch evidence pack flow); g. Refer the matter to law enforcement or regulators; h. Pursue civil action for injunctive relief and damages.

4. Honeypot and Defense System

Gvoya operates a hash-chained Defense system that records security-relevant events with severity ratings (low/medium/high/critical) and a Merkle-rooted evidence chain suitable for legal action. Repeated abuse — even from rotating IPs or distributed sources — is correlated and may result in:

  • Permanent IP-range blocks
  • ASN-level blocks
  • Reports to the relevant abuse@asn email and ASN abuse handler
  • Evidence Pack ZIP exports submitted to platforms, registrars, or law enforcement

5. Reporting Abuse

If you observe a violation of this Policy by another user, Partner, or third party (including stolen content of yours appearing in our Service, or impersonation of yours through the Service), please report it:

6. Changes

This Policy may be updated. Material changes are announced thirty (30) days before they take effect (in-app banner + email). Continued use after the effective date constitutes acceptance.

7. Contact

GRANDROUTES GLOBAL PTE. LTD. (operating Gvoya), Singapore abuse@gvoya.com · legal@gvoya.com · security@gvoya.com