Acceptable Use Policy
Last updated 26 September 2026
The short version
Use Alejo OS lawfully, protect access to your account, don’t touch other hotels’ data, and be honest with guests about what they are charged.
1. Purpose
This policy keeps Alejo OS safe and reliable for every hotel and guest that depends on it. It applies to hotels, their staff and anyone using the guest pages. It is part of the Terms of Service.
2. You must not
- use Alejo OS for anything unlawful, fraudulent or deceptive, including money laundering or handling proceeds of crime;
- put in personal data you have no right to collect, or use guest data for purposes the guest was not told about;
- share logins, or let someone use your account who is not authorised by your hotel;
- try to access another hotel’s data, bypass access controls, or probe, scan or test the security of the Service without our written permission;
- upload malware, or interfere with or overload the Service, including through automated requests beyond normal use;
- reverse engineer, scrape, copy or resell the Service, or use it to build a competing product;
- send spam, or use email, notification or guest messaging features to send unsolicited marketing;
- use payment features to process transactions for goods or services other than your own hotel’s, or to evade a payment partner’s rules;
- misdescribe charges to guests, including how the optional online payment service charge is presented (see the Payment Terms);
- remove or hide the “Powered by Tappa” mark on guest-facing pages;
- use the NFC or door-access features to tag, track or unlock anything you are not authorised to.
3. Security responsibilities
- Give staff only the role they need, and remove access promptly when they leave.
- Turn on two-factor authentication for owners and managers.
- Report a suspected compromise to consulawtech@gmail.com as soon as you notice it.
- If you find a security weakness, tell us privately and give us reasonable time to fix it before disclosing it. We will not take action against good-faith research that follows this policy and does not access other people’s data.
4. What happens if this policy is broken
Depending on the seriousness, we may warn you, remove content, limit features (for example the guest service charge), suspend access or end the agreement, as described in the Terms. Where we can and it is safe to, we will tell you first and give you a chance to put things right. We may report unlawful activity to the authorities.
5. Contact
Questions or reports: consulawtech@gmail.com.
