Back to Home
Legal · Acceptable Use

Acceptable Use Policy

Last updated 20 May 2026·Effective 3 June 2026·Version 1.0
Service provider
SMS Bite Limited
trading as SMSBite
5.17/F. Bonham Trade Centre, 50 Bonham Strand
Sheung Wan, Hong Kong
Company Registration N° 78685084

01Scope and application

This Acceptable Use Policy (the “AUP”) governs all traffic submitted to the SMSBite platform, APIs and related services (the “Service”) operated by SMS Bite Limited, a company incorporated in Hong Kong under Company Registration N° 78685084 and trading as SMSBite.

The AUP is incorporated by reference into the Terms of Service and forms part of the agreement between SMSBite and each customer (“Customer”, “you”). It expands on, and must be read together with, the acceptable-use and prohibited-activities sections of the Terms. Where a term is defined in the Terms, it carries the same meaning here.

This AUP applies to:

  • The Customer entity that holds the contract and every sub-account, API credential, sender ID and integration issued under it.
  • The Customer’s employees, contractors, agents, integrators and platform users.
  • The Customer’s own end customers and any third party on whose behalf the Customer submits traffic.

The Service is offered to verified business entities only. There are no consumer accounts and no self-service consumer sign-up. The Customer is responsible for all traffic submitted under its account, whether or not it authorised that traffic.

02Lawful basis for sending

You must have a lawful basis for every message you submit, determined under the law of the recipient’s jurisdiction and not the law of your own. For marketing, promotional or advertising traffic you must hold valid, demonstrable consent or opt-in wherever the applicable law requires it, obtained before the message is sent and covering the specific sender and the specific purpose.

You are the sender of record. SMSBite is a technical communications infrastructure provider: it transports messages you originate, does not author message content, does not select recipients and does not verify the accuracy of any claim you make in a message. Responsibility for content, targeting, consent and the legality of the underlying campaign rests entirely with you.

Transactional and service traffic — one-time passcodes, account alerts, delivery notifications and similar — may rely on a lawful basis other than consent where the destination law permits, but must remain strictly within the scope of the transaction or relationship that justifies it. Attaching promotional content to a transactional message makes the whole message marketing traffic.

03Prohibited content and use cases

The following categories of traffic are prohibited on the Service. The list is illustrative and not exhaustive.

  • Spam and unsolicited bulk messaging — any message sent without a valid lawful basis, to purchased, scraped, appended or otherwise unverified recipient lists, or in volumes disproportionate to the consent held.
  • Phishing, smishing and credential harvesting — messages designed to induce a recipient to disclose passwords, passcodes, card details, banking credentials or other secrets, including links to look-alike login pages.
  • Fraud and financial scams — advance-fee fraud, fake delivery or customs-fee notifications, invoice and supplier redirection schemes, refund and support scams, romance scams, and “pig-butchering” investment fraud.
  • Impersonation — presenting messages as originating from any natural person, brand, employer, bank, payment provider, courier, public authority, regulator or emergency service without that party’s written authority, including through synthetic or AI-generated content.
  • Malware and malicious links — distribution of viruses, trojans, spyware, stalking or surveillance software, or links to sites that deliver such code or execute drive-by attacks.
  • Destination-masking link shorteners — public or shared URL shorteners that conceal the final destination. Links must resolve to a domain that the recipient can associate with the sender; branded or dedicated shortener domains registered to the Customer and declared to SMSBite are acceptable.
  • Illegal goods and services — anything unlawful in the destination country, including counterfeit goods, stolen data and hacking services.
  • Controlled substances — narcotics, prescription-only medicines offered without a valid prescription, and unapproved pharmaceutical, sexual-health or weight-loss products.
  • Weapons— firearms, ammunition, explosives, and their components or conversion parts, where the offer or sale is restricted in the destination country.
  • Child sexual abuse material — any sexual content involving minors and any CSAM. Zero tolerance: immediate termination, preservation of records and reporting to law-enforcement and the relevant hotline organisations.
  • Human trafficking and exploitation — recruitment, transport, advertising or coordination of forced labour, sexual exploitation or bonded servitude.
  • Gambling— betting, casino, lottery and prize-draw promotion into any destination where the Customer does not hold the licence that destination requires.
  • Unlicensed financial promotion — investment, securities, forex, lending, insurance, cryptocurrency, token-sale or digital-asset promotion into any destination where the Customer lacks the required authorisation, and any signal, tip or trading-advice campaign.
  • Deceptive or misleading claims — false urgency, fabricated endorsements, invented prizes or debts, undisclosed charges, and guaranteed-return or guaranteed-outcome claims.
  • Hate speech, harassment and extremism — content promoting hatred or violence against individuals or groups on protected characteristics, and threatening, abusive, coercive or extortionate messaging, including content supporting violent extremism or terrorism.

04Prohibited technical practices

The following practices are prohibited irrespective of message content, because they damage operator relationships, degrade delivery for other customers or defeat the controls that regulators and operators require.

  • SIM farms, SIM boxes and interconnect bypass — terminating traffic through retail SIM estates or any arrangement that bypasses the licensed interconnect of the destination operator.
  • Grey routes— knowingly submitting traffic for delivery over routes that are not commercially and contractually authorised by the destination operator, or requesting that SMSBite do so.
  • Spoofed or unregistered sender IDs — using an alphanumeric sender, short code or long number you are not entitled to use, or one that has not been registered where the destination requires registration.
  • Snowshoeing— spreading a single campaign across many sender IDs, sub-accounts, routes or entities in order to stay below complaint or volume thresholds.
  • Traffic pumping and Artificially Inflated Traffic (AIT) — generating message volume for revenue share, payout or billing manipulation rather than genuine communication, including traffic directed at ranges selected for their termination rate.
  • International Revenue Share Fraud and artificial voice traffic — generating, procuring or facilitating voice traffic to premium-rate, revenue-share or artificially inflated number ranges, whether through the voice one-time-password fallback or otherwise, and any scheme designed to generate termination revenue rather than to reach a genuine recipient.
  • Auto-generated or bot-driven verification requests — scripted, automated or fraudulent triggering of sign-up, login or verification flows in order to force the sending of messages.
  • Filter circumvention — deliberate obfuscation of content, sender or destination to evade operator filters, spam detection or any technical control applied by SMSBite or its upstream partners, including character substitution, homoglyphs, padding and deliberate misspelling.
  • Load and stress testing — performance, throughput or penetration testing against the Service without SMSBite’s prior written approval and an agreed test window.
  • Unauthorised resale — reselling, sub-licensing or providing access to the Service to third parties without a written reseller agreement with SMSBite.

05Sender identity and registration

Sender identifiers must accurately identify the party on whose behalf the message is sent. A recipient must be able to tell from the sender ID, or from the body of the message, who is contacting them.

Where a destination country or operator operates a sender-ID registry or pre-clearance regime — including the Telecom Regulatory Authority of India’s DLT framework, the Saudi CITC registry and equivalent schemes elsewhere — the sender ID and, where required, the message template must be registered and approved before traffic is submitted. Traffic using unregistered identifiers into such destinations may be blocked, altered or discarded by the operator, and SMSBite gives no delivery undertaking for it.

You warrant that you are entitled to use every sender ID, brand name, trade mark, short code and number submitted under your account, and that you hold written authority from the rights holder where the identifier belongs to a third party. SMSBite may require documentary evidence of that entitlement at onboarding or at any time afterwards, and may withhold or withdraw a sender ID pending evidence.

06Verification and OTP traffic

A one-time passcode or verification message may only be sent to a mobile number that the end user has supplied for that purpose, in an authentication or verification flow that is active at the moment of sending. OTP traffic may not be sent to numbers obtained from a list, a database, an enrichment provider or a previous unrelated interaction.

You must operate effective rate limiting and anti-abuse controls on any flow that can cause a message to be sent. That includes per-number, per-session, per-device and per-IP limits, cool-down periods between resend attempts, a cap on attempts per number per day, bot mitigation on the triggering endpoint, and monitoring of conversion between codes sent and codes successfully entered. A sustained fall in that conversion rate is a primary AIT indicator and must be investigated by you promptly.

You may not send verification traffic on behalf of an undisclosed third party. If OTPs are sent for an end customer or a platform you operate, that relationship must be disclosed to SMSBite at onboarding and kept current, and the end customer must be identifiable to SMSBite on request.

07Customer obligations

You are required to:

  • Maintain auditable records of opt-in evidence — timestamp, source channel, consent wording presented and method of capture — and of every opt-out, suppression and do-not-contact request, for a minimum of five (5) years, and produce them to SMSBite within forty-eight (48) hours of a written request.
  • Honour opt-out promptly. Support STOP and the recognised local-language equivalents for each destination, include opt-out instructions in marketing messages where the destination requires it, and suppress the recipient across all sender IDs and sub-accounts used for that campaign.
  • Keep a named, monitored abuse contact on file with SMSBite and update it whenever it changes. The contact must be reachable on business days.
  • Cooperate fully and without delay with SMSBite, operator and regulator investigations, including providing campaign details, consent evidence, message samples, traffic explanations and end-customer identity.
  • Flow down this AUP to every end customer, sub-account holder and third party for whom you send, impose obligations no less protective, and enforce them.
  • Notify SMSBite promptly if you become aware of traffic under your account that breaches this AUP.

08Monitoring and enforcement

SMSBite operates controls designed to detect breaches of this AUP before, during and after they occur:

  • Know-Your-Business and Know-Your-Customer verification at onboarding, covering corporate registration, beneficial ownership, sanctions screening, declared use case, sender identity and expected volumes.
  • Traffic monitoring against declared volumes, destinations, routes and delivery patterns.
  • Content pattern analysis for known abuse signatures, and handling of complaint signals received from operators, recipients and regulators.
  • AIT detection, including destination-range concentration analysis and verification-conversion monitoring.

Graduated response. Where a breach is identified, SMSBite will normally respond in proportion to its severity and persistence: written warning and a request for explanation; rate limiting of the affected traffic; restriction of specific routes, destinations or sender IDs; suspension of the sender ID, sub-account or account; and termination of the agreement.

Immediate suspension. SMSBite may suspend traffic in whole or in part without prior notice where the breach is severe — including CSAM, phishing and smishing, fraud campaigns, sender-ID spoofing, AIT, interconnect bypass — or where an operator, regulator or law-enforcement authority instructs it. Where the law permits, SMSBite will notify you of the suspension and its reason as soon as practicable afterwards.

Liability for costs. You remain liable for all operator fines, regulatory penalties, blocking fees, remediation charges and other pass-through costs levied on SMSBite as a result of traffic submitted under your account, together with the fees for traffic already submitted, whether or not that traffic was delivered.

09Reporting abuse

Anyone — a message recipient, an operator, a regulator, a brand owner or a security researcher — may report suspected abuse of the Service to abuse@smsbite.com. Reports are accepted in English.

To let us act on a report, please include:

  • The full message text, ideally as a screenshot and as plain text.
  • The sender ID, short code or number that the message displayed.
  • The receiving number in full international format, or as much of it as you are willing to share.
  • The date, time and time zone of receipt.
  • The destination country and, if known, the receiving mobile network operator.
  • Any URL contained in the message, sent as text rather than as a live link.
  • Your contact details, if you are willing to answer follow-up questions.

We aim to acknowledge abuse reports within two (2) business days. This is an operational target rather than a guarantee, and investigation timelines vary with the complexity of the report and the cooperation of the parties involved. Please do not include payment-card details, passwords or passcodes in a report.

This AUP sits alongside the following documents. Where this AUP and another document address the same subject, the AUP provides the operational detail and the Terms of Service govern in the event of a genuine conflict.

  • Terms of Service — the contract into which this AUP is incorporated, including suspension, termination, indemnity and liability.
  • Anti-Spam Policy — consent, opt-out and complaint-rate requirements in detail.
  • Privacy Policy — how SMSBite processes personal data, including end-recipient data processed on your instructions.
  • Service Level Agreement — platform availability targets. Message delivery itself is best-effort and depends on mobile network operators, aggregators, regulators and handset conditions.

11Changes and contact

SMSBite may update this AUP to reflect new operator or regulatory requirements, newly observed abuse patterns or changes to the Service. Material changes are notified to account contacts by email and posted on this page at least thirty (30) days before they take effect. Changes required immediately by an operator, regulator or law-enforcement authority, and non-material changes such as clarifications and corrections, take effect on publication.

Continued use of the Service after the effective date of a revision constitutes acceptance of the revised AUP.

SMS Bite Limited, trading as SMSBite5.17/F. Bonham Trade Centre, 50 Bonham StrandSheung Wan, Hong KongCompany Registration N° 78685084