Acceptable Use Policy
1. Scope, Accounts and Authorised Users
This policy applies where a customer, its personnel or an approved contractor receives access to a dashboard, API, VPN, network segment, remote-management tool, monitoring system, support portal or hosted-miner control made available by or through The Mining Shop UK Limited. It supplements the applicable Hosting Terms, service schedule, order and Website Terms of Use.
Access is limited to the named customer, authorised users and agreed business purpose. The customer must keep its user list current, apply least privilege, use unique credentials and multi-factor authentication where available, and notify us promptly when access should be changed or removed. Credentials, API keys, VPN profiles and recovery codes must not be shared through insecure channels or published.
The customer remains responsible for activity performed through its accounts unless caused by our breach. Suspected compromise, unexpected configuration changes or unauthorised access must be reported immediately.
2. Permitted and Prohibited Use
Services may be used only for lawful monitoring, configuration, maintenance and operation of equipment and services within the customer's authorised scope. Users must follow applicable law, manufacturer requirements, pool and network rules, sanctions and export controls, and reasonable security instructions.
Users must not:
- access another customer's miner, wallet, pool account, data, credentials, network or service;
- probe, scan, exploit, bypass, disrupt or overload systems, controls, limits, logging or authentication without prior written authorisation under the Security and Vulnerability Disclosure Policy;
- introduce malware, unauthorised firmware, cryptojacking code, traffic interception, denial-of-service activity or deceptive network traffic;
- use a service for unlawful mining, fraud, sanctions evasion, money laundering, intellectual-property infringement, harassment or harmful content;
- conceal identity, falsify telemetry, tamper with metering or monitoring, or interfere with other hosted customers;
- connect unapproved equipment or expose an internal service directly to the internet; or
- reverse engineer, scrape or automate a service beyond documented interfaces and agreed limits.
3. Operational Security, Data and Monitoring
Customers must keep endpoints, browsers, operating systems and authorised integrations supported and patched; protect wallet and pool credentials; review alerts; and maintain their own recovery information. Never provide seed phrases or private keys to us. Remote access does not transfer responsibility for the customer's wallet, pool, tax records or commercial decisions.
We may collect proportionate authentication, security, configuration, performance, API and audit logs to provide the service, detect misuse, investigate incidents, meet legal obligations and protect customers. Personal data is handled under the Privacy Policy and Data Protection and UK GDPR Governance Policy.
Monitoring does not guarantee that every compromise, misconfiguration, hardware failure or loss will be detected. Customers must maintain independent records and promptly verify material instructions, payout addresses and access changes.
4. Investigation, Suspension and Reporting
We may investigate suspected misuse and take proportionate protective action. This may include requesting information, restricting an account, revoking a token, isolating a device or network, preserving relevant logs, suspending remote access or terminating the affected service in accordance with the contract. Urgent action may be taken without advance notice where reasonably necessary to protect people, systems, customers or legal compliance.
We will consider severity, intent, recurrence, customer cooperation and the risk of continuing access. Where practicable, we will explain the reason and restoration requirements. Nothing in this policy prevents lawful reporting to regulators, law enforcement, emergency services or protected whistleblowing.
Report suspected misuse or compromise to [email protected]. A technical vulnerability should follow our coordinated disclosure policy and must not be tested against customer data or live operations without written authorisation.
Review, Questions and Contact
This policy is reviewed at least annually and after a material legal, operational or service change.
The Mining Shop UK Limited · Company number 14666497 · VAT GB482035600
Registered office: Enterprise House, 202 to 206 Linthorpe Road, Middlesbrough, England, TS1 3QW
Shop and repair centre: 38 Church Street, Hartlepool, TS24 7DG, United Kingdom
Email: [email protected] · Phone: 01429 408034
View the complete policy set in our Legal, Policies and Terms index.