BerthRight

Acceptable Use Policy

Version 1.0

Effective Date: August 24, 2026

Last Updated: August 24, 2026

Berth Right MGMT LLC — Marina Management Platform

1. Introduction and Application

1.1 Purpose. This Acceptable Use Policy (this “AUP”) governs the use of the BerthRight marina management platform and all related services (the “Services”) provided by Berth Right MGMT LLC, a Florida limited liability company doing business as BerthRight (“BerthRight,” “we,” “us”). It is designed to protect BerthRight, its customers, its customers’ boater customers, its infrastructure providers, and the internet at large from misuse of the Services.

1.2 Who this applies to. This AUP applies to:

(a) each Customer or Marina Operator that accesses the Services under a Master Services Agreement, an Order Form, or BerthRight’s online Terms of Service;

(b) each Authorized User — every owner, manager, dockmaster, harbormaster, service writer, yard hand, seasonal employee, bookkeeper, contractor, or other individual to whom Customer grants access; and

(c) each End User — each boater, slip holder, vessel owner or operator, transient guest, storage or service customer — to the extent that person accesses Customer-branded pages, portals, or communications delivered through the Services.

1.3 Customer is responsible for its users. Customer is responsible for all activity conducted under its account and by its Authorized Users, and for its End Users’ use of the Customer-branded portions of the Services, as if that activity were Customer’s own. Customer will ensure that its Authorized Users are aware of and comply with this AUP.

1.4 Incorporation and updates. This AUP is incorporated by reference into the agreement between BerthRight and Customer. A violation of this AUP is a breach of that agreement. BerthRight may update this AUP from time to time; material adverse updates are subject to the advance-notice and objection provisions of the applicable agreement.

1.5 Not an exhaustive list. The prohibitions below are illustrative, not exhaustive. Conduct that is not specifically listed but that is unlawful, that harms BerthRight or its other customers, or that a reasonable person would recognize as abusive, is prohibited.

1.6 Definitions. Capitalized terms not defined here have the meanings given in the applicable agreement or in the BerthRight Data Processing Addendum (the “DPA”), available at https://berthright.app/dpa.

2. General Rule

Customer will use the Services only for its lawful, internal business purposes of operating its marina facility and serving its boater customers, in compliance with all applicable laws, regulations, and industry standards, and in a manner that does not harm BerthRight, other customers, End Users, or any third party.

3. Prohibited Content

Customer will not use the Services to store, transmit, display, distribute, or make available any content that:

(a) is unlawful, or that promotes, facilitates, or provides instruction in unlawful activity;

(b) infringes or misappropriates any patent, copyright, trademark, trade secret, right of publicity, or other intellectual property or proprietary right;

(c) is defamatory, libelous, trade-libelous, or knowingly false in a manner injurious to a person or business;

(d) is harassing, threatening, abusive, or intended to intimidate a specific individual, or that constitutes stalking;

(e) is obscene, pornographic, or sexually explicit, or that depicts, promotes, or facilitates the sexual exploitation or abuse of a minor;

(f) promotes or incites violence, terrorism, or unlawful discrimination, or that constitutes hate speech directed at a protected class;

(g) contains or transmits malware, viruses, worms, ransomware, keyloggers, or other malicious code;

(h) constitutes phishing, spoofing, or an attempt to obtain credentials, financial information, or personal information by deception; or

(i) violates the privacy or publicity rights of any individual.

4. Prohibited Conduct

Customer will not, and will not permit any Authorized User or third party to:

(a) use the Services in violation of any applicable federal, state, local, or foreign law or regulation, including consumer protection, telemarketing, anti-discrimination, fair housing, tax, maritime, and environmental laws;

(b) use the Services to engage in fraud, deceptive trade practices, money laundering, sanctions evasion, or the sale of stolen goods or stolen vessels;

(c) misrepresent its identity or affiliation, impersonate any person or entity, or falsely state or imply an affiliation with BerthRight;

(d) resell, sublicense, rent, lease, timeshare, or provide the Services as a service bureau to any third party, except that a marina management company may use the Services to operate marina facilities it manages under a written management agreement, provided each such facility is properly licensed and accounted for under the applicable Order Form;

(e) reverse engineer, decompile, disassemble, or attempt to derive the source code, structure, or underlying ideas of the Services, except to the limited extent that such a restriction is unenforceable under applicable law;

(f) copy, modify, or create derivative works of the Services or the Documentation, or remove or obscure any proprietary notice;

(g) use the Services to build, train, or benchmark a competing product or service, or provide access to a competitor of BerthRight for that purpose;

(h) use the Services in connection with any activity where failure or delay could result in death, personal injury, or severe environmental damage, or as a substitute for marine safety, navigation, emergency dispatch, or life-safety systems. The Services are business management software and are not designed, tested, or warranted for safety-of-life or emergency-response use;

(i) use the Services in a manner that violates the terms of service of any BerthRight infrastructure provider, including Vercel, Supabase, Clerk, Stripe, Cloudflare, or BerthRight’s email or SMS providers; or

(j) take any action reasonably likely to cause BerthRight to breach a contract with, or be suspended or terminated by, any of those providers.

(k) Fair housing caution. Where a marina offers liveaboard slips or other accommodations that may constitute a dwelling, Customer will not use the Services — including waitlist prioritization, screening notes, rate assignment, or messaging — in a manner that discriminates on the basis of race, color, religion, sex, familial status, national origin, disability, or any other protected characteristic under applicable federal, state, or local law.

5. Security Violations

Customer will not, and will not permit any Authorized User or third party to:

5.1 Unauthorized testing. Conduct any penetration test, vulnerability scan, load or stress test, fuzzing, port scan, automated crawling, or other security or performance testing of the Services without BerthRight’s prior written authorization. BerthRight will not unreasonably withhold authorization for a legitimate, scoped assessment; requests should be sent to info@berthright.app at least ten (10) business days in advance and must identify the tester, the scope, the source addresses, the window, and the testing methodology. Authorized testing is subject to Section 11.3(f) of the DPA.

5.2 Tenant isolation. Attempt to access, probe, enumerate, or interfere with any tenant, account, data, or environment other than Customer’s own, or attempt to circumvent, disable, or test the multi-tenant isolation controls of the Services, including tenant scoping or subdomain routing.

5.3 Access controls. Attempt to circumvent, disable, or defeat any authentication, authorization, rate limiting, licensing, metering, or other technical control of the Services; escalate privileges beyond those granted; or access any portion of the Services, its systems, or its networks without authorization.

5.4 Credential sharing. Share, sell, transfer, or permit the use of Authorized User credentials by more than one individual. Each Authorized User must have their own individually named account. Generic, shared, or “front desk” logins used by multiple staff members are prohibited. Customer will require its Authorized Users to keep credentials confidential, will not permit credentials to be posted, written down in shared areas, or stored in shared documents, and will notify BerthRight promptly at info@berthright.app upon learning of any actual or suspected unauthorized access to or use of its account.

5.5 Interference. Interfere with or disrupt the integrity, security, or performance of the Services or the data contained therein, including by denial-of-service attack, injection attack, session hijacking, or deliberate overload.

5.6 Circumvention of communications controls. Circumvent or attempt to circumvent any opt-out, unsubscribe, suppression list, STOP handling, frequency cap, or rate limit implemented in the Services. Re-adding a contact who has opted out, in order to resume messaging, is a violation of this Section and of Section 6.

5.7 Responsible disclosure. If Customer or an Authorized User discovers a security vulnerability in the Services, Customer will report it promptly and confidentially to info@berthright.app and will not publicly disclose it, exploit it, or use it to access data other than Customer’s own. BerthRight will not pursue claims against a person who discovers and reports a vulnerability in good faith, in accordance with this Section, and without accessing, altering, or exfiltrating data belonging to BerthRight or another customer.

6. Messaging — Email and SMS

This Section is the most operationally important part of this AUP. BerthRight’s ability to deliver email and text messages for every customer depends on the sending reputation of shared infrastructure and on the standing of BerthRight’s registered A2P 10DLC campaigns with the mobile carriers. One marina sending to a purchased list can degrade or suspend messaging for every other marina on the platform. The rules in this Section are enforced strictly, and Section 9.4 (campaign-level suspension) exists specifically so that BerthRight can stop a bad campaign without taking a marina’s whole operation offline.

6.1 Consent — the core rule

(a) Customer will not send, or cause to be sent, any email or SMS message through the Services to any End User or other recipient without a valid, documented legal basis for that message, including any consent required by applicable law for the type of message being sent.

(b) Customer is solely responsible for obtaining, documenting, and maintaining records of consent, including the date, time, method, source, and exact language of the disclosure to which the recipient agreed, and for retaining those records for as long as required by applicable law and for a reasonable period thereafter.

(c) BerthRight provides the mechanisms; Customer provides the consent. BerthRight supplies consent-capture fields, preference management, opt-out and STOP handling, suppression lists, and consent audit records as features of the Services. BerthRight does not obtain consent on Customer’s behalf, does not verify the validity of any consent Customer records, and is not responsible for Customer’s failure to obtain or document consent. Use of BerthRight’s consent-capture tooling is not a legal opinion that Customer’s consent practice is adequate.

(d) Customer will use the Services’ consent-capture and preference-management features to record consent status, and will not maintain consent status solely outside the Services in a manner that prevents the Services from honoring opt-outs.

6.2 Prohibited list sources

Customer will not send messages through the Services to any recipient whose contact information was:

(a) purchased, rented, leased, or licensed from a third party, including boat-show attendee lists, vessel registration data, USCG documentation records, marina association rosters, or any commercially available list;

(b) scraped, harvested, or automatically collected from websites, directories, social media, classified listings, or public records;

(c) obtained from a third party without the recipient’s consent to receive communications from Customer specifically — consent given to another business is not consent to hear from Customer, and consent given to a prior owner of a marina does not automatically transfer without an appropriate basis;

(d) collected through deceptive means, including a disclosure that did not clearly state who would be messaging the recipient and about what; or

(e) obtained from a co-registration, lead generation, or affiliate arrangement unless Customer can produce the specific disclosure and consent record for each recipient.

6.3 SMS and text messaging — specific requirements

Customer will comply with all applicable requirements for text messaging, including:

(a) the Telephone Consumer Protection Act (TCPA) and its implementing regulations, including all consent requirements applicable to the type of message sent — noting that prior express written consent is generally required for marketing or promotional text messages, and that a lesser standard may apply to purely transactional or informational messages, but that Customer, not BerthRight, is responsible for determining which standard applies to each message it sends;

(b) applicable state telemarketing and mini-TCPA statutes, which in several states impose consent, disclosure, calling-time, and registration requirements stricter than federal law and which apply based on the recipient’s location — a Jersey shore marina messaging a boater whose mobile number is in another state may be subject to that state’s rules;

(c) A2P 10DLC registration requirements, including accurate registration of Customer’s brand and campaign use case, accurate sample message content, and accurate opt-in description. Customer will provide accurate registration information and will notify BerthRight before materially changing its messaging use case, because carriers may reject, throttle, or suspend traffic that does not match the registered campaign;

(d) applicable CTIA Messaging Principles and Best Practices and carrier requirements, including prohibitions on messaging content categories that carriers restrict;

(e) mandatory honoring of STOP and HELP. Customer will not disable, circumvent, or interfere with the Services’ automatic processing of STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, and equivalent opt-out keywords, or of HELP and INFO keywords. An opt-out is effective immediately upon receipt. Customer will not re-add, re-import, or otherwise resume messaging an opted-out recipient absent a new, documented opt-in from that recipient;

(f) identification and disclosure. Customer’s messages will clearly identify the marina as the sender; consent language presented to recipients will identify the marina by name, describe the types of messages, state message frequency, and state that message and data rates may apply; and

(g) quiet hours and frequency. Customer will observe applicable restrictions on the time of day at which messages may be sent, measured by the recipient’s local time, and will not send at a frequency materially exceeding what recipients were told to expect.

6.4 Email — specific requirements

Customer will comply with all applicable requirements for commercial email, including the CAN-SPAM Act:

(a) Accurate headers and routing. Header information, including the “From,” “To,” “Reply-To,” and originating domain and address, must be accurate and must not be false or misleading;

(b) Non-deceptive subject lines. Subject lines must accurately reflect the content of the message;

(c) Identification as an advertisement, where the message is commercial in nature, in a clear and conspicuous manner;

(d) Valid physical postal address. Every commercial message must include Customer’s valid physical postal address. Customer will configure and maintain its own physical postal address in the Services. Customer will not use BerthRight’s address;

(e) Clear and conspicuous opt-out mechanism in every commercial message, which must remain operational for at least thirty (30) days after the message is sent;

(f) Prompt honoring of opt-outs. Opt-out requests must be honored within ten (10) business days, and Customer will not require a recipient to pay a fee, provide information beyond an email address and opt-out preference, or take any step other than sending a reply or visiting a single web page in order to opt out;

(g) No transfer of opted-out addresses. Customer will not sell, lease, exchange, or otherwise transfer an email address of a recipient who has opted out, except to a provider assisting Customer in complying with its opt-out obligations; and

(h) Responsibility for messages sent on Customer’s behalf. Customer remains responsible for compliance even where a third party sends on its behalf.

6.5 Content of messages

Customer will not use the Services to send messages that: promote illegal goods or services; relate to cannabis, firearms, gambling, high-risk financial services, or other content categories that carriers and email providers restrict; contain misleading claims about pricing, availability, or marina services; or that a reasonable recipient would regard as unrelated to the marina relationship on which the recipient’s consent was based.

6.6 Deliverability and reputation

(a) Customer will maintain reasonable list hygiene, including promptly removing invalid addresses and numbers and honoring hard bounces.

(b) Customer will not send to addresses or numbers that have repeatedly hard-bounced, and will not use the Services to validate, test, or clean a list.

(c) BerthRight may impose sending limits, throttles, warm-up requirements, or approval requirements on messaging volume, and may require Customer to authenticate its own sending domain (SPF, DKIM, and DMARC) as a condition of higher volume.

(d) BerthRight may monitor aggregate deliverability metrics — bounce rates, spam complaint rates, opt-out rates, and carrier filtering — and may require Customer to remediate, pause a campaign, or reduce volume where those metrics indicate a compliance or reputation problem. Sustained spam complaint or opt-out rates materially above industry norms are, on their own, grounds for action under Section 9.

7. Prohibited Data

7.1 No sensitive categories. Customer will not submit to the Services, and will instruct its Authorized Users not to submit, any of the following:

(a) Health, medical, disability, accessibility, or mobility information about any individual, including notes about medical conditions, medications, treatments, physical or mental limitations, mobility devices, pregnancy, or any need for health-related accommodation;

(b) Social Security numbers, taxpayer identification numbers, driver’s license numbers, state identification card numbers, passport numbers, or other government-issued identification numbers;

(c) Full payment card numbers, card security codes (CVV/CVC), magnetic stripe or chip data, PINs, or full bank account and routing number combinations — see Section 7.3;

(d) biometric or genetic identifiers;

(e) precise geolocation data about an individual;

(f) information about racial or ethnic origin, religious or philosophical beliefs, citizenship or immigration status, union membership, sexual orientation, or sex life;

(g) personal information of a known child under thirteen (13) years of age; or

(h) information subject to a sectoral regulatory regime that imposes requirements BerthRight has not agreed in writing to meet, including protected health information under HIPAA, information governed by the Gramm-Leach-Bliley Act, criminal history or background check information governed by the Fair Credit Reporting Act, or classified or export-controlled information.

7.2 Health information — why this matters here. BerthRight recognizes that marina staff have legitimate operational reasons to record accommodation needs — which slip is closest to the ramp, which finger pier has a wider walkway, who should not be assigned to a boat requiring a long walk. Do not record those needs as health information. Record the operational fact (“assign to A-dock, ramp access required”) and not the medical reason for it, and do not record diagnoses, conditions, medications, or treatments. Several states regulate consumer health data broadly, with obligations — and in at least one state a private right of action — that attach to a business that collects it, and a marina that fills its reservation notes with medical detail may take on those obligations without realizing it.

7.3 Payment card numbers — a specific and serious rule. Never type or paste a full payment card number into any field of the Services. This includes reservation notes, work order descriptions, customer comments, service instructions, message bodies, uploaded documents and images, and any other free-text or file field.

(a) BerthRight is architected so that full card numbers never enter its systems. Card details are captured exclusively in Stripe-hosted payment fields — Stripe Elements, the Payment Element, Stripe Checkout, or the Stripe virtual terminal — and BerthRight stores only a Stripe token, the card brand, the last four digits, and the expiration date.

(b) Typing a card number into a free-text field defeats that architecture. It places cardholder data into a database, a backup, a log, and potentially an email or text message that were never designed, scoped, or assessed to hold it. It expands the marina’s and BerthRight’s obligations under the Payment Card Industry Data Security Standard (PCI DSS), and it can convert a minor incident into a reportable cardholder data breach with card-brand fines and forensic obligations attached.

(c) If a boater gives a card number over the phone or on paper, enter it directly into the Stripe virtual terminal or the Stripe-hosted payment form and nowhere else, and destroy any written copy. Do not record it “just in case,” do not email it to the office, do not photograph it, and do not store it in a note for next season.

(d) BerthRight may scan for, redact, reject, or delete content that appears to contain a full payment card number, and may notify Customer when it does. BerthRight has no obligation to detect such content, and its failure to detect it does not excuse Customer’s violation of this Section.

7.4 Designated fields. Where the Services expressly provide a designated, labeled field for a specific data element, Customer may use that field for its stated purpose. The prohibitions in this Section 7 apply to all other fields.

7.5 Consequences. Submission of prohibited data is a violation of this AUP. BerthRight may, on notice to Customer, redact or delete prohibited data, and Customer remains responsible for the submission and for any resulting obligation, cost, or liability. See DPA §§ 3.6 and 3.7 and Annex I § 4.

8. Resource Use and Rate Limits

8.1 Reasonable use. Customer will use the Services in a manner consistent with normal marina operations and will not consume system resources in a way that degrades the Services for other customers.

8.2 Prohibited resource abuse. Customer will not:

(a) use automated means — bots, scripts, scrapers, or crawlers — to access, query, or extract data from the Services, other than through documented APIs or export features and within their published limits;

(b) use the Services as general-purpose file storage, backup, media hosting, or content distribution unrelated to marina operations, or upload files that are not reasonably related to the marina business;

(c) engage in cryptocurrency mining, distributed computing, or similar resource-intensive activity;

(d) circumvent, or attempt to circumvent, any storage, bandwidth, API, messaging, seat, slip-count, or other usage limit; or

(e) generate load through repeated automated requests, excessive polling, or runaway integrations.

8.3 Rate limits and fair use. BerthRight may establish and enforce rate limits and usage thresholds, including limits on API requests, export frequency and size, file upload size and total storage, messaging volume and send rate, and concurrent sessions. Current limits are available from BerthRight on request and may be adjusted on reasonable notice.

8.4 Enforcement of limits. Where Customer exceeds a limit, BerthRight may throttle, queue, or reject requests; require Customer to upgrade or purchase additional capacity; or act under Section 9. BerthRight will use reasonable efforts to notify Customer before throttling non-abusive traffic.

9. Reporting, Enforcement, and Suspension

9.1 Reporting a violation. Report suspected violations of this AUP to info@berthright.app, with as much detail as possible, including the marina involved, the conduct observed, the approximate date and time, and any message content or headers.

9.2 Investigation. BerthRight may investigate suspected violations and may access Customer’s account and data to the extent reasonably necessary to do so, subject to the confidentiality and data protection obligations in the applicable agreement and the DPA. Customer will cooperate reasonably with an investigation and will provide requested information, including consent records, promptly.

9.3 Notice and cure — the ordinary case. Where BerthRight determines that Customer has violated this AUP and the violation does not present an imminent risk under Section 9.4, BerthRight will:

(a) notify Customer in writing, describing the violation with reasonable specificity;

(b) allow Customer ten (10) business days to cure, or a shorter period proportionate to the seriousness of the violation, stated in the notice; and

(c) if Customer cures within that period, take no further action, except that repeated violations of the same kind may be treated as uncured.

9.4 Immediate suspension — imminent harm. BerthRight may suspend Customer’s access to the Services, or any portion of them, immediately and without prior notice where BerthRight reasonably determines that:

(a) the conduct presents an imminent risk of harm to BerthRight, to another customer, to an End User, or to a third party;

(b) the conduct presents an imminent risk to the security, integrity, or availability of the Services, including an account compromise;

(c) the conduct exposes BerthRight to imminent legal liability, regulatory action, or suspension or termination by an infrastructure provider, an email or SMS provider, or a mobile carrier;

(d) the conduct involves unlawful content or activity, including the content categories in Sections 3(e) and 3(f); or

(e) suspension is required by law or by a governmental or judicial order.

BerthRight will notify Customer of a suspension under this Section as promptly as reasonably practicable, will limit the suspension in scope and duration to what is reasonably necessary to address the risk, and will restore access promptly once the risk is resolved. Suspension does not relieve Customer of its obligation to pay fees, except as provided in the applicable agreement.

9.5 Campaign-level suspension — narrow remedies first. BerthRight may suspend, pause, throttle, or block a specific messaging campaign, message template, sending domain, sending number, contact list, or feature without suspending Customer’s entire account, and will prefer the narrowest effective remedy.

BerthRight recognizes that a marina depends on the Services to run its daily operations — to check boats in, assign slips, dispatch yard crews, and take payments — and that taking a marina’s whole system offline in the middle of a busy summer weekend because of a problem confined to one email blast would be disproportionate and harmful to boaters who have done nothing wrong. Accordingly, where a violation is confined to a particular campaign, list, template, or feature, BerthRight will ordinarily suspend only that campaign, list, template, or feature and leave the remainder of the Services running.

9.6 Other remedies. In addition to suspension, BerthRight may: remove or disable access to violating content; require Customer to remediate, including by re-verifying consent for a contact list or purging non-compliant records; require Customer to indemnify BerthRight in accordance with the applicable agreement; terminate the agreement for material breach in accordance with its terms; and report unlawful conduct to law enforcement or to affected third parties.

9.7 Escalation and reinstatement. Customer may contest a suspension or other action by writing to info@berthright.app. BerthRight will respond within two (2) business days and will reinstate access promptly if it determines the action was mistaken or the violation has been cured.

9.8 No obligation to monitor. BerthRight has no obligation to monitor Customer’s use of the Services or the content Customer submits, and does not review, approve, or endorse Customer’s content or communications. BerthRight’s failure to enforce this AUP in any instance is not a waiver of its right to enforce it in another.

9.9 Effect on other rights. BerthRight’s rights under this AUP are in addition to, and not in place of, its rights under the applicable agreement and at law.

10. Customer Acknowledgments

Customer acknowledges and agrees that:

(a) Customer, not BerthRight, is responsible for obtaining and documenting consent for every email and SMS message sent through the Services, and for determining which consent standard applies to each message;

(b) BerthRight supplies consent-capture, preference-management, and opt-out mechanisms as tools, and Customer’s use of those tools is not a determination by BerthRight that Customer’s practices comply with applicable law;

(c) Customer is the controller of End User personal information and BerthRight is its processor and service provider, as set forth in the DPA;

(d) Customer is the merchant of record for payments processed through its own Stripe account and is responsible for its own obligations to Stripe and under PCI DSS;

(e) messaging depends on shared infrastructure and on carrier and provider relationships that one customer’s misuse can jeopardize for all customers; and

(f) nothing in this AUP or in BerthRight’s provision of the Services constitutes legal advice, and Customer is responsible for obtaining its own advice on its compliance obligations.

11. General

11.1 Relationship to other documents. This AUP supplements the applicable agreement, the DPA, and the Documentation. In the event of a conflict, the order of precedence in the applicable agreement governs.

11.2 Updates. BerthRight may update this AUP as provided in Section 1.4. The current version is always available at https://berthright.app/aup. Continued use of the Services after an update takes effect constitutes acceptance of the updated AUP, subject to any objection right in the applicable agreement.

11.3 Governing law. This AUP is governed by the laws of the State of Florida, with exclusive venue in Palm Beach County, Florida, as provided in the applicable agreement.

11.4 Contact.

Berth Right MGMT LLC

Email: info@berthright.app

Phone: (609) 881-2656

Web: https://berthright.app

Related documents: Terms of Service · Privacy Policy · Data Processing Addendum · Subprocessors