Last updated Last updated: 8 August 2026

Acceptable Use Policy

1. Zero tolerance

The conduct below ends the account the moment it is confirmed: service terminated, no balance refunded, evidence preserved and handed to the authorities as the Cybersecurity Law and the Anti-Telecom and Online Fraud Law of the PRC require. There is no warning period and no reinstatement on appeal.

• Denial of service: launching, joining or assisting any form of DoS or DDoS attack, including traffic floods, reflection and amplification, slow-connection exhaustion, and high-concurrency hammering of assets you do not own under the label of load testing.

• Financial fraud: carding and bulk card testing, use of stolen payment credentials, fabricated transactions, cash-out schemes, money laundering, and supplying tools, accounts or channels that enable any of these.

• Child sexual abuse material: accessing, storing, producing, distributing or trading content that sexually exploits minors, in any form. This is terminated immediately and reported to the authorities without exception.

• Phishing and stolen credentials: hosting spoofed sign-in pages or phishing sites, sending phishing email or SMS, credential stuffing and brute-force attacks, trading in or using other people's account credentials, and hijacking their sessions.

2. Network abuse

The following degrades target networks, other customers, or the residential pool itself. Depending on severity the Company will rate-limit, suspend or terminate. In most cases you are told first and asked to stop, but accounts that cause actual damage or ignore the notice are terminated outright.

• Port and vulnerability scanning: probing ports, fingerprinting services, running vulnerability scans or penetration tests against assets you do not own. Security testing of your own assets requires advance notice to the Company, proof that the assets are yours and written authorisation.

• Spam: sending bulk email, SMS, direct messages or platform messages to recipients who did not consent; evading unsubscribe mechanisms, rate limits or anti-spam filters; and forging sender details or mail headers.

• Bulk fake accounts: mass-registering accounts on third-party platforms by automation, or using them for engagement farming, fake orders, fake reviews, vote manipulation or artificial traffic. This also breaches almost every target platform's own terms, and whatever they do to those accounts is your problem, not ours.

• Malware and command-and-control: distributing viruses, trojans, ransomware or cryptominers, or using the Service as a botnet command-and-control channel, a payload distribution node or a relay hop for attack traffic.

3. Scraping ethics

Most customers use these proxies to collect public data, which is legitimate work. But the capability has limits. The following applies to every collection job run through the Service; breaching it is dealt with according to severity and may at the same time breach the Data Security Law and the Personal Information Protection Law of the PRC.

• No government or critical infrastructure: automated collection or scanning against government, military, judicial, public-health and financial-regulator sites is prohibited, as is any system falling within the PRC Regulations on the Security Protection of Critical Information Infrastructure.

• No sensitive personal data: do not harvest identity document numbers, biometrics, medical and health records, financial accounts, location trails, communications content, or any personal information about children under 14. Where public data contains personal information at all, you need a lawful basis for collecting it and must keep to what is genuinely necessary.

• Respect rate limits and robots directives: follow the target's robots rules, API terms and published rate limits; keep concurrency and request frequency at a level that does not slow the target down or take it offline. Requests should be identifiable and contactable, and must not impersonate a search-engine crawler.

• Public data only: do not defeat login walls, paywalls or access controls, do not scrape from behind someone else's credentials, and do not break encryption or circumvent technical protection measures. How the collected data is stored, used and redistributed afterwards is your responsibility.

4. Enforcement and reporting

Enforcement is graded. A first, lower-severity breach draws a warning and a deadline to fix it, during which the sub-account may be rate-limited or restricted to certain exit regions. Inadequate remediation or repetition suspends the account. Anything in section 1, anything that causes real damage, and anything a competent authority finds unlawful ends the account immediately with no refund of the balance, and the Company reserves the right to recover its own losses.

Investigation: session metadata logs are retained for abuse investigation. During an investigation the Company may ask you to explain the use case, produce authorisation for the assets you are testing, or change your collection settings. Where an authority makes a lawful request through proper procedure, the Company checks its legal basis and standing and then cooperates within the scope the law defines.

Reporting abuse: if you believe traffic from a ZapIP address is abusing your systems, write to the contact email published on our site with Abuse in the subject line. To let us find it, include the affected domain or IP, the time and time zone, the source exit IP, a log excerpt or sample requests, and what you would like done about it.

Response time: valid reports get a reply and an investigation within 24 hours, confirmed abuse is acted on immediately, and the outcome is communicated back to the reporter so far as the law allows. Malicious reports, fabricated evidence and reports used as a competitive tactic are grounds for legal action.

Legal entity
Hangzhou ZapIP Network Technology Co., Ltd.
Address
Bldg 1, Changdi Torch Mansion, 259 Wensan Rd, Xihu District, Hangzhou, Zhejiang, China
Governing law
Laws of the People's Republic of China