Pricing/tax entries, order acceptance, SKU/catalog accuracy, merchant returns, discounts, customer credit records, receipts, auditability and local fiscal invoicing. Noxtill does not guarantee a credit account, collect a debt, create a banking relationship or warrant legal tax classification. Merchant owes customer-facing obligations and must configure taxes/returns.
Appointment availability, reminders, customer cancellation rules, address data, rider location consent, subcontractor status, service failures, warranty/returns, support tickets, queue fairness and customer-visible statuses. Arrival, dispatch and completion depend on authoritative signals.
Confidence and evidence, model hallucinations, import/review, role-gated action execution, external provider success, financial approval gates, human oversight, advertising disclosures, AI content labeling where applicable, model/provider change notification and operator training. Low confidence or missing source blocks consequential writes.
Artificial/prerecorded-voice consent, recording/transcription notices, suppression, permitted-hour checks, automated call transfer/barging authorization, number leasing, minute rounding disclosure, regional toll charges, emergency use restrictions and telecom service limitations.
Accounting controls, job segregation, record correction, supplier terms, payment tokenization, dispute management, employee data/lawful basis, tax advice disclaimer, eSign consent and audit trail, asset safety/maintenance obligations, payroll country availability and export/retention exceptions.
Credential custody, webhook signatures, secrets rotation, abuse prevention, retries/idempotency, human approvals, third-party store content, source mapping, robots/directives, DNS/domain owner obligations, intellectual property licenses, usage cap and external provider boundaries.
Functional scope: point-of-sale entry, payment method selection, receipts, customer links and voice-entry sales.
Primary public legal pages: Terms; Privacy; Refunds; Messaging & Consent; Security.
Legal position: The merchant is responsible for lawful goods/services, prices, taxes and customer disclosures. Voice-entry sale interpretation must be confirmed before a financial record is committed. Receipt delivery must follow messaging eligibility.
Mandatory product controls: Confirmation step for voice sale; receipt consent/channel eligibility; immutable transaction timestamps; role-limited void/refund actions; audit trail.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: quotes, orders, invoices, returns/refund decisions and receipts.
Primary public legal pages: Terms; Privacy; Refund & Cancellation; DPA.
Legal position: Orders is the canonical source for the commercial order, invoice and return decision. Payment execution belongs to Payments & Billing. Customer-facing documents must not misstate tax, refund or delivery rights.
Mandatory product controls: Versioned quotes/invoices; permissioned discount/return decisions; deep-link to payment transaction; export controls; customer identity consistency.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: product/service catalogue, variants, prices and supplier links.
Primary public legal pages: Terms; AUP; Website & Commerce merchant clauses.
Legal position: Customers are responsible for product legality, safety, descriptions, pricing and IP rights. Restricted/regulated products may be blocked under AUP/provider rules.
Mandatory product controls: Required price/currency; product content ownership attestation; prohibited-product screening where appropriate; change history.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: appointments, queue, deposits, reminders, rescheduling, no-shows and availability.
Primary public legal pages: Terms; Privacy; Messaging & Consent; DPA.
Legal position: The business sets availability, cancellation/no-show rules and service obligations. Noxtill must not promise appointment availability until canonical booking state confirms it.
Mandatory product controls: Consent-aware reminders; timezone handling; cancellation-policy acknowledgement; provider-confirmed payment/deposit state; staff privacy.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: customer balances, statements, credit ledger and reminders.
Primary public legal pages: Terms; Privacy; Messaging & Consent; Security.
Legal position: Noxtill provides recordkeeping and reminders; it does not become a lender or debt collector solely through this module. Businesses are responsible for lending/credit laws, interest/fees and collection practices.
Mandatory product controls: Immutable ledger entries/corrections; balance visibility permissions; consent-aware reminders; no coercive templates; payment links deep-link to provider.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: customer identity, segments, loyalty, notes, pipeline and consent evidence.
Primary public legal pages: Privacy; DPA; Messaging & Consent; Security.
Legal position: CRM is canonical customer identity. Customer import does not imply marketing consent. Sensitive notes must be permissioned and relevant. Privacy-right requests must resolve against canonical identity.
Mandatory product controls: Consent records; deduplication; data-subject request linking; field-level permissions; import provenance; suppression state.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: review requests, monitoring, replies, complaint/reputation workflows.
Primary public legal pages: AUP; Terms; Privacy; AI Transparency.
Legal position: No fake reviews, sentiment-conditioned incentives, undisclosed insider endorsements, deceptive suppression or intimidation. AI replies remain drafts unless approved/configured within safe rules.
Mandatory product controls: Neutral request templates; incentive disclosure controls; complaint escalation; source platform links; review deletion/suppression audit.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: campaign audiences, email/WhatsApp/SMS campaigns, templates and performance.
Primary public legal pages: Messaging & Consent; Privacy; Cookie Policy; AUP.
Legal position: Campaign eligibility must be evaluated at send time. Opt-out/suppression overrides automation. Claims must be truthful and substantiated.
Mandatory product controls: Purpose-specific consent filter; suppression check; sender identity; quiet hours/rate limits; campaign approval; evidence of claim/source.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: profit, cash flow, operational analytics and management reporting.
Primary public legal pages: Terms; Privacy; AI Transparency.
Legal position: Analytics are decision-support, not professional accounting/tax advice. Estimated/partial data must be labeled and not presented as audited financial statements.
Mandatory product controls: Metric definitions; source/freshness; FX basis; role-based profit visibility; export watermark where appropriate.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: team identity, attendance, shifts, timesheets, commissions, advances, roles and activity.
Primary public legal pages: Privacy; DPA; Security; Terms.
Legal position: The customer is employer/controller and must comply with labor/privacy rules. Employee monitoring and attendance data must be proportionate and disclosed where required.
Mandatory product controls: Least-privilege roles; employee self-access where configured; change/audit history; retention policy; manager scope.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: multi-location structure, branch settings and scoped records.
Primary public legal pages: Privacy; Security; Terms.
Legal position: Branch scoping must never weaken tenant isolation. Cross-branch visibility is permission-based.
Mandatory product controls: Tenant+branch authorization tests; branch transfer audit; location-specific legal settings; scoped exports.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: stock, movements, receiving, counts, reordering and purchasing references.
Primary public legal pages: Terms; AI Transparency; Security.
Legal position: Inventory is canonical stock truth. AI may recommend but cannot invent availability or silently adjust stock without permitted action.
Mandatory product controls: Append-only stock movements; correction reasons; approval for high-impact adjustments; provider/PO reconciliation.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: business questions, summaries, drafts, suggestions and tool-assisted actions.
Primary public legal pages: AI Transparency; Privacy; AUP; Security.
Legal position: AI output is not guaranteed accurate and cannot override permissions or canonical records. Context must be minimum necessary.
Mandatory product controls: Feature disclosure; evidence/source refs; tool permission allow-list; approval for consequential writes; incident/report button.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: scheduled/ad-hoc reports, PDF/CSV/XLSX exports and sharing.
Primary public legal pages: Privacy; Security; Terms.
Legal position: Reports may contain sensitive business, customer or workforce information. Export and sharing must respect role/field permissions.
Mandatory product controls: Export audit; sensitivity label; password-protected delivery where supported; recipient verification for scheduled reports.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: business profile, terminology, taxes/currency, notifications, privacy/security, developer settings.
Primary public legal pages: Terms; Privacy; Security; DPA.
Legal position: Settings can materially change legal behavior and must be permissioned. Security/privacy changes should be auditable and high-risk changes may require re-authentication.
Mandatory product controls: Owner/admin-only controls; before/after audit; re-auth for security changes; safe defaults; policy version links.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: ad accounts, campaigns, audiences, budgets and performance.
Primary public legal pages: AUP; Privacy; Cookie Policy; Terms.
Legal position: Noxtill does not guarantee ROAS/leads. Businesses must comply with platform ad policies, consumer-protection law, targeting restrictions and consent/opt-out requirements.
Mandatory product controls: Budget/spend limits; approval; audience provenance; consent signals; provider-confirmed publish state; claim substantiation notes.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: directory profiles, business facts and listing synchronization.
Primary public legal pages: Terms; Privacy; AUP.
Legal position: The business is responsible for accuracy of public facts and rights to content. Provider rules control publication.
Mandatory product controls: Source-of-truth fields; publish preview; provider status; change history; removal/claim workflow.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: public/authorized competitor observations and AI summaries.
Primary public legal pages: AUP; AI Transparency; Privacy.
Legal position: No unauthorized access, circumvention, confidential-data acquisition or prohibited scraping. Inferences must be labeled and supported by lawful sources.
Mandatory product controls: Source URL/date; robots/API compliance checks where applicable; inference confidence; no personal sensitive inference.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: AI call answering, transcription, booking, FAQs, lead capture and handoff.
Primary public legal pages: AI Transparency; Messaging & Consent; Privacy; Security.
Legal position: Disclose AI where required; recording/transcription consent must be jurisdiction-aware. AI cannot misrepresent prices/availability and must escalate outside authority.
Mandatory product controls: Opening disclosure; recording policy; consent event; safe knowledge base; human handoff; call retention setting; restricted tool actions.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: photo/image extraction into structured business data.
Primary public legal pages: AI Transparency; Privacy; DPA.
Legal position: OCR/vision output can be wrong and requires review before canonical import. Users must have rights to images/data.
Mandatory product controls: Preview+confirm; confidence flags; original-image retention controls; sensitive-data warning; audit of accepted corrections.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: dispatch, rider assignment, GPS/location and proof of delivery.
Primary public legal pages: Privacy; DPA; Security; Terms.
Legal position: Location tracking must be necessary, disclosed and scoped to work purposes. Customer/rider evidence must be protected.
Mandatory product controls: Tracking on/off state; retention; staff notice; proof access controls; route sharing minimization; incident safety controls.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: OAuth, API keys, webhooks, provider connections and sync health.
Primary public legal pages: Terms; Privacy; Security; Subprocessors.
Legal position: Third-party providers have their own terms/roles. Credentials must be securely stored and never exposed to browser/logs/AI prompts.
Mandatory product controls: Scope display; reauth/revoke; secret vault; webhook signing; provider role disclosure; data-flow preview.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: WhatsApp, email, SMS, social and chat conversations with customer context.
Primary public legal pages: Messaging & Consent; Privacy; DPA; AI Transparency.
Legal position: Unified Inbox is canonical conversation surface. Staff see only authorized conversations. AI drafts never auto-send by default. Provider reply-window rules must be evaluated before composer/send.
Mandatory product controls: Assignment RBAC; customer sensitive fields hidden for staff; provider window gate; suppression check; AI draft evidence; delivery status.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: projects, tasks, milestones, calendars and time tracking.
Primary public legal pages: Terms; Privacy; DPA; Security.
Legal position: Projects may contain customer/confidential information. Access should be project/team scoped and exports permissioned.
Mandatory product controls: Project membership ACL; task audit; time-entry corrections; file links to Documents; retention/archive.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: triggers, actions, approvals, AI agents, webhooks, queues and execution history.
Primary public legal pages: Terms; AUP; AI Transparency; Security; Privacy.
Legal position: Automation is orchestration, not a shadow database. External and money-moving actions remain pending until verified. AI agents operate within explicit tools/budgets/approvals.
Mandatory product controls: Versioned workflow; test/staging/production separation; idempotency; approval records; DLQ; execution logs; secret references only.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: business brain, simulations, opportunities, diagnoses and digital twin views.
Primary public legal pages: AI Transparency; Privacy; Terms.
Legal position: Simulation/prediction is not guaranteed. Evidence, assumptions and source freshness must be visible.
Mandatory product controls: Scenario labeling; confidence/assumptions; no protected-trait inference; deep links to canonical facts; user acknowledgement for consequential use.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: site audits, keywords, rank tracking, content optimization and SEO actions.
Primary public legal pages: AUP; AI Transparency; Terms.
Legal position: No ranking guarantee. No cloaking, deceptive structured data, spam or rights-infringing content. Customer approves material publishing actions.
Mandatory product controls: Source/search-console connection; content review; technical change preview; rollback; platform-policy checks.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: product radar, sourcing, listings, fulfillment, optimization, experiments and B2B/subscriptions.
Primary public legal pages: Terms; AUP; AI Transparency; Privacy; Security.
Legal position: AI recommendations are not supplier/product legality guarantees. High-impact listing, spend, fulfillment and vendor award actions require policy/approval.
Mandatory product controls: Provider confirmation; supplier evidence; margin assumptions; experiment guardrails; approval thresholds; marketplace policy status.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: chart of accounts, ledger, journals, AR/AP, bank feeds, reconciliation, tax and statements.
Primary public legal pages: Terms; Privacy; Security; DPA.
Legal position: Noxtill is software, not accountant/tax adviser. Customer owns classifications/filings. Financial records need strong permissions and immutable audit.
Mandatory product controls: Restricted roles; journal approvals; reconciliation evidence; bank token security; period close locks; export audit.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: service requests, work orders, dispatch, technician location, parts/labor and service agreements.
Primary public legal pages: Privacy; DPA; Security; Terms.
Legal position: Customer/technician location and on-site evidence are personal/business data. Signatures/photos prove workflow events but not payment unless provider confirms.
Mandatory product controls: Technician scope; location retention; customer signature consent; parts post only on confirmed use; status timeline.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: tickets, SLA, assignments, knowledge, RMA/warranty support and analytics.
Primary public legal pages: Privacy; DPA; Messaging & Consent; Terms.
Legal position: Tickets are not message threads; messages link to Unified Inbox. Sensitive customer context must be permissioned.
Mandatory product controls: SLA audit; ticket merge preservation; resolution category; channel consent for outbound replies; knowledge publishing review.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: customer account, orders, bookings, payments, returns, support and loyalty self-service.
Primary public legal pages: Privacy; Terms; Security; DPA.
Legal position: Strong authentication and tenant/customer isolation. Merchant-specific consumer policies must be shown where relevant; Noxtill policies do not replace merchant terms.
Mandatory product controls: Account verification; privacy controls; session security; lawful invoice/payment display; request history; consent preferences.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: document library, contracts, approvals, signature requests, renewals and compliance files.
Primary public legal pages: Terms; Privacy; Security; DPA.
Legal position: Electronic signature enforceability varies by document/jurisdiction. Signed versions/evidence should be immutable; legal holds may override deletion.
Mandatory product controls: Signature consent; version hash; signer authentication; audit certificate; retention/legal hold; restricted template access.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: asset register, service history, maintenance requests/work orders and inspections.
Primary public legal pages: Terms; Privacy; DPA.
Legal position: Asset records may include employee/customer location or assignment. Maintenance history should remain auditable after retirement.
Mandatory product controls: Asset access scope; meter readings append-only; disposal/retirement preserves history; work-order links.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: transactions, payment links, failed payment recovery, refunds, disputes, settlements, recurring collections and routing.
Primary public legal pages: Terms; Refund & Cancellation; Privacy; Security.
Legal position: Provider/Merchant-of-Record rules govern money movement. Noxtill must not claim success before provider confirmation. Refund execution follows canonical return decision and mandatory rights.
Mandatory product controls: Provider state; idempotency; dispute evidence; payout/reconciliation roles; refund reason/approval; test/live separation.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: purchase requests, RFQs, supplier contracts, 3-way match, spend control and analytics.
Primary public legal pages: Terms; AUP; Privacy; AI Transparency.
Legal position: Supplier recommendations are not legal/commercial guarantees. Procurement approvals/spend thresholds must be enforced.
Mandatory product controls: RFQ audit; supplier evidence; approval routing; 3-way match exception; contract link; no duplicate PO/vendor bill.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: recruitment, applicants, interviews, offers, onboarding, leave, payroll, performance, training and offboarding.
Primary public legal pages: Privacy; DPA; Security; Terms; AI Transparency.
Legal position: High sensitivity. Customer remains employer. AI must not make unsupported protected-trait or suitability inferences. Payroll outputs require review/approval and provider confirmation.
Mandatory product controls: Restricted HR fields; applicant retention; consent/notices; payroll approval; payslip access; leave privacy; offboarding access revocation.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.
Functional scope: site/pages, blog, forms, storefront, checkout experience, branding, domains and publishing.
Primary public legal pages: Terms; Privacy; Cookie Policy; AUP; Messaging & Consent.
Legal position: Customer is publisher/merchant. It is responsible for own consumer/store policies, products, claims, cookies, accessibility and lawful form/marketing consent.
Mandatory product controls: Form consent mapping; cookie controls; publish history/rollback; checkout revalidation; deep links to canonical Products/Orders/Payments/SEO.
Required UI disclosures and backlinks
- Link to the relevant public policy from the action that creates the legal risk, not only from the global footer.
- Show the acting business/branch, relevant provider or source-of-truth record, and a clear status before a consequential action is confirmed.
- Where a consent, permission, approval, signature, payment, message or provider result is required, the server must validate it at execution time. Client-side visibility alone is not sufficient.
- High-impact actions must create an audit event containing actor, role, entity, timestamp, reason/approval reference, correlation ID and external provider result where applicable.
- Data exports and bulk actions must enforce the same field-level permissions as the interactive UI and must not silently widen access.

Functional scope: social publishing, scheduling, comments/engagement and connected accounts.
Primary public legal pages: AUP; Privacy; Messaging & Consent; Terms.
Legal position: Businesses are responsible for platform terms, rights in content, advertising/endorsement disclosures and account authorization.
Mandatory product controls: OAuth scope display; content approval; material-connection disclosure prompts; removal/revocation handling.
Required UI disclosures and backlinks