← Governance framework
Financial & Anti-Fraud

Fraud, Abuse and Misuse Policy

Prohibited behaviours, detection controls and response actions for fraudulent, abusive or manipulative use of the platform.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
Head of Trust & Safety
Approver
Executive Team
Anchored by content hashissued 2026-07-29
Payload hash
911501e1c9e069cf8b8bbd58c6a0d791c52a56bb77dd7b5e82b29277b0c7401b
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:911501e1c9e069cf

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • All users and organisations

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • Velocity and anomaly checks on participation and donation flows
  • Duplicate-evidence detection on activity uploads
  • Reach-reward discounting for non-genuine traffic

1. Prohibited

  • Manufactured or duplicated evidence of impact.
  • Collusion to inflate IMI or leaderboard standing.
  • Bot-driven amplification of verified shares.
  • Misrepresentation of charitable status or use of funds.

2. Response

  • Warning, suspension, credential revocation or account termination depending on severity.
  • Financial recovery pursued where feasible.
  • Regulator or law-enforcement referral where required.
Questions or concerns about this policy? Contact the DPO.

Related policies