Payment first · mandatory SMS identification · protected uploads

Business Truth Audit™ Payment, Authority and Security Terms

These terms apply to the Stripe purchase, mandatory mobile identification, paid business intake, uploaded data, report preparation and use of the completed DCME Business Truth Audit™.

Legal review noticeThis is operational protection wording and should be reviewed by a qualified Australian legal adviser before final public launch.

1. Payment-first order

The A$22.00 Stripe payment is completed before business details or files are accepted. Only a signed Stripe webhook can mark the order paid and unlock the intake. A browser return page does not approve payment.

2. Payment is a legitimacy signal, not proof of authority

Successful payment supports the legitimacy of the request but does not itself prove ownership of, employment by or authority from the named business. The person submitting must be the owner/director, an authorised manager or an adviser with documented authority. Mandatory SMS confirmation is an additional security control, not a substitute for authority.

Stripe payer emailThe business submission email must match the email supplied during Stripe Checkout.
Authority declarationThe submitter confirms authority to order the report and act for the named business.
Data ownership declarationThe submitter confirms ownership or express authority to provide every uploaded file.
Manual reviewDCME may request evidence, pause, refuse or refund a request where authority or intent is unclear.

3. Mandatory SMS mobile identification

After Stripe payment, the submitter must confirm an Australian mobile using a 6-digit SMS code before report scope, uploads or final submission can proceed. The code expires after 10 minutes and the complete identification window closes after 15 minutes from the first successful send.

Automatic security restrictionFive incorrect codes, excessive provider-accepted sends, or no successful response after 5c SMS confirms delivery stops the process. The paid reference, Stripe payer email and mobile are then placed on the automatic security blacklist pending manual review. Provider rejection, delivery failure or unconfirmed delivery stops the automatic process without blacklisting the customer. IP address alone is not used as a permanent blacklist key because shared networks can affect unrelated businesses.

No uploads can be submitted after a security restriction. A new automatic attempt is not available. A person who believes the restriction is incorrect may email blacklist@dcme.com.au with the Business Truth reference and an explanation. DCME may approve one controlled reattempt after manual review. A security restriction does not by itself determine any refund entitlement; payment and refund questions remain subject to review and applicable Australian law.

4. ABN and website are optional supporting information

An ABN and public website may be provided when available, but they are not mandatory automated gates. A supplied ABN must pass the normal 11-digit checksum, and a supplied website must be a valid public URL. DCME may manually review or verify either before releasing the completed report.

5. Named-business internal-use licence

The report and derived material are licensed only to the named business for its own internal review and improvement. The report must not be sold, sublicensed, published as a competing product or used to reproduce DCME methods.

6. Not available for competitors, developers or probing

This service is not available to competing POS vendors, SaaS operators, software developers, data brokers, consultants acting for competing software, unauthorised analysts, scrapers, security testers without written authority or anyone seeking to copy, benchmark, probe, map, reverse engineer or imitate DCME Industry Core Intelligence™, its report design, calculations, mapping, scoring or workflows.

7. Authority and data ownership

The submitter confirms that the uploaded data relates to the named business; they control the data or have express authority to provide it; and the upload does not breach privacy, confidentiality, employment, payment-card, licensing or contractual obligations.

8. Prohibited uploads

Do not upload passwords, API keys, private encryption keys, payment-card numbers, government identity documents, unrelated health or identity information, malware, executable code, active scripts, macro-enabled spreadsheets, nested archives, stolen data or files belonging to another business.

Upload protectionFile extensions are not trusted by themselves. DCME checks file type, archive structure and active content, requires malware scanning and stores accepted files outside the public website. No internet-facing system can be represented as immune from every possible attack.

9. Security and audit records

DCME may retain timestamps, hashed IP signals, keyed mobile and payer-email identifiers, payment references, SMS challenge outcomes, blacklist or manual-release records, authority declarations, file names, file hashes, scan outcomes and rejection reasons for security, integrity and service administration. Raw SMS codes are not retained.

10. Report limits and owner inputs

The A$20.00 + GST audit reports only what the supplied data can prove. Missing or incomplete dockets, items, payments, prices, customers, accounts, costs or operating inputs are identified as requirements rather than replaced with invented answers.

11. Business guidance, not professional advice

The report is business intelligence and operational guidance only. It is not accounting, taxation, legal, employment, insurance, cybersecurity, investment or financial advice. The owner remains responsible for checking inputs and decisions with qualified advisers.

12. Refusal, suspension and refund

DCME may refuse, pause, request further evidence or refund the A$22.00 payment where the request appears unauthorised, competitive, unsafe, outside scope, based on data the submitter does not control or likely to create security, privacy or legal risk.

13. Data use and retention

Uploaded files are used to prepare the requested report, communicate with the paid contact and investigate security or integrity concerns. Raw files are retained only for the configured review and report workflow, with analysis snapshots retained where required for the delivered report.

14. Intellectual property

DCME retains all rights in DCME Industry Core Intelligence™, Business Truth Audit™, calculation models, report structure, interface, scoring, mapping, workflows, documentation and derived methods.

15. Governing law

The purchase, submission, licence and report use are governed by the laws of New South Wales and applicable laws of Australia, unless DCME agrees otherwise in writing.