A lot of this discussion seems to boil down to several key issues:
1. Should you ever refuse service to someone because you disapprove of their lawful activities?
2. If so, where do you draw the line?
3. If so, how do you deal with the fact that you can only enforce the policy when a customer's activities are specifically brought to your attention?
To answer #1, I'd make an analogy to the social responsibility rules some companies voluntarily impose on themselves. (Some companies say they will only buy from vendors who meet certain fair labor standards. Others say they will only buy from environmentally friendly vendors. Et cetera.)
Refusing service based on an ethical principle is very similar to these types of policies, except you're declining to sell something instead of buy. Companies that follow these rules are generally lauded for it. Likewise, companies that are perceived as not doing so are criticized. (Think of Apple's relationship with Foxconn.)
So I think it's pretty safe from a P.R. standpoint to refuse service based on ethical principles. You might have to ditch a handful of paying customers, but if your business model is about volume, it's probably not going to matter.
As for the ethical imlications of refusing service, I say that nobody is entitled to use your service any more than you're entitled to customers. So I don't see a problem there.
Question #2 is harder. Where do you draw the line? I'd say that's up to each company to decide, but here are some reasonable examples of things you might forbid:
- Patent trolls
- Hate groups
- Technically lawful but sleezy stuff, e.g. certain infoproducts
The exact list a company chooses would of course depend on the subjective ethical beliefs of its leadership. Which is fine--it's their company. In any case, it's very important to clearly state these rules in the TOS. You really don't want to be seen as capricious, and it's not fair to your customers, even the evil ones.
Question #3 is probably the hardest. As the OP pointed out, you can't just dig through your customers' data, looking for possible violations. So you'd have to wait until something was brought to your attention. And then, as the OP said, you'd have de facto tolerance for offenders who don't speak up. Which seems kind of unfair.
But here, I'd make an analogy to the TOS rules concerning criminal activity. There must be tons of people using legitimate web services for crime. Occassionally, some of these are discovered, and their accounts are terminated. The rest get away with it.
I doubt anyone would say you should ignore reports of criminal activity just because some other crime goes unreported. So I think the same applies to these ethical restrictions.