Limits & Enforcement Policy
Last updated: 2026-09-06 Version: 1.1
This page documents the rate limits, abuse thresholds, enforcement actions, and appeals process that operationalise the Terms of Service and the Acceptable Use Policy. It is the operational reference for what happens when a user (intentionally or accidentally) breaches the rules.
1. Rate limits — anonymous users
| Endpoint | Window | Limit | On breach |
|---|---|---|---|
/best-quote | 1 minute / IP | 30 requests | 429 with Retry-After: 60 |
/api/search (free Reports) | 1 minute / IP | 10 requests | 429 |
| Static pages (HTML, JS, CSS) | Cloudflare default | High; bot management applies | Challenge or block |
| AI Concierge messages | 1 hour / IP | 20 | 429 + in-UI throttle message |
agent.swaps.app/llm/* | 1 minute / IP | 60 | 429 |
agent.swaps.app/openapi | 1 minute / IP | 600 | Soft throttle |
These limits are dynamic — we may tighten them in response to abuse without notice. We log breaches and use them as an abuse signal.
2. Rate limits — authenticated users
Authenticated users get higher limits and per-Account quotas:
| Resource | Quota | Reset / refresh |
|---|---|---|
| Free Search Reports | 3 lifetime per Account | One-time |
| Credit-pack reports | 5 / 10 / 20 per pack | Consumed at use |
| AI Concierge messages | 100 / day / Account | 24 hours |
/best-quote (signed-in) | 60 / minute / Account | Rolling window |
| Friend Rate referrals — rewarded events | No hard cap, but anti-fraud applies | Continuous |
2a. Product-specific limits and access gates
These limits operationalise the Payment Link Terms and the Payroll Terms.
| Product | Limit / gate | Set by |
|---|---|---|
| Payment Links | Individual Payer cap: up to USD $4,000 equivalent per payment, and lower on some rails — see §2b. Merchant activation requires a Provider-verified (Bridge KYB) business in approved status. Available rails and any further limits are Provider-determined and may change without notice. | Swaps (cap) + Provider (rails/further limits) |
| Payroll | Access gate: Provider-verified individual or business customer (Bridge KYC/KYB) in good standing; private beta, access-gated. Rails, supported currencies, and networks are Provider-determined. | Provider |
Where the Provider determines a rail, currency, limit, or eligibility condition, Swaps does not warrant its continued availability and it may change at any time without notice.
2b. Individual and person-to-person payment thresholds
The Provider (Bridge) applies its own thresholds to person-to-person third-party payments — a payment sent by one individual to another individual — and states them as: USD wire and ACH, USD $4,000.00; Mexican SPEI, MXN $15,000; EUR SEPA, GBP and SWIFT, varies by developer. The Provider may lower any of these at any time, and states that person-to-person payments above them are outside its risk tolerance. The Provider does not publish fixed thresholds for first-party ("me to me"), business-to-business, or business-to-consumer (for example, payroll) payments, but applies heightened scrutiny to them and reserves the right to reverse any payment it considers unsubstantiated or high-risk. Source: Provider fraud policy, 2026-03-31.
Where a payer pays as an individual, the amount Swaps will accept is therefore at most the USD $4,000 equivalent, and in several cases less:
| Case | Cap applied |
|---|---|
| Payer is a registered business | No Swaps cap |
| Individual payer, business Merchant | USD $4,000 equivalent per payment |
| Individual payer, individual Merchant — USD rails (ACH, wire, FedNow) | USD $4,000 where the Merchant's US residency is confirmed; otherwise USD $2,000, which includes every case where residency is unconfirmed |
| Individual payer, individual Merchant — SEPA | USD $4,000 equivalent per payment |
| Individual payer, individual Merchant — Mexican SPEI | MXN 15,000 per payment, in Mexican pesos |
| Individual payer, individual Merchant — Pix and UK Faster Payments | Not available |
These are ceilings, not entitlements: the Provider may decline, hold, or reverse a payment below any of them, and Swaps may apply a lower limit without notice. Amounts in a currency other than the one named are converted at the rate available to Swaps at the time of the check; where no rate is available the payment is declined rather than allowed through.
3. Abuse thresholds and detection
We treat the following as abuse signals (non-exhaustive):
- More than 3 Accounts created from the same browser fingerprint within 24 hours.
- More than 5 referral events from the same fingerprint or IP cluster within 7 days.
- More than 50 unique address scans per hour from one Account, IP, or fingerprint.
- Repeated 429 breaches (more than 100 in one hour from the same IP).
- KYC denials at the Provider followed by re-attempts from the same Swaps Account with different identity info.
- Attempts to bypass geo-block detected by VPN signatures, proxy fingerprints, or impossible geolocation jumps.
- Sanctions-list match (immediate hard action — see the Sanctions policy).
Detection runs continuously. Thresholds are tuned based on observed traffic; specific numbers may be adjusted in the codebase from time to time without changing this document materially.
4. Enforcement actions — escalation ladder
| Step | Action | Notice to user | Reversible |
|---|---|---|---|
| 1 — Throttle | HTTP 429 with Retry-After | Header + UI message | Yes — wait for window |
| 2 — Soft block | IP-level Cloudflare challenge | Cloudflare interstitial | Yes — pass challenge or change network |
| 3 — Account warning | In-product banner explaining the breach | Banner + email | Yes — change behaviour |
| 4 — Account restriction | Disable specific features (e.g., referral rewards, Search) | Yes — appeal | |
| 5 — Account suspension | Login disabled pending review | Yes — appeal | |
| 6 — Account termination | Login disabled permanently, data retained for legal-retention windows | Email + final notice | No — but data subject rights still apply |
| 7 — IP block | Network-level block | None to user | Yes — appeal via different IP |
| 8 — Cooperation with authorities | Data disclosed under lawful request | Where law permits notice | n/a |
We skip steps for major or critical breaches (sanctions match, child sexual exploitation content, attack on the Service): we move directly to step 5 or 6.
5. Provider-side enforcement
We do not control Provider enforcement. If a Provider KYC-denies you, freezes your transaction, or blocks your account, that is the Provider's decision under its own rules. Your appeal goes to the Provider, not to Swaps. We can help you locate the right Provider contact — see Limits & Enforcement §8 below — but we cannot reverse a Provider's compliance decision.
For Payment Links and Payroll, refunds, disputes, chargebacks, recalls, and failed, returned, or reversed payments are likewise routed to the Provider (Bridge) and resolved under the Provider's terms. Swaps never received or held the funds and cannot reverse, recall, or refund a Payment Links payment or a payroll payout. Swaps assists by sharing the information it holds (such as the request, reference code, transaction status, and timestamps) so you can reach the Provider, under the §8 mechanism below.
Requests for information, and the deadline attached to them. The Provider may hold a payment it considers risky and ask for supporting information — the relationship with the sender, the purpose of the payment, the source of funds, or documentation such as signed and dated contracts, invoices, or bank statements. The Provider states that it decides on a flagged payment within 2 business hours during its business hours (EU Monday–Friday 08:00–17:00 CET; US Monday–Friday 09:00–19:00 EST, excluding US bank holidays), and outside those hours by the next business day. Where it opens a request for information, it states that it waits 2 business days for the reply, and after that reverses the payment back to the sender and pauses the customer until the request is completed. It further states that it does not hold funds for more than two business days unless legally required to do so.
Where we are notified of such a request, we relay it to you and pass on your reply, but this step is not automated in every case, may require manual action on our side, and is not guaranteed to complete before the Provider's deadline; we cannot extend the Provider's deadline, and we cannot prevent or undo a reversal made under it. A payment reversed this way is returned to the sender; it is not a refund by Swaps, and §6 does not apply to it. Providing the requested information quickly and completely is the only thing that stops the clock. Source: Provider fraud policy, 2026-03-31.
Fraud claims raised by a sending bank. Where the Provider receives a fraud claim from the bank that sent a payment, it pauses the affected customer immediately and notifies us. The Provider states that such a customer can be re-enabled only after the sender withdraws the claim, and that the Provider does not broker that withdrawal — it is a matter between you, the sender, and the sender's bank. Swaps cannot lift a Provider-side pause and does not adjudicate the underlying claim. Closing your Swaps Account does not withdraw or extinguish such a claim.
6. Refund policy
| Situation | Refund |
|---|---|
| You initiated a transaction, the Provider executed it: outcome was not what you wanted | Not refundable by Swaps — we did not receive payment. Contact Provider. |
| You initiated a transaction, the Provider failed to execute (timeout, outage), and the Provider already received payment | Not refundable by Swaps. Contact Provider. |
| You bought a Credit pack and used all Credits: results were unsatisfactory | Not refundable. Credits are non-cash; use of a Credit is final. |
| You bought a Credit pack but Reports returned empty data (zero signals, zero context) | One-time Credit re-credit per pack, within 24 hours, on request to legal@swaps.app. See the Search Address Report Terms. |
| Your Account was terminated for a minor or moderate AUP breach | Residual unused Credit balance refunded on request. |
| Your Account was terminated for a major or critical AUP breach | No refund. |
| You stop using the Service voluntarily with unused Credits | Credits remain in your Account; no cash refund. |
Refunds, where due, are processed within 14 calendar days via the same payment method used to purchase. Bank or payment-processor processing time is additional.
7. Appeals process
If you believe an enforcement action against you is incorrect:
- Email legal@swaps.app with the subject line "Appeal — [Account email or last-seen IP]".
- Include a brief description of the action you are appealing and why you believe it is incorrect.
- We will acknowledge within 3 business days and respond substantively within 30 calendar days.
- If your appeal is upheld, we reverse the action and restore access.
- If your appeal is denied, our written response explains the basis. You may then escalate to your data-protection supervisory authority (for GDPR/UK GDPR/CCPA matters) or to a court of competent jurisdiction (see the Terms of Service §21-22).
8. Helping you reach a Provider after a failure
We do not custody funds, so we cannot return funds the Provider holds. But where the Provider has failed you, we will share, on request, the information we hold about your interaction (transaction reference, Provider used, time, requested pair) so you can pursue the Provider through its own support channel.
Email legal@swaps.app with subject "Provider failure — assistance" and the approximate date/time. We respond within 5 business days. We do not act as your agent against the Provider, and we do not litigate Provider failures on your behalf, but we will not gatekeep the information you reasonably need to make your case.
9. Lawful information requests
For requests from law enforcement, regulators, or other authorities:
- Send the request on official letterhead to legal@swaps.app, or by post to the registered office.
- Specify the legal basis (statute, treaty, MLAT).
- Specify the data requested with reasonable specificity.
- Specify whether user notification is permitted.
We comply with lawful requests within the limits of GDPR, our retention windows, and Estonian law. We do not produce data in response to informal requests. We may notify the affected user where lawful and where notification is not prohibited.
10. Data-subject requests during enforcement
Account suspension or termination does not suspend your GDPR/UK GDPR/CCPA/LGPD/DPDP rights. You can request access, rectification, deletion, etc. regardless of Account status. See the Privacy Policy §8. Data we are required to retain for legal-retention reasons (e.g., tax, AML cooperation, defending claims) is retained in restricted-access form for the period required.
11. Transparency
We publish aggregate enforcement statistics (rate-limit hits, suspensions, lawful information requests received) on the Service's status page on a best-effort annual basis, redacted to prevent harm to ongoing investigations and to protect user privacy.
Contact: legal@swaps.app