Limits & Enforcement Policy

Last updated: 2026-09-06 Version: 1.1

This page documents the rate limits, abuse thresholds, enforcement actions, and appeals process that operationalise the Terms of Service and the Acceptable Use Policy. It is the operational reference for what happens when a user (intentionally or accidentally) breaches the rules.


1. Rate limits — anonymous users

EndpointWindowLimitOn breach
/best-quote1 minute / IP30 requests429 with Retry-After: 60
/api/search (free Reports)1 minute / IP10 requests429
Static pages (HTML, JS, CSS)Cloudflare defaultHigh; bot management appliesChallenge or block
AI Concierge messages1 hour / IP20429 + in-UI throttle message
agent.swaps.app/llm/*1 minute / IP60429
agent.swaps.app/openapi1 minute / IP600Soft throttle

These limits are dynamic — we may tighten them in response to abuse without notice. We log breaches and use them as an abuse signal.

2. Rate limits — authenticated users

Authenticated users get higher limits and per-Account quotas:

ResourceQuotaReset / refresh
Free Search Reports3 lifetime per AccountOne-time
Credit-pack reports5 / 10 / 20 per packConsumed at use
AI Concierge messages100 / day / Account24 hours
/best-quote (signed-in)60 / minute / AccountRolling window
Friend Rate referrals — rewarded eventsNo hard cap, but anti-fraud appliesContinuous

2a. Product-specific limits and access gates

These limits operationalise the Payment Link Terms and the Payroll Terms.

ProductLimit / gateSet by
Payment LinksIndividual Payer cap: up to USD $4,000 equivalent per payment, and lower on some rails — see §2b. Merchant activation requires a Provider-verified (Bridge KYB) business in approved status. Available rails and any further limits are Provider-determined and may change without notice.Swaps (cap) + Provider (rails/further limits)
PayrollAccess gate: Provider-verified individual or business customer (Bridge KYC/KYB) in good standing; private beta, access-gated. Rails, supported currencies, and networks are Provider-determined.Provider

Where the Provider determines a rail, currency, limit, or eligibility condition, Swaps does not warrant its continued availability and it may change at any time without notice.

2b. Individual and person-to-person payment thresholds

The Provider (Bridge) applies its own thresholds to person-to-person third-party payments — a payment sent by one individual to another individual — and states them as: USD wire and ACH, USD $4,000.00; Mexican SPEI, MXN $15,000; EUR SEPA, GBP and SWIFT, varies by developer. The Provider may lower any of these at any time, and states that person-to-person payments above them are outside its risk tolerance. The Provider does not publish fixed thresholds for first-party ("me to me"), business-to-business, or business-to-consumer (for example, payroll) payments, but applies heightened scrutiny to them and reserves the right to reverse any payment it considers unsubstantiated or high-risk. Source: Provider fraud policy, 2026-03-31.

Where a payer pays as an individual, the amount Swaps will accept is therefore at most the USD $4,000 equivalent, and in several cases less:

CaseCap applied
Payer is a registered businessNo Swaps cap
Individual payer, business MerchantUSD $4,000 equivalent per payment
Individual payer, individual Merchant — USD rails (ACH, wire, FedNow)USD $4,000 where the Merchant's US residency is confirmed; otherwise USD $2,000, which includes every case where residency is unconfirmed
Individual payer, individual Merchant — SEPAUSD $4,000 equivalent per payment
Individual payer, individual Merchant — Mexican SPEIMXN 15,000 per payment, in Mexican pesos
Individual payer, individual Merchant — Pix and UK Faster PaymentsNot available

These are ceilings, not entitlements: the Provider may decline, hold, or reverse a payment below any of them, and Swaps may apply a lower limit without notice. Amounts in a currency other than the one named are converted at the rate available to Swaps at the time of the check; where no rate is available the payment is declined rather than allowed through.

3. Abuse thresholds and detection

We treat the following as abuse signals (non-exhaustive):

  • More than 3 Accounts created from the same browser fingerprint within 24 hours.
  • More than 5 referral events from the same fingerprint or IP cluster within 7 days.
  • More than 50 unique address scans per hour from one Account, IP, or fingerprint.
  • Repeated 429 breaches (more than 100 in one hour from the same IP).
  • KYC denials at the Provider followed by re-attempts from the same Swaps Account with different identity info.
  • Attempts to bypass geo-block detected by VPN signatures, proxy fingerprints, or impossible geolocation jumps.
  • Sanctions-list match (immediate hard action — see the Sanctions policy).

Detection runs continuously. Thresholds are tuned based on observed traffic; specific numbers may be adjusted in the codebase from time to time without changing this document materially.

4. Enforcement actions — escalation ladder

StepActionNotice to userReversible
1 — ThrottleHTTP 429 with Retry-AfterHeader + UI messageYes — wait for window
2 — Soft blockIP-level Cloudflare challengeCloudflare interstitialYes — pass challenge or change network
3 — Account warningIn-product banner explaining the breachBanner + emailYes — change behaviour
4 — Account restrictionDisable specific features (e.g., referral rewards, Search)EmailYes — appeal
5 — Account suspensionLogin disabled pending reviewEmailYes — appeal
6 — Account terminationLogin disabled permanently, data retained for legal-retention windowsEmail + final noticeNo — but data subject rights still apply
7 — IP blockNetwork-level blockNone to userYes — appeal via different IP
8 — Cooperation with authoritiesData disclosed under lawful requestWhere law permits noticen/a

We skip steps for major or critical breaches (sanctions match, child sexual exploitation content, attack on the Service): we move directly to step 5 or 6.

5. Provider-side enforcement

We do not control Provider enforcement. If a Provider KYC-denies you, freezes your transaction, or blocks your account, that is the Provider's decision under its own rules. Your appeal goes to the Provider, not to Swaps. We can help you locate the right Provider contact — see Limits & Enforcement §8 below — but we cannot reverse a Provider's compliance decision.

For Payment Links and Payroll, refunds, disputes, chargebacks, recalls, and failed, returned, or reversed payments are likewise routed to the Provider (Bridge) and resolved under the Provider's terms. Swaps never received or held the funds and cannot reverse, recall, or refund a Payment Links payment or a payroll payout. Swaps assists by sharing the information it holds (such as the request, reference code, transaction status, and timestamps) so you can reach the Provider, under the §8 mechanism below.

Requests for information, and the deadline attached to them. The Provider may hold a payment it considers risky and ask for supporting information — the relationship with the sender, the purpose of the payment, the source of funds, or documentation such as signed and dated contracts, invoices, or bank statements. The Provider states that it decides on a flagged payment within 2 business hours during its business hours (EU Monday–Friday 08:00–17:00 CET; US Monday–Friday 09:00–19:00 EST, excluding US bank holidays), and outside those hours by the next business day. Where it opens a request for information, it states that it waits 2 business days for the reply, and after that reverses the payment back to the sender and pauses the customer until the request is completed. It further states that it does not hold funds for more than two business days unless legally required to do so.

Where we are notified of such a request, we relay it to you and pass on your reply, but this step is not automated in every case, may require manual action on our side, and is not guaranteed to complete before the Provider's deadline; we cannot extend the Provider's deadline, and we cannot prevent or undo a reversal made under it. A payment reversed this way is returned to the sender; it is not a refund by Swaps, and §6 does not apply to it. Providing the requested information quickly and completely is the only thing that stops the clock. Source: Provider fraud policy, 2026-03-31.

Fraud claims raised by a sending bank. Where the Provider receives a fraud claim from the bank that sent a payment, it pauses the affected customer immediately and notifies us. The Provider states that such a customer can be re-enabled only after the sender withdraws the claim, and that the Provider does not broker that withdrawal — it is a matter between you, the sender, and the sender's bank. Swaps cannot lift a Provider-side pause and does not adjudicate the underlying claim. Closing your Swaps Account does not withdraw or extinguish such a claim.

6. Refund policy

SituationRefund
You initiated a transaction, the Provider executed it: outcome was not what you wantedNot refundable by Swaps — we did not receive payment. Contact Provider.
You initiated a transaction, the Provider failed to execute (timeout, outage), and the Provider already received paymentNot refundable by Swaps. Contact Provider.
You bought a Credit pack and used all Credits: results were unsatisfactoryNot refundable. Credits are non-cash; use of a Credit is final.
You bought a Credit pack but Reports returned empty data (zero signals, zero context)One-time Credit re-credit per pack, within 24 hours, on request to legal@swaps.app. See the Search Address Report Terms.
Your Account was terminated for a minor or moderate AUP breachResidual unused Credit balance refunded on request.
Your Account was terminated for a major or critical AUP breachNo refund.
You stop using the Service voluntarily with unused CreditsCredits remain in your Account; no cash refund.

Refunds, where due, are processed within 14 calendar days via the same payment method used to purchase. Bank or payment-processor processing time is additional.

7. Appeals process

If you believe an enforcement action against you is incorrect:

  1. Email legal@swaps.app with the subject line "Appeal — [Account email or last-seen IP]".
  2. Include a brief description of the action you are appealing and why you believe it is incorrect.
  3. We will acknowledge within 3 business days and respond substantively within 30 calendar days.
  4. If your appeal is upheld, we reverse the action and restore access.
  5. If your appeal is denied, our written response explains the basis. You may then escalate to your data-protection supervisory authority (for GDPR/UK GDPR/CCPA matters) or to a court of competent jurisdiction (see the Terms of Service §21-22).

8. Helping you reach a Provider after a failure

We do not custody funds, so we cannot return funds the Provider holds. But where the Provider has failed you, we will share, on request, the information we hold about your interaction (transaction reference, Provider used, time, requested pair) so you can pursue the Provider through its own support channel.

Email legal@swaps.app with subject "Provider failure — assistance" and the approximate date/time. We respond within 5 business days. We do not act as your agent against the Provider, and we do not litigate Provider failures on your behalf, but we will not gatekeep the information you reasonably need to make your case.

9. Lawful information requests

For requests from law enforcement, regulators, or other authorities:

  • Send the request on official letterhead to legal@swaps.app, or by post to the registered office.
  • Specify the legal basis (statute, treaty, MLAT).
  • Specify the data requested with reasonable specificity.
  • Specify whether user notification is permitted.

We comply with lawful requests within the limits of GDPR, our retention windows, and Estonian law. We do not produce data in response to informal requests. We may notify the affected user where lawful and where notification is not prohibited.

10. Data-subject requests during enforcement

Account suspension or termination does not suspend your GDPR/UK GDPR/CCPA/LGPD/DPDP rights. You can request access, rectification, deletion, etc. regardless of Account status. See the Privacy Policy §8. Data we are required to retain for legal-retention reasons (e.g., tax, AML cooperation, defending claims) is retained in restricted-access form for the period required.

11. Transparency

We publish aggregate enforcement statistics (rate-limit hits, suspensions, lawful information requests received) on the Service's status page on a best-effort annual basis, redacted to prevent harm to ongoing investigations and to protect user privacy.


Contact: legal@swaps.app

Related Pages