Acceptable Use Policy
Last updated: 2026-10-03 Version: 2.1 Status: Advance notice Effective: New products and features: first use on or after 7 October 2026; existing services: 10 November 2026, subject to the notice period below
For newly available products and features, this edition applies when you first choose to use the relevant service and accept its terms, on or after 7 October 2026. The product must actually be launched and available to you. For changes to services you already use, this edition applies from 10 November 2026, but never earlier than 30 days after we notify you of the changes, or a later date required by applicable law. Until then, the previous conditions continue for those existing services. Accepting in advance does not shorten that transition. Publication and acceptance do not make a product available or establish regulatory permission.
This policy applies to every Swaps interface and integration under the Terms of Service. Supa Labs OÜ, registry code 17399414, operates Swaps. Contact: legal@swaps.app.
1. Lawful and authorised use
Use the Service only for lawful purposes, within your authority and the permissions of the product. Identify the correct person or business and accurately describe payments. Provide information reasonably needed for a permitted feature or provider requirement. Do not bypass a country, identity, account, asset, network, amount or risk restriction.
A payment tool does not authorise you to operate a regulated business. If your activity requires a licence, registration or provider agreement, you must satisfy that requirement and obtain any separately required integration approval before using the Service for it.
2. Prohibited financial activity
Do not use the Service for:
- Fraud, theft, scams, money laundering, terrorist financing or handling criminal proceeds.
- Sanctions evasion, dealings prohibited by applicable law, or concealing a prohibited beneficiary or beneficial owner.
- Tax evasion, false invoices, fabricated commercial relationships or misleading payment descriptions.
- Market manipulation, deceptive investment schemes, impersonation or unauthorised access to another person's assets.
- Unlawful goods or services, exploitation, or activity prohibited for the selected provider or rail.
- Undisclosed collection, pass-through payments, pooled customer funds or escrow for other persons outside an expressly supported and authorised arrangement.
- Splitting transactions, changing identities, routing through another country or using another person's account to evade checks or limits.
Payment on your own genuine invoice, or an authorised payment to your own worker or supplier, is distinct from running a payment service for undisclosed third parties. Being technically able to submit an instruction does not establish permission.
3. Technical abuse
Do not attack, overload, probe for credentials, exploit vulnerabilities, bypass authentication, tamper with signatures or replay protections, or access another user's data. Do not pool keys, rotate accounts or IP addresses to multiply quotas, scrape against access controls, or resell access without the required agreement.
Use documented integration interfaces. Restrictions on copying or reverse engineering do not remove rights mandatory law grants for interoperability or other permitted purposes. See Limits and Enforcement for rate limits and responses.
4. Content and personal data
Do not submit unlawful or infringing content, threats, harassment, child sexual exploitation material or instructions to commit crime. Do not upload private keys, seed phrases, signing secrets, full payment-card details or unnecessary sensitive personal data.
Provide recipient and business data only with appropriate authority, notices and lawful basis. Identity and compliance documents may be submitted when genuinely requested through the designated secure channel; do not place them in public payment descriptions, URLs, agent prompts or unrelated support fields. Do not expose another person's invoice, payroll or report through a public link without authority.
5. Product requirements
Address Check reports
Reports contain fallible signals, not a finding that a person committed a crime or a guarantee that funds are safe. Do not present them as official certification, fabricate attribution, use them to harass people, or sell a compliance determination without an agreed right and appropriate legal basis. Do not create extra accounts to obtain repeated free allowances. The Address Check Terms govern permitted report use.
Referrals
Do not self-refer, create fake users or use deceptive incentives and artificial activity to generate rewards. The Referral Terms determine eligible activity and adjustments.
Payment Links and Crypto Processing
Identify the real merchant or requesting person and the purpose of payment. Do not misrepresent business status, collect for an undisclosed third party, issue fraudulent invoices or disguise a financial product as an ordinary purchase.
Recurring invoice scheduling must not be presented as an authorised wallet debit. Do not treat an overpayment, unmatched deposit or expired invoice as permission to appropriate funds, change a recipient or manufacture a refund instruction. Follow the product's investigation and return process.
Payroll, Pay an Invoice and Accounts
Use truthful worker, supplier, beneficiary and account-holder details. Do not misclassify employment or conceal a third-party payer. Use only funding sources permitted by the route. Provider-issued deposit instructions are not permission to collect funds for any business model or to represent Swaps as a bank.
Wallet
Do not solicit another person's signing material or impersonate support. Do not present a prepared transaction as already signed or settled. Obtain the user's actual authority for wallet actions; an API key does not supply a wallet signature.
6. API, MCP, agents and webhooks
Keep keys and webhook secrets in appropriate secret storage, not public repositories, client code or prompts. Use supported scopes and account membership; do not share a credential across unrelated legal entities or impersonate another holder.
Agents must act within the authority actually granted. Where an operation requires per-transaction confirmation, obtain it for the material action and details. Do not fabricate a confirmation flag or infer a payment mandate from a request to research, quote or prepare a draft.
Follow documented idempotency and retry rules. After an uncertain money-operation response, reconcile its status before retrying in a way that could duplicate it. Honour throttling and retry guidance.
Register webhook destinations you control or are authorised to use. Verify signatures and deduplicate events before acting; reconcile settlement through the authoritative transaction state. A test event or unverified callback is not proof that money moved.
Test mode is for simulations: no real funds or personal data, and no attempt to reach live capabilities through test resources. Respect each surface's tool catalogue; a public read-only variant does not grant access to authenticated financial actions. The API Terms provide the full contract.
7. Enforcement and review
We can throttle, restrict a feature, revoke credentials, deactivate links or suspend an account where reasonably necessary. Severity, evidence, recurrence, impact and legal obligations inform the response. Urgent action can precede notice; an automated restriction is not a conclusive finding of misconduct.
See Limits and Enforcement for notice, review and complaints. Restrictions do not automatically reverse provider or blockchain activity, transfer ownership of funds to Swaps, or forfeit paid entitlements. Mandatory refund, privacy and consumer rights remain.
8. Reporting concerns
Send suspected fraud, misuse or disputed enforcement to legal@swaps.app. Send suspected vulnerabilities or credential exposure to security@swaps.app. Include a useful reference and description without signing secrets or unnecessary personal data.
Unsolicited testing does not grant permission to access another person's account, move funds, defeat controls or disrupt the Service. Test only resources you control within their authorised scope. Reporting a vulnerability does not create a paid engagement or entitlement to a bounty. We assess reports and any conduct on their facts and under applicable law.