Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches

Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches
Natty Hatty Signature logo

Back

Usage, Restrictions & Safety

icon

Natty Hatty — Rate Limiting & Anti-Abuse Policy

Version: v1.0

Effective Date: November 15, 2025

Natty Hatty is committed to maintaining a safe, high-performance, and secure environment for youth-sports organizations, parents, coaches, and athletes.

To protect platform stability and prevent misuse, Natty Hatty enforces automated and manual rate limits, traffic controls, and anti-abuse protections across all products.

This policy applies to all users, including Organizations, staff, teams, parents, coaches, and automated systems.

1. Purpose of Rate Limiting

Rate limiting is designed to:

  • Prevent abuse, fraud, and scraping

  • Ensure fair use of shared infrastructure

  • Protect minors’ data from automated harvesting

  • Maintain platform performance and uptime

  • Prevent unauthorized bots or scripted automation

  • Secure login endpoints from brute-force attempts

2. General Platform Rate Limits

Natty Hatty uses dynamic rate-limiting thresholds based on system load, user behavior, and risk signals.

2.1 Typical Default Limits (Examples)

(Not user-visible; subject to change for security reasons.)

  • Login Attempts: Limited per IP/device

  • Password Reset Requests: Limited per account per hour

  • Signature Requests: Bounded to prevent mass-signature abuse

  • API Calls: Bounded per IP, token, or session

  • File Uploads: Size and frequency limited

  • Messaging: Spam protections apply (see Anti-Spam Policy)

  • Payment Calls: High-security throttling to prevent fraud

Natty Hatty may throttle or block excessive requests without notice.

3. High-Risk Activity Controls

Natty Hatty applies stricter rate limits to high-risk actions, including:

3.1 Authentication

  • Repeated failed logins

  • Multiple login attempts from different locations

  • Device rotation and suspicious fingerprinting

3.2 Payments

  • Rapid payment submissions

  • Multiple attempts using different cards

  • Excessive refunds or dispute submissions

3.3 Signature Workflows

  • Mass document creation

  • Bulk signature request attempts

  • Automated signing or tampering attempts

3.4 Data Access

  • High-volume roster exports

  • Automated scraping

  • Rapid page crawling

  • Unauthorized data harvesting

3.5 Messaging

  • Large-volume outbound messages

  • Duplicate messages

  • Suspicious promotional blasts

These protections support COPPA, CPRA, and CAN-SPAM/CASL compliance.

4. When Rate Limits Are Triggered

If usage exceeds acceptable thresholds, Natty Hatty may:

  • Temporarily throttle requests

  • Block specific IPs, devices, or accounts

  • Require re-authentication or MFA

  • Disable high-risk actions

  • Freeze signature or payment functionality temporarily

  • Alert the Organization or account owner

  • Escalate to trust & safety review

  • In severe cases, Natty Hatty may suspend or disable the account.

5. Prohibited Technical Behaviors

Organizations and users may not:

  • Use automated bots or scripts to interact with Natty Hatty

  • Scrape or harvest data through automated tools

  • Run load tests, stress tests, or penetration tests

  • Attempt to bypass or defeat rate limits

  • Use proxy networks or VPNs for evasion

  • Deploy browser automation at scale (e.g., Selenium, Puppeteer)

  • Access private APIs or undocumented endpoints

  • Build competing systems using scraped Natty Hatty data

These are treated as security violations and may trigger immediate account termination.

6. IP Blocking & Abuse Mitigation

Natty Hatty may automatically block:

  • Known bot networks

  • Suspicious IP addresses

  • Known malicious VPNs or proxy servers

  • Geolocations with high attack signatures

  • Flooding traffic or DDoS-like patterns

Blocks may be temporary or permanent based on severity.

7. Anti-Scraping Protections

Natty Hatty enforces a strict no-scraping policy, including for:

  • Rosters

  • Player data

  • Event lists

  • Coach profiles

  • Pricing

  • Tryout information

  • Waivers, PDFs, reports

Any scraping or harvesting is prohibited under ToS, AUP, and this policy.

Violations may result in:

  • Permanent account bans

  • Legal action

  • IP blacklisting

  • Reporting to authorities (for child-data violations)

8. Automated Abuse Detection

Natty Hatty employs automated systems to monitor:

  • Request patterns

  • IP reputation

  • Device fingerprints

  • Anomalous login behavior

  • Rapid-fire API or UI actions

  • Suspicious sequence patterns resembling bots

Natty Hatty may use:

  • Behavioral analysis

  • Rate-based throttling

  • CAPTCHA challenges

  • Automated lockouts

  • Machine-risk scoring (no AI/ML used for decisioning; only rule-based detection)

9. Organization Responsibilities

  • Use the platform responsibly and within expected levels

  • Ensure staff do not use bots or scraping tools

  • Prevent unauthorized third parties from accessing the platform

  • Refrain from exporting data into unauthorized systems

  • Never attempt to bypass payment or signature limits

  • Educate coaches and admins on acceptable usage

Organizations are fully liable for violations by their staff.

10. Violations & Enforcement

Natty Hatty may take one or more actions:

  • Temporary rate-limit block

  • Session resets

  • Forced MFA

  • Account suspension

  • Payment freeze

  • Signature freeze

  • Data access restrictions

  • Permanent ban

  • Termination of Organization account

  • Legal action for severe breaches

  • Child safety–related scraping or data harvesting may be escalated to authorities.

11. Appeal Process

If you believe your account was incorrectly rate-limited or blocked, contact:

security@nattyhatty.com

Provide:

  • Your Organization name

  • Account email

  • Approximate time the issue occurred

  • Description of the action that was blocked

Natty Hatty will investigate using audit logs and telemetry.