Back
Usage, Restrictions & Safety
Natty Hatty — Rate Limiting & Anti-Abuse Policy
Version: v1.0
Effective Date: November 15, 2025
Natty Hatty is committed to maintaining a safe, high-performance, and secure environment for youth-sports organizations, parents, coaches, and athletes.
To protect platform stability and prevent misuse, Natty Hatty enforces automated and manual rate limits, traffic controls, and anti-abuse protections across all products.
This policy applies to all users, including Organizations, staff, teams, parents, coaches, and automated systems.
1. Purpose of Rate Limiting
Rate limiting is designed to:
Prevent abuse, fraud, and scraping
Ensure fair use of shared infrastructure
Protect minors’ data from automated harvesting
Maintain platform performance and uptime
Prevent unauthorized bots or scripted automation
Secure login endpoints from brute-force attempts
2. General Platform Rate Limits
Natty Hatty uses dynamic rate-limiting thresholds based on system load, user behavior, and risk signals.
2.1 Typical Default Limits (Examples)
(Not user-visible; subject to change for security reasons.)
Login Attempts: Limited per IP/device
Password Reset Requests: Limited per account per hour
Signature Requests: Bounded to prevent mass-signature abuse
API Calls: Bounded per IP, token, or session
File Uploads: Size and frequency limited
Messaging: Spam protections apply (see Anti-Spam Policy)
Payment Calls: High-security throttling to prevent fraud
Natty Hatty may throttle or block excessive requests without notice.
3. High-Risk Activity Controls
Natty Hatty applies stricter rate limits to high-risk actions, including:
3.1 Authentication
Repeated failed logins
Multiple login attempts from different locations
Device rotation and suspicious fingerprinting
3.2 Payments
Rapid payment submissions
Multiple attempts using different cards
Excessive refunds or dispute submissions
3.3 Signature Workflows
Mass document creation
Bulk signature request attempts
Automated signing or tampering attempts
3.4 Data Access
High-volume roster exports
Automated scraping
Rapid page crawling
Unauthorized data harvesting
3.5 Messaging
Large-volume outbound messages
Duplicate messages
Suspicious promotional blasts
These protections support COPPA, CPRA, and CAN-SPAM/CASL compliance.
4. When Rate Limits Are Triggered
If usage exceeds acceptable thresholds, Natty Hatty may:
Temporarily throttle requests
Block specific IPs, devices, or accounts
Require re-authentication or MFA
Disable high-risk actions
Freeze signature or payment functionality temporarily
Alert the Organization or account owner
Escalate to trust & safety review
In severe cases, Natty Hatty may suspend or disable the account.
5. Prohibited Technical Behaviors
Organizations and users may not:
Use automated bots or scripts to interact with Natty Hatty
Scrape or harvest data through automated tools
Run load tests, stress tests, or penetration tests
Attempt to bypass or defeat rate limits
Use proxy networks or VPNs for evasion
Deploy browser automation at scale (e.g., Selenium, Puppeteer)
Access private APIs or undocumented endpoints
Build competing systems using scraped Natty Hatty data
These are treated as security violations and may trigger immediate account termination.
6. IP Blocking & Abuse Mitigation
Natty Hatty may automatically block:
Known bot networks
Suspicious IP addresses
Known malicious VPNs or proxy servers
Geolocations with high attack signatures
Flooding traffic or DDoS-like patterns
Blocks may be temporary or permanent based on severity.
7. Anti-Scraping Protections
Natty Hatty enforces a strict no-scraping policy, including for:
Rosters
Player data
Event lists
Coach profiles
Pricing
Tryout information
Waivers, PDFs, reports
Any scraping or harvesting is prohibited under ToS, AUP, and this policy.
Violations may result in:
Permanent account bans
Legal action
IP blacklisting
Reporting to authorities (for child-data violations)
8. Automated Abuse Detection
Natty Hatty employs automated systems to monitor:
Request patterns
IP reputation
Device fingerprints
Anomalous login behavior
Rapid-fire API or UI actions
Suspicious sequence patterns resembling bots
Natty Hatty may use:
Behavioral analysis
Rate-based throttling
CAPTCHA challenges
Automated lockouts
Machine-risk scoring (no AI/ML used for decisioning; only rule-based detection)
9. Organization Responsibilities
Use the platform responsibly and within expected levels
Ensure staff do not use bots or scraping tools
Prevent unauthorized third parties from accessing the platform
Refrain from exporting data into unauthorized systems
Never attempt to bypass payment or signature limits
Educate coaches and admins on acceptable usage
Organizations are fully liable for violations by their staff.
10. Violations & Enforcement
Natty Hatty may take one or more actions:
Temporary rate-limit block
Session resets
Forced MFA
Account suspension
Payment freeze
Signature freeze
Data access restrictions
Permanent ban
Termination of Organization account
Legal action for severe breaches
Child safety–related scraping or data harvesting may be escalated to authorities.
11. Appeal Process
If you believe your account was incorrectly rate-limited or blocked, contact:
Provide:
Your Organization name
Account email
Approximate time the issue occurred
Description of the action that was blocked
Natty Hatty will investigate using audit logs and telemetry.