Last Updated: August 11, 2026
These Swipesum Platform and Services Terms of Service (these "Terms") are a legally binding agreement between Swipesum, Inc., dba Swipesum ("Swipesum") and the business entity or sole proprietor identified in an Order Form or otherwise accessing or using the Services ("Customer"). Customer may be identified as a "Partner," "Merchant," "Client," or similar term in an Order Form; each such reference means Customer for purposes of these Terms.
By signing or accepting an Order Form, clicking an acceptance button, creating an account, accessing the Platform, or using any Service, Customer acknowledges that it has reviewed and understands these Terms and agrees to be bound by the Agreement. The individual accepting the Agreement represents and warrants that the individual is at least eighteen (18) years old and has authority to bind Customer. The Services are offered only for business and commercial use and not for personal, family, or household use. If Customer does not agree to the Agreement, Customer must not access or use the Services.
1.1. Agreement. The "Agreement" consists of these Terms, each applicable Order Form, any service-specific terms, addendum, data processing terms, statement of work, merchant or processing agreement, policy, or other document expressly incorporated by reference, and the Documentation. Each Order Form is incorporated into the Agreement. A purchase order, vendor portal term, click-through term supplied by Customer, or other Customer document will not modify the Agreement, even if accepted, processed, or referenced by Swipesum, unless Swipesum expressly agrees in a writing signed by an authorized officer.
1.2. Order Forms and Selected Services. Only the Services identified in an applicable Order Form or otherwise enabled by Swipesum are included. Service-specific provisions apply only to the corresponding Service. Pricing, usage commitments, minimums, revenue share, residuals, implementation scope, and other commercial terms are stated in the applicable Order Form and are not established by these Terms.
1.3. Order of Precedence. In the event of a conflict: (a) an Order Form controls with respect to the specific Services, pricing, quantities, term, and commercial terms expressly stated in that Order Form; (b) a service-specific addendum or the applicable provisions in Part II control with respect to the applicable Service; (c) Section 7 controls with respect to the processing of Personal Data; and (d) these general Terms control in all other respects. A Merchant Agreement or acquiring or processing agreement controls solely with respect to underwriting, acquiring, authorization, clearing, settlement, funding, reserves, chargebacks, and other merchant-processing matters governed by that agreement. If a separate Swipesum Consulting Services Agreement is incorporated into an Order Form, that agreement controls solely with respect to consulting and advisory services.
1.4. Effective Date. The "Effective Date" is the earliest date on which Customer accepts the Agreement by any method described above or first accesses or uses a Service.
2.1. Acquirer. "Acquirer" means a bank, processor, financial institution, or other entity that acquires, authorizes, clears, or settles payment transactions for a Merchant.
2.2. Applicable Law. "Applicable Law" means all laws, statutes, regulations, orders, ordinances, regulatory guidance, sanctions, export controls, privacy and data-protection requirements, consumer-protection requirements, and governmental requirements applicable to a party, the Services, Customer, a Merchant, an End Customer, an End User, or a transaction.
2.3. Customer Data. "Customer Data" means data, content, records, instructions, materials, and information submitted to, transmitted through, generated from, or made available to the Services by or on behalf of Customer, a Merchant, an End Customer, or an End User, including Transaction Data and Personal Data, but excluding Swipesum technology, system-generated telemetry that does not identify Customer or an individual, and Aggregated Data as described in Section 7.10.
2.4. Customer Product. "Customer Product" means any website, application, platform, software, hardware, product, or service owned, controlled, operated, or provided by Customer that integrates with, accesses, embeds, displays, or uses a Service.
2.5. Documentation. "Documentation" means Swipesum's and its Service Providers' then-current technical specifications, API documentation, implementation guides, operating instructions, security requirements, support procedures, usage limits, policies, and other materials made available in connection with the Services, as updated from time to time.
2.6. End Customer and End User. "End Customer" means a business to which Customer is expressly authorized by Swipesum to provide access to or use of a Service. "End User" means a cardholder, consumer, payor, employee, or other natural person whose data or transaction is submitted to or processed through a Service.
2.7. Fees. "Fees" means all amounts payable to Swipesum under the Agreement, including usage fees, recurring fees, implementation fees, pass-through costs, taxes, reimbursements, assessments, losses, and other charges stated in an Order Form or otherwise permitted by the Agreement.
2.8. Gateway Services. "Gateway Services" means CPO Gateway, Swipesum Gateway, and any other Swipesum-branded payment gateway, API, portal, transaction-routing, tokenization, stored-credential, account-updater, authentication, fraud-screening, reporting, or related gateway functionality identified in an Order Form or enabled by Swipesum.
2.9. Gateway Transaction. "Gateway Transaction" means each billable operation completed, evaluated, submitted, routed, facilitated, or otherwise processed through a Gateway Service, whether approved, declined, failed, reversed, or otherwise responded to. Gateway Transactions include, without limitation, authorization, capture, purchase or pay, disbursement, refund or credit, void or reversal, verification, validation, update authorization, token retrieval, authentication, fraud check, settlement, and any other operation identified in the Documentation. Separate operations arising from the same payment attempt may constitute separate Gateway Transactions.
2.10. Merchant. "Merchant" means Customer or an End Customer that accepts or seeks to accept payments or receives payment-related Services. A Merchant may be required to enter into a Merchant Agreement before receiving acquiring, processing, settlement, or related services.
2.11. Merchant Agreement and Merchant Losses. "Merchant Agreement" means an agreement among a Merchant and Swipesum, an Acquirer, processor, sponsor bank, payment facilitator, or other Service Provider governing payment processing or related services. "Merchant Losses" means chargebacks, returns, refunds, reversals, fraud losses, unpaid fees, negative balances, reserves, fines, assessments, penalties, data or security losses, unauthorized transactions, bankruptcy losses, and other losses or liabilities arising from a Merchant, a Merchant Agreement, or payment activity.
2.12. Order Form. "Order Form" means any service and fee schedule, enrollment form, application, proposal, statement of work, order, registration form, electronic selection, or similar document accepted by Swipesum that identifies Services or commercial terms.
2.13. Payment Network. "Payment Network" means Visa, Mastercard, American Express, Discover, debit networks, Nacha, alternative payment method providers, wallet providers, and any other payment network, scheme, association, or provider applicable to a Service or transaction.
2.14. Personal Data and Transaction Data. "Personal Data" means information relating to an identified or identifiable natural person, or any similar term under Applicable Law. "Transaction Data" means information relating to a payment, payment credential, payment request, authorization, capture, refund, settlement, chargeback, authentication, fraud screen, or related activity.
2.15. Platform and Services. "Platform" means the websites, portals, applications, APIs, systems, networks, software, tools, technology, and Documentation made available by or through Swipesum. "Services" means the Platform and all software, payment gateway, payment facilitation, payment processing, merchant account, onboarding, KYB, KYC, AML, risk, fraud, settlement, tokenization, authentication, reporting, audit, analytics, optimization, CPO, support, and other products or services identified in an Order Form or enabled by Swipesum.
2.16. Rules. "Rules" means the then-current rules, bylaws, standards, requirements, mandates, operating regulations, and guidelines of Payment Networks, Acquirers, sponsor banks, processors, regulators, PCI Security Standards Council, and Service Providers, together with the Documentation and Swipesum policies applicable to the Services.
2.17. Service Provider. "Service Provider" means any Swipesum affiliate, licensor, technology provider, payment gateway provider, Payment Network, Acquirer, processor, sponsor bank, financial institution, cloud provider, security provider, data provider, subcontractor, or other third party used in connection with the Services. "Service Provider Guidelines" means the Rules, documentation, terms, standards, and requirements imposed by a Service Provider.
2.18. Territory. "Territory" means the country or countries identified in the applicable Order Form or Documentation. If no Territory is identified, the Territory is the United States.
3.1. Provision of Services. Subject to Customer's timely payment of Fees and compliance with the Agreement, Swipesum will make the selected Services available during the applicable term. Swipesum may provide the Services directly or through Service Providers. The Services are non-exclusive, and Swipesum may provide similar services to others.
3.2. Limited License. Swipesum grants Customer a limited, revocable, non-exclusive, non-transferable, and non-sublicensable right during the applicable term to access and use the selected Services in the Territory solely for Customer's internal business purposes and, only where expressly authorized in an Order Form, to integrate the Services with Customer Products or provide access to approved End Customers. No right is granted by implication.
3.3. Accounts, Users, and Affiliates. Customer will provide complete and accurate registration information and keep it current. Customer is responsible for all activity under its accounts and for the acts and omissions of its personnel, contractors, agents, Affiliates, Merchants, and End Customers. Customer Affiliates may use the Services only if identified in an Order Form or approved by Swipesum, and Customer remains fully liable for their use.
3.4. Customer Systems and Connectivity. Customer is solely responsible for obtaining, maintaining, securing, and supporting the Customer Products, devices, equipment, software, internet access, telecommunications, certificates, keys, and other systems needed to access or use the Services. Swipesum is not responsible for Customer systems or for public networks, mobile networks, browsers, operating systems, devices, or third-party software.
3.5. Integration and Testing. Customer is solely responsible for the proper, accurate, secure, and compliant design, implementation, testing, certification, maintenance, and operation of each integration and Customer Product. Customer will use the Services only in accordance with the Documentation, implement required API, security, authentication, and integration updates within the timeframe specified by Swipesum, and promptly correct defects. Integration errors, retries, duplicate calls, inaccurate instructions, or Customer system failures may result in duplicate or failed transactions, Fees, declines, chargebacks, settlement delays, data incidents, or other losses for which Customer is responsible to the extent caused by Customer or parties under its control.
3.6. Credentials. Customer will safeguard all usernames, passwords, API keys, certificates, tokens, encryption keys, and other credentials; restrict them to authorized personnel with a need to know; use appropriate access controls and multi-factor authentication where available; and immediately revoke access when no longer required. Swipesum may rely on all instructions and activity submitted using Customer credentials. Customer is responsible for such activity until Customer notifies Swipesum of unauthorized use and Swipesum has had a reasonable opportunity to act.
3.7. Data and Instructions. Customer is responsible for the legality, accuracy, completeness, integrity, formatting, and timeliness of Customer Data and all transaction requests and instructions submitted by or on behalf of Customer. Swipesum may rely on Customer Data and instructions without independent verification. Customer will review reports, transaction responses, statements, and outputs and promptly report suspected errors.
3.8. Service Changes and Required Updates. Swipesum may add, modify, replace, restrict, or discontinue features, APIs, integration methods, supported processors or Acquirers, and other components of the Services. Swipesum will use commercially reasonable efforts to provide advance notice of a material change that materially reduces core functionality, unless the change is required sooner for security, legal, regulatory, Payment Network, Service Provider, or operational reasons. Customer's failure to implement a required update may result in degradation, loss of support, suspension, or termination without liability to Swipesum.
3.9. Beta, Preview, and Pilot Services. A beta, preview, trial, proof-of-concept, or pilot feature is provided "AS IS" for evaluation, may be incomplete or changed at any time, may be subject to additional terms, and may be withdrawn without notice. Swipesum has no obligation to continue or generally release such feature, and Customer uses it at its own risk.
3.10. Support and Service Levels. Swipesum will provide support in accordance with the applicable Order Form and its then-current support procedures. Unless a separate written service-level agreement expressly states otherwise, response times are targets only and no uptime, availability, response-time, resolution-time, recovery-time, or service-credit commitment applies.
3.11. Territory. Customer will use the Services only in the Territory and only for approved legal entities, locations, business models, payment methods, and use cases. Customer will not export, re-export, access, or provide the Services outside the Territory or to a prohibited person or jurisdiction without Swipesum's prior written approval.
4.1. Permitted Use. Customer will use the Services only for lawful, bona fide business activity and in accordance with the Agreement, the Rules, and the Documentation.
4.2. Prohibited Conduct. Customer will not, and will not permit any other person to: (a) use the Services for illegal, deceptive, abusive, fraudulent, sanctioned, or prohibited activity; (b) submit transactions for a person, entity, business, product, location, or merchant account not approved for the applicable Service; (c) aggregate transactions or provide payment services to a third party except as expressly authorized in an Order Form; (d) resell, sublicense, lease, timeshare, distribute, or otherwise provide the Services to a third party except as expressly permitted; (e) copy, modify, adapt, translate, create derivative works from, reverse engineer, decompile, disassemble, discover source code or non-public APIs, or otherwise attempt to derive the composition or underlying ideas of the Services; (f) build, train, benchmark, offer, or promote a product or service that competes with the Services using non-public information obtained through the Services; (g) remove proprietary notices or use Swipesum or Service Provider names or marks without authorization; (h) bypass, disable, defeat, probe, scan, or test security controls, rate limits, fraud controls, or authentication mechanisms without prior written approval; (i) conduct card testing, card enumeration, credential stuffing, account testing, penetration testing, vulnerability scanning, or similar activity; (j) introduce malware or harmful code, interfere with system operations, or create an unreasonable or excessive load; (k) use automated tools in a manner exceeding documented limits or reasonably expected human usage; (l) access another customer's data or account; (m) submit false, misleading, incomplete, unauthorized, or manipulated data or transactions; or (n) use the Services in a manner that exposes Swipesum or a Service Provider to legal, regulatory, financial, security, operational, competitive, or reputational risk.
4.3. Security Controls and Monitoring. Swipesum may monitor use of the Services, apply rate limits, require additional authentication, block requests, disable credentials, or implement fraud and security controls. Customer may not disable or circumvent a required control. If Swipesum approves an exception to a security or fraud-control requirement, Customer assumes all resulting risk and liability and will reimburse and indemnify Swipesum and the affected Service Providers for related losses, fees, fines, and claims.
4.4. Sensitive Authentication Data. Customer will not store card verification values, PIN data, magnetic-stripe or chip track data, or other sensitive authentication data after authorization, and will not cause Swipesum or a Service Provider to store such data except where expressly permitted by the Rules and Documentation.
4.5. Remedial Action. Customer will promptly investigate and remediate any misuse, prohibited activity, security weakness, or violation associated with Customer or its users. Swipesum may require Customer to provide evidence of remediation before restoring access.
5.1. Customer Business. Customer represents and warrants that it is engaged in a lawful business, is duly organized and in good standing where required, holds all licenses, registrations, permissions, and consents necessary to conduct its business and use the Services, and will not materially change its business, ownership, control, products, services, locations, or transaction profile without providing notice where required by Swipesum, the Rules, or Applicable Law.
5.2. Goods, Services, and End Users. Customer is solely responsible for its and its Merchants' goods and services; marketing; pricing; taxes; order fulfillment; refunds; returns; warranties; customer service; consumer disclosures; recurring-payment terms; cancellation processes; and disputes with End Users. Swipesum is not a party to any transaction between a Merchant and an End User and bears no risk regarding the underlying goods or services.
5.3. Transaction Authorization and Accuracy. Customer will submit only bona fide transactions authorized by the applicable End User and permitted by the Rules. Customer is responsible for verifying transaction amounts, currency, merchant identity, payment instructions, approval or decline responses, settlement, and reconciliation. An authorization, authentication, token, fraud score, or gateway response does not guarantee settlement, funding, validity, collectability, or absence of fraud or chargebacks.
5.4. Fraud, Chargebacks, and Losses. Customer bears the risk of fraudulent, unauthorized, disputed, reversed, or charged-back transactions and of goods or services provided in reliance on a payment response, except to the extent a Merchant Agreement expressly allocates such risk otherwise. Fraud, authentication, account-updater, tokenization, and risk tools are aids only and do not shift that responsibility.
5.5. Records and Reconciliation. Customer will maintain complete records of transactions, authorizations, consents, refunds, communications, and fulfillment for the period required by Applicable Law and the Rules. Customer will reconcile transaction and settlement records and notify Swipesum of a suspected error within thirty (30) days after the applicable statement or report is made available, or any shorter period required by a Merchant Agreement.
5.6. Complaints and Investigations. Customer will promptly notify Swipesum of any material complaint, regulatory inquiry, Payment Network inquiry, fraud event, or claim concerning the Services and will cooperate in the investigation and resolution. Customer will not make admissions or commitments on behalf of Swipesum or a Service Provider.
6.1. Fees. Customer will pay all Fees stated in each Order Form and all other amounts due under the Agreement. Unless an Order Form states otherwise, one-time Fees are due on the applicable Order Form effective date, recurring Fees are billed in advance, usage-based Fees are billed in arrears, and invoices are due within fifteen (15) days. Fees are non-cancelable and non-refundable except as expressly stated in the Agreement.
6.2. Billing Authorization. Customer authorizes Swipesum to debit or credit the bank account or charge the payment method Customer provides for amounts due under the Agreement and will execute any additional authorization reasonably requested. Customer will maintain accurate billing information and sufficient funds. Swipesum may set off amounts Customer owes against amounts Swipesum owes Customer.
6.3. Third-Party and Pass-Through Costs. Payment Network fees, Acquirer and processor fees, sponsor-bank fees, telecommunications costs, taxes, assessments, fines, and other third-party costs may change. Swipesum may pass through new or increased third-party costs, including costs imposed retroactively, without an amendment to the Order Form, and may make corresponding changes to the Services or billing methodology. Swipesum will use commercially reasonable efforts to provide notice of material recurring increases when practicable.
6.4. Late Payments and Collection. Past-due amounts accrue interest at the lesser of one and one-half percent (1.5%) per month or the maximum lawful rate. Customer will reimburse reasonable collection costs, including attorneys' fees. Swipesum may suspend Services for nonpayment after any notice and cure period required by the Agreement or Applicable Law. Suspension does not waive or reduce Customer's payment obligations.
6.5. Billing Disputes. Customer must submit a good-faith billing dispute in writing, with reasonable detail and supporting documentation, within thirty (30) days after the invoice, statement, or report is made available. Customer waives a billing claim not timely raised. Customer will timely pay all undisputed amounts.
6.6. Residuals and Revenue Share. If an Order Form provides for residuals, revenue share, or other payments to Customer, those amounts are calculated only on revenue actually received and retained by Swipesum, net of Fees, pass-through costs, chargebacks, refunds, credits, losses, reserves, taxes, fines, assessments, uncollected amounts, and other deductions permitted by the Agreement or Order Form. Swipesum may withhold, offset, or reverse payments to correct errors or cover amounts owed.
6.7. Taxes. Fees are exclusive of taxes. Customer is responsible for all sales, use, excise, value-added, withholding, gross-receipts, transaction, and similar taxes and governmental charges arising from the Services or transactions, except taxes based on Swipesum's net income. If Customer is required to withhold an amount, Customer will gross up the payment so Swipesum receives the amount it would have received absent the withholding, unless prohibited by Applicable Law.
This Section 7 constitutes the parties' data processing terms for Personal Data processed in connection with the Services, except to the extent a separate data processing addendum signed by the parties expressly supersedes it.
7.1. Customer Data Ownership. As between the parties, Customer retains its rights in Customer Data. Customer grants Swipesum and its Service Providers a worldwide, non-exclusive right and license during the Agreement, and thereafter as permitted by Applicable Law, to host, receive, access, use, reproduce, transmit, route, store, tokenize, update, disclose, analyze, and otherwise process Customer Data as necessary to provide, secure, support, administer, bill for, and improve the Services; prevent fraud and abuse; resolve disputes and chargebacks; comply with the Rules and Applicable Law; and exercise Swipesum's rights under the Agreement.
7.2. Roles and Instructions. To the extent Swipesum processes Personal Data on Customer's behalf, Customer is the controller or business and Swipesum is the processor or service provider, as those terms are defined by Applicable Law. The Agreement and Customer's documented use of the Services constitute Customer's instructions. Swipesum and applicable Service Providers may process Personal Data as independent controllers where permitted by Applicable Law and described in applicable terms or privacy notices, including for account administration, billing, fraud and risk management, security, legal compliance, dispute resolution, product administration, and creation and use of Aggregated Data.
7.3. Customer Privacy Obligations. Customer represents and warrants, for itself and each Merchant and End Customer, that it: (a) has a valid legal basis for all Personal Data and Transaction Data submitted to or processed through the Services; (b) provides all required notices and obtains all required consents, including for stored credentials, recurring transactions, automatic credential updates, authentication, device and browser data, and cross-border processing; (c) gives Swipesum only lawful instructions; (d) maintains accurate, relevant, and reasonably current data; (e) responds to End User requests and honors privacy choices; (f) does not submit Personal Data beyond what is reasonably necessary for the Services; and (g) does not submit protected health information, biometric identifiers, children's data, government-issued identification numbers, or other specially regulated data unless the applicable Service or Documentation expressly requests or permits it and Customer has satisfied all legal requirements.
7.4. Swipesum Processing Obligations. When acting as a processor or service provider, Swipesum will: (a) process Personal Data only in accordance with the Agreement and lawful documented instructions; (b) ensure personnel authorized to process Personal Data are subject to confidentiality obligations; (c) maintain reasonable security measures appropriate to the risk; (d) provide reasonable assistance, taking into account the nature of the processing, with data-subject requests, security incidents, assessments, and legally required consultations; and (e) notify Customer if Swipesum reasonably believes an instruction violates Applicable Law. To the extent required by U.S. state privacy laws, Swipesum will not sell or share Customer Personal Data for cross-context behavioral advertising, retain, use, or disclose it outside the direct business relationship except as permitted by law, or combine it with data from unrelated sources except as permitted by law.
7.5. Service Providers and Subprocessors. Customer authorizes Swipesum to engage Service Providers and subprocessors, including Swipesum affiliates, to process Customer Data. Swipesum will impose data-protection obligations on subprocessors as required by Applicable Law. Where required by Applicable Law, Swipesum will provide notice of a material new subprocessor and consider a reasonable written objection. If the parties cannot reasonably resolve an objection, Customer's sole remedy is to discontinue the affected Service in accordance with the applicable Order Form. Customer also authorizes lawful international transfers of Personal Data using an applicable transfer mechanism.
7.6. Security Program. Each party will maintain a written information-security program with administrative, technical, organizational, and physical safeguards appropriate to the nature of the data and risk, including access controls, encryption where appropriate, logging, vulnerability management, incident response, business continuity, and secure disposal. No system is completely secure, and Swipesum does not guarantee that unauthorized access will never occur.
7.7. PCI and Payment Data. Customer and each Merchant will comply with all applicable PCI Security Standards and Payment Network requirements, maintain any required validation, and provide evidence of compliance upon request. Customer is responsible for determining its PCI scope. Use of tokenization, hosted fields, encryption, or other security technology may reduce but does not eliminate Customer's PCI or security responsibilities. Customer will not store or transmit payment data except as permitted by the Rules and Documentation.
7.8. Security Incidents. Customer will notify Swipesum immediately, and in no event later than twenty-four (24) hours after discovery, of any actual or reasonably suspected unauthorized access, disclosure, loss, alteration, compromise, or misuse of Customer Data, credentials, Customer systems, or the Services. Customer will preserve evidence, investigate, contain, remediate, make legally required notifications, and cooperate with Swipesum and affected Service Providers. Swipesum will notify Customer without undue delay after becoming aware of a breach of security involving Personal Data processed by Swipesum on Customer's behalf, as required by Applicable Law, and will provide available information reasonably necessary for Customer to meet its legal obligations. Customer is responsible for costs and losses to the extent caused by Customer or parties under its control.
7.9. Data Retention, Return, and Deletion. Customer is responsible for maintaining its own legally required records and backups. The Services are not a permanent archival system unless an Order Form expressly states otherwise. Swipesum may retain Customer Data for the period needed to provide the Services, comply with law and the Rules, resolve disputes, prevent fraud, enforce the Agreement, and maintain ordinary backups. Upon termination and written request, Swipesum will delete or return Personal Data processed solely on Customer's behalf where reasonably practicable and legally permitted, subject to technical limitations, backup cycles, retention obligations, Service Provider restrictions, and payment of applicable professional-services fees. Swipesum has no obligation to provide raw card data, encryption keys, or portable tokens.
7.10. Aggregated and Deidentified Data. Swipesum may create and use data that has been aggregated or deidentified so that it cannot reasonably identify Customer or an individual ("Aggregated Data") for analytics, benchmarking, fraud prevention, security, service improvement, research, and other lawful business purposes. Swipesum will not attempt to reidentify deidentified data except to test deidentification as permitted by Applicable Law.
7.11. Compliance Evidence and Audits. Upon reasonable request, Swipesum may provide available third-party audit reports, certifications, or summaries subject to confidentiality restrictions. Customer may conduct a direct audit only where required by Applicable Law, no more than once annually absent a confirmed incident, after exhausting available reports, on reasonable notice, during business hours, without access to other customers' data or Swipesum trade secrets, and at Customer's expense. Customer will reasonably cooperate with Swipesum, Service Provider, Payment Network, regulator, and bank audit or information requests relating to Customer's use of the Services.
7.12. Privacy Policy. Swipesum's Privacy Policy describes certain processing for which Swipesum acts as an independent controller and is incorporated to the extent applicable. If the Privacy Policy conflicts with this Section regarding Personal Data processed by Swipesum solely on Customer's behalf, this Section controls.
7.13. Processing Details. The subject matter of processing is the Customer Data needed to provide the selected Services. Processing continues for the applicable term and any lawful retention period. The nature and purposes may include account and profile administration; onboarding and identity verification; transaction submission, routing, authorization messaging, authentication, tokenization, credential updating, fraud and risk screening, processing, settlement support, chargeback and dispute support; reporting, analytics, audit, support, security, billing, service improvement, and compliance. Data subjects may include Customer and Merchant personnel, beneficial owners, contractors, End Customers, End Users, cardholders, consumers, and payors. Personal Data may include identity and contact information; business, ownership, licensing, tax, and compliance information; bank-account and payment-card information; tokens and other payment credentials; transaction, order, authentication, risk, fraud, chargeback, and settlement information; device, browser, IP-address, geolocation, and usage information; account credentials; and support communications. Processing occurs continuously or as data is submitted or generated in connection with the Services.
8.1. Swipesum and Service Provider Ownership. Swipesum and its licensors and Service Providers retain all right, title, and interest in and to the Platform, Services, Documentation, APIs, software, systems, data models, reports, templates, designs, trademarks, technology, improvements, and all related intellectual-property and proprietary rights. The Services are licensed, not sold. Customer acquires no ownership interest in the Services or any upstream agreement, merchant account, gateway system, or Service Provider technology.
8.2. Customer Ownership. As between the parties, Customer retains its rights in Customer Products, Customer Data, and Customer marks. Customer represents and warrants that it has all rights necessary for Swipesum and its Service Providers to use Customer Data, Customer Products, and Customer marks as permitted by the Agreement and that such use will not infringe or violate any third-party right.
8.3. Customer Marks. Customer grants Swipesum and its Service Providers a non-exclusive, worldwide, royalty-free license during the applicable term to use Customer's name, marks, and branding as necessary to configure, co-brand where authorized, operate, support, and provide the Services and to identify Customer as a Swipesum customer in customer lists and standard marketing materials. A detailed case study, press release, or use that reasonably suggests Customer's endorsement requires Customer's prior consent unless an Order Form states otherwise.
8.4. Feedback. Customer may provide ideas, suggestions, requests, or feedback. Customer grants Swipesum a perpetual, irrevocable, worldwide, transferable, sublicensable, royalty-free right to use and exploit feedback without restriction or obligation, provided Swipesum does not publicly identify Customer as the source without consent.
8.5. Third-Party and Open-Source Components. The Services may include or interoperate with third-party or open-source components. Third-party and open-source license terms govern those components to the extent required by their licenses. Swipesum is not responsible for third-party products or services not controlled by Swipesum.
8.6. Marks and Branding Restrictions. Customer will not use the name, logo, trademark, domain, or other mark of Swipesum, a Payment Network, an Acquirer, or a Service Provider except as expressly authorized in writing and in accordance with applicable branding guidelines. Customer will immediately cease such use upon request or termination.
9.1. Confidential Information. "Confidential Information" means non-public information disclosed by or on behalf of a party or a Service Provider that is designated confidential or should reasonably be understood to be confidential, including pricing, Order Forms, Customer Data, Personal Data, security information, APIs, Documentation, software, technical information, business plans, financial information, and trade secrets.
9.2. Protection and Use. The receiving party will use Confidential Information only to perform or exercise rights under the Agreement; protect it using at least reasonable care and no less than the care used for its own similar information; and disclose it only to personnel, professional advisers, financing sources, auditors, Affiliates, and subcontractors with a need to know who are bound by confidentiality obligations at least as protective as these Terms. The receiving party is responsible for their compliance.
9.3. Exclusions. Confidential Information does not include information the receiving party can document: (a) was lawfully known without restriction before disclosure; (b) becomes public without breach; (c) is received lawfully from a third party without confidentiality duty; or (d) is independently developed without use of Confidential Information.
9.4. Required Disclosure. A receiving party may disclose Confidential Information as required by law, court order, regulator, Payment Network, Acquirer, sponsor bank, or Service Provider requirement. Where legally permitted and reasonably practicable, it will provide advance notice and reasonable assistance to seek protective treatment. Swipesum may disclose Customer information to Service Providers and authorities without notice where needed for the Services, risk management, fraud prevention, compliance, or an investigation.
9.5. Duration and Remedies. Confidentiality obligations continue for five (5) years after disclosure; obligations for trade secrets, Personal Data, payment data, credentials, and security information continue for so long as the information remains protected under Applicable Law or retains its confidential nature. Unauthorized use or disclosure may cause irreparable harm, and the disclosing party may seek injunctive relief in addition to other remedies.
9.6. Return and Destruction. Upon termination or request, the receiving party will return or destroy Confidential Information where reasonably practicable, except copies retained in routine backups or as required by law, the Rules, or legitimate record-retention policies, which remain subject to this Section.
10.1. Compliance with Laws and Rules. Customer will comply with Applicable Law, the Rules, the Documentation, and Swipesum security and compliance requirements, as each may change. Customer will not use the Services in a manner that causes Swipesum or a Service Provider to violate any requirement or incur an investigation, fine, assessment, penalty, loss, or reputational harm.
10.2. Sanctions, Export Controls, and Anti-Corruption. Customer will not provide the Services to, transact with, or act for any person or jurisdiction subject to applicable sanctions or export restrictions and will comply with anti-bribery, anti-corruption, anti-money-laundering, tax-evasion-prevention, and terrorist-financing laws. Customer will not offer, promise, pay, solicit, or accept anything of value to obtain an improper advantage.
10.3. Prohibited and High-Risk Businesses. Swipesum may decline, condition, restrict, or terminate Services for any business, product, person, location, or activity prohibited by Applicable Law, the Rules, a Service Provider, or Swipesum policy, or that Swipesum reasonably determines creates unacceptable legal, financial, fraud, security, operational, competitive, or reputational risk.
10.4. Information and Screening. Customer will provide accurate and complete ownership, control, identity, licensing, financial, business, transaction, and compliance information requested by Swipesum or a Service Provider and promptly report material changes. Swipesum and its Service Providers may conduct identity, sanctions, business, background, credit, and risk checks on Customer, beneficial owners, controllers, personnel, Merchants, and End Customers. Customer represents that it has obtained any consent required to provide personal information or authorize a consumer report and will provide evidence upon request.
10.5. Programs and Monitoring. Where Customer provides Services to Merchants or End Customers, Customer will maintain risk-based KYC, KYB, AML, sanctions, fraud, transaction-monitoring, and complaint-management programs appropriate to its role and required by the Rules. Customer will maintain records and provide evidence of those programs on request.
10.6. Inspections and Remediation. Customer will cooperate with reasonable audits, inspections, information requests, remediation plans, and investigations by Swipesum, Service Providers, Payment Networks, financial institutions, or regulators. Swipesum may require corrective action, additional controls, reserves, restrictions, or suspension where reasonably necessary.
11.1. Use of Service Providers. Swipesum may use Service Providers to perform any portion of the Services and may change Service Providers without Customer consent, subject to Applicable Law and any express Order Form commitment. Customer authorizes Swipesum to share information and instructions with Service Providers as necessary for the Services.
11.2. Third-Party Agreements. A third-party product, payment method, Acquirer, processor, bank, wallet, device, telecommunications service, or other service may require Customer to enter into a separate agreement. Swipesum is not a party to, and has no responsibility under, an agreement between Customer and a third party. Customer is responsible for complying with third-party terms.
11.3. Dependencies. The Services may depend on Payment Networks, Acquirers, issuers, processors, banks, cloud providers, internet and telecommunications networks, devices, and other systems outside Swipesum's control. Swipesum is not responsible for their acts or omissions, availability, decisions, delays, outages, data, fees, settlement, or performance.
11.4. No Upstream Rights. Customer is not a party to or third-party beneficiary of any agreement between Swipesum and a Service Provider and has no direct right against a Service Provider arising from the Agreement. Customer will look solely to Swipesum for contractual claims under the Agreement, subject to its limitations. Customer will not represent that a Service Provider has any direct obligation to Customer, a Merchant, an End Customer, or an End User.
11.5. Service Provider Beneficiaries. Swipesum's affiliates, licensors, Payment Networks, Acquirers, processors, sponsor banks, and other Service Providers are intended third-party beneficiaries of provisions that protect their intellectual property, Confidential Information, data, systems, marks, legal and regulatory interests, disclaim warranties, limit liability, require indemnification, or authorize suspension or termination, and may enforce those provisions directly.
12.1. Authority. Each party represents that it has authority to enter into the Agreement and perform its obligations.
12.2. Customer Warranties. Customer represents and warrants that: (a) all information and instructions it provides are true, accurate, complete, and authorized; (b) Customer and its use of the Services comply with the Agreement, Applicable Law, and the Rules; (c) Customer has all rights, notices, consents, licenses, and permissions required for Customer Data, Customer Products, transactions, and End Customers; (d) transactions are bona fide and relate to lawful goods or services; and (e) Customer will not make a representation, warranty, promise, or guarantee concerning the Services beyond the Agreement and Documentation.
12.3. DISCLAIMER. EXCEPT AS EXPRESSLY STATED IN AN ORDER FORM SIGNED BY AN AUTHORIZED OFFICER OF SWIPESUM, THE PLATFORM, SERVICES, DOCUMENTATION, REPORTS, RECOMMENDATIONS, AND ALL RELATED TECHNOLOGY ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, SWIPESUM AND ITS SERVICE PROVIDERS DISCLAIM ALL EXPRESS, IMPLIED, STATUTORY, AND OTHER WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, COMPLETENESS, SECURITY, AVAILABILITY, UNINTERRUPTED OR ERROR-FREE OPERATION, COMPATIBILITY, AND RESULTS. SWIPESUM DOES NOT WARRANT THAT THE SERVICES WILL PREVENT FRAUD, CHARGEBACKS, DATA LOSS, OR SECURITY INCIDENTS; THAT A TRANSACTION WILL BE AUTHORIZED, SETTLED, FUNDED, OR COLLECTIBLE; THAT A MERCHANT OR PAYMENT METHOD WILL BE APPROVED; OR THAT CUSTOMER WILL ACHIEVE SAVINGS, REVENUE, OR ANY PARTICULAR BUSINESS OUTCOME.
12.4. Third-Party and Network Disclaimer. Swipesum makes no warranty concerning a Service Provider, Payment Network, Acquirer, processor, bank, issuer, third-party application, device, public network, or other third-party product or service. Customer may not rely on a representation made by a reseller, sales agent, Service Provider, or other third party that conflicts with the Agreement.
12.5. Sole Remedy for Material Nonconformity. If a paid Service materially fails to conform to express Documentation due solely to Swipesum and Customer promptly notifies Swipesum, Swipesum will use commercially reasonable efforts to correct the material nonconformity. If Swipesum cannot do so within a reasonable period, Customer may terminate the affected Service. This is Customer's exclusive remedy for service interruption, outage, delay, or nonconformity, except as expressly stated in a separate service-level agreement.
13.1. Customer Indemnification. Customer will defend, indemnify, and hold harmless Swipesum, its affiliates, and their respective Service Providers, officers, directors, employees, agents, successors, and assigns from and against all claims, demands, actions, investigations, losses, liabilities, damages, judgments, settlements, penalties, fines, assessments, chargebacks, costs, and expenses, including reasonable attorneys' fees, arising out of or relating to: (a) Customer's or any Merchant's, End Customer's, End User's, Customer Product's, personnel's, or agent's access to or use of the Services; (b) Customer Data, transactions, goods, services, marketing, refunds, recurring-payment practices, or End User claims; (c) fraud, card testing, unauthorized transactions, chargebacks, Merchant Losses, security incidents, or prohibited activity associated with Customer or parties under its control; (d) Customer's breach of the Agreement, Applicable Law, the Rules, or a third-party agreement; (e) a claim that Customer Data, Customer Products, or Customer materials infringe or violate a third-party right; (f) inaccurate, incomplete, illegal, or unauthorized data or instructions; (g) a Merchant Agreement or Customer's relationship with a Merchant, End Customer, or End User; or (h) any fee, fine, assessment, penalty, tax, or other amount imposed on Swipesum or a Service Provider because of Customer or parties under Customer's control. Payment Network and Service Provider fines and assessments are direct damages and are not subject to any exclusion of consequential damages or liability cap applicable to Customer.
13.2. Swipesum IP Indemnification. Swipesum will defend Customer against a third-party claim that Customer's authorized use of a paid Service, as provided by Swipesum and used in accordance with the Agreement and Documentation, directly infringes a United States patent, copyright, or trademark, and will pay damages finally awarded or settlements approved by Swipesum. Swipesum has no obligation for a claim arising from Customer Data, Customer Products, third-party components, modifications not made by Swipesum, use outside the Agreement or Documentation, continued use after notice, or combination with items not supplied by Swipesum. If a Service is or may be subject to such a claim, Swipesum may modify or replace it, obtain continued rights, or terminate the affected Service and refund prepaid recurring Fees for the unused terminated period. This Section states Swipesum's entire liability and Customer's exclusive remedy for intellectual-property claims.
13.3. Procedure. The indemnified party will promptly notify the indemnifying party, provide reasonable cooperation at the indemnifying party's expense, and permit the indemnifying party to control the defense and settlement. Delay in notice relieves obligations only to the extent materially prejudicial. The indemnifying party may not settle a claim in a manner that admits wrongdoing or imposes a non-monetary obligation on the indemnified party without consent, not to be unreasonably withheld.
14.1. EXCLUSION OF DAMAGES. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER SWIPESUM NOR ANY SERVICE PROVIDER WILL BE LIABLE UNDER ANY THEORY FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES; LOSS OF PROFITS, REVENUE, SAVINGS, BUSINESS, GOODWILL, REPUTATION, OPPORTUNITY, OR ANTICIPATED BENEFIT; COST OF SUBSTITUTE SERVICES; LOSS, CORRUPTION, OR UNAVAILABILITY OF DATA; BUSINESS INTERRUPTION; OR CLAIMS OR LOSSES SUFFERED BY A THIRD PARTY, EVEN IF ADVISED OF THE POSSIBILITY.
14.2. TRANSACTION AND THIRD-PARTY EXCLUSIONS. SWIPESUM AND ITS SERVICE PROVIDERS WILL NOT BE LIABLE FOR THE VALUE OF ANY TRANSACTION OR FUNDS; FRAUD, CHARGEBACKS, REFUNDS, REVERSALS, DECLINES, DUPLICATE OR FAILED TRANSACTIONS; FAILURE OR DELAY IN AUTHORIZATION, AUTHENTICATION, ROUTING, PROCESSING, CLEARING, SETTLEMENT, FUNDING, TOKENIZATION, ACCOUNT UPDATING, OR FRAUD SCREENING; CUSTOMER OR MERCHANT GOODS OR SERVICES; OR ANY ACT, OMISSION, DECISION, OUTAGE, OR FAILURE OF A PAYMENT NETWORK, ACQUIRER, PROCESSOR, BANK, ISSUER, TELECOMMUNICATIONS PROVIDER, CLOUD PROVIDER, SERVICE PROVIDER, CUSTOMER SYSTEM, MERCHANT SYSTEM, END USER, OR OTHER THIRD PARTY, EXCEPT TO THE EXTENT DIRECTLY CAUSED BY SWIPESUM'S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT AND LIABILITY CANNOT BE DISCLAIMED BY LAW.
14.3. LIABILITY CAP. TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE TOTAL AGGREGATE LIABILITY OF SWIPESUM, ITS AFFILIATES, AND ALL SERVICE PROVIDERS ARISING OUT OF OR RELATING TO THE AGREEMENT OR SERVICES WILL NOT EXCEED THE GREATER OF: (A) ONE THOUSAND DOLLARS ($1,000); OR (B) THE FEES PAID BY CUSTOMER TO SWIPESUM FOR THE AFFECTED SERVICE DURING THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO LIABILITY. THE CAP APPLIES IN THE AGGREGATE TO ALL CLAIMS AND DOES NOT INCREASE BECAUSE MORE THAN ONE CLAIM, THEORY, SERVICE, OR PARTY IS INVOLVED.
14.4. Customer Obligations Not Limited. The exclusions and cap in this Section do not limit Customer's obligations to pay Fees, taxes, Merchant Losses, chargebacks, refunds, fines, assessments, indemnification amounts, or other third-party amounts; Customer's liability for breach of Sections 3.5 through 3.7, 4, 5, 7, 8, 9, 10, 19, 20, or 21; Customer's fraud, willful misconduct, gross negligence, or violation of law; or any liability that cannot lawfully be limited. Nothing limits either party's liability for death or bodily injury caused by its negligence or for fraud to the extent liability cannot be limited by law.
14.5. Allocation of Risk. The Fees and commercial terms reflect this allocation of risk. The limitations apply even if a limited remedy fails of its essential purpose and to the maximum extent permitted regardless of the form of action.
15.1. Suspension Rights. Swipesum may immediately suspend, restrict, rate-limit, disable, or refuse any Service, account, Merchant, End Customer, user, credential, transaction, payment method, integration, or data flow, with or without notice, if Swipesum reasonably determines that: (a) Customer has breached or is likely to breach the Agreement; (b) Fees are overdue; (c) fraud, card testing, unauthorized access, abuse, or a security incident has occurred or may occur; (d) Customer fails to implement a required update or maintain a supported Acquirer, processor, device, or integration; (e) suspension is requested or required by a Service Provider, Payment Network, financial institution, regulator, or Applicable Law; (f) Customer or its activity creates legal, regulatory, financial, security, operational, competitive, or reputational risk; (g) continued use may harm the Services or another person; or (h) Swipesum needs to investigate or prevent loss.
15.2. Scope and Liability. Swipesum may tailor a suspension to the affected Service, Merchant, account, user, or transaction, but is not required to do so. Swipesum is not liable for losses arising from a good-faith suspension or protective action. Suspension does not relieve Customer of accrued or ongoing obligations, including committed Fees and minimums.
15.3. Reinstatement. Swipesum may condition reinstatement on payment, remediation, additional controls, updated information, testing, certification, reserves, a modified Order Form, or approval from a Service Provider. Swipesum is not obligated to reinstate a Service.
16.1. Term. The Agreement begins on the Effective Date and continues while any Order Form or Service remains in effect. Each Order Form continues for the term and renewal structure stated in it. Unless an Order Form expressly states otherwise, the initial term for the applicable Services is three (3) years from the Effective Date and automatically renews for successive two (2)-year periods unless either party gives at least sixty (60) days' written notice of non-renewal before the current term ends. Early-termination fees, minimum commitments, and non-cancelable obligations stated in an Order Form remain enforceable.
16.2. Termination for Cause. Either party may terminate an affected Order Form for the other party's material breach if the breach remains uncured twenty (20) days after written notice. Swipesum may terminate immediately for fraud, prohibited activity, security risk, insolvency, loss of required licenses or approvals, repeated breach, non-curable breach, or failure to pay after a reasonable cure period.
16.3. Service Provider, Legal, and Product Changes. Swipesum may terminate an affected Service immediately or on such notice as is practicable if a Service Provider relationship, license, supported Acquirer, Payment Network approval, legal requirement, or material technical dependency ends or changes; if continued performance becomes unlawful, commercially unreasonable, or materially risky; or if Swipesum discontinues the Service generally. If Swipesum terminates a prepaid Service under this Section for reasons not caused by Customer, Customer's sole remedy is a pro rata refund of prepaid recurring Fees for the unused terminated period, excluding setup, usage, pass-through, professional-services, and non-refundable Fees.
16.4. Effect of Termination. Upon termination: (a) Customer will stop using the affected Services, APIs, Documentation, credentials, and marks; (b) all accrued and committed amounts become due; (c) licenses end; (d) each party will handle Confidential Information and Personal Data as required by Sections 7 and 9; and (e) Customer will cooperate in an orderly wind-down. Swipesum may retain access necessary to complete pending settlement, chargebacks, refunds, investigations, data retention, and compliance obligations.
16.5. Data and Token Migration. Any data export, token migration, credential transfer, or transition assistance is subject to Applicable Law, the Rules, Service Provider capabilities and approval, security validation, technical feasibility, payment of all amounts due, and Swipesum's then-current professional-services fees. Tokens, cryptograms, credentials, and payment data may be non-portable, and Swipesum has no obligation to export raw payment-card data.
16.6. Survival. Provisions that by their nature should survive will survive, including payment obligations, data and record obligations, intellectual property, confidentiality, warranties and disclaimers, indemnification, limitations of liability, dispute resolution, and general provisions.
17.1. Informal Resolution. Before initiating arbitration, a party will provide written notice describing the dispute and requested relief and allow at least thirty (30) days for good-faith informal resolution, unless emergency injunctive relief is reasonably necessary.
17.2. Binding Arbitration. Except for the exclusions below, any dispute arising out of or relating to the Agreement, Services, transactions, or the parties' relationship will be resolved by binding arbitration under the Federal Arbitration Act and the Commercial Arbitration Rules of the American Arbitration Association ("AAA"). A single arbitrator will decide the dispute. The arbitrator may award any individual relief available in court, subject to the Agreement, and the award may be entered in any court with jurisdiction.
17.3. Appeal of Large Award. If an award exceeds $1,000,000, either party may appeal to a three-arbitrator appellate panel administered by AAA by filing written notice within thirty (30) days after the award. The panel's decision is final, subject to rights under the Federal Arbitration Act.
17.4. Individual Proceedings Only. ALL CLAIMS MUST BE BROUGHT IN AN INDIVIDUAL CAPACITY. THERE IS NO RIGHT OR AUTHORITY FOR A DISPUTE TO BE ARBITRATED OR LITIGATED AS A CLASS, COLLECTIVE, CONSOLIDATED, JOINT, MASS, PRIVATE-ATTORNEY-GENERAL, OR REPRESENTATIVE ACTION. PROCEEDINGS MAY NOT BE COMBINED WITHOUT THE WRITTEN CONSENT OF ALL PARTIES. AN ARBITRATOR MAY AWARD INJUNCTIVE RELIEF ONLY TO THE INDIVIDUAL PARTY AND ONLY AS NECESSARY TO RESOLVE THAT PARTY'S CLAIM.
17.5. Location and Costs. Arbitration will take place in St. Louis, Missouri, unless the parties agree otherwise. Each party will initially bear its own fees and costs, subject to the arbitrator's authority to award fees and costs where authorized by the Agreement or law.
17.6. Excluded Claims. Either party may bring an eligible individual claim in small-claims court. A party may seek temporary or injunctive relief in a court of competent jurisdiction to protect Confidential Information, intellectual property, data, security, or systems, without waiving arbitration of other claims. Questions concerning the scope or enforceability of this arbitration section are for a court, unless Applicable Law requires otherwise.
17.7. Time Limit. To the maximum extent permitted by law, a claim must be brought within one (1) year after the claimant knew or reasonably should have known of the facts giving rise to the claim, or it is permanently barred. This limit does not apply to Swipesum's collection of unpaid amounts, indemnification claims, intellectual-property misuse, fraud, or claims that cannot lawfully be shortened.
17.8. Governing Law; Jury Waiver. The Agreement is governed by Missouri law, without regard to conflict-of-law principles. Court proceedings permitted under this Section must be brought exclusively in state or federal courts located in St. Louis, Missouri, and each party consents to jurisdiction and venue. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY KNOWINGLY AND IRREVOCABLY WAIVES TRIAL BY JURY.
18.1. Changes to These Terms. Swipesum may update these Terms by posting a revised version and providing notice through email, the Platform, an account portal, an Order Form, or another reasonable channel. A change may take effect immediately if required by Applicable Law, the Rules, a Service Provider, security, fraud prevention, or technical necessity; otherwise, a material change will take effect no earlier than thirty (30) days after notice. Continued use after the effective date constitutes acceptance. A change will not modify pricing or a committed commercial term in a signed Order Form except as permitted by that Order Form or Section 6.3.
18.2. Assignment. Customer may not assign, delegate, transfer, or undergo a change of control affecting the Agreement without Swipesum's prior written consent, which may be conditioned on due diligence, risk review, and updated documentation. An unauthorized assignment is void. Swipesum may assign or delegate the Agreement, in whole or part, to an affiliate, successor, financing source, or third party in connection with a reorganization, sale, or transfer of the applicable business or Services.
18.3. Notices. Operational and contractual notices may be delivered by email to an address on file, through the Platform or account portal, or by another standard electronic channel and are deemed delivered when sent or posted. Formal notices of breach, termination for cause, indemnity, or arbitration must also be sent by nationally recognized overnight courier or certified mail to the address in the applicable Order Form or the current address designated by the receiving party. Notices to Swipesum must be addressed to "Legal." Customer will keep its contact information current.
18.4. Force Majeure. Swipesum is not liable for delay or failure caused by events beyond its reasonable control, including natural disasters, fire, war, terrorism, civil unrest, labor disputes, epidemics, governmental action, sanctions, utility or telecommunications failure, internet or cloud outage, Payment Network or financial-institution failure, Service Provider failure, cyberattack, denial-of-service attack, malware, or widespread security incident.
18.5. Independent Contractors; No Agency. The parties are independent contractors. The Agreement does not create a partnership, joint venture, fiduciary, franchise, agency, employment, or exclusive relationship. Customer has no authority to bind Swipesum or a Service Provider or make a representation, warranty, or commitment on their behalf.
18.6. Entire Agreement and No Reliance. The Agreement is the entire agreement concerning its subject matter and supersedes prior or contemporaneous proposals, discussions, and understandings concerning that subject matter. Customer acknowledges that it is not relying on a statement, promise, forecast, savings estimate, or representation not expressly included in the Agreement.
18.7. Waiver and Severability. A waiver must be in writing and applies only to the specific instance. If a provision is unenforceable, it will be modified to the minimum extent necessary and the remaining provisions will remain effective.
18.8. Cumulative Remedies. Except where the Agreement states an exclusive remedy, remedies are cumulative. Swipesum may seek equitable relief to protect its or a Service Provider's intellectual property, Confidential Information, data, security, systems, and legal or regulatory interests.
18.9. Construction. Headings are for convenience only. "Including" means "including without limitation." The singular includes the plural and vice versa. References to a law, Rule, policy, or document include amendments and replacements. No presumption will be applied against a party because it drafted a provision.
18.10. Electronic Acceptance and Counterparts. Electronic acceptance, electronic signatures, PDF signatures, and counterparts are effective and together form one agreement. A record maintained electronically by Swipesum is admissible as evidence of acceptance, use, notices, and transactions.
This Section 19 applies whenever Customer receives or uses Gateway Services.
19.1. Nature of Gateway Services. Gateway Services receive payment and related requests from Customer systems or devices, validate and route those requests to a supported Acquirer, processor, Payment Network, or other destination, receive responses, and return those responses to Customer. Gateway Services may include portals, reports, tokenization, stored credentials, account updater, authentication, fraud screening, and other features identified in an Order Form or Documentation.
19.2. Gateway Is Not Acquiring or Settlement. Unless an Order Form expressly includes separate Processing Services, the Gateway Services do not include merchant acquiring, underwriting, authorization decisioning by an issuer, clearing, settlement, funding, chargeback handling, or deposit services. Swipesum is not a bank, issuer, Acquirer, or money transmitter merely by providing Gateway Services. Authorization or successful transmission does not guarantee settlement, funding, final payment, or validity.
19.3. Merchant Account and Supported Acquirer. Customer must maintain a valid agreement and account with a supported Acquirer or processor and provide accurate merchant identifiers, terminal identifiers, credentials, routing information, and configuration data. Gateway Services may be available only while that relationship remains valid and supported. Swipesum may suspend or terminate Gateway Services without liability if the Acquirer, processor, Payment Network, or other relevant provider no longer accepts Customer's messages or supports the configuration.
19.4. Gateway Accounts and Approved Use. Each gateway account, merchant profile, MID, or similar identifier may be used only by the approved Merchant, legal entity, location, business model, and use case. Customer may not use one account to process for multiple merchants or third parties, operate a marketplace or payment intermediary, or aggregate transactions unless an Order Form expressly authorizes that model.
19.5. Gateway Transactions and Billing. Gateway Transactions are billable as stated in the applicable Order Form. Unless the Order Form states otherwise, a Gateway Transaction becomes billable when the Gateway Service returns an authentication, approval, decline, error, or other processor or system response. Each authorize, capture, refund, void, verification, authentication, fraud check, token retrieval, or other operation may be billed separately, even when related to the same payment attempt. An operation that fails solely because of an error within the Gateway Service before any response is returned will not be treated as a billable Gateway Transaction.
19.6. Transaction Responsibility. Customer is responsible for transaction content, authorization, accuracy, duplicates, retries, refunds, reversals, settlement instructions, reconciliation, and compliance with the applicable Acquirer and Payment Network requirements. Customer will not rely solely on the Gateway Services as its system of record and will retain and reconcile its own records. Swipesum may rely on transaction instructions submitted through Customer credentials.
19.7. Card Testing, Credits, and Fraudulent Use. Customer will maintain controls to prevent card testing, enumeration, credential attacks, automated fraud, and unauthorized access. Customer will not submit a credit or refund that does not correspond to a bona fide underlying transaction unless Swipesum and the applicable Acquirer expressly approve it. Swipesum may block, delay, decline, rate-limit, reverse, or suspend activity reasonably suspected to be fraudulent, abusive, unauthorized, or inconsistent with the Rules. Customer is responsible for related Fees, assessments, and losses.
19.8. Tokenization and Stored Credentials. Where tokenization or vault services are enabled, Customer authorizes Swipesum and Service Providers to store or manage tokenized payment credentials on Customer's and its Merchants' behalf. Customer will comply with stored-credential, recurring-payment, account-updater, and credential-on-file Rules; obtain required End User consent; provide required notices; honor revocation and deletion requests; and maintain evidence of consent. Tokens may be restricted to particular systems, Acquirers, Payment Networks, or use cases and may not be portable. Tokenization does not eliminate Customer's PCI responsibilities.
19.9. Account Updater, Authentication, and Fraud Services. Account updater, EMV 3-D Secure, fraud screening, and similar tools may use issuer, device, browser, behavioral, identity, and transaction data. Customer authorizes that processing and is responsible for lawful notices and consents. Results may be incomplete, delayed, unavailable, or inaccurate and do not guarantee an approval, identity, absence of fraud, liability shift, or successful update. Customer is responsible for settings and transaction decisions.
19.10. Wallets, Network Tokens, Device Payments, and Alternative Methods. Wallets, network tokens, Click to Pay, device payments, alternative payment methods, and other optional features are subject to availability, eligibility, technical requirements, Payment Network and provider terms, and additional Fees in the Order Form. Customer will enter into any required provider agreement and will not impose a fee or condition prohibited by the applicable Rules. A provider may suspend, change, or discontinue a feature without liability to Swipesum.
19.11. Portals, Reports, and Data Retention. Gateway portals and reports are operational tools and may display only a limited period of history. Customer will download and retain records it needs. Swipesum may correct, remove, or reprocess data and is not responsible for errors in data supplied by Customer, an Acquirer, processor, issuer, Payment Network, or other third party.
19.12. Availability and Maintenance. Gateway Services are network-based and may be interrupted by maintenance, upgrades, cyberattacks, third-party failures, or events outside Swipesum's control. Swipesum may perform scheduled or emergency maintenance and apply fixes, enhancements, or security changes. No specific availability commitment applies unless stated in a separate signed service-level agreement.
19.13. Testing Environments. Sandbox, test, certification, preview, or non-production environments are provided solely for testing and may be reset, modified, restricted, or unavailable at any time. Customer will use only test credentials and test data unless the Documentation expressly permits otherwise and will not submit live payment credentials or Personal Data to a non-production environment. Successful testing does not guarantee production approval, compatibility, or performance.
This Section 20 applies when an Order Form includes payment processing, merchant account, payment facilitation, settlement, sub-merchant boarding, risk, residual, or Swipesum Connect services (collectively, "Processing and Connect Services").
20.1. Processing Structure. Processing and Connect Services may be provided by Swipesum together with an Acquirer, processor, sponsor bank, or other Service Provider. Customer and each Merchant must execute and comply with any required Merchant Agreement, underwriting application, bank agreement, or Payment Network disclosure. Those agreements may impose additional rights, obligations, reserves, and termination provisions.
20.2. Merchant Boarding and Approval. Customer will submit complete and accurate onboarding information and assist Merchants in providing required documentation. Swipesum and its Service Providers may approve, condition, decline, suspend, or terminate any Merchant or payment method in their discretion subject to Applicable Law and the Rules. Customer will not promise approval, rates, funding, settlement timing, or continued service.
20.3. Merchant Solicitation and Agreements. Customer will market and solicit Processing and Connect Services only in the manner approved by Swipesum and permitted by the Rules. Unless the applicable structure expressly permits Customer to contract in its own name, each Merchant will enter into a Merchant Agreement with Swipesum or the applicable Service Provider, and the merchant account and Merchant Agreement rights will be controlled by the applicable contracting party. Customer has no ownership interest in a Merchant Agreement or merchant account except as expressly stated in an Order Form or separate written agreement.
20.4. Registered Payment Facilitators. If Customer has its own sponsor relationship and is registered with the Payment Networks as a payment facilitator, the Order Form may limit Swipesum's role to technology or program services and exclude authorization, acquiring, clearing, settlement, or sponsor-bank services. Customer will be solely responsible for its merchant agreements, underwriting, KYC, KYB, AML, sanctions, monitoring, tax reporting, reserves, settlement, compliance, and Merchant Losses except as expressly stated otherwise. Customer merchant agreements must contain the protections required by Section 21.
20.5. Settlement, Holds, and Reserves. Settlement and funding are performed by financial institutions or processors and are subject to received funds, chargebacks, reserves, holds, fraud reviews, cutoff times, banking days, Payment Network rules, and Merchant Agreements. Funds may be held in custodial, settlement, or for-benefit-of accounts controlled by financial-institution partners. Swipesum does not guarantee settlement timing and may delay instructions, withhold amounts, or assist a Service Provider in applying a reserve or hold as permitted by the applicable agreements and Rules.
20.6. Merchant Losses. Customer is fully responsible for Merchant Losses caused in whole or part by Customer, Customer Products, Customer personnel, Customer instructions, a Customer security incident, inaccurate onboarding information, failure to follow the Rules, or an unenforceable or deficient customer merchant agreement. Other Merchant Losses may be allocated as stated in the Order Form or Merchant Agreement and may be deducted from merchant funds, residuals, revenue share, reserves, or other amounts payable to Customer. Swipesum may debit or invoice Customer for amounts Customer owes.
20.7. Residual and Program Administration. Any residual or revenue-share payment is governed by Section 6.6 and the Order Form. Swipesum may rely on processor and bank reporting, adjust prior calculations, and withhold payment while an account is under review, amounts remain uncollected, or related losses or liabilities are unresolved.
20.8. Risk and Compliance Services. KYC, KYB, AML, fraud, risk, and monitoring services assist with compliance but do not shift Customer's independent obligations or guarantee that a person or transaction is legitimate or compliant. Customer will promptly respond to requests, report suspicious activity to the appropriate party where required, and follow instructions concerning suspension, reserves, remediation, or termination.
This Section 21 applies whenever an Order Form authorizes Customer to market, distribute, embed, white label, resell, sublicense, administer, or otherwise make any Service available to an End Customer.
21.1. Limited Distribution Right. Customer may provide authorized End Customers access only to the Services, Territory, business models, and use cases approved in the Order Form and Documentation. Any right to sublicense an API, SDK, portal, or Documentation is limited to the minimum access necessary for the End Customer to receive the authorized Service and does not permit further resale or sublicensing.
21.2. Required End-Customer Agreement. Before enabling an End Customer, Customer will enter into a legally enforceable written agreement with that End Customer containing provisions at least as protective of Swipesum and its Service Providers as the Agreement in all material respects. At a minimum, the agreement must address: authorized use and territory; confidentiality; API, SDK, Documentation, intellectual-property and mark restrictions; credentials and security; PCI and data protection; stored credentials and required consents; compliance with Applicable Law, the Rules, and Service Provider requirements; prohibited use and card testing; transaction and merchant responsibility; third-party dependencies; suspension and termination; warranty disclaimers; limitations of liability; indemnification; and the right of Swipesum and Service Providers to enforce protective provisions. Customer will provide its template and executed copies to Swipesum upon reasonable request.
21.3. Responsibility for End Customers. Customer is exclusively responsible for its relationship with End Customers, its own products and fees, and all acts and omissions of End Customers and their personnel. An End Customer's act or omission is deemed Customer's act or omission for purposes of the Agreement. Customer will defend and indemnify Swipesum and Service Providers from End Customer and End User claims relating to the Services or Customer's offering.
21.4. No Agency or Additional Promises. Customer will not represent that it is an agent of a Service Provider, pledge a Service Provider's credit, bind Swipesum or a Service Provider, or make a promise, warranty, service level, liability commitment, or representation concerning the Services beyond the Agreement and Documentation. Customer is solely responsible for any additional commitment it makes.
21.5. End-Customer Eligibility and Monitoring. Customer will conduct appropriate due diligence before enabling an End Customer, maintain required programs under Section 10, monitor use, promptly notify Swipesum of additions and removals, and prevent access by prohibited persons or businesses. Swipesum may require Customer to reject, suspend, or terminate an End Customer, including where access creates legal, security, financial, competitive, intellectual-property, or reputational risk.
21.6. Data and Portal Access. Customer will obtain all rights and consents necessary for Customer and Swipesum to access, administer, and process End Customer and transaction data through partner or merchant portals. Customer is responsible for the accuracy of data entered into a portal and for restricting portal access to authorized personnel.
21.7. Support. Unless an Order Form states otherwise, Customer will provide first-line onboarding, support, troubleshooting, and communications to End Customers. Customer will use commercially reasonable efforts to diagnose and resolve an issue before escalating it to Swipesum and will provide information reasonably requested. No Service Provider has a direct support obligation to Customer or an End Customer.
21.8. Complaints and Enforcement. Customer will promptly notify Swipesum of a material End Customer complaint or claim concerning the Services and will enforce its End Customer agreement at Swipesum's request. Customer will not settle a claim or make an admission that creates liability for Swipesum or a Service Provider without consent.
This Section 22 applies to Swipesum CPO, Swipesum Audit, statement analysis, fee auditing, benchmarking, analytics, reporting, optimization, recommendations, and similar Services.
22.1. Data-Dependent Outputs. Outputs depend on data, statements, files, contracts, assumptions, and third-party information provided or made available to Swipesum. Customer is responsible for completeness and accuracy. Swipesum may rely on the information without independent verification, and an error or omission in source information may affect the output.
22.2. Informational Nature. Reports, dashboards, classifications, alerts, recommendations, forecasts, benchmarks, and automated or artificial-intelligence-assisted outputs are informational business tools. They are not legal, tax, accounting, investment, compliance, or other regulated professional advice and do not replace Customer's independent review or professional advisers.
22.3. No Guaranteed Results. Swipesum does not guarantee savings, fee reductions, recoveries, approvals, processor performance, pricing accuracy, contract outcomes, revenue, or any other result. Benchmarks and estimates may be based on assumptions, sampling, historical data, or third-party information and may change.
22.4. Customer Decisions and Implementation. Customer is responsible for deciding whether to act on an output or recommendation, obtaining internal and third-party approvals, reviewing legal and contractual obligations, and implementing changes. Swipesum is not responsible for a third party's response, fees, performance, refusal, or implementation unless expressly assumed in an Order Form.
22.5. Automated Features. Automated and AI-assisted features may produce incomplete or inaccurate results. Customer will use appropriate human review before relying on a material output or taking an action affecting a Merchant, End User, contract, payment, compliance obligation, or financial decision.
This Section 23 applies to any Service or feature not otherwise addressed in Part II.
23.1. Additional Services. Swipesum may offer additional Services, modules, payment methods, integrations, hardware, or features under an Order Form, activation flow, addendum, or Documentation. Those Services are governed by the general Terms and any terms presented or incorporated when Customer orders, enables, or uses them.
23.2. Additional Requirements. An additional Service may require eligibility review, certification, implementation, third-party agreements, updated Documentation, additional data, or additional Fees stated in an Order Form. Customer will comply with all applicable requirements and obtain all necessary rights and consents.
23.3. Conflict. If terms specifically presented for an additional Service conflict with these Terms, the specific terms control only for that Service and only to the extent of the conflict.
23.4. Implementation and Professional Services. Unless a separate consulting agreement or statement of work controls, implementation, configuration, migration, training, custom development, and other professional services are governed by the applicable Order Form. Customer will timely provide access, information, decisions, personnel, testing, and cooperation; delays or dependencies outside Swipesum's control extend schedules and may increase Fees as stated in a change order or Order Form. Unless expressly stated otherwise, Swipesum retains ownership of its pre-existing and reusable tools, templates, code, methods, and know-how, and Customer receives only the license needed to use a deliverable with the applicable Service. A deliverable is deemed accepted unless Customer identifies a material nonconformity in reasonable detail within ten (10) business days after delivery.
23.5. Hardware and Devices. Hardware, terminals, readers, devices, and accessories are subject to the applicable Order Form, Documentation, and manufacturer or third-party terms. Unless an Order Form states otherwise, risk of loss passes to Customer upon shipment, returns require prior authorization, and Customer is responsible for installation, connectivity, physical security, tampering, damage, loss, and use. Swipesum may remotely configure, update, disable, or replace supported devices for security, compliance, or operational reasons. To the extent permitted by law, hardware warranties are limited to any transferable manufacturer warranty expressly made available to Customer.