Privacy Policy

Applies to the website at swapps.com, the Swapps mobile application for Android and iOS (package identifier com.swapps.idk), and the Swapps account that the application signs in to.

This policy replaces the previous privacy policy published at this address.

Effective date: 2026-09-03

Who is responsible for your data

Swapps USA LLC, a limited liability company incorporated in Florida, United States, is the data controller for everything described here. Its place of business is 175 SW 7th Street Ste. 1716, Miami FL 33130, United States.

Contact for anything in this policy, including requests to exercise your rights: privacy@swapps.com.

What we collect on the website

Information you type into a form. When you request a quote or contact us through the site, we receive what you enter - typically your name, email address, company, and a description of what you need - together with the page you submitted it from. We use it to answer you and to follow up commercially.

Text you send to the AI assistant. Where the site offers to improve or expand what you have written, the text you submit is sent to a large language model to produce the suggestion. See "Artificial intelligence" below.

Anti-abuse checks. Forms are protected by Google reCAPTCHA, which receives information about your interaction with the page in order to distinguish people from automated submissions.

Analytics and advertising measurement. The site loads Google Tag Manager and Google Analytics, and reports a conversion to Google Ads when a quote request is submitted. These receive information about your visit - pages viewed, approximate location derived from your IP address, device and browser, and referral source - and set cookies for that purpose.

Cloudflare Web Analytics. Every page also loads a measurement beacon served from static.cloudflareinsights.com. It reports the page you viewed, the page that referred you, and basic device, browser and page-timing information. It sets no cookies and does not follow you across other sites.

Session replay. The site loads Smartlook, which records your session so we can see how the interface is actually used: pointer movement, clicks, scrolling, the pages you move between, and the content rendered on your screen. Smartlook stores those recordings in its European Union data region. The same recording runs on the Swapps Platform web application at app.swapps.com and on go.swapps.com, where the screens it captures can include contract, rate and billing figures.

Cookies. Cookies are small files placed on your device. We use them to remember your preferences and for the analytics and advertising measurement described above. The session replay described above sets a cookie whose name begins with SL_C_ so that a recording stays tied to a single visit. You can refuse or delete cookies in your browser; the site remains usable, though parts of it may behave less conveniently. Every cookie this site sets is listed one by one in our Cookie Policy.

Newsletter and subscriptions. If you subscribe, we keep your email address in order to send you what you asked for. Every message carries an unsubscribe link, and you can also unsubscribe by writing to the address above.

What the mobile application collects

Most of the personal and content data shown in the application is something you typed, something you uploaded, or something your Swapps account already held before you installed it. The application and your device also generate the limited technical identifiers described below for sessions and notifications. The application is not a public consumer product: it is used by Swapps clients and staff to follow their own contracts, reports and support requests, and every account in it is created by Swapps rather than by self-registration.

Account and profile. Your email address, username, first and last name, job title, profile photograph, preferred language, system role, the organisations you belong to, and the contracts your account can reach. Name, surname and language are editable from the application; the rest is shown read-only.

Sign-in credentials. Your email address and password are sent to the Swapps server when you sign in. The password is not stored on the device. The session token the server returns is kept in the operating system's own protected storage - the Keychain on iOS, encrypted shared preferences on Android - and is deleted when you sign out.

Support requests. The subject, body, replies and file attachments of any support request you open or answer, together with the time each message was sent and whether you have read it.

Contract and billing information. Contract names and dates, budgets, rates, booked hours, executed tasks and instalments belonging to the contracts your account can reach. The application displays these; it does not let you change them.

Notification registration. If - and only if - you turn on notifications, the application registers a push token for the installation, the platform it is running on, and a random identifier generated on the device to tell your installations apart. That identifier is not an advertising identifier, is not derived from any hardware serial, and a reinstall produces a new one.

Crash diagnostics. When the application crashes, it sends the error, the stack trace, the application and device version, and a short trail of the preceding navigation and network calls. Sentry additionally derives an approximate location from the connection the report arrives on. All of it is subject to the constraints described in "Crash reporting" below.

What the mobile application does not collect

The application requests no location permission and never reads GPS or any device location. An approximate location is nevertheless derived from your connection when a crash report is sent, and that is described in "Crash reporting" below. It does not read your contacts, your calendar, your call history, your SMS messages, or your files beyond the images and documents you explicitly pick to attach. It contains no advertising identifier, no advertising SDK and no third-party analytics or attribution SDK, and it does not track you across other applications or websites.

The analytics, advertising measurement and session replay described in the website section are not present in the mobile application. Session replay does also run on the Swapps Platform web application at app.swapps.com and on go.swapps.com, but those are websites, reached in a browser, and not this application.

Swapps does not sell personal data, and does not share it for advertising or marketing purposes.

Permissions the application asks for

Photos and files. Asked the first time you attach an image or document to a support request, or set a profile photograph. Only the items you select are read. The application does not request camera or microphone access.

Notifications. Asked when you turn notifications on, so the application can tell you that support has replied to one of your requests. Declining it leaves every other part of the application working.

Why we use it

We use what is described above for these purposes and no others:

  • To authenticate you and keep you signed in, which is the basis for showing you your own contracts and nobody else's.
  • To show you the contracts, reports and support requests your account is entitled to see - the service you asked for.
  • To deliver and answer your support requests, including passing them to the support system Swapps operates on.
  • To notify you about activity on your own requests, if you switched notifications on.
  • To answer commercial enquiries you send us through the website, and to follow up on them.
  • To understand how the website is used and to measure the effectiveness of our advertising.
  • To find and fix crashes, so the software keeps working.

Artificial intelligence

Some features send text you have written to a large language model in order to draft, improve or summarise it. This happens on the website where a form offers to improve what you have written, and in the support workflow where the text of a request may be processed the same way.

The model used is Google Gemini, reached through a proxy that Swapps operates. Only the text needed for the feature is sent. Text sent this way is not used to train the model. On the website, the writing-assistance feature is optional and runs only when you request it. In the support workflow, the text of an incoming request may be processed automatically to classify, draft, improve or summarise it so Swapps can route and respond to the request.

Who else receives your data

Swapps uses the following processors. Each is listed with what it receives and why; none of them receives anything for its own purposes.

Front. Support requests are conversations in Front, the system Swapps runs its support desk on. Front receives the content of your requests, your replies and your attachments, and the email address and name they are attributed to.

Google. Google receives: analytics and advertising measurement data from the website, through Google Tag Manager, Google Analytics and Google Ads; reCAPTCHA interaction data from forms; on Android, the notification payload in transit and the device's messaging token, through Firebase Cloud Messaging; the text submitted to the AI features, through Gemini; and the install and crash information that Google Play collects for every application on the platform.

Apple. On iOS, notifications reach the device over the Apple Push Notification service, and the App Store distributes the application, on the same terms as Google Play above.

Expo (Expo Application Services). Push notifications are delivered through Expo's push service. Expo receives the push token for your installation and the content of the notifications sent to it. Expo also serves over-the-air updates where that is switched on for a build.

Sentry. Crash diagnostics from the mobile application. What Sentry receives is constrained deliberately - see the next section.

Smartlook. Session replay for the website and for the Swapps Platform web application. Smartlook receives the recording described in "What we collect on the website" - pointer movement, clicks, scrolling, navigation and the content rendered on screen - together with the browser and device the session ran on and the approximate location derived from the connection. Its data region is the European Union.

Cloudflare. The website and its form endpoint are served through Cloudflare, which processes requests in transit and applies security filtering. Cloudflare also provides the web analytics for the site: the beacon described above reports each page view to Cloudflare, without a cookie.

Swapps also uses ordinary infrastructure providers to host the service. They store data on Swapps' behalf and are not permitted to use it for anything else.

Crash reporting

Because the application displays contract and billing figures, its crash reporting is configured to exclude the things that would carry them. This is enforced in the application, before anything is sent.

These constraints govern crash reporting in the mobile application. They do not govern the session replay described above, which runs in the browser on the website and on the Swapps Platform web application, and which does capture what is rendered on screen.

  • You are identified in a crash report by an opaque account identifier only - never your name and never your email address. Your IP address is not stored, but Sentry derives an approximate location from it as the report arrives - a city and region, not a street or a coordinate - and keeps that. The application itself never reads or sends any location.
  • No screenshot and no view hierarchy is ever attached. A picture of this application is a picture of a contract.
  • Request and response bodies are dropped rather than filtered, because there is no useful part of a billing payload to keep.
  • Console output is not recorded, and session tokens, authorisation headers and similar credentials are replaced before a report leaves the device.
  • Performance tracing is switched off.

How long we keep it

Account, contract and support data is kept for as long as your Swapps account is active, and for as long afterwards as Swapps is required to keep the underlying commercial and accounting records.

Enquiries sent through the website are kept for as long as the commercial relationship they belong to is live, and then for the period our record-keeping obligations require.

The push registration for a device is deleted when you turn notifications off, when you sign out, or when the delivery service reports the installation as gone. Crash diagnostics are kept for a limited retention window and then deleted. Analytics data is retained according to the retention setting configured in Google Analytics.

Your rights

You may ask to know what personal data is held about you, have it corrected or updated, ask for it to be deleted, and withdraw a consent you gave. Depending on where you live, local law may give you further rights; write to us and we will tell you which of them apply to you and how to use them.

You can change your name and your language yourself in the application, under Account. For anything else, write to the contact address at the top of this policy.

Deleting your account. To request deletion of your Swapps account and the personal data associated with it, write to the same address. We will confirm the request, delete the account and the personal data we are not legally required to retain, and tell you what was kept and why. Commercial and accounting records that we are obliged to keep are retained for the period the law requires and are not used for any other purpose.

Children

Neither the website nor the application is directed at children. Accounts are created by Swapps for the staff and clients of the organisations it works with.

Security

Personal data is held on systems accessible only to the people who need it for the purposes described here. Traffic between your device and our servers is encrypted in transit. Session tokens are held in the operating system's protected storage on mobile devices.

Changes to this policy

If this policy changes, the new text is published at this same address with a new effective date. The address itself does not change.

Contact

Write to privacy@swapps.com for anything in this policy, including a request to exercise your rights or to delete your account. The postal address below is the same one named at the top.

Swapps175 SW 7Th Street Ste. 1716, Miami FL 33130United Statesprivacy@swapps.com(202) 888-2733