Swipy.

Privacy Policy · Swipy

Effective: July 29, 2026 Last updated: July 29, 2026

Your privacy matters. This policy explains exactly what data Swipy collects, why we collect it, and how you can control it. We do not sell your personal data to third parties.


1. Introduction

This Privacy Policy describes how Swipy Limited ("we," "us," or "our") collects, uses, and protects information when you use the Swipy mobile application ("App"). By using Swipy, you agree to the collection and use of information in accordance with this policy.

We are committed to handling your data responsibly and in compliance with applicable privacy laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and Apple's App Store privacy requirements.


2. Information We Collect

Account Information

  • Email address — used to create and authenticate your account
  • Display name — the name you choose during registration, shown only to you
  • If you sign in with Apple, we receive only what Apple shares based on your preferences (typically email and name)

Location Data

  • Approximate or precise location (GPS) — collected only while you are actively using the App to discover nearby restaurants
  • Your location is used to query the Google Places API for restaurants near you
  • We do not store your GPS coordinates on our servers
  • Location access requires your explicit permission and can be revoked at any time in your device Settings

Usage Data Stored on Your Device

The following data is stored locally on your device only (via AsyncStorage) and is not transmitted to our servers:

  • Restaurants you have saved and your album organization
  • Your filter preferences (cuisine type, price range, distance, etc.)
  • Swipe session statistics

Data We Do Not Collect

  • Payment or financial information (the App is free)
  • Contacts or address book
  • Photos, camera, or microphone access
  • Browsing history outside the App
  • Precise location stored on our servers

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Service — creating and managing your account, authenticating your identity
  • Restaurant discovery — using your location to find and display nearby restaurants via Google Places
  • Service improvement — understanding how the App is used to fix bugs and improve features
  • Communication — sending important service updates or responding to your support requests
  • Security — detecting and preventing fraud and unauthorized access
  • Legal compliance — meeting our obligations under applicable laws

Legal basis (GDPR): We process your data under the legal bases of (a) contractual necessity — to provide the Service you've requested; (b) legitimate interests — to improve the Service and ensure security; and (c) your consent — for location access, which you can withdraw at any time.


4. Third-Party Services & Data Processors

We share certain information with trusted third-party services necessary to operate the App. These parties process data only as directed by us and under binding data protection agreements.

Supabase

We use Supabase for user authentication and storing your display name and account profile. Data is stored on Supabase's infrastructure (SOC 2 Type II compliant).

  • Data shared: email address, display name, user ID
  • Purpose: authentication and account management

Google Places API

Your location coordinates are sent to Google's Places API to retrieve nearby restaurant data. Google processes this request under their own Privacy Policy.

  • Data shared: your approximate or precise location (coordinates only)
  • Purpose: finding restaurants near you
  • Google does not receive your name or email

Apple Sign In

If you choose to authenticate via Apple, your sign-in is handled by Apple, Inc. We only receive the data Apple forwards based on your choices.

We do not sell, rent, or trade your personal information to advertisers or any third parties for their own marketing purposes.


5. Data Storage & Security

Your account data (email, display name) is stored securely on Supabase servers protected by industry-standard encryption at rest and in transit (TLS 1.2+).

Your saved restaurants, albums, and preferences are stored locally on your device using React Native's AsyncStorage. This data does not leave your device unless you explicitly share content using the App's share feature.

We implement reasonable technical and organizational measures to protect your information. However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

In the event of a data breach that affects your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.


6. Data Retention

We retain your personal data only as long as necessary for the purposes described in this policy:

  • Account data — retained for as long as your account is active, or as needed to provide the Service
  • Locally stored data (albums, preferences) — stored on your device until you delete the App or clear App data
  • Upon account deletion, your account data is removed from our servers within 30 days
  • Anonymized, aggregated analytics data (if any) may be retained indefinitely as it cannot identify you

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

For all users

  • Access — request a copy of the personal data we hold about you
  • Correction — request that inaccurate data be corrected
  • Deletion — request that your account and associated data be deleted
  • Opt-out of location — revoke location permission at any time in your device Settings

EU / EEA users (GDPR)

  • Portability — receive your data in a structured, machine-readable format
  • Restriction — request restriction of processing in certain circumstances
  • Objection — object to processing based on legitimate interests
  • Lodge a complaint — with your local data protection supervisory authority

California users (CCPA)

  • Right to know what personal information is collected, used, or disclosed
  • Right to delete personal information
  • Right to opt out of the sale of personal information (we do not sell data)
  • Right to non-discrimination for exercising your privacy rights

To exercise any of these rights, contact us at support@swipyteam.com. We will respond within 30 days (GDPR) or 45 days (CCPA) of receiving your request.


8. Children's Privacy

Swipy is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal data from a child under 13 without verification of parental consent, we will delete that information promptly.

Users between 13 and 18 should obtain parental consent before using the App. If you believe a child under 13 has provided us with personal information, contact us immediately at support@swipyteam.com.


9. International Transfers

Your information may be transferred to and processed on servers located outside your country of residence, including in the United States where Supabase maintains infrastructure. These transfers are protected by appropriate safeguards, including Standard Contractual Clauses as approved by the European Commission.

By using the Service, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection rules.


10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date and by providing a prominent notice within the App or via email.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes acceptance of the updated policy.


11. Contact & Data Controller

For any privacy-related questions, concerns, or to exercise your rights, please contact:

Data Controller: Swipy Limited Email: support@swipyteam.com

EU/EEA users may also contact your local supervisory authority. A list is available at edpb.europa.eu.