Privacy Policy

Last updated: December 2024

1. Introduction

Welcome to Swappahome ("we", "us", "our"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform accessible at swappahome.com ("the Platform").

Please read this Privacy Policy carefully. By accessing or using our Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, please do not use our Platform.

2. Data Controller

For the purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, Swappahome is the data controller responsible for your personal data.

Contact email: privacy@swappahome.com

3. Information We Collect

3.1 Information You Provide

When you register, create a listing, or use our services, you may provide us with:

  • Account Information: Name, email address, password, phone number
  • Profile Information: Profile photo, bio, location, languages spoken
  • Identity Verification: Government ID, selfie photos (processed by third-party verification services)
  • Property Information: Address, photos, descriptions, amenities, availability
  • Communications: Messages exchanged with other users and our support team
  • Reviews and Ratings: Feedback you provide about other users and properties

3.2 Information Collected Automatically

When you access our Platform, we automatically collect:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages viewed, features used, time spent, search queries
  • Location Data: General location based on IP address (precise location only with your consent)
  • Cookies and Tracking: See Section 8 for details

3.3 Information from Third Parties

We may receive information from third-party services you connect to your account (e.g., social login providers), identity verification services, and publicly available sources.

4. How We Use Your Information

We use your personal data for the following purposes:

  • Provide Services: Create and manage your account, process bookings, facilitate communications
  • Verification: Verify your identity and property ownership to maintain trust and safety
  • Communications: Send service updates, booking confirmations, and respond to inquiries
  • Improvements: Analyze usage to improve our Platform and develop new features
  • Safety: Detect and prevent fraud, abuse, and security incidents
  • Legal Compliance: Comply with legal obligations and enforce our Terms of Service
  • Marketing: Send promotional communications (with your consent, which you can withdraw at any time)

5. Legal Basis for Processing (GDPR)

Under the GDPR, we process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide our services to you
  • Legitimate Interests: Processing necessary for our legitimate business interests (e.g., fraud prevention, platform security, service improvements)
  • Consent: Processing based on your explicit consent (e.g., marketing communications)
  • Legal Obligation: Processing necessary to comply with legal requirements

6. Information Sharing

We may share your information in the following circumstances:

6.1 With Other Users

When you request or confirm a booking, certain information is shared with the other party, including your name, profile photo, and communication history. Property addresses are shared only after a booking is confirmed.

6.2 Service Providers

We share data with trusted third-party service providers who assist us in operating the Platform:

  • Cloud hosting and infrastructure (Vercel, Supabase)
  • Identity verification services
  • Email and communication services
  • Analytics providers
  • Customer support tools

6.3 Legal Requirements

We may disclose your information if required by law, court order, or government request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

6.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

7. Your Rights (GDPR)

Under the GDPR and other applicable laws, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Restriction: Request restriction of processing in certain circumstances
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Complaint: Lodge a complaint with a supervisory authority

To exercise these rights, contact us at privacy@swappahome.com. We will respond within 30 days.

8. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience:

8.1 Types of Cookies

  • Essential Cookies: Required for the Platform to function (authentication, security)
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how you use the Platform
  • Marketing Cookies: Used to deliver relevant advertisements (only with consent)

8.2 Managing Cookies

You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Platform. Most browsers allow you to refuse cookies or alert you when cookies are being sent.

9. Data Retention

We retain your personal data for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain business records as required by law

When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain certain information for legal or legitimate business purposes.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/SSL)
  • Encryption of sensitive data at rest
  • Access controls and authentication
  • Regular security assessments
  • Employee training on data protection

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

11. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Transfers to countries with adequacy decisions
  • Other legally approved transfer mechanisms

12. Children's Privacy

Our Platform is not intended for children under 18 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.

13. Third-Party Links

Our Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal data.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically. Your continued use of the Platform after any changes constitutes acceptance of the updated Privacy Policy.

15. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

🇪🇺 GDPR Compliant

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR). If you are a resident of the European Economic Area, you have specific rights regarding your personal data as outlined in Section 7.