Swapitoy — Privacy Policy
This Privacy Policy explains how we process personal data when you use Swapitoy (the "Service").
1) Controller
Controller: AlpineWebStudio.com
Address: Bolzano, Italy
Privacy email: privacy@swapitoy.com
2) Personal data we collect
Data you provide
- Account data: email, login credentials, username
- Profile data: optional profile photo, location text (city/meetup area), language preference
- Listings: toy title/description, category, condition, age range, tags, and listing photos
- Communications: messages you send in chat with matches (when enabled)
Data generated by use
- Swipes/likes/passes, match records, and related metadata
- Moderation and safety signals (e.g., reports, enforcement actions), if you submit a report or are the subject of one
Device and technical data
- App and device info for security and reliability (e.g., platform, app version)
- Push notification token if you enable notifications
Location
- We process your location text (city/area)
- If we later add "nearby" features using precise GPS, we will request device permission before collecting it
3) Why we process your data
We process personal data to:
- Provide the Service (accounts, profiles, listings, discovery, matching, chat)
- Maintain safety and trust (policy enforcement, reporting, moderation)
- Send service notifications (e.g., match/message alerts) when enabled
- Analyze and improve the Service (analytics) where enabled
- Comply with legal obligations and enforce our Terms
4) Legal bases (EEA/UK)
Where GDPR applies, we use:
- Contract — to provide the Service
- Legitimate interests — security, abuse prevention, service improvement, balanced against your rights
- Consent — for optional analytics and certain notification settings where required
- Legal obligation — compliance with law
5) Sharing and processors
We share personal data with vendors who help us operate the Service, such as:
- Backend/database/auth/storage providers (e.g., Supabase)
- Push notification services (e.g., Expo) if you enable notifications
- Analytics providers if enabled in-app
We may also share data with moderators/admins under authorization for safety enforcement, and with authorities if required by law.
6) International transfers
If we transfer personal data outside the EEA/UK, we will use appropriate safeguards (e.g., adequacy decisions or Standard Contractual Clauses) where required.
7) Retention
We keep personal data only as long as necessary for the purposes described:
- Account data: while your account is active, plus limited backup/security/legal periods
- Listings/media: until you delete them or your account is deleted, unless needed for moderation or legal compliance
- Messages: while the match is active or until deletion is requested/required, subject to legal/technical constraints
- Analytics: for a limited period, respecting your settings
8) Your rights
Depending on your location, you may have rights to access, correct, delete, restrict processing, object, and request portability, and to withdraw consent at any time.
To exercise rights, contact: privacy@swapitoy.com
9) Security
We use reasonable technical and organizational measures to protect personal data. No system is fully secure; use a strong password and keep your device secure.
10) Children
The Service is intended for adults/guardians, not children. If you believe a child provided personal data, contact privacy@swapitoy.com.
11) Changes to this Policy
We may update this Policy from time to time. We will post the updated version in the app and update the "Last updated" date.
12) Contact
Privacy: privacy@swapitoy.com
Support: support@swapitoy.com