Privacy Policy
Last updated: July 21, 2026
SwiftCard ("SwiftCard", "we", "us"), a brand operated by Swift Card Inc, provides digital business cards, link-in-bio pages, and contact-management tools at swiftcard.me and in our mobile app (together, the "Service"). This policy explains what information we collect, how we use it, and the choices and rights you have. We keep it in plain English on purpose. For personal information of account holders, SwiftCard is the data controller; for the contacts you collect through your card, you are the controller and we process that data on your instructions. Mobile numbers and SMS consent are the one exception: because Swift Card Inc is the sender of every automated text we send, we are the controller of that number and that consent record, and we never hand either to the account holder or to anyone else for their own messaging.
Privacy at a glance
- We never sell your personal information — or your contacts' — to anyone.
- No third-party advertising trackers, and no cross-app "tracking" as Apple defines it.
- Your card shows only what you choose to make public. Everything else stays private.
- You can export or permanently delete your data anytime from Settings.
Information you give us
- Account details — your name and email address when you sign up (or the profile shared by Google if you sign in with Google).
- Card content — everything you choose to put on your card or Swift Links page: name, title, company, phone numbers, email, website, address, photo, logo, bio, and social links. This content is public by design — anyone with your card link can see it.
- Contacts you collect — when someone fills out the "share your info" form on your card, their name, phone, email, company, and message are stored in your account's contact list.
- Payment details — handled entirely by Stripe. We never see or store your card number.
- Business-card photos — if you use the AI card scanner, the photo you take is sent to Google (our AI provider) to extract the contact details, then used only to create the contact. Because the card belongs to someone else, that photo can contain their personal details; we ask your permission before the first time anything is sent, and you can decline.
- Messages to us — anything you send through the contact form, feedback, or support.
Information collected automatically
- View analytics — when someone opens a card or Swift Links page, we record the view with an approximate location (city/country derived from IP address by our hosting provider), the source (QR code, link, etc.), and basic device info. We do not store visitors' IP addresses with these views.
- Product analytics — we use PostHog to understand how the app is used (pages visited, features used, general device/browser info) so we can improve it. We use this for product improvement only, not third-party advertising.
- Fraud-prevention signals — when you create an account we record your IP address and a coarse, non-unique device signature (derived from your browser type and language). If you subscribe, our payment processor (Stripe) also gives us a non-reversible fingerprint of your payment card — a one-way hash, never your card number. We use these solely to detect abuse of our referral program (for example, one person inviting themselves or claiming the same offer repeatedly across accounts) and to rate-limit abuse. We do not use them for advertising.
- Usage basics — standard server logs and cookies needed to keep you signed in and keep the service secure. We don't run third-party advertising trackers, and we do not use your data for cross-context behavioral advertising.
App privacy — what our app collects (Apple disclosure)
Apple requires apps to disclose the categories of data they collect. Whether you use SwiftCard in the browser or in our iOS app, the data practices are identical, and here they are in Apple's categories. None of this data is used for "tracking" as Apple defines it — we do not link your data with third-party data for advertising, and we do not share it with data brokers.
| Category | What it includes | Linked to you? | Used to track you? |
|---|---|---|---|
| Contact info | Name, email, phone number you add to your account or card | Yes | No |
| User content | Card content, photos & logo, bio, the contacts you collect, messages to support | Yes | No |
| Identifiers | Your account ID | Yes | No |
| Purchases | Subscription/purchase history (payments handled by Stripe) | Yes | No |
| Usage data | Pages visited and features used (product analytics) | Yes | No |
| Diagnostics | Standard server logs used for security and reliability | Yes | No |
| Coarse location | City/country of card views, derived from IP (visitor IPs not stored with views) | No | No |
How we use information
- To run the product: host your card, deliver your Swift Links page, store your contacts, and show you your analytics.
- To send messages you set up: follow-up emails (and, where enabled, texts) to your contacts, sent on your behalf with your name.
- To notify you: new-contact alerts by in-app notification, and by push notification if you turn push on.
- To bill you (Stripe) and to send service emails like receipts. Marketing emails are optional — every one includes an unsubscribe link.
- To keep the Service secure, prevent fraud and abuse, and comply with law.
- We never sell your personal information, we don't "share" it for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act), and we never sell your contacts' data. Your contact list is yours.
Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract (running the Service you signed up for), legitimate interests (security, fraud prevention, product analytics, and improving the Service), consent (optional marketing and push notifications — withdrawable anytime), and legal obligation (tax and accounting records).
Who we share it with
Only the service providers needed to run SwiftCard, under contracts limiting them to processing on our instructions. Each is required to protect your data to at least the same standard this policy describes:
- Supabase — database, file storage, and authentication.
- Vercel — hosting and content delivery.
- Stripe — payments and subscriptions.
- Resend — sending email.
- Twilio — sending text messages (where SMS features are enabled).
- PostHog — product analytics.
- Upstash — rate limiting (helps stop abuse of our forms and APIs).
- Google(the Gemini API) — our AI provider. Data reaches Google only when you use a feature that needs it, and only the data that feature needs: the photograph you take when you scan a business card; a contact's name, company, where you met and your notes when AI drafts a follow-up for them; the design photo you upload to rebuild a card; and the messages you type to the in-app assistant. Google processes it to return the result and we do not send it anywhere else. We ask for your permission in the app before any of this is sent, and you can decline — the rest of SwiftCard keeps working and AI features stay off. We use the Gemini API under Google's API terms, which bind Google to protect this data to a standard at least equal to this policy: Google processes it to return the response, may not use it for advertising or sell it, and — because we use the paid API tier — does not use it to train its models.
If you connect an integration yourself — GoHighLevel, Pipedrive, HubSpot, Google Contacts or Zapier — we send new contacts to that service because you asked us to. Disconnect anytime in Settings → Integrations. SwiftCard's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We may also disclose information if required by law or legal process, to protect the rights, safety, or property of SwiftCard or others, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply and we'll notify you of any successor).
Text messaging (SMS) and mobile information
We do not share, sell, or otherwise provide your mobile phone number or messaging consent information to any third parties or affiliates for marketing or promotional purposes. Mobile numbers and SMS opt-in data are used only to deliver the messages described in our SMS & Messaging Terms — replies and follow-ups from the SwiftCard user you shared your information with.
Necessary service providers (such as Twilio, our text-messaging provider) process mobile numbers solely to deliver those messages on our instructions — never for their own marketing. Consent to receive texts is collected on the share form via a checkbox next to the submit button, which states the types of messages you would receive and is never pre-ticked. Ticking it is the opt-in; it is optional, so you can share your contact information without it and we will not text you. It is never a condition of submitting the form, of creating an account, or of making a purchase.
Message frequency varies — messages are sent by the individual SwiftCard user you shared your information with, so volume depends on that person and is typically only a few messages following your meeting. Message and data rates may apply. Reply STOP to any message to opt out across all of SwiftCard, or HELP for help. Messages are sent from (917) 905-7335.
International transfers
We are based in the United States and our providers process data primarily in the U.S. If you use SwiftCard from outside the U.S. (including the EEA, UK, or Switzerland), your information is transferred to the U.S. Where required, we rely on our processors' safeguards for those transfers, such as Standard Contractual Clauses and Data Privacy Framework certifications.
Your privacy rights
Everyone can access, correct, export, or delete their information — most of it directly in the app (Settings → Manage account, and CSV export for contacts), or by contacting us via the contact page. We respond to verifiable requests within the time required by applicable law, and we never discriminate against you for exercising a privacy right.
If you're in California
The CCPA/CPRA gives you the right to know what personal information we collect and how it's used (this policy), to access it, correct it, delete it, and to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information(including that of anyone under 16), and we do not use or disclose sensitive personal information for purposes requiring a right to limit. You may designate an authorized agent to make requests for you. Because we don't sell or share data, browser opt-out signals such as Global Privacy Control and "Do Not Track" don't change how we process your data; we treat all visitors by the standards in this policy.
If you're in the EEA, UK, or Switzerland
You have the rights of access, rectification, erasure, restriction, portability, and objection (including to processing based on legitimate interests), and the right to withdraw consent at any time without affecting prior processing. You can also lodge a complaint with your local supervisory authority, though we'd appreciate the chance to resolve any concern directly first.
Contacts collected through cards
If your information was collected by a SwiftCard user (you filled out someone's card form), that user controls it — contact them directly, or contact us and we'll assist. You can opt out of their messages at any time: replying STOP to a text suppresses texts to your number across SwiftCard (reply HELP for help), and every automated email includes an unsubscribe link. See our SMS & Messaging Terms for the full messaging program.
Data retention & deleting your account
We keep your data while your account is active. You can delete your account in Settings → Manage account — after deletion you have one month to reopen it by logging back in; after that the deletion is permanent and your data is removed from our production systems (residual copies in encrypted backups expire on their normal rotation). We retain billing records as required by tax law. You can export your contacts to CSV before deleting.
Security
Data is encrypted in transit (HTTPS everywhere) and at rest by our database provider. Integration tokens (like your Google connection) are stored encrypted. No system is 100% secure, but we design so that a visitor can only ever see what you chose to make public. If a breach affecting your personal information occurs, we'll notify you and regulators as required by law.
Children
SwiftCard is a professional networking tool. It is not directed to children, and you must be at least 16 years old to create an account (see our Terms of Service). We do not knowingly collect personal information from anyone under 16 — and never from children under 13, consistent with the U.S. Children's Online Privacy Protection Act (COPPA). If we learn that an account belongs to someone under 16, we will terminate it and delete the associated personal information. If you believe a child has provided us personal information, contact us via the contact pageand we'll delete it promptly.
Changes
If we make meaningful changes to this policy we'll update the "Last updated" date above and, for significant changes, notify you by email or in the app before they take effect.
Contact us
Questions or requests (including data access, correction, or deletion): email hello@swiftcard.me or reach us through the contact page. SwiftCard is operated by Swift Card Inc · New York, NY, USA.