Privacy
Privacy Policy
This page explains the information used by the current swap-first marketplace, who can see it, and what account deletion does.
Information you provide
- Account information, including your email address and authentication details handled through Supabase Auth.
- Basic public profile information, such as display name, avatar and public location label if you add one.
- Listing information, including item title, description, category, brand, model, condition, known issues and listing status.
- Item photos you upload to show the things you want to swap.
- Messages, offers, counters, acceptances, declines and completion confirmations linked to swap negotiations.
- Exchange method, dispatch and receipt progress, and any carrier or tracking reference you choose to enter.
- Reviews, disputes, blocks and reports when you use trust and safety tools.
- Support messages you choose to send through the Contact page.
Information other members may see
Marketplace screens require sign-in. Active listings, basic profiles, public location labels and published reviews can be shown to other members within the app's access rules. Listings and member profiles are not public search pages. Item photos use shareable image delivery URLs: sign-in to a screen does not make an already-shared photo URL private. Do not include addresses, documents or other private information in listing photos.
Swap offers, counters and conversation messages are intended for the two members involved in that negotiation. Historical swap context may remain visible to those participants so accepted, declined, completed or blocked conversations still make sense.
Profile photos, reviews and exchange details
New profile-photo uploads use authenticated storage and can be viewed by members when linked to your profile. Older external profile photos may still load from their original provider. Removing a photo cannot recall copies another person has already downloaded.
Exchange and tracking details are for the swap participants. Reviews can be submitted during the 14 days after completion and remain blind until both members review or that window ends. Published reviews can contribute to member reputation; hidden reviews do not.
Approximate location
If you save a location, Swapties stores a coarse public location label on your profile and approximate rounded coordinates separately for distance filtering. Other members should not receive your raw stored latitude or longitude.
When you enter a UK postcode or postcode area, the server sends it to Postcodes.io for lookup and stores the derived swap area, not a persistent exact-postcode profile field. Do not treat this as a promise that providers keep no request logs. Share an exact meeting or delivery address only when needed with the other swap participant.
Interactions and swap activity
Swapties stores Likes, Maybes and Passes so Discover can avoid repeatedly showing the same items and so item owners can see inbound Likes. We also store offer status, counter lineage, read/seen state and completion timestamps to operate the swap flow.
Messages and email notifications
Conversation messages are stored so both participants can read their swap history. Swapties also stores read state to show message activity and to avoid sending repeated unread-chat emails during the same unread period.
Swapties uses transactional email for account-related messages through Supabase Auth and for swap notifications through a server-side email worker. Email links point back to Swapties.
AI listing assistance and moderation
When you ask Swapties to suggest listing details from a photo, the app sends the image and any short target-object hint to a server-side listing assistant. The assistant is used to suggest visible facts and draft listing copy; you remain responsible for checking and editing the final listing before publishing.
Listing safety checks also use Google Gemini. The server may send the listing's text, category, condition, known issues and uploaded item images to Gemini to check for prohibited or uncertain content. The check can allow, block or hold a listing for review. A suggestion is not a safety decision, and an unavailable or inconclusive check does not publish a listing. Changing relevant text or photos requires a fresh check.
Automated checks can be wrong. Ask about a decision through Contact and Support. Do not put private documents, addresses or credentials into listing text or photos.
Blocks, reports and moderation
Block records are used to reduce new interaction between members while preserving historical context. Reports may include the reported member, reason, optional details and relevant item or conversation context. Admin moderation views are restricted to approved Swapties admins.
Dispute statements and participant-facing status are visible to the participants and authorised admins. Internal moderation notes, account-enforcement history and cleanup inventories are not public profile information. Reporting or opening a dispute does not automatically restrict another account.
How Swapties uses information
- To create accounts, keep people signed in and protect authenticated routes.
- To publish listings, show Discover, save interactions and build swap offers.
- To deliver messages, activity badges and transactional notifications.
- To prevent blocked members from starting new interaction.
- To investigate reports, restrict misuse and keep the service reliable.
- To diagnose errors and maintain security, performance and availability.
Third-party services
Swapties currently relies on service providers in these categories:
- Supabase for authentication, database, storage, realtime updates, Edge Functions, scheduled jobs and account emails.
- Postcodes.io for UK postcode and postcode-area lookup when you save a profile location.
- Resend for transactional swap-notification and support-contact email delivery.
- Google Gemini for photo-based listing suggestions and listing safety moderation.
- Google Fonts to load Swapties typography.
- Vercel for hosting the Swapties web app.
Troubleshooting and service logs
Optional troubleshooting counters in Profile are off by default. If you enable them, fixed action and failure counts stay in this tab's memory, with no names, messages, locations or error details. Turning them off, reloading, signing out or changing account clears them. They are not sent as an analytics report.
Hosting and backend providers also maintain service and security logs. Listing-provider diagnostics record coarse timings, request sizes and outcome categories rather than listing text or images. The support flow uses hashed email/IP rate-limit keys to reduce abuse; the submitted support message itself is delivered by email. Local counters do not replace or erase these provider and operational records.
Cookies and local storage
Swapties uses essential authentication/session storage so the app can keep you signed in and protect account routes. A short-lived password-recovery marker is used only during recovery flows. The current app code does not include non-essential analytics, advertising or marketing cookies.
Retention and requests
Swapties keeps information while it is needed to operate accounts, listings, swaps, messages, safety tools and records of completed or moderated activity. Some historical information may be retained so swap history, reports and safety decisions remain understandable.
Request account deletion from Profile and type DELETE to confirm. The in-app flow is blocked while accepted swaps are unfinished or disputes are unresolved. Use support if you cannot complete it or want an individual privacy request reviewed; this product restriction is not a determination of your legal rights.
Deletion removes account access, clears private profile location and unused listings and photos where safe, and replaces your displayed identity with Deleted member. Necessary swap, message, review, report, dispute and moderation history can remain under its access controls. Removing a name does not make every retained message or record anonymous. A failed photo cleanup can require an operator to finish; it must not restore account access or delete another member's historical evidence.
Deletion does not instantly recall emails, downloaded copies, provider caches or backups. For privacy questions, access or correction requests, or concerns about retained data, use the support form. You can also find independent guidance and the privacy complaint route at the Information Commissioner's Office.
