Privacy policy · Version 7 August 2026
Your identity is not the product.
This policy explains what Swapcard processes, why it is needed, how long it is kept, and how the two-sided contact reveal works.

Who controls the data
The controller is SBrusse SRL, the Belgian company that operates Swapcard. It decides what is collected and why, and it is the organisation your rights are exercised against.
- SBrusse SRL, Rue Auguste Baccus 14/2, 1350 Folx-les-Caves, Belgium.
- Crossroads Bank for Enterprises number 0644.917.861; VAT BE 0644.917.861.
- Privacy requests: privacy@swapcard.app. Anything else: support@swapcard.app.
We verify account ownership before acting on a request. We have not appointed a data protection officer, and we are not required to: Swapcard is a small operation that does not monitor people on a large scale and does not handle special-category data as a core activity. The people who answer privacy@swapcard.app are the people who built the service.
Data we process
- Account and membership data: email address, authentication provider, username, adult confirmation, consent history, trial/paid access dates, Stripe customer and subscription references, and system-generated pair-scoped pseudonyms. We do not receive or store card numbers.
- Approximate location: country, postcode-derived locality and area label, and a postcode-derived centroid. The raw postcode is processed during onboarding or a region update but is not retained; no home address or precise GPS point is used for matching.
- Collection data: joined card sets, doubles available to trade, wanted cards, and when those trade lists were confirmed. An internal owned-quantity field is used only to represent how many copies are available for a swap.
- Card photos: a server-sanitized WebP derivative, card association, visibility choice, moderation state, dimensions, and upload time. Location metadata and the original upload are removed during processing.
- Optional publication data: whether you publish a wanted page or join a country, city, or masked-postcode-area collection leaderboard. Both choices are off by default.
- Swap data: reciprocal matches, room state, proposal versions, approvals, messages, blocks, reports, and audit events.
- Technical data: security, authentication, and service logs needed to prevent abuse and keep the service available.
Why we process it, and on what legal basis
Each purpose has its own basis under article 6 of the GDPR. They are not interchangeable, so they are listed separately.
- Running the service you asked for — your account, collection, approximate matching location, matches, rooms, proposals, contact reveals, uploaded photos, and the emails about your own swaps. Basis: performance of the contract, article 6(1)(b). Without this data there is no service to provide.
- Taking payment — the Stripe customer and subscription references that connect your account to a payment. Basis: performance of the contract, article 6(1)(b).
- Invoices and accounting — the billing records behind that payment. Basis: legal obligation, article 6(1)(c), under Belgian accounting and VAT law.
- Recording what you agreed to — adult confirmation, and which version of these documents you accepted and when. Basis: legal obligation, article 6(1)(c); we have to be able to show that consent and the adults-only rule were actually obtained.
- Publishing your wanted page or joining a leaderboard — both off until you switch them on. Basis: consent, article 6(1)(a). You can withdraw either in Settings at any time, and withdrawal does not affect what was lawful before it.
- Keeping collectors and the service safe — sign-in rate limits, abuse and fraud prevention, blocks, reports, moderation of publicly shared photos, and security logs. Basis: legitimate interests, article 6(1)(f). The interests are specifically: protecting collectors from harassment, impersonation and fraud; protecting children whose cards are being swapped by the adults on both sides; keeping the service available against automated abuse; and being able to establish or defend legal claims. We balanced these against your interests and kept the data minimal and short-lived.
Where a report or a court order obliges us to retain or disclose something, the basis is legal obligation, article 6(1)(c).
Automated matching, and what it does not decide
Matching is automated. The system compares your wanted cards and doubles against other collectors’, filters by the distance limits you both chose, checks that a trade works in both directions, and proposes the pairs that survive. That is ranking and filtering, nothing more.
No decision with a legal or similarly significant effect on you is made automatically. Nothing is scored for creditworthiness, eligibility, or advertising, and no swap happens unless both people approve the same proposal by hand.
What another collector can see
Before a swap is mutually approved, another collector sees only a pseudonym generated for that collector pair, a broad distance band, recent inventory activity, and the cards relevant to that specific reciprocal match. They do not see your email, country, postcode, exact distance, complete inventory, or other rooms.
If you publish your wanted page, anyone with its unlisted URL can see your username, wanted-card labels, and only sanitized card photos you explicitly submit and we approve for public display. If you join leaderboards, eligible opted-in collectors in your own region can see your username and delayed score only after at least five people qualify. Suppressed boards reveal neither the location label nor the cohort count. These are separate choices and can be withdrawn in Settings.
Contact details are revealed only after both collectors approve the same version of the proposed swap. Each collector chooses which of their own fields to share. Editing a proposal requires fresh approvals.
Cookies
There is no analytics, no advertising, no pixel, no tag manager, and no third-party tracker anywhere in Swapcard. Nobody is measuring which cards you look at, and nothing about you is sold or shared for marketing. That is why there is no cookie banner: every cookie below is strictly necessary to deliver a service you actively asked for, which is the one case where European law does not require consent.
- Authentication cookies whose names begin with
sb-, set by our sign-in library. They hold your session so each page knows it is you. They are cleared when you sign out. swapcard-remember-browser— records whether you asked to stay signed in on this browser, which is what decides whether the session survives closing the window. Lasts 30 days, server-side only, not readable by page scripts.swapcard-pending-verification— remembers which address a verification link was sent to, so the screen after signup can show it and resend without asking you to retype it. Lasts 24 hours, server-side only.
Stripe sets its own cookies on its hosted checkout pages, which are on Stripe’s domain rather than ours; those are covered by Stripe’s policy and are used for payment security and fraud prevention.
Processors and international transfers
A short list, because a short list is easier to keep honest. Each provider processes only what its job needs, under a data-processing agreement.
- Hetzner Online GmbH (Germany) — the isolated Supabase stack holding identity, application data, and card photo storage. Inside the EU, so no transfer safeguard is needed.
- Vercel Inc. (United States) — serves the web interface. Transfers rely on Vercel’s certification under the EU–US Data Privacy Framework and on the European Commission’s Standard Contractual Clauses in its data-processing agreement.
- Stripe (Ireland, with onward transfer to the United States) — hosted checkout, subscriptions, and invoices. Transfers rely on Stripe’s Data Privacy Framework certification and on Standard Contractual Clauses.
- Resend (United States, sending from the European Union) — used to send transactional email such as sign-in links, verification messages and match notifications. Your address is processed in Resend’s Ireland region; transfers to its United States parent rely on Standard Contractual Clauses.
Ask privacy@swapcard.app and we will tell you which mechanism covers a given provider and send you a copy of the relevant clauses.
How long we keep it
- Account, collection, wanted lists, photos, and swap history: until you delete the account. Deletion happens straight away and is not reversible; we do not sweep up inactive accounts on our own.
- Raw postcode: never stored. It is turned into a locality, an area label, and a centroid during onboarding or a region change, and then discarded.
- Match suggestions: 15 minutes, then they expire and are regenerated.
- Contact-detail grants: 30 days from the second approval, or immediately when the swap is cancelled, the grant is revoked, or someone is blocked.
- Sign-in and recovery links: verification links 24 hours, password-reset links 30 minutes.
- Cookies: as stated in the section above — 30 days for the remember-browser preference, 24 hours for the pending-verification address, and the session for the authentication cookies.
- Notification queue entries: they hold opaque identifiers only, and are removed with the account.
- Invoices and accounting records: seven years, counted from 1 January of the year following the financial year they belong to, because Belgian accounting and VAT law requires it. Deleting your account removes the reusable Stripe customer profile; Stripe keeps the transaction records it is legally obliged to keep.
- Security and service logs: as briefly as the platform allows, and never more than 12 months.
- Safety reports and moderation records: while the review is open, and afterwards only as long as needed for safety or for legal claims. A report you filed is deleted with your account; a report filed about you is kept as a safety record with the link to your account removed.
Security
Your account, inventory, sanitized photos, and swap history stay visible only to you and remain readable after the demo or membership ends; publication and new activity stop. Card images are delivered through an authorization-checking, no-store media route, so a visibility or membership change takes effect on the next request. Encryption in transit, row-level access rules, access-controlled storage, least-privilege credentials, and audit events protect the service.
Your choices and rights
You can download a self-service copy of selected account and service data or delete the account from Settings. The copy reports location only as matching settings, postcode-derived locality, and masked area; the internal centroid and privacy-cell identifier remain server-internal. For a verified privacy-rights request covering data beyond that copy, contact privacy@swapcard.app. Depending on applicable law, you may also request access, correction, restriction, portability, objection, or erasure, and you may object at any time to the processing we base on legitimate interests.
If you think we have got this wrong, you can complain to the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, or to the supervisory authority where you live.
Children
Swapcard is for adults aged 18 or over. The cards belong to the children; the account belongs to the adult. We do not knowingly provide the service directly to children.