Privacy policy · Version 3 August 2026
Your identity is not the product.
This policy explains what Swapcard.app processes, why it is needed, and how the two-sided contact reveal works.

Who controls the data
Swapcard.app operates from Belgium. Privacy requests can be sent to privacy@swapcard.app. We will verify account ownership before acting on a request.
Data we process
- Account and membership data: email address, authentication provider, username, adult confirmation, consent history, trial/paid access dates, Stripe customer and subscription references, and system-generated pair-scoped pseudonyms. We do not receive or store card numbers.
- Approximate location: country, postcode-derived locality and area label, and a postcode-derived centroid. The raw postcode is processed during onboarding or a region update but is not retained; no home address or precise GPS point is used for matching.
- Collection data: joined card sets, doubles available to trade, wanted cards, and when those trade lists were confirmed. An internal owned-quantity field is used only to represent how many copies are available for a swap.
- Card photos: a server-sanitized WebP derivative, card association, visibility choice, moderation state, dimensions, and upload time. Location metadata and the original upload are removed during processing.
- Optional publication data: whether you publish a wanted page or join a country, city, or masked-postcode-area collection leaderboard. Both choices are off by default.
- Swap data: reciprocal matches, room state, proposal versions, approvals, messages, blocks, reports, and audit events.
- Technical data: security, authentication, and service logs needed to prevent abuse and keep the service available.
Why we process it
We process account, collection, matching, messaging, and consent data to provide the service you request. We process proportionate security and abuse-prevention data for our legitimate interest in protecting collectors and the platform. Where consent is the appropriate basis, you can withdraw it without affecting earlier lawful processing.
What another collector can see
Before a swap is mutually approved, another collector sees only a pseudonym generated for that collector pair, a broad distance band, recent inventory activity, and the cards relevant to that specific reciprocal match. They do not see your email, country, postcode, exact distance, complete inventory, or other rooms.
If you publish your wanted page, anyone with its unlisted URL can see your username, wanted-card labels, and only sanitized card photos you explicitly submit and we approve for public display. If you join leaderboards, eligible opted-in collectors in your own region can see your username and delayed score only after at least five people qualify. Suppressed boards reveal neither the location label nor the cohort count. These are separate choices and can be withdrawn in Settings.
Contact details are revealed only after both collectors approve the same version of the proposed swap. Each collector chooses which of their own fields to share. Editing a proposal requires fresh approvals.
Processors and international transfers
The application uses Vercel to serve the web interface, an isolated Supabase stack on a Hetzner server in Germany for identity, object storage, and application data, Stripe for hosted checkout and subscription administration, and Google/Gmail for transactional email. We assess processors and safeguards before enabling them.
Retention and security
Your account, inventory, sanitized photos, and swap history remain visible only to you and readable after the demo or membership ends; publication and new activity stop. They remain until you delete the account or we must remove them. Short-lived match suggestions expire after 15 minutes. Card images are delivered through an authorization-checking, no-store media route so a visibility or membership change takes effect on the next request. Contact grants expire and are revoked when a swap is cancelled. Billing records and abuse reports may be retained where required for accounting, legal claims, fraud prevention, or safety obligations. Encryption in transit, row-level access rules, access-controlled storage, least-privilege credentials, and audit events protect the service.
Your choices and rights
You can download a self-service copy of selected account and service data or delete the account from Settings. The copy reports location only as matching settings, postcode-derived locality, and masked area; the internal centroid and privacy-cell identifier remain server-internal. For a verified privacy-rights request covering data beyond that copy, contact privacy@swapcard.app. Depending on applicable law, you may also request access, correction, restriction, portability, objection, or erasure. You may complain to the Belgian Data Protection Authority or your local supervisory authority.
Children
Swapcard is for adults aged 18 or over. We do not knowingly provide the service directly to children.