Privacy

Privacy Policy

How Swipz handles your account, location, restaurant activity, and device data.

Draft updated September 28, 2026

Information Swipz collects

  • Account identifiers, email address, verification status, display name, profile image, password-verification hash, and linked identity-provider identifiers. Swipz does not store the password itself.
  • If you join the waitlist, the name and email address you submit, approval status, and signup and approval timestamps.
  • If you send feedback, the ticket type, subject, message, account details for signed-in tickets, any optional landing-page reply email, and up to four optional images you choose to attach. Swipz removes embedded image metadata before delivery, but visible image content may still contain personal information.
  • For public website visits, Vercel Web Analytics records page views, page paths without query parameters, referrers, approximate location, and browser and device information. The public website does not send waitlist form fields or feedback messages as Vercel Analytics events.
  • The selected search location, radius, filters, default market, and daypart. Approximate or precise device location can be used for nearby discovery and as a starting point for directions only after you allow location access.
  • Swipe activity, saved restaurants, visit status, undo actions, restaurant identifiers, recommendation impressions, ranking positions, model versions, and learned recommendation weights.
  • Account-linked restaurant interactions such as detail, happy-hour, hours, photo, review, menu, website, and directions actions; profile and Liked views; the app platform; event time; and the rounded restaurant distance displayed at the time. In the mobile app, Swipz also records pages opened in its in-app browser, the website domain and a filtered path, time spent on each page, and requests to preview directions. Browser history excludes URL query strings, fragments, credentials, and opaque path identifiers. Swipz does not add the device's physical location to directions activity history. Directions open through Apple Maps on iOS or Google Maps on Android; Maps may use your current location as the starting point if you allow it. Swipz cannot observe activity after you leave for another browser or maps app, and these events do not prove a restaurant visit or purchase.
  • Device platform, app version, notification preference, and push token after mobile notification opt-in.
  • Request timing, response status, rate-limit events, diagnostics, and privacy-scrubbed crash data used for reliability and security.

How information is used

  • Manage waitlist signups and decide which email addresses can access the early Swipz pilot.
  • Review problem reports and suggestions, use optional attached images to understand the issue, and reply when contact information is available.
  • Create your pilot account, verify the password during sign-in, and protect active sessions. During the current pilot, the @kent.edu address entered at account creation is not independently verified; the password protects account continuity but does not prove ownership of the mailbox.
  • Find, rank, display, and cache nearby restaurant recommendations.
  • Save likes and visits, learn preferences, and reduce repeated suggestions.
  • Measure restaurant discovery and show authorized Swipz staff account-linked in-app browser and map activity, website actions, and directions intent. These reports describe actions recorded in Swipz and do not prove an in-person visit or purchase.
  • Understand which public website pages are visited using aggregated traffic reports.
  • Deliver mobile reminders only after you opt in.
  • Prevent abuse, enforce quotas, investigate failures, and monitor service reliability and latency.

Service providers

Depending on production configuration, Swipz may use WorkOS and your selected identity provider; Vercel for hosting and public website analytics; database infrastructure; Resend for password setup, password recovery, and support-ticket email delivery; Expo and Apple platform services; Google Places for attributed restaurant photos; S3-compatible media infrastructure; OpenStreetMap contributors and Overture Maps open datasets; openly licensed media indexed by Openverse; and representative food photography from Pexels contributors. Restaurant recommendations and profile data come from the dashboard-managed Swipz catalog; when enabled, the active restaurant card requests photo metadata and images from Google Places.

Catalog data includes © OpenStreetMap contributors and Overture Maps Foundation. OpenStreetMap data is available under the Open Database License, and Overture release and source-specific attribution terms also apply.

Retention and deletion

Active account data is retained while the account is open and as needed to provide the service. Shorter periods should apply to sessions, device registrations, caches, and diagnostics. Exact retention periods and the backup-overwrite window must be finalized before launch.

A waitlist name, email, and access status remain in the active waitlist until Swipz staff removes the record. Revoking access ends active sessions but keeps the waitlist record so its status remains visible to staff.

Feedback text and available contact details are stored as a support ticket. Optional images are delivered to the Swipz support inbox through the email provider rather than stored in the ticket database. The exact support-ticket and support-email retention periods must be finalized before launch.

Deleting your account removes the active Swipz identity, sessions, saved restaurants, swipe, product, and recommendation interaction events, recommendation impressions, personalization weights, and device registrations. Local Swipz caches are cleared on the device where deletion is confirmed.

Your controls

  • Decline or revoke location and notification permissions in Swipz or system settings.
  • Remove saved restaurants and update visit status.
  • Sign out or permanently delete your account from Profile.
  • Use the public account-deletion resource if you no longer have the mobile app.

Security, children, and contact

Swipz should use reasonable safeguards, but no service can guarantee absolute security. The operator name, monitored privacy email, postal address, minimum age, supported countries, and international-transfer disclosures remain required launch items.