Home|Privacy Policy

Privacy Policy

Last updated: June 18, 2026

SwapU Privacy Policy

Version: 2.0
Last Updated: June 18, 2026
Effective Date: June 18, 2026


1. INTRODUCTION

SwapU ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our vehicle swapping platform.

This Policy Applies To:

  • The SwapU website (swapu.com.au)
  • Mobile applications (when available)
  • All services provided by SwapU

Australian Privacy Law Compliance:

  • Privacy Act 1988 (Cth)
  • Australian Privacy Principles (APPs)
  • Spam Act 2003
  • Do Not Call Register Act 2006

Contact: For privacy questions, email privacy@swapu.com.au


2. INFORMATION WE COLLECT

2.1 Information You Provide

Account Information:

  • Email address (required)
  • Phone number (optional, for SMS notifications)
  • Display name
  • Profile photo (optional)
  • Location (suburb or city)
  • Date of birth (to verify 18+ age requirement)

Vehicle Information:

  • Year, make, model
  • Registration details
  • VIN (Vehicle Identification Number)
  • Mileage (odometer reading)
  • Condition description
  • Photos of vehicle
  • Service records (optional)
  • Valuation information

Communication Data:

  • Messages with other users
  • Conversations with Nicholas AI
  • Support inquiries
  • Feedback and reviews

Financial Information:

  • Coordination fee payment records (the fee is processed by Stripe - see Section 2.5)
  • Coordination fee transaction history

Identity Documents:

  • SwapU does not currently collect government identity documents (such as a driver's licence or proof of address) and does not run third-party identity verification at this stage. If we introduce identity verification in future, this Policy will be updated first and you will be told what is collected and by whom.

2.2 Information Collected Automatically

Usage Data:

  • Pages viewed
  • Search queries
  • Listings viewed
  • Time spent on platform
  • Features used
  • Button clicks and interactions

Device Information:

  • IP address
  • Browser type and version
  • Operating system
  • Device type (mobile, tablet, desktop)
  • Screen resolution
  • Referral source

Location Data:

  • Approximate location (city/region) from IP address
  • Precise location (if you grant permission for meeting location suggestions)

2.3 Cookies and Tracking Technologies

We use cookies and similar technologies:

  • Essential Cookies: Required for platform functionality (login, session, preferences)
  • Analytics Cookies: Help us understand usage patterns (Google Analytics 4)

We do not currently run third-party advertising or ad-targeting cookies.

Cookie Control: You can disable cookies in your browser settings, but this may limit platform functionality.

2.4 Information from Third Parties

PPSR Reports:

  • If a PPSR report is ordered through the platform, we receive the vehicle encumbrance data returned by the register

SwapU accounts are created with email and password only — there is no Google, Facebook, or other social sign-in, so we do not receive profile information from social networks. We also do not currently use a third-party identity-verification service.

2.5 Payment Information

Stripe Processing: Payment card details are NOT stored by SwapU. All payment information is processed by Stripe (our payment processor) and subject to Stripe's Privacy Policy.

We receive from Stripe:

  • Last 4 digits of card
  • Transaction success/failure status
  • Payment amount and date

3. HOW WE USE YOUR INFORMATION

3.1 Primary Uses

Platform Functionality:

  • Create and manage your account
  • Display your vehicle listings
  • Match you with potential swap partners
  • Facilitate communication between users
  • Process the coordination fee
  • Provide customer support

AI Coordination (Nicholas AI):

  • Analyze your swap preferences
  • Generate personalized recommendations
  • Coordinate swap timelines
  • Draft communication messages
  • Identify potential issues or concerns

Safety and Verification:

  • Verify your identity
  • Prevent fraud and abuse
  • Detect suspicious activity
  • Protect user safety

Legal Compliance:

  • Comply with legal obligations
  • Respond to legal requests
  • Enforce our Terms of Service
  • Resolve disputes

3.2 Communications

We may contact you for:

  • Transactional messages: Swap updates, payment confirmations, security alerts
  • Notifications: New match found, message received, meeting scheduled
  • Marketing: Platform updates, new features, tips (you can opt out)
  • Surveys: Feedback requests to improve the platform

Opting Out:

  • Transactional messages: Cannot opt out (essential for service)
  • Marketing emails: Click "Unsubscribe" link in any email
  • SMS notifications: Reply STOP to any SMS
  • Push notifications: Disable in device settings

3.3 Analytics and Improvement

Platform Improvement:

  • Analyze usage patterns to improve features
  • Test new features with user groups
  • Measure platform performance
  • Identify and fix bugs

Matching Algorithm:

  • Improve matching accuracy using historical swap data
  • Train AI models on successful swaps
  • Optimize recommendations

3.4 Aggregate Data

We create anonymized, aggregate statistics for:

  • Public reporting (e.g., "1,000 swaps completed")
  • Research and analysis
  • Marketing materials
  • Industry reports

Aggregate data cannot identify you personally.


4. HOW WE SHARE YOUR INFORMATION

4.1 With Other Users

Public Profile Information:

  • Display name
  • Profile photo
  • Location (suburb/city only)
  • User rating/reviews

When You Express Interest:

  • Your vehicle details shared with potential swap partner
  • Your contact information (after both parties agree to connect)

When Swap Agreed:

  • Full contact details (email, phone)
  • Vehicle documents (for inspection)
  • Meeting location details

4.2 Service Providers

We share data with third-party providers who help us operate the platform:

Firebase / Google Cloud (Hosting, Database & Authentication):

  • Account data, listings, messages, authentication
  • Data stored in the Sydney, Australia region
  • Subject to the Google Cloud Privacy Policy

Stripe (Payment Processing):

  • Coordination fee payment information
  • Subject to the Stripe Privacy Policy

Resend (Email Delivery):

  • Email address and email content
  • For transactional and service emails

Twilio (SMS — optional):

  • Phone number and message content, only if you opt in to SMS notifications
  • Subject to the Twilio Privacy Policy

Anthropic (AI Services for Nicholas AI):

  • Conversation data used to generate Nicholas AI responses
  • Anthropic servers may be located outside Australia (see Section 8)
  • Subject to Anthropic's Privacy Policy

Google Analytics 4 (Usage Analytics):

  • Pseudonymous usage and device data
  • Subject to the Google Privacy Policy; you can opt out (see Section 9)

4.3 Legal Requirements

We may disclose information:

  • To comply with law: Court orders, subpoenas, legal processes
  • To protect rights: Enforce Terms of Service, investigate violations
  • To prevent harm: Fraud, security threats, illegal activity
  • In emergencies: Imminent danger to person or property

4.4 Business Transfers

If SwapU is acquired or merges with another company, your information may be transferred to the new owner. We'll notify you before your information is subject to a different privacy policy.

4.5 With Your Consent

We may share information for other purposes with your explicit consent.


5. DATA SECURITY

5.1 Security Measures

We implement technical and organizational measures to protect your data:

Technical Safeguards:

  • Encryption in transit (TLS/SSL)
  • Encryption at rest (AES-256)
  • Secure authentication (Firebase Auth)
  • Regular security audits
  • Intrusion detection systems

Organizational Safeguards:

  • Access controls (need-to-know basis)
  • Employee training on data protection
  • Confidentiality agreements
  • Incident response procedures

5.2 Your Responsibility

You are responsible for:

  • Keeping your password confidential
  • Using a strong, unique password
  • Logging out on shared devices
  • Reporting suspicious activity immediately

5.3 No Absolute Security

Important: No security system is 100% secure. While we take reasonable measures, we cannot guarantee absolute security of your data.


6. YOUR RIGHTS

6.1 Access Your Data

You have the right to request a copy of your personal information. Email privacy@swapu.com.au with your request.

We'll provide:

  • Account information
  • Listing history
  • Message history
  • Transaction records

Response Time: Within 30 days of verified request.

6.2 Correct Your Data

You can update most information directly in your account settings. For other corrections, contact privacy@swapu.com.au.

6.3 Delete Your Data

Account Deletion:

  • Email support@swapu.com.au requesting account deletion
  • We'll delete your account within 30 days
  • Some data retained for legal compliance (see Section 6.7)

Partial Deletion:

  • Delete specific listings
  • Remove profile photo
  • Clear message history

6.4 Restrict Processing

You can request we limit how we use your data in certain situations:

  • You contest the accuracy of data
  • Processing is unlawful but you don't want deletion
  • We no longer need the data but you need it for legal claims

6.5 Data Portability

You can request your data in a portable format (JSON, CSV) to transfer to another service.

6.6 Object to Processing

You can object to:

  • Marketing communications (opt out anytime)
  • Automated decision-making (request human review)
  • Use of data for specific purposes

6.7 Data Retention

Active Accounts:

  • Data retained while your account is active

Deleted Accounts:

  • Most data deleted within 30 days
  • Backup copies deleted within 90 days
  • Retained for legal compliance (12 months):
    • Transaction records (tax, financial reporting)
    • Legal agreements (dispute resolution)
    • Fraud prevention data

Legal Holds:

  • Data subject to legal proceedings retained until resolved

7. CHILDREN'S PRIVACY

SwapU is NOT intended for users under 18 years of age.

We do NOT knowingly:

  • Collect data from children under 18
  • Allow children to create accounts
  • Market to children

If we discover a child's account, we'll delete it immediately.

Parents: If you believe your child has created an account, contact privacy@swapu.com.au immediately.


8. INTERNATIONAL DATA TRANSFERS

Primary Data Location: Australia (Firebase Sydney region)

AI Processing: Anthropic servers may be located outside Australia. Data is:

  • Encrypted in transit
  • Processed per Anthropic's privacy policy
  • Subject to appropriate safeguards

User Location: Platform intended for Australian users. If you access from outside Australia, your data may be subject to Australian law.


9. COOKIES AND TRACKING

9.1 Cookie Types

Essential Cookies (Cannot Disable):

  • firebase:auth - Authentication session
  • firebase:anonymous - Anonymous user tracking
  • session_id - Platform session

Analytics Cookies (Can Disable):

  • _ga - Google Analytics 4 client identifier
  • _ga_* - Google Analytics 4 session/property identifier

Preference Cookies (Can Disable):

  • location - Saved location preference

9.2 Managing Cookies

Browser Settings:

  • Chrome: Settings → Privacy → Cookies
  • Firefox: Preferences → Privacy → Cookies
  • Safari: Preferences → Privacy → Cookies

Opt-Out Tools:

  • Google Analytics Opt-Out: tools.google.com/dlpage/gaoptout

9.3 Do Not Track

We currently do not respond to browser Do Not Track signals, but we respect your cookie preferences.


10. THIRD-PARTY LINKS

The Platform may contain links to third-party websites:

  • PPSR (ppsr.gov.au)
  • Insurance providers
  • Mechanic directories
  • Legal resources

We are NOT responsible for:

  • Privacy practices of third-party sites
  • Content on third-party sites
  • Use of your data by third parties

Review their privacy policies before providing personal information.


11. CHANGES TO THIS PRIVACY POLICY

11.1 Right to Modify

We may update this Privacy Policy to reflect:

  • Changes in our practices
  • Changes in law
  • New features or services
  • User feedback

11.2 Notification

For material changes:

  • Email notification to your registered email
  • Prominent notice on Platform
  • 30 days' notice before changes take effect

For minor changes:

  • Updated "Last Updated" date
  • Continued use constitutes acceptance

11.3 Version History

Previous versions available upon request.


12. COMPLAINTS AND DISPUTES

12.1 Internal Complaints

If you have a privacy concern:

  1. Email privacy@swapu.com.au with details
  2. We'll acknowledge within 5 business days
  3. We'll investigate and respond within 30 days
  4. We'll work with you to resolve the issue

12.2 External Complaints

If you're not satisfied with our response, you can lodge a complaint with:

Office of the Australian Information Commissioner (OAIC)
Website: oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
Mail: GPO Box 5218, Sydney NSW 2001

12.3 Governing Law

This Privacy Policy is governed by Australian law (Queensland jurisdiction).


13. CONTACT INFORMATION

Privacy Officer: Nicholas (Founder)
Email: privacy@swapu.com.au
Support: support@swapu.com.au
Address: Brisbane, Queensland, Australia

For privacy requests:

  • Access your data
  • Correct your data
  • Delete your account
  • Opt out of marketing
  • Lodge a complaint

14. CONSENT

By using SwapU, you consent to:

  • Collection of your personal information as described
  • Use of your information for purposes stated
  • Disclosure to third parties as outlined
  • Storage in Australia and potential processing overseas
  • Use of cookies and tracking technologies

You can withdraw consent by deleting your account, but this will prevent you from using the Platform.


15. ACKNOWLEDGMENT

By clicking "I Accept" or using the Platform, you acknowledge that:

✓ You have read and understood this Privacy Policy
✓ You consent to collection and use of your data as described
✓ You understand your rights regarding your personal information
✓ You are at least 18 years of age
✓ You understand data is stored in Australia
✓ You agree to receive necessary transactional communications


END OF PRIVACY POLICY

This Privacy Policy is a draft prepared for implementation and will be reviewed by a qualified lawyer before final public launch.