Privacy Policy

Effective October 7, 2026 (version 2) · Swop Technologies Inc. (“Swop”, “we”, “us”)

What changed. Version 2 replaces version 1 published earlier on October 7, 2026, which replaced the version effective July 30, 2026. Compared with the July 30 version, it adds how card payments and seller verification handle your data (section 4), names our main service providers (section 6), and adds sections on international transfers and your privacy rights. Version 2 also names Swop Technologies Inc. as the company responsible for your information and describes how Swop’s AI features process what you send them, including the providers currently used, one of which is based in China (sections 6 and 8).

1. What Swop is

Swop Technologies Inc. (“Swop”) operates the Swop app, the Swop mobile apps, and swopme.co, and is responsible for the personal information described in this policy (where data-protection law uses the term, Swop Technologies Inc. is the controller). Swop is a self-custody platform for digital identity and payments: you create a public SmartSite, manage crypto wallets you control, and sell or accept payments. Your wallets are embedded wallets provided through Privy; Swop does not hold your private keys or the funds in your crypto wallets. If you choose to grant Swop a delegated signing permission (for example, for an agent or automation), Swop can sign the transactions you allowed until you revoke it. Checkout payments can work differently: a card charge settles through Swop’s payment processor (section 4), and some crypto checkout payments pass through a Swop settlement wallet, before reaching the seller.

2. Information we collect

  • Account information — name, email address, and profile details you provide when you sign up or edit your SmartSite. Sign-in and embedded wallets are provided by Privy, which processes your login identifiers (such as email or a linked account) to authenticate you.
  • Wallet addresses — the public blockchain addresses linked to your account. Blockchain transactions are public by design.
  • Content you publish — anything you place on your public SmartSite is public.
  • Visitor submissions — when a visitor fills a form or books a meeting on someone’s SmartSite, we collect what they enter (such as name and email) and deliver it to that SmartSite’s owner.
  • Card payment records — when a purchase is paid by card, we keep references to the payment held by our processor, the amounts, and the status of the payment, refunds, and disputes. We do not receive or store card numbers. See section 4.
  • Seller verification status — if you sell and accept card payments, we keep a summary of your verification outcome. The identity documents themselves go to our payment processor, not to us. See section 4.
  • Messages to AI features — what you send to Ask Swop, Swop’s agent features, and SmartSite AI assistants, which is processed by AI models, as described in section 6, to generate a response. Those currently include a provider based in China.
  • Usage and device data — logs, IP address, and analytics used to operate and secure the service.

3. Google user data (Calendar template)

If you connect Google Calendar to power the Calendar template on your SmartSite, Swop accesses your Google data strictly to run that feature:

  • What we access — your Google account email address (to show which account is connected), free/busy information from your calendar (to compute open time slots), and permission to create calendar events (to add a booking, with a Google Meet link, when a visitor books).
  • What we store — encrypted OAuth tokens, your Google account email, and the bookings created through Swop. We do not store the contents of your calendar: event titles, attendees, and details of your existing events never leave the availability computation.
  • What we never do — we do not sell Google user data, do not use it for advertising, do not transfer it to third parties except as necessary to provide the feature (or for security or legal compliance), and humans do not read it except with your permission, for security, or to comply with law.
  • Revoking access — disconnect at any time from your SmartSite editor, or from your Google Account at myaccount.google.com/permissions. Disconnecting deletes our stored tokens.

Swop’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Card payments and seller verification

Card payments are being introduced gradually and are not yet available to every seller. Where enabled, sellers can accept card payments alongside crypto. Card payments are processed by Stripe, and this section describes what that means for your data. It applies only to card payments. Crypto and x402 payments on Swop are not identity-verified and nothing in this section applies to them.

  • If you pay by card — you enter your card details directly into Stripe’s own payment form (on the web) or Stripe’s payment sheet (in the Swop mobile app, on app versions that support it). Those details go to Stripe, not to Swop. We never receive, process, or store your card number, expiry date, or security code, and we do not store your card brand or last four digits either. What we keep is the reference Stripe gives us for the payment, the amount, the currency, and the status of the payment and of any refund or dispute. Your name and billing address, if Stripe collects them, stay with Stripe.
  • If you sell and accept card payments — Stripe verifies your identity before you can be paid, and collects what it needs to satisfy its legal obligations. That typically includes your legal name, date of birth, address, contact details, a government-issued identity document, in some cases a selfie taken for liveness checking, your business details, your tax identification number, and the bank account or debit card you want to be paid into. You provide some of it on Stripe’s own hosted pages and some of it in the Swop app. When you provide it in the Swop app, your name, date of birth, addresses, phone, email, business details, and the last four digits of a national identity number pass through Swop’s servers to Stripe and are not stored by Swop. Identity documents are uploaded from your device directly to Stripe, and your full identity number, tax identification number, and bank or card numbers are converted into single-use Stripe tokens on your device, so Swop does not receive those values. To let you tell your payout accounts apart, the app shows you the bank or card name and last four digits, read live from Stripe and not stored by Swop. If you accept Stripe’s terms in the app, Swop passes the date, IP address, and device details of that acceptance to Stripe.
  • What Swop keeps about a verified seller — a summary of the outcome, not the evidence behind it: whether you are verified, whether you are currently able to accept charges and receive payouts, your two-letter country, coded descriptions of anything Stripe is still waiting on, a reference we use to look your account up with Stripe, and records of the payouts sent to you (amount, currency, status, and arrival date — never the bank account they landed in).
  • Stripe’s own role — Stripe handles this data for its own legal and regulatory purposes (including fraud, sanctions, and anti-money-laundering checks) as well as on our instructions, so Stripe’s privacy terms govern what Stripe does with it. Read them at stripe.com/privacy. Deleting your Swop account does not by itself delete the records Stripe is required to keep.
  • How long we keep it — payment records, verification status, and the underlying accounting entries are kept while your account is open and afterwards for as long as we need them to complete refunds and disputes, keep accurate financial records, and meet our legal and tax obligations. Where a purchase is paid by card, we cannot delete the record of that payment on request while those obligations are still running.

5. How we use information

To provide and improve the service, process payments you initiate, deliver notifications you request, prevent fraud and abuse, and comply with legal obligations. We do not sell your personal information.

6. Sharing

We share data only with service providers that operate the platform for us — including cloud hosting (such as Amazon Web Services and Vercel), sign-in and embedded wallets (Privy), email delivery, live video, media storage, AI model providers for AI features, and payment processing (Stripe for card payments and seller verification, as described in section 4) — when you direct us to (for example, a booking is shared with the SmartSite owner you booked, or an order is sent to a swap, bridge, prediction-market, or perpetuals venue you chose to use, which receives your wallet address and order details), and where required by law. Public blockchains are public; anything you publish to your SmartSite is public. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

AI processing. When you use Ask Swop, Swop’s agent features (such as trading agents), or the AI assistant on a SmartSite, the messages you send and the context the feature needs to answer (for example, relevant profile, wallet, portfolio, order, or market information) are processed by AI models to generate the response. Those models are run by third-party AI model providers or are open-source models that we host. The models we use may change over time, and we will update this section when they do. Currently, depending on the feature and the model it is configured to use, the providers are Anthropic (United States), OpenAI (United States), and DeepSeek. Each provider handles that data under its own terms and privacy policy.

DeepSeek is based in the People’s Republic of China, and Ask Swop and the agent features can currently use it, so what you send to them may be transferred to, processed in, and stored in China, where data-protection law differs from the law where you live; see section 8.

Please do not include sensitive personal information, passwords, private keys, or recovery phrases in messages to AI features.

7. Security & retention

Sensitive credentials (including Google OAuth tokens) are encrypted at rest, and access is limited to systems that need it. We retain data while your account is active or as needed to provide the service; you can request deletion of your account and associated data at any time from account settings or by contacting us. Payment, refund, dispute, and seller-verification records are the exception: we keep those for as long as our financial, tax, and legal obligations require, as described in section 4. Data written to a public blockchain cannot be deleted by anyone. No system is perfectly secure, and we cannot guarantee the security of information sent to or stored by us.

8. International transfers

Swop and its service providers operate in the United States and other countries, so your information may be processed outside the country where you live, including in countries whose data-protection laws differ from yours. In particular, messages and context sent to AI features that currently use DeepSeek may be processed and stored in the People’s Republic of China (see section 6). For our other service providers, where the law requires it, we use contractual safeguards such as standard contractual clauses where the provider offers them. We do not have such an agreement with DeepSeek: if you do not want your messages processed in China, do not use the AI features that rely on it, or contact us and we will tell you which features those are.

9. Your choices and rights

You can access, update, or delete your account information, revoke connected integrations, and control notification preferences in the app. Depending on where you live (for example, under the EU and UK GDPR or California and other U.S. state privacy laws), you may also have the right to know what personal information we hold, and to access, correct, delete, or receive a portable copy of it, to object to or restrict certain processing, to withdraw consent where we rely on it, and to appeal a decision we make about your request. Email support@swopme.co to exercise them; we may need to verify your identity first, and you may use an authorized agent where the law allows. We will not discriminate against you for exercising these rights. You may also complain to your local data-protection authority.

10. Children

Swop is intended for people aged 18 and over and is not directed to children. We do not knowingly collect personal information from anyone under 18; if we learn that we have, we will delete it.

11. Changes & contact

We will post any changes to this policy here with a new effective date, which is never earlier than the day it is posted, and we will tell you about a material change in the app or by email before it takes effect. Swop Technologies Inc. can be reached with questions or requests at support@swopme.co.