DRAFT for legal review. Not yet in force. Items in [brackets] are to be completed.
Privacy Policy
Last updated: [DATE]
This policy explains what personal data SwapTrip collects, why, who we share it with, how long we keep it and your rights.
1. Who is responsible
[COMPANY LEGAL NAME], [ADDRESS], Greece, is the controller of your personal data on swap-trip.com. Contact for privacy questions: [email protected].
2. What we collect
- Account: name, email, optional country, password (stored hashed by our authentication provider), two-factor settings.
- Identity check: performed by Stripe. We receive whether it passed, not your ID documents or selfie.
- Payouts: Stripe collects your bank details; we store only a Stripe account reference and whether payouts are enabled.
- Bookings you list: hotel, dates, prices, a scrambled (hashed) reservation number, your notes, and the proof documents you upload (confirmation email, invoice, updated confirmation).
- Purchases and sales: amounts, status history, problem reports and their outcome.
- Messages with the other party to a booking, and reviews.
- Saved searches, notifications and email preferences; credits.
- Security and technical data: IP address (for rate limiting and fraud prevention), login events, error reports (without cookies, form contents or request bodies).
3. Why we use it and our legal basis
- To provide SwapTrip and carry out transactions you request: performance of a contract (GDPR Art. 6(1)(b)).
- Identity checks, document review, flagging off-platform payment attempts and fraud prevention: our legitimate interest in a safe marketplace and protecting users (Art. 6(1)(f)), and legal obligations where they apply.
- Keeping transaction and accounting records: legal obligation (Art. 6(1)(c)).
- Service emails about your bookings: performance of a contract. Saved-search alerts: your choice; you can turn them off any time.
We do not sell your data or use it for advertising profiles.
4. Who we share it with
With the other party to a deal, only what's needed: a Seller sees the Buyer's full name (to change the guest name); Buyers see a Seller's first name, ID-verified status and reviews. Our service providers process data on our behalf under data-processing agreements:
- Supabase (database, authentication, file storage), hosted in the EU (Frankfurt).
- Stripe (payments, payouts, identity checks).
- Resend (sending emails), EU region.
- Cloudflare (Turnstile bot protection, DNS).
- Vercel (hosting) and Sentry (error monitoring).
- Google (hotel names, addresses and photos via Google Places; no personal data about you).
Some providers may access data from outside the EEA; where they do, transfers rely on the EU-US Data Privacy Framework or Standard Contractual Clauses. [LEGAL REVIEW: confirm each provider's transfer mechanism.]
5. How long we keep it
- Account data: until you delete your account.
- Listings that never sold and their documents: deleted with your account.
- Records of completed or refunded transactions (deals, payments, proof documents tied to a sale): for as long as Greek tax and accounting law requires [LEGAL REVIEW: period, typically 5-10 years], then deleted. If you delete your account we anonymize your profile and keep only these records.
- Security logs: [90 days]. Error reports: [30 days].
6. Your rights
You can access and download your data (Account → Your data → Download), correct it, delete your account, object to or restrict certain processing, and receive your data in a portable format. Contact [email protected] for anything you can't do in the app; we reply within one month.
You can complain to the Hellenic Data Protection Authority (www.dpa.gr) or your local data protection authority.
7. Cookies
We use only cookies that are strictly necessary: to keep you logged in, remember the "stay logged in" choice, and protect forms from bots (Cloudflare Turnstile). We don't use advertising or analytics cookies. [If analytics are added, update this section and ask for consent where required.]
8. Security
We protect data with encryption in transit, strict access controls at the database level, two-factor authentication for staff, virus and content scanning of uploads, and audit logs of administrative actions. No system is perfectly secure; if a breach affects you, we'll tell you as the law requires.
9. Children
SwapTrip is not for people under 18, and we do not knowingly collect their data.
10. Changes
We'll update this policy when our practices change and tell you about significant changes in advance.