Draft pending legal review
This policy accurately describes how the Swap Leads platform is built and what it does with data. It has not been reviewed by a qualified lawyer, and it is not legal advice.
Every highlighted field must be completed, and the whole document reviewed by counsel in your operating jurisdiction, before Swap Leads handles real users or real money.
Swap Leads is a marketplace for business opportunities. That means we hold personal data about two very different groups: our members, and the business contacts who appear inside the listings our members create. This policy explains both, because the second group deserves an explanation even though they never signed up with us.
1Who we are
Swap Leads is operated by [LEGAL ENTITY NAME], registered in [COUNTRY OF INCORPORATION] under company number [COMPANY NUMBER], with a registered office at [REGISTERED ADDRESS].
For the purposes of the UK GDPR, the EU GDPR and comparable data protection laws, we are the data controller for member data, and a controller alongside our members for the contact data held inside listings. Section 2 explains what that distinction means in practice.
You can reach our privacy contact at privacy@swapleads.app. [APPOINT A DATA PROTECTION OFFICER IF REQUIRED — ARTICLE 37]
2Two kinds of people in our system
Almost every privacy question about Swap Leads becomes clearer once you separate these two groups.
Members
People who create an account to buy or sell leads. You gave us your data directly, you agreed to our Terms, and you control your account. Sections 3, 5, 6, 9 and 10 are principally about you.
Listed contacts
Named individuals at companies who appear inside a listing — the decision maker, the person who mentioned a requirement. You did not sign up with us and you may not know a listing about your company exists. Section 11 sets out your rights and how to exercise them, and we treat those requests as a priority.
Where responsibility sits. The member who submits a listing decides what to include and warrants they have a lawful basis to share it. We decide how the platform stores, protects and transmits it. Both of us carry duties to you — and you may exercise your rights against either of us.
3What we collect about members
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email address, password (hashed, never stored in readable form), display name, organisation type, technology domains, generated alias | You, at registration |
| Verification | Phone number, verification status, which channel you used (Telegram, WhatsApp or SMS), timestamps | You, plus the channel provider |
| Messaging | Telegram chat ID, WhatsApp number, web push subscription — only if you connect them | You, plus Telegram or WhatsApp |
| Marketplace activity | Listings created, leads purchased, credit balance and ledger, saved searches, search queries | Generated as you use the service |
| Payment | Transaction records, amount, package purchased, Stripe reference. We never see or store your card number. | Stripe |
| Technical | IP address, browser and device type, timestamps, error logs | Collected automatically |
| Support | Messages you send us and our replies | You |
We do not collect special category data (health, biometrics, political opinions and so on), and you should never submit it to us.
4Data inside a listing
This is the heart of the service and the part that deserves the most precision.
What is encrypted
Six fields are encrypted in your browser using AES-GCM 256-bit encryption before they are transmitted to us: company name, contact name, contact email, contact phone number, website and LinkedIn URL. They travel as ciphertext and rest in our database as ciphertext.
What is not encrypted
Industry, company size, country, requirement type, pain point description, budget range, timeline, decision authority, relationship basis and relationship strength are stored in readable form. These are what a buyer sees before purchase, and they are deliberately chosen to convey commercial fit without identifying the company.
Who can read the encrypted fields
- The member who created the listing, in the browser that created it
- A buyer who has purchased that specific listing
- Our lead validators, who must see the full submission to review it
- Our super administrators, for fraud investigation and legal compliance
Access by validators and administrators is authenticated, role-restricted and written to an audit log. Other members — including buyers browsing the marketplace — cannot access these fields at all.
An honest limitation. Your encryption key is generated per browser and stored in that browser. If you clear your site data or switch device, you lose the ability to read your own past listings, and we cannot recover them for you — we never held your key. Buyers who already purchased are unaffected.
5Why we use your data
- To run the marketplace — create and display listings, process purchases, maintain credit balances
- To verify identity — confirm your email and phone so both sides of a trade are accountable
- To validate listings — human review of every submission against our quality bar
- To take payment — process credit purchases and keep transaction records
- To notify you — lead approvals, sales, saved-search alerts, on the channels you chose
- To power search — including the conversational AI search described in section 7
- To prevent fraud and abuse — detect fabricated listings, duplicate accounts and circumvention
- To meet legal obligations — tax records, responding to lawful requests
- To improve the service — aggregated and anonymised usage analysis
We do not sell member personal data, and we do not use it for third-party advertising.
6Legal bases for processing
| Purpose | Legal basis |
|---|---|
| Providing the marketplace to you | Performance of a contract |
| Payment processing and records | Contract, and legal obligation for tax records |
| Identity verification | Contract, and legitimate interests in trust and safety |
| Fraud prevention and platform security | Legitimate interests |
| Service and transactional notifications | Contract |
| Marketing emails to members | Consent, withdrawable at any time |
| Processing listed-contact data | Legitimate interests of the member and buyer in B2B commerce, subject to section 11 |
| Complying with law enforcement or regulators | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You can ask us for that assessment, and you can object — see section 10.
7Who we share data with
We use the following processors. Each is bound by contract to process data only on our instructions.
| Provider | Purpose | What it receives |
|---|---|---|
| Google (Firebase) | Authentication, database, hosting infrastructure | All stored data, including encrypted fields as ciphertext |
| Vercel | Application hosting and delivery | Request data, IP addresses, logs |
| Stripe | Payment processing | Email, payment details you enter directly with them |
| Resend | Transactional email | Email address, message content |
| Telegram | Bot notifications, Mini App, phone verification | Telegram user ID, message content, phone number if you verify this way |
| Green API | WhatsApp notifications and verification | Phone number, message content |
| Anthropic | Conversational AI search over listings | Your search query and the non-encrypted listing fields. Encrypted contact data is never sent. |
We also share data:
- With buyers — the contact details of a listing they have purchased
- With sellers — that a sale occurred, and the buyer's alias only. Never the buyer's identity.
- Where the law requires it — court orders, regulators, law enforcement, subject to review
- In a business transfer — if we are acquired or merged, with notice to you beforehand
Between members, identity is never shared. Members see
only a generated alias such as Cobalt-Falcon-4821. Linking
an alias to a real person is restricted to super administrators, is
limited to fraud, safety and legal compliance, and is logged every time.
8International transfers
Our providers operate globally, so your data may be processed outside your country — including in the United States. Where we transfer personal data out of the UK or the European Economic Area, we rely on adequacy decisions where they exist, and otherwise on Standard Contractual Clauses together with supplementary technical measures.
Client-side encryption of the six contact fields is one such measure: those fields cross borders as ciphertext. [CONFIRM YOUR FIREBASE REGION AND LIST IT HERE]
9How long we keep data
| Data | Retention |
|---|---|
| Account and profile | While your account is open, then [30/90] days after deletion |
| Purchased leads | Retained for the buyer indefinitely, as purchased content |
| Unsold and withdrawn listings | [12/24] months, then deleted |
| Transaction and credit records | [6/7] years, to satisfy tax and accounting law |
| Verification records | Life of the account plus 12 months |
| Administrative audit logs | [24] months |
| One-time verification codes | 10 minutes |
| Technical logs | [90] days |
Deleting your account does not withdraw leads already sold — a buyer who paid for a lead keeps it. Ask us and we will anonymise your association with those records.
10Your rights
Depending on where you live, you have some or all of the following rights. They apply to members and to listed contacts alike.
- Access — a copy of the personal data we hold about you
- Rectification — correction of anything inaccurate
- Erasure — deletion, where we have no overriding lawful reason to keep it
- Restriction — pause our processing while a dispute is resolved
- Portability — your data in a machine-readable format
- Objection — to processing based on legitimate interests, including profiling
- Withdraw consent — at any time, where consent is the basis
- Non-discrimination — we will not degrade your service for exercising these rights
Email privacy@swapleads.app. We respond within one month, and will tell you if we need longer. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with our response you may complain to your data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your national supervisory authority. [NAME YOUR LEAD SUPERVISORY AUTHORITY]
11If you appear in a listing
You may have reached this page because you learned that your name, work email or work phone number appeared in a Swap Leads listing. You have full rights over that data, and you do not need an account to exercise them.
What to do
Email privacy@swapleads.app with enough detail to identify the record — your name, your company, and the email address or phone number involved. We will:
- Locate every listing containing your details
- Tell you what is held, when it was submitted, and whether it was sold
- Remove the listing from the marketplace on request
- Erase your details from our systems unless we are legally required to keep a record
- Tell any buyer who purchased it that erasure has been requested
A limit we must be honest about. Once a buyer has purchased a lead, your details are in their possession and in their systems. We will identify that buyer to you and require them to comply with your request, but we cannot technically un-send data they already hold. Their use of it makes them a controller in their own right, with their own obligations to you.
You may also object to your details being listed at all. We will honour that and record it, so that future submissions naming you are refused at validation.
12How we protect data
- Client-side encryption — AES-GCM 256 on the six contact fields, applied before transmission
- Encryption in transit — TLS on every connection
- Verified accounts — email and phone confirmed before meaningful platform access
- Least privilege — staff roles are separated, so a lead validator cannot touch credit balances and a credit administrator cannot read listings
- Server-authoritative permissions — sensitive fields such as credit balance, admin role and verification status can only be written by our servers, never by a browser
- Audit logging — every administrative action is recorded with actor, target and timestamp
- Database rules — enforced at the storage layer, not only in application code
No system is perfectly secure. If a breach occurs that risks your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and tell you directly where the risk is high.
13Cookies and local storage
We use only what the service needs to function:
- Authentication — keeps you signed in between visits
- Encryption key storage — your browser holds your own key in local storage; it is never transmitted to us
- Preferences — interface settings you have chosen
- Security — reCAPTCHA where SMS verification is used, to prevent abuse
We do not use advertising or cross-site tracking cookies. If we later add analytics, we will ask for your consent first and update this section.
14Children
Swap Leads is a business tool for adults. It is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a minor has created an account, contact us and we will delete it.
15Changes to this policy
We will update this policy as the service develops. The version number and effective date at the top always reflect the current text. For material changes we will email members at least 14 days before they take effect, and where the law requires it we will ask for fresh consent.
16Contact us
Privacy questions and rights requests:
privacy@swapleads.app
General enquiries:
hello@swapleads.app
Post: [REGISTERED ADDRESS]
See also our Terms and Conditions, which govern your use of the platform.