Legal

Privacy Policy

Last updated 11 September 2026. This is a working draft pending legal review — see the note at the bottom of this page.

1. Who we are

Swftap (“Swftap,” “we,” “us”) is operated by [PLACEHOLDER: registered business name and ABN]. We provide a platform for dynamic QR codes and links, digital business card profiles, and secure document sharing. This policy explains how we collect, use, store, and protect personal information, and your rights under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

We handle personal information in line with the full Australian Privacy Principles, regardless of whether the small business exemption in the Privacy Act would otherwise apply to us.

2. Information we collect

We collect the following categories of personal information:

  • Account information: your email address and authentication details when you register.
  • Profile content: information you choose to add to a digital profile — name, role, company, photo, contact details, and links.
  • Content you upload: documents you store or share via the Briefcase feature.
  • Usage and analytics data: QR scans, link clicks, profile views, and document engagement — including approximate device type, country, and timestamp — for the analytics we provide to you about your own content.
  • Billing information: handled directly by our payment processor, Stripe — we do not store your full card details ourselves.
  • Site analytics: we use Google Analytics to understand how our own marketing and account pages are used.

3. How we use your information

We use personal information to:

  • provide and operate the Swftap platform, including generating your QR codes, hosting your profile pages, and delivering shared documents to their intended recipients;
  • show you analytics about how your own QR codes, profiles, and shared documents are being used;
  • process payments and manage your subscription;
  • communicate with you about your account, including security notices and, where you have not opted out, product updates;
  • detect and prevent fraud, abuse, and security incidents; and
  • comply with our legal obligations.

4. Who we share information with

We do not sell personal information. We share information only with the service providers we rely on to run Swftap, each acting under their own privacy and security obligations:

  • Supabase — our database, authentication, and file storage provider (data hosted in Australia).
  • Stripe — payment processing.
  • attachmentAV — malware scanning for documents you upload.
  • Google Analytics — aggregated, anonymised site-usage analytics.

If you share a Briefcase document or a profile publicly, the information in it is of course visible to whoever you share that link with — that’s the feature working as intended, not a third-party disclosure.

We do not disclose personal information overseas except where a service provider listed above does so as part of providing their service to us.

5. Data security

Access to your workspace’s data — QR codes, profiles, and documents — is restricted to you and the members of that workspace; every request is checked against workspace membership at the server, not just hidden in the interface. Sensitive connected-account credentials are encrypted at rest. Uploaded documents are scanned for malware before being stored. Privileged administrative actions are recorded in an internal audit log.

No method of transmission or storage is 100% secure, but we take reasonable technical and organisational steps to protect your information appropriate to its sensitivity.

6. Data retention and deletion

We retain your personal information for as long as your account is active, and for a reasonable period afterwards to meet legal, accounting, or reporting requirements [PLACEHOLDER: confirm exact retention period, e.g. 7 years for financial records].

You can permanently delete your account and its personal data at any time from your account settings. Deleting your account removes your profiles, links, and uploaded documents; if you belong to a team workspace, your membership there ends but the workspace and its other members’ data are unaffected.

7. Access and correction

You can view and correct most of your personal information directly within the app at any time. You can download a copy of your personal information from your account settings. If you need a copy of information not available there, contact us using the details below.

8. Cookies and tracking

We use essential cookies to keep you signed in and to remember your preferences. We use Google Analytics to understand aggregate usage of our own site — this does not identify you individually to us beyond what you’ve told us by creating an account.

9. Making a complaint

If you have a concern about how we’ve handled your personal information, contact us first at [PLACEHOLDER: privacy contact email] so we can try to resolve it directly. If you’re not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10. Changes to this policy

We may update this policy from time to time. We’ll update the “last updated” date above when we do, and let you know of any material change.

11. Contact us

For any privacy question or request, contact [PLACEHOLDER: privacy contact email].

Note for Neville: this is a real first draft, not filler text — every claim above is checked against what Swftap actually does today (see checklist row H4 for the full list). The bracketed [PLACEHOLDER: ...] items are the only facts I can’t supply myself (your registered business name/ABN, retention-period specifics, and a real contact address) — fill those in, then have it reviewed by a solicitor before treating it as final. Once confirmed, remove this note.

Back to Swftap