← Home
Legal document — Chapter I

Privacy Policy

Version 1.1 · Last updated: August 6, 2026

1. Who we are

SWNG (the "Platform") is a private service for adults aged 18 or over to connect, communicate and organise events in the swinger community. It is operated by TOPHAT SOFT S.R.L. (Florești, Cluj, Romania), the data controller — full details are in our Legal Notice.

2. Data we collect

  • Account data: email, password (bcrypt hash), role, creation date.
  • Profile data: display name, age, city, bio, photos, preferences.
  • Technical data: IP address, browser agent, last login (security).
  • Communication: messages between users (encrypted in transit, stored on server).
  • Payments: processed by Stripe — we never see card details.

3. Why we collect it

  • Providing the service (matching, messaging, events).
  • Security (fraud detection, brute-force blocking).
  • Legal compliance (18+ verification, GDPR, payment AML).
  • Communication (notifications, only with your consent).

4. Legal basis for processing

We process your data under Article 6 GDPR: performance of our contract with you (providing the service); your consent (notifications, optional analytics, preferences you choose to share); compliance with a legal obligation (age verification, anti-money-laundering, tax records); and our legitimate interest (security, fraud prevention, improving the Platform). You may withdraw consent at any time, without affecting processing carried out beforehand.

5. Your rights (GDPR)

  • Right of access (full export from Settings).
  • Right to rectification (edit your profile anytime).
  • Right to erasure (30-day soft delete, then permanent).
  • Right to portability (JSON export from Settings).
  • Right to object to processing (disable notifications, analytics).
  • Right to lodge a complaint with your data protection authority.

6. Who we share with

  • Bunny.net (BunnyWay d.o.o., Slovenia, EU) — photo and video hosting and delivery.
  • Stripe (Stripe Technology Europe Ltd., Ireland, EU) — subscription payments; we never see or store your card details.
  • Resend (US) — transactional email (verification, security and account notices), under Standard Contractual Clauses.
  • Sentry (Functional Software, Inc., US) — error and crash diagnostics, under Standard Contractual Clauses.
  • Google (Gemini API) — on-demand translation and public assistance features; see "Automated processing, AI and translation" below.
  • Mistral AI (France, EU) — automated safety screening (scam and abuse detection).
  • OpenAI (US) — text embeddings for semantic search, under Standard Contractual Clauses, where enabled.
  • Never: advertising networks, data brokers or search engines. We do not sell your personal data.

7. International data transfers

The Platform is hosted on servers in the EU (Germany). Some processors listed above operate outside the EEA (for example in the United States); those transfers are protected by the European Commission’s Standard Contractual Clauses or an applicable adequacy decision. We never sell your personal data.

8. Automated processing, AI and translation

Matches, recommendations and search results are generated automatically from your preferences and activity. Automated safety screening (scam and abuse detection) runs through an EU-based AI processor (Mistral AI, France). When you tap "Translate" on a piece of content, the selected text — including a private message, if you choose to translate one — is sent to Google’s Gemini API to produce the translation; this happens only on your explicit action and the original text is never changed. These processes do not produce legal or similarly significant effects within the meaning of Article 22 GDPR; you may object to them or request human review by contacting us.

9. How we protect your data

We protect your data with encryption in transit (HTTPS/TLS), passwords stored only as salted bcrypt hashes (never in plain text), strict access controls and audit logging of sensitive actions. No system is perfectly secure, but if a breach is likely to affect your rights we will notify the competent supervisory authority within 72 hours and inform you where the law requires it.

10. Retention

  • Active account: for the duration of use.
  • Deleted account: 30 days soft delete, then full anonymisation.
  • Technical logs (IP, audit): 90 days.
  • Payments: 7 years (tax obligation).

11. Age restriction

The Platform is strictly for adults aged 18 or over. We do not knowingly collect data from anyone under 18; if we learn that we have, we delete the account and its data without delay.

12. Changes to this policy

We may update this policy for legal or technical reasons. Material changes will be announced in-app or by email before they take effect. The version and date shown above always indicate the current edition.

13. Contact

For any question about your personal data, email [email protected]We respond within 30 days, per GDPR Art. 12.