Legal
Privacy Policy
Last updated: 12 February 2026 ยท Effective: 12 February 2026
1. Who we are
Swishr Desk ("we", "us", "our") is operated from the United Arab Emirates. This Privacy Policy explains what personal data we collect when you visit swishrdesk.com, create an account, or use our products and tools.
If you have questions, get in touch via our contact form at /contact.
2. What we collect
Account data: when you sign up, we collect your name, email address, business name (optional), and a securely-hashed password. If you sign in with Google, we receive your name, email and profile photo from Google.
Document data: documents you create (proposals, invoices, quotations, contracts) and the client details you choose to enter. We never use this data to train any AI model.
Payment data: when you upgrade, Stripe processes your card directly. We never see or store your full card number โ only the last 4 digits and the Stripe customer ID.
Usage data: pages visited, features used, IP address, browser type and approximate location (city-level only). We use this to fix bugs and improve the product.
Marketing-source data: when you sign up we ask "How did you find Swishr?" and may record UTM parameters from your landing URL.
Cookies: we use essential cookies for login (HttpOnly JWT) and optional cookies for analytics. You can decline non-essential cookies.
3. Why we collect it
To provide the service โ generate your documents, store them securely, send them to clients on your behalf.
To bill you and prevent fraud โ Stripe handles payments; we use your billing data only to apply the right plan and tax.
To improve the product โ anonymised usage data tells us which features are broken or under-used.
To send you transactional emails โ receipts, signature confirmations, password resets. These are required for the service to function.
To send you marketing emails โ only if you opted in (e.g. when you submitted a directory listing or downloaded a free tool with the marketing-opt-in box ticked). You can unsubscribe any time from the link in every marketing email.
4. Who we share it with
Stripe โ payment processing. (Privacy Policy: stripe.com/privacy)
Resend โ transactional email delivery. (resend.com/legal/privacy-policy)
Cloudflare R2 โ encrypted document storage. (cloudflare.com/privacypolicy)
MongoDB Atlas โ primary database, hosted on AWS regions inside your data-residency boundary where possible.
Google Cloud (Gemini / OpenAI / Anthropic) โ AI document generation. The prompts you submit are processed by these providers under their respective enterprise data-handling agreements and are NOT used to train their models.
We do NOT sell your data. Ever. We do NOT rent, lend or trade your personal data with any third party for marketing purposes.
If we're legally compelled (court order, valid warrant), we will respond โ but we will notify you first unless legally prohibited.
5. How long we keep it
Active accounts: as long as you have a Swishr Desk account.
Closed accounts: 90 days after you request deletion, at which point all personal data is irreversibly removed except where retention is legally required (e.g. tax records โ 7 years).
Documents: stored as long as your account is active. You can delete any document at any time. Deleted documents are purged from backups within 35 days.
Marketing leads (Directory submissions, free-tool email captures): until you unsubscribe. After unsubscribe, we keep an unsubscribed flag indefinitely so we never re-add you.
6. Your rights
Under EU GDPR, UK GDPR, UAE PDPL 2021, Canadian CASL/PIPEDA, and California CCPA, you have the right to:
โข Access โ request a copy of the data we hold on you.
โข Rectify โ correct any inaccurate data.
โข Erase โ delete your account and all associated personal data.
โข Restrict โ pause certain processing.
โข Object โ opt out of marketing or profiling.
โข Data portability โ receive your data in a structured machine-readable format (JSON).
โข Withdraw consent โ for any processing based on consent (marketing, optional analytics).
To exercise any of these rights, get in touch via our contact form. We respond within 30 days and charge no fee.
7. Security
Passwords are hashed with bcrypt (cost factor 12).
All data in transit uses TLS 1.3 over HTTPS.
Database encryption at rest is provided by MongoDB Atlas (AES-256).
Backups are encrypted and stored in a separate region.
Access to production data is restricted to two named engineers, both on hardware security keys + 2FA.
We do not store full credit-card numbers, CVV or PINs anywhere โ Stripe handles all of that.
If we ever experience a data breach affecting you, we will notify you within 72 hours per GDPR Article 33.
8. Children
Swishr Desk is a business tool. It is not directed at and we do not knowingly collect data from anyone under 16. If you believe we have collected data from a minor, email us and we will delete it.
9. International transfers
Some of our sub-processors (Stripe, Resend, MongoDB Atlas, AI providers) operate from the United States or the European Union. By using Swishr Desk, you consent to your data being processed in those regions.
For EU/UK users: we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to safeguard data transferred outside the EEA.
10. Changes to this policy
We may update this policy as our service evolves. The "Last updated" date at the bottom of this page changes each time. For material changes (new sub-processors, new data categories, new sharing partners), we will email all active users at least 14 days before the change takes effect.
11. Contact
Data controller: Swishr Desk (UAE)
Contact: via the contact form at /contact
We do not currently have a postal address available for public publication. For data-subject access requests under GDPR/PDPL, the contact form is the official channel.
