Privacy Policy
Last updated: September 3, 2026
This Privacy Policy describes how Swiftlook, Inc. ("Swiftlook," "we," "us," or "our") collects, uses, shares, and protects information in connection with the swiftlook.com marketing website, the Swiftlook web application at app.swiftlook.com, the Swiftlook Chrome extension, and any related products, services, or APIs (collectively, the "Service"). It applies to Swiftlook account holders, their team members and administrators, prospective customers, website visitors, and viewers who receive a Swiftlook link from a Swiftlook customer.
By using the Service, you consent to this Privacy Policy and to our Terms of Service. If you do not consent, do not use the Service.
1. Information we collect
1.1 Information you provide
When you create an account, use the Service, or contact us, we collect:
- Account information: name, email address, password (stored hashed via Supabase Auth), organization name and role, profile photo (if provided), timezone, and any other information you enter into your profile or organization settings.
- Billing information: processed by Stripe. Card numbers, expiry dates, and CVCs are transmitted directly to Stripe and are not received or stored by Swiftlook. We receive a Stripe customer identifier, invoice history, and the last four digits and brand of your card for display purposes.
- Communications: the content of any support tickets, sales inquiries, feedback, survey responses, or other correspondence you send us.
- Invitation content: phone numbers, email addresses, and message templates you enter when you send viewer link invitations, and the delivery status of each invitation.
- Content shared during sessions: we do not persistently store the video content of screen shares (see Section 3), but transient copies may exist in memory or in third-party service provider systems (e.g., our WebRTC media relay) for the brief moments required to transmit the stream.
1.2 Information we collect automatically
- Session metadata: presenter identity, session start and end timestamps, session duration, viewer link identifier, viewer join and leave times, watch duration, engagement events (page visibility changes, disconnect reason), device type, browser, viewport size, and coarse geographic location derived from IP.
- Log and device data: IP address, user-agent string, referring URL, pages accessed, timestamps, error messages, and diagnostic data — retained as needed for security, fraud prevention, product improvement, legal compliance, and other legitimate business purposes.
- Cookies and similar technologies: app.swiftlook.com uses first-party cookies required to keep you signed in, remember your preferences, and prevent fraud. The marketing site currently uses no cookies. We may add analytics or product-improvement cookies in the future; where required by law, we will obtain your consent first.
1.3 Information we receive from third parties
We may receive information about you from third-party services you connect to Swiftlook (such as HubSpot or Salesforce when you enable the CRM integration), from our sub-processors, and from publicly available sources for security and fraud prevention.
2. How we use information
We use the information we collect for any lawful purpose, including to:
- Provide, operate, maintain, secure, and improve the Service.
- Authenticate you, personalize your experience, and remember your preferences.
- Process transactions and administer your subscription.
- Send transactional messages (invoices, security notices, service announcements, invitation delivery, password resets) — you cannot opt out of these while your account is active because they are necessary to operate the Service.
- Send product updates, tips, and marketing communications where permitted by law. You can opt out of non-transactional marketing at any time using the unsubscribe link in those messages or by emailing support@swiftlook.com.
- Deliver engagement analytics back to you in your dashboard and, where you enable it, write session outcomes to your CRM.
- Investigate and prevent fraud, abuse, security incidents, and violations of our Terms of Service.
- Conduct research, analytics, benchmarking, and product development, including with the aid of aggregated or de-identified data (see Section 4).
- Comply with legal obligations, respond to lawful requests from public authorities, enforce our agreements, protect our rights, and defend against claims.
- Any other purpose disclosed at the time of collection or with your consent.
3. Screen-share content
Swiftlook is architected so that the video content of a screen share transits our infrastructure and is discarded. We do not maintain a persistent recording, transcript, or archival copy of the content displayed during a session unless recording is explicitly enabled on an Enterprise plan with the account owner's consent and configuration.
This is a deliberate design decision and is enforced in code. However, no computer system is perfectly secure and no representation about a system's behavior can be absolute. Session content may be transiently held in memory or in caches of third-party network providers for the brief moments required to transmit it. You should not use the Service to display information whose momentary transmission through commercial internet infrastructure would be unacceptable.
4. Aggregated and de-identified data
We may create aggregated, anonymized, or de-identified data from information collected through the Service. Aggregated data does not identify you or any individual and is not treated as Personal Information under this Policy. We may use, disclose, and retain aggregated data in perpetuity for any purpose, including improving the Service, benchmarking, marketing, research, and commercial arrangements with third parties.
5. How we share information
We share information as follows:
- Within your organization. Your organization's owners and administrators can access account details, session records, engagement analytics, and billing information for your account and for other members of the organization. If you use the Service through an organization, that organization controls your use of the Service and this Policy operates alongside any policies your organization has adopted.
- Sub-processors and service providers. We share information with third parties who process it on our behalf to deliver the Service, including but not limited to Supabase (authentication and database), Stripe (payments), Twilio (SMS delivery), SendGrid (email delivery), Cloudflare (DNS and edge), Railway (application hosting), and Hetzner Cloud (media relay infrastructure). We may add or change sub-processors at any time; the current list is available on request. Sub-processors are bound by contractual obligations to protect the information they process.
- Integrations you enable. If you connect a third-party integration (such as HubSpot or Salesforce), we will share session data and account information with that provider as necessary to deliver the integration you requested. The receiving provider's use of the shared information is governed by its own privacy policy.
- Corporate transactions. If Swiftlook is involved in a merger, acquisition, financing, reorganization, sale of all or part of its assets, bankruptcy, or similar transaction, information about you may be transferred to the successor or acquirer as part of that transaction, and this Policy may be updated by the new entity.
- Legal and safety. We may disclose information when we believe in good faith that disclosure is necessary to comply with applicable law, respond to lawful requests from public authorities (including in response to national security or law enforcement demands), enforce our Terms of Service, protect the rights, property, or safety of Swiftlook, our users, or the public, or in connection with an investigation of suspected or actual illegal activity.
- With your consent. We may share information in other cases when you direct us to.
We do not sell your personal information in the ordinary meaning of that term. Certain state privacy laws define "sale" or "share" broadly enough to include our operational disclosures to service providers; if any such transfer qualifies as a "sale" or "share" under a specific law, you have the right to opt out as described in Section 8.
6. Data retention
We retain information for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods vary by data type and depend on legal, operational, and security requirements. In general:
- Account and organization data — retained for the life of your account plus a reasonable period after deletion.
- Session metadata and engagement telemetry — retained as needed for product analytics, benchmarking, and CRM integration.
- Access logs, IP records, and security data — retained as needed for fraud prevention, security investigation, and legal compliance.
- Billing records — retained as required by tax and financial-recordkeeping laws (typically at least seven years in the U.S.).
- Backups — retained on a rolling cycle in accordance with our disaster-recovery policy. Information deleted from active systems persists in backups until they are cycled out.
We reserve the right to modify retention periods as needed to serve legitimate business purposes or to comply with legal obligations.
7. Your choices
- Access, correction, deletion. You can review and update most of your account information from your Account page. To request deletion of your account, contact us at support@swiftlook.com. We may retain certain information after deletion as described in Section 6.
- Marketing communications. You can opt out of marketing emails via the unsubscribe link or by contacting us. Transactional messages will continue while your account is active.
- Cookie choices. You may control cookies through your browser settings. Disabling cookies on app.swiftlook.com will prevent you from signing in.
- Do Not Track. Because there is no consistent industry standard for how to respond to "Do Not Track" signals, we do not currently respond to them.
8. State-specific rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another U.S. state with a comprehensive privacy law, you may have rights including: the right to know what personal information we collect and how we use it; the right to access and receive a copy of your personal information; the right to correct inaccurate personal information; the right to request deletion of personal information; the right to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising (we do not engage in such activity); the right to limit use of sensitive personal information (we do not use sensitive personal information for secondary purposes); and the right not to be discriminated against for exercising these rights.
To exercise any of these rights, email support@swiftlook.com from the address associated with your account, or contact your organization's administrator if you use the Service through an organization. We may request additional information to verify your identity before responding to a request. We will respond within the timeframes required by applicable law (generally 45 days).
You may designate an authorized agent to make requests on your behalf; we may require written proof of the agent's authority.
9. International users
Swiftlook is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other countries in which we or our sub-processors operate. By using the Service, you consent to the transfer of your information to countries that may have data-protection laws different from those in your jurisdiction. Where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the right to lodge a complaint with your local data protection authority.
10. Security
We use commercially reasonable administrative, technical, and physical safeguards to protect information from loss, misuse, unauthorized access, disclosure, alteration, or destruction. These include TLS in transit, encryption at rest on Supabase-managed Postgres, row-level security keyed on organization, ephemeral time-limited credentials for the media relay, least-privilege staff access, and logging of administrative actions. Despite these measures, no system is perfectly secure and we cannot guarantee the security of information you provide.
If you believe you have discovered a security vulnerability, please email support@swiftlook.com.
11. Children
The Service is intended for use by adults (18+) in a business context. It is not directed to children and we do not knowingly collect information from children. If you believe a child has provided us information, contact support@swiftlook.com and we will delete it.
12. Third-party links and services
The Service may contain links to, or integrations with, third-party websites and services. This Policy does not apply to those third parties. We encourage you to review the privacy policies of any third party before providing information to them. We are not responsible for the acts, omissions, or privacy practices of any third party.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated by email to account owners or by in-product notice a reasonable period before taking effect. Non-material changes take effect on posting. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
14. Contact
Questions, comments, complaints, or requests about this Privacy Policy: support@swiftlook.com.