דלג לתוכן הראשי
Legal Document

Privacy Policy

Effective: 19 בSeptember 2026
v1.4
Updated: 19/09/2026

Introduction

This Privacy Policy describes how the Swapli Platform collects, uses, retains, and shares your personal information. This Policy is an integral part of our Terms of Service and complies with the requirements of the General Data Protection Regulation of the European Union (GDPR — Regulation (EU) 2016/679) and the Israeli Privacy Law (1981-5741).

By using the Platform at swapli.net, you confirm that you have read and understood this Privacy Policy.


Definitions

"Swapli" or "we" — Swapli by Webguy BV, a company registered in the Netherlands, company registration number KVK 72381647, located in Amsterdam, The Netherlands.

"Platform" — The website swapli.net, including all subdomains, applications, and related services operated by Swapli.

"Personal Information" — Any information relating to an identified or identifiable natural person, including name, email, phone number, address, photographs, payment details, and identity information.

"Data Subject" — A person whose personal information is processed by Swapli — a user classified according to their status in the community (Visitor, Registered, Member (Free), or Premium Member) in accordance with our Terms of Service.

"Data Processor" — A third party that processes personal information on our behalf and under our instructions, such as Stripe, Supabase, Vercel, and others.

"Biometric Data" — Information relating to the physical characteristics of a person, such as facial recognition or liveness verification.


1. Swapli as Data Controller

Swapli is the Data Controller as defined in GDPR Article 4(7). This means we determine the purposes and means of processing your personal information.


2. What Information We Collect

2.1 Information You Provide Directly

During Registration:

  • Full name (as it appears on your identification document)
  • Email address
  • Mobile phone number
  • Password — optional. Registration is completed without a password (a one-time code by email or a Google account). If you choose to set a password, it is stored hashed (bcrypt) and Swapli does not retain the password itself.
  • Referral code (if entered during registration)

When Creating a Profile:

  • Profile photograph (Required)
  • Personal description (Required)

When Listing a Property:

  • Partial property address — country and city/town only
  • Property description
  • Property information: number of rooms, number of beds, amenities, pets, and more
  • Up to 20 photographs of the property

When Conducting an Exchange:

  • Requested dates
  • Number of guests
  • Notes and special requests
  • Responses to checklist (optional)

When Setting Matching Preferences:

  • Preferences you provide for matching — desired destinations, availability dates and travel wishes, and alert settings (such as "Radar") — are processed to show you relevant matches and to send the alerts you have requested.

During Communication:

  • Messages between Members (text)
  • Exchange requests and responses
  • Support inquiries

2.2 Information Collected Automatically

Technical Details:

  • IP address
  • Browser type and operating system
  • Device type
  • Cookies
  • Server logs (access times, pages viewed)

Platform Activity:

  • The home searches you run — destination, date range, number of guests, the amenities you filtered by, and how many results were returned
  • Homes you marked as favourites
  • Destinations and dates you set as desired holidays
  • Enquiries you created and exchange requests you sent

This information is collected for signed-in Members only. We do not record searches made by visitors who are not signed in to an account.

During Payment Processing:

  • Payment details are processed by Stripe only — Swapli does not see or retain credit card numbers
  • Payment history (amount, date, status)
  • Invoices
  • Automatic renewal status

2.3 Biometric Data — Identity Verification (KYC)

When you undergo identity verification through Didit or Stripe:

  • Government-issued identification document photograph
  • Selfie photograph (processed by third-party provider only)
  • Biometric data — facial recognition and liveness verification (processed by third-party provider only)

What Swapli Retains from the Verification Process:

  • Verification result (pass/fail)
  • Name as it appears on the document
  • Date of birth
  • Document type (passport, identity card, etc.)
  • Document number (partially encrypted)
  • Issuing country

What Swapli Does Not Retain:

  • Photographs of identity documents
  • Selfie photographs
  • Video recordings
  • Raw biometric data
  • Residential address — even if it appears on the identity document, Swapli does not retain it

Verification may also be performed via a human video call on WhatsApp, initiated by the Member, with scheduling handled by an external scheduling tool (TidyCal) that receives only name, email, phone, and time. During the call an identification document is shown for visual verification; Swapli stores only the verification result (as detailed above) and does not record the call. This path does not involve automated biometric processing.


3. Legal Basis for Processing Personal Information

In accordance with GDPR Article 6, all processing of personal information is based on one of the following legal bases:

PurposeLegal BasisRelevant Information
Account creation and managementContract performance (Article 6(1)(b))Name, email, phone, password
Identity verification (KYC)Contract performance + Legitimate interest (Article 6(1)(b) + (f))Name, date of birth, document details
Biometric data processingExplicit consent (Article 9(2)(a))Facial recognition data
Payment processingContract performance (Article 6(1)(b))Payment details via Stripe
Platform operationLegitimate interest (Article 6(1)(f))IP, logs, technical data
Tax record retentionLegal obligation (Article 6(1)(c))Payment records
Newsletter and marketing emailsExplicit consent (Article 6(1)(a))Email, name, preferences
Use of photographs for marketingContract performance — license in Terms of Service (Article 6(1)(b))Property photographs

4. Biometric Data — Special Category

In accordance with GDPR Article 9, biometric data is a special category of personal information requiring enhanced protection.

Legal Basis: Your explicit consent (Article 9(2)(a)). You will be asked to provide clear and explicit consent before beginning the identity verification process. Without consent — no processing occurs.

Processing by Third Party: Biometric data is processed by Didit or Stripe only, in accordance with their privacy policies. Swapli does not retain raw biometric data — only the verification result.

Your Rights:

  • You may withdraw your consent at any time (see Section 7). Note that withdrawal of consent will not affect the legality of processing that occurred before the withdrawal, but may affect your ability to use services requiring identity verification.
  • You may request access to retained data (see Section 7).
  • You may request deletion, subject to legal retention obligations (see Section 7).

5. How We Use Your Information

5.1 Essential Purposes (Do Not Require Separate Consent)

  1. Account and Profile Management: Creating, retaining, and managing your account, authentication, password reset.
  2. Platform Operation: Server maintenance, performance improvement, technical troubleshooting.
  3. Payment Processing: Collecting membership fees, managing automatic renewal, issuing invoices.
  4. Identity Verification: Verification according to KYC requirements, strengthening community trust.
  5. Exchange Management: Matching between Members, communication, managing requests and agreements.
  6. Security and Fraud Prevention: Detecting suspicious activity, preventing misuse.
  7. Legal Compliance: Tax record retention, reporting to authorities as required.
  8. Heart Notifications: When another Member marks your home with a heart (❤️), Swapli may notify you so that it is easier for the two of you to get in touch.
  9. Matching and Recommendations: We analyse your activity on the Platform (searches, desired holidays, favourites, and enquiries) in order to suggest relevant homes and exchange partners to you, and to identify gaps in supply. Legal basis: performance of the contract (Article 6(1)(b)) and legitimate interest (Article 6(1)(f)) — matching Members is the essence of the service.

5.2 Purposes Requiring Consent

Processing for the following purposes takes place only after we obtain your consent. Consent can be given or withdrawn per category via the cookie banner or the "Cookie Settings" link in the site footer:

  1. Newsletter and Marketing Emails: News, tips, offers, and special promotions (via FluentCRM and Resend).
  2. Measurement and Analytics: Usage measurement and analytics via Google Analytics 4 and Vercel Analytics. These tools load only after "analytics" consent is given; until then, Google Consent Mode keeps storage denied.
  3. Marketing and Conversion Measurement: Meta Pixel and Facebook Conversions API for marketing and conversion measurement — only after "marketing" consent is given.
  4. Affiliate Attribution: Referral attribution via Affonso (referral id and a first-party attribution cookie).

5.3 Review of Communications Between Members

To keep the community safe and respectful and to improve the service, Swapli may review and process the content of messages sent through the internal messaging system — by automated means (filtering and detection of violations) and, in certain cases, by human review by authorized staff. The purposes are: (1) monitoring and enforcement of the community guidelines and Terms of Service; (2) safety — detecting and preventing harassment, threats, fraud and prohibited content, and maintaining respectful language; (3) protecting platform integrity — identifying attempts to share contact details or arrange exchanges outside the platform to circumvent the rules; (4) improving the service and the quality of matches. The legal basis is legitimate interest (Article 6(1)(f)) and performance of a contract (Article 6(1)(b)). We do not read private messages for targeted advertising and do not sell their content.


6. Sharing Personal Information with Third-Party Service Providers

Swapli shares personal information with external service providers only insofar as required to operate the Platform or when you have consented to such sharing. We do not sell personal information and do not share it with any parties not listed in the table below.

Table of Service Providers (Data Processors)

ServiceFunctionData TransferredServer LocationLegal ProtectionDPA Signed
SupabasePrimary databaseAll personal data (account, profile, property, messages, exchanges, photographs)EU (Frankfurt)GDPR DPAYes
VercelWebsite hosting and deliveryIP address, logs, cookiesEU (Paris + Frankfurt)GDPR DPAYes
StripePayment processingPayment tokens (not card numbers), payment history, invoicesUS (with EU processing)EU-US DPF, PCI-DSSYes
Stripe Identity (optional)KYC identity verificationIdentification document, selfie, verification detailsUSEU-US DPF, SCCsYes
Didit (optional)KYC identity verificationIdentification document, selfie, biometric dataEU / AWSExplicit consent + DPARequired
Google (GA4)Measurement and analyticsUsage events, device/cookie ids, truncated IPUS / GlobalEU-US DPF + SCCsYes
Vercel AnalyticsCookieless analyticsAggregate usage eventsUS / EUEU-US DPFYes
Meta PlatformsPixel + Conversions APIConversion events, cookie ids (_fbp), hashed email (CAPI)USEU-US DPF + SCCsYes
AffonsoAffiliate attributionReferral id, conversion eventSCCs / DPFYes
TidyCalScheduling of verification calls only (like Calendly)Name, email, phone, timeUSEU-US DPF / SCCsYes
WhatsApp (Meta)Medium of the verification video call (Member-initiated)Phone number, video callUSEU-US DPFYes
YouTube (Google)Embedded videos that may be displayed on the siteIP, player data (Google)US / GlobalEU-US DPFYes
Bunny (bunny.net)Explainer-video streamingIP, player data (no Member personal data)EU / CDNGDPR DPAYes
ResendSystem emailsEmail address, name, message contentUSEU-US DPFYes
TwilioSMS authentication (OTP)Phone numberUSEU-US DPFYes
FluentCRM (WordPress)Customer relationship management and newsletterName, email, preferencesEUGDPR DPAYes

Important Notes

  1. Credit card numbers do not pass through Swapli servers — Stripe handles them directly.
  2. Your password is encrypted on the server and no third-party provider can see it.
  3. Service providers in the US are protected by the EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs).
  4. We do not share information with any parties not listed in this table.

7. International Data Transfers

Swapli operates from the Netherlands. Most data is stored within the European Union:

Within the European Union:

  • Supabase — Frankfurt, Germany
  • Vercel — Paris, France + Frankfurt, Germany
  • FluentCRM — Europe

Transfer to the United States:

  • Stripe, Resend, Twilio — United States
  • Legal Basis: EU-US Data Privacy Framework (DPF)
  • If Necessary: Standard Contractual Clauses (SCCs)

Didit (identity verification): Production data is processed and stored in the European Union by default, on Amazon Web Services (AWS). Encryption applies at every stage — AES‑256 at rest across every database, object store, and backup; TLS 1.3 in transit on every API call, webhook, and console session; biometric data is encrypted under a separate Customer Master Key. Retention is configurable per application between 30 days and 10 years (default: indefinite unless a shorter period is configured); individual sessions can be deleted at any time.


8. Data Retention Periods

Swapli retains data only for as long as necessary to achieve the purpose for which it was collected:

Type of InformationRetention PeriodReason
Account details (name, email, phone)While account is active + 30-day grace periodService provision + account recovery
Password (encrypted)While account is active + 30-day grace periodSecurity + account recovery
Profile photograph and descriptionWhile account is active + 30-day grace periodProfile display + account recovery
Property photographsWhile account is active + 30-day grace periodProperty profile display + account recovery
Messages between MembersAccount deletion + 90 daysDocumentation in case of disputes
Payment records7 years from payment dateDutch tax law requirement
Identity verification results (KYC)5 years from verificationDutch limitation period + legal defense
Identity document photographs, selfies, biometric dataNot retained by SwapliProcessed and retained by third-party provider only (per its own retention)
Searches and platform activity24 months, or until account deletion — whichever comes firstHome matching, service improvement, and identifying supply gaps
IP addresses and technical logs90 daysSecurity and monitoring
CookiesUp to 12 monthsPreferences and functionality

Following account deletion and completion of the grace period (30 days), all information is permanently deleted — except information required by law to be retained (payment records) or for legal protection purposes (identity verification results).


9. Your Rights Under GDPR

As a Data Subject, you have the following rights:

9.1 Right of Access (Article 15)

You are entitled to request a copy of all personal information retained about you. Swapli will provide this information within 30 days of receiving your request. Contact privacy@swapli.net.

9.2 Right of Rectification (Article 16)

If personal information retained about you is inaccurate or incomplete, you are entitled to request correction. You may update most details directly through your account settings.

9.3 Right of Erasure — "Right to be Forgotten" (Article 17)

You are entitled to request deletion of all your information. Deletion will occur after a grace period of 30 days. Note: Certain information is retained even after deletion where required by law — payment records are retained for 7 years under Dutch tax law, and identity verification results are retained as detailed in Section 8.

9.4 Right to Restrict Processing (Article 18)

You are entitled to request that we limit the processing of your information — for example while we verify its accuracy or while you contest a decision.

9.5 Right to Data Portability (Article 20)

You are entitled to request that we transfer your information in a structured, commonly-used, and machine-readable format (such as CSV or JSON) to you or to another service.

9.6 Right to Object (Article 21)

You are entitled to object to the processing of information based on legitimate interest, and in particular to processing for direct marketing purposes.

9.7 Right to Withdraw Consent (Article 7(3))

You may withdraw your consent at any time — particularly regarding biometric data, newsletter, and marketing emails. Withdrawal of consent will not affect the legality of processing that occurred before withdrawal.

9.8 Right Regarding Automated Decisions (Article 22)

If a decision that affects you was made automatically — for example, failure of identity verification or content removal — you have the right to request that a member of the Swapli team review the decision. Contact us at support@swapli.net and we will review the case within 14 business days.

Recommendations of homes and exchange partners are not an "automated decision" within the meaning of Article 22 — they are a suggestion only, they produce no legal effect or similarly significant effect, and every approach is made on your own initiative and with your approval.

9.9 How to Exercise Your Rights

For any request relating to your rights, contact privacy@swapli.net or dpo@swapli.net. We will respond within 30 days. If we cannot fulfill your request, we will explain why.


10. Your Rights Under Israeli Privacy Law

Swapli is a Dutch company and is directly subject to GDPR. The Israeli Privacy Law (5741-1981) does not formally apply to us. However, because the Platform is directed at Israeli families and processes information of Israeli residents, we voluntarily respect the rights granted under Israeli law:

  1. Right of Inspection: You are entitled to inspect information retained about you.
  2. Right of Rectification: You are entitled to request correction of inaccurate information.
  3. Right of Erasure: You are entitled to request deletion of information in accordance with law.
  4. Right to Object: You are entitled to object to the use of information for marketing purposes.

For requests: privacy@swapli.net


11. Cookies

11.1 Essential Cookies

  • session_id — Maintaining login status (deleted after inactivity period)
  • csrf_token — Protection against CSRF attacks
  • auth_token — User authentication

11.2 Preference Cookies

  • theme_preference — Display preference (light/dark)
  • language_preference — Preferred language
  • timezone — Time zone

11.3 Third-Party Cookies

Subject to your consent, Swapli uses Google Analytics 4, Vercel Analytics (cookieless), Meta Pixel and the Facebook Conversions API, as well as affiliate attribution (Affonso). These tools load only in accordance with your choice in the cookie banner, and you may change your consent at any time via the "Cookie Settings" link in the site footer. For further details, see the full Cookie Policy and Section 6.

Full Cookie Policy available at: swapli.net/legal/cookie-policy


12. Children's Privacy

Swapli is intended for persons 18 years of age and older. We do not knowingly collect personal information from minors. If we discover that information of a person under 18 has been collected, we will delete it immediately.


13. Information Security

13.1 Our Measures

Swapli implements technical and organizational security measures to protect your information:

  • Communication Encryption: All communication with the Platform is encrypted using HTTPS/TLS.
  • Password Encryption: Passwords are encrypted using bcrypt (one-way hashing). Even we cannot see your password.
  • Access Control: Only authorized staff members can access personal information, and only to the extent required for their role.
  • Encrypted Backups: Database backups are encrypted and stored securely.
  • Monitoring: We monitor our systems to detect suspicious activity.

13.2 Your Role

You are also a partner in securing your account:

  • Choose a strong password (at least 12 characters, combining letters, numbers, and symbols).
  • Do not share your password or OTP codes with anyone.
  • Be cautious when connecting through unsecured public Wi-Fi networks.
  • Keep your browser updated.

If you suspect unauthorized access to your account, report it immediately to security@swapli.net.


14. Data Breach Notification

In accordance with GDPR Articles 33-34:

14.1 Our Obligations

If a data breach is discovered that may harm your rights:

  1. We will report to the Dutch supervisory authority (Autoriteit Persoonsgegevens) within 72 hours.
  2. We will notify you within a reasonable time, typically within 5 business days.
  3. The notice will include: the nature of the breach, what data was affected, what we are doing about it, and how you can protect yourself.

14.2 Methods of Notification

We will notify you via: email to the address registered on your account, notification within the Platform, and in serious cases — also through public announcement.


15. Marketing Communications

15.1 Consent

Marketing emails and newsletters are sent only based on your explicit consent. Consent is obtained during registration or through your account settings.

15.2 Withdrawal of Consent

You may unsubscribe from marketing communications at any time — via the "unsubscribe" link at the bottom of each marketing email, or through your account settings.

15.3 Non-Marketing Emails

Emails related to service operation (registration confirmations, exchange notifications, renewal reminders, and reminders and guidance about completing your profile in order to make exchanges) do not require consent and will be sent as long as your account is active.


16. Changes to This Policy

Swapli may update this Privacy Policy from time to time. Material changes will:

  1. We will make an effort to publish them on the website in advance where possible.
  2. Be notified via email to all registered Members.
  3. Upon your next login to the Platform following an update, you will be prompted to approve the updated Policy. You cannot continue using the Platform without providing your approval. Once approved, the updated Policy takes effect immediately.

If you do not agree with changes, you may cancel your membership and close your account.


17. Filing Complaints

In the Netherlands:

In Israel:


18. Prevailing Language

This Privacy Policy is available in Hebrew and in English. In the event of any conflict or inconsistency between the versions, the Hebrew version shall prevail.


19. Contact

Data Protection Officer (DPO): Daniel, Founder of Swapli Email: dpo@swapli.net

Privacy questions: privacy@swapli.net Security reports: security@swapli.net Legal questions: legal@swapli.net General support: support@swapli.net

Swapli by Webguy BV Amsterdam, The Netherlands Registration Number: KVK (COC) 72381647


© 2026 Swapli by Webguy BV. All rights reserved.

What's new in this version

September 2026 update: we clarified which platform-activity information we collect — home searches, favourites, desired holidays, and enquiries — and what for (matching homes and exchange partners, and identifying supply gaps), added the retention period for that information (24 months), and clarified that recommendations are not an "automated decision". This information is collected for signed-in Members only. Please read the updated document and approve.

Have questions?

Our support team is happy to help.

אנחנו משתמשים בעוגיות

אנחנו משתמשים בעוגיות כדי לשפר את חווית השימוש שלך. קרא עוד