Privacy Policy
Last Updated: April 7, 2026
1. Introduction
Welcome to Swite, a business communication and automation platform operated by Switeco ("we", "us", or "our"). This Privacy Policy describes how we collect, use, store, disclose, and protect information when you use our platform, website, and related services (collectively, the "Service").
We are committed to safeguarding your privacy and the privacy of your customers. We do not sell, rent, or monetize personal information for advertising purposes. By accessing or using Swite, you acknowledge the practices described in this policy.
2. Information We Collect
2.1 Account & Organization Information
When you register and set up your workspace, we collect:
- Identity data: name, email address, and authentication credentials.
- Organization data: company name, country, industry, and team structure (departments, roles, member invitations).
2.2 Customer Data You Store
Swite acts as a data processor on your behalf. Through normal use of the platform you may store:
- Contacts and leads: names, phone numbers, email addresses, physical addresses, social profiles, and custom attributes.
- Conversations: message history across connected channels (WhatsApp, Telegram, Instagram, Messenger, LinkedIn), including text, images, audio, video, files, and location data.
- Tickets: support cases, assignment history, and resolution details.
- Campaigns and templates: message templates and campaign data you create within the platform.
- Files: documents, images, and media you upload.
You are the data controller for this customer data and are responsible for ensuring you have the appropriate legal basis to collect and process it.
2.3 Usage & Analytics Data
We collect aggregated, anonymized data about how you interact with the platform, including feature usage patterns, session duration, and navigation paths, to improve our services.
2.4 Technical & Security Data
We automatically collect:
- Device information: browser type and version, operating system, and screen resolution.
- Network information: IP address, approximate geolocation (country/region level), and referring URL.
- Log data: timestamps of access, API requests, and error logs for security monitoring and troubleshooting.
2.5 Payment Information
Payment processing is handled entirely by Stripe. We do not store credit card numbers or full payment credentials on our servers. We retain only transaction references, plan details, and billing history necessary to manage your subscription.
3. How We Use Your Information
We use the information we collect solely to operate, maintain, and improve the Service:
- Deliver core functionality: unified messaging, ticketing, contact management, campaigns, and AI-powered features.
- Manage your account: authentication, authorization, role-based access, and workspace administration.
- Process payments: subscription billing and invoicing through Stripe.
- Provide support: respond to your inquiries and troubleshoot issues.
- Ensure security: detect and prevent fraud, abuse, and unauthorized access.
- Improve the platform: analyze aggregated usage patterns to enhance features, performance, and reliability.
- Communicate with you: send transactional emails (account verification, password resets, billing notifications) and, with your consent, product updates.
We do NOT use your data or your customers' data for advertising, behavioral profiling, or sale to third parties.
4. Data Security
We implement comprehensive security measures to protect your data:
- Encryption: all data is encrypted at rest and in transit using industry-standard TLS protocols.
- Infrastructure: hosted on enterprise-grade cloud infrastructure (Vercel, Neon, AWS) with SOC 2 and ISO 27001 certifications.
- Access controls: role-based access with the principle of least privilege for all internal systems.
- Audit logging: all administrative actions are recorded for accountability and compliance.
- Regular assessments: we conduct periodic security reviews and vulnerability testing.
- Incident response: we maintain documented procedures for security incident detection, containment, and notification.
5. Third-Party Services & Integrations
Swite integrates with external services to deliver its functionality. These include:
- Messaging providers: WhatsApp (via WAHA), Telegram, Instagram, Messenger, and LinkedIn.
- AI services: OpenAI and Google Gemini for AI-powered smart replies and automation.
- Payment processing: Stripe for subscription and billing management.
- Email delivery: Resend for transactional emails.
- Scheduling and other integrations: Cal.com, ElevenLabs, Google Meet, Facebook Leads, and custom webhook integrations you configure.
For each integration:
- We share only the minimum data necessary for the integration to function.
- Each third-party service is governed by its own privacy policy and terms.
- We evaluate third-party services for adequate security and privacy practices.
- You control which integrations are enabled in your workspace.
6. Data Sharing & Disclosure
We do not sell or share personal information with third parties for marketing purposes. We may disclose information only in the following circumstances:
- Service providers: trusted vendors who process data on our behalf (hosting, email delivery, payment processing), bound by contractual data protection obligations.
- Legal requirements: when required by law, regulation, legal process, or governmental request.
- Protection of rights: to enforce our Terms of Service, protect our rights and safety, or protect the rights and safety of our users or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to affected users.
7. Your Rights & Data Control
You maintain full control over your data:
- Access: view and export all data stored in your workspace at any time.
- Correction: update or correct any information through the platform interface.
- Deletion: remove individual records or request complete account deletion.
- Account deletion: upon account deletion, all associated data — including conversations, contacts, tickets, files, and organization settings — is permanently removed within 30 days.
- Data portability: export your data in standard formats.
7.1 California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know: request disclosure of the categories and specific pieces of personal information we have collected.
- Right to delete: request deletion of personal information we hold about you.
- Right to opt-out: we do not sell personal information, so there is no need to opt out of sales.
- Non-discrimination: we will not discriminate against you for exercising your privacy rights.
To exercise any of these rights, contact us at legal@swite.co.
8. Data Retention
- Active accounts: we retain your data for the duration of your active subscription.
- Deleted accounts: all data is permanently removed within 30 days of account deletion.
- Legal obligations: we may retain certain records longer if required by applicable law, regulation, or legal proceedings.
- Aggregated data: anonymized, aggregated data that cannot identify any individual may be retained indefinitely for analytics and service improvement.
9. International Data Transfers
Swite's infrastructure may process data in multiple regions. When data is transferred across borders, we ensure appropriate safeguards are in place, including standard contractual clauses and reliance on providers with recognized certifications (SOC 2, ISO 27001).
10. Children's Privacy
Swite is a business platform and is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us at legal@swite.co and we will promptly delete it.
11. Cookies & Tracking Technologies
Swite uses cookies and similar technologies for:
- Essential cookies: authentication, session management, and locale preferences.
- Analytics: aggregated usage metrics to improve the platform (no third-party advertising trackers).
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect platform functionality.
12. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, services, or legal requirements. When we make material changes, we will notify you by email or through a prominent notice within the platform before the changes take effect.
We encourage you to review this policy periodically. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:
Switeco Email: legal@swite.co