Privacy Policy
Last updated: 31 August 2026 · Version 2026.08.31
This Privacy Policy explains how Entity Promotions LTD (company number NI721452), a private limited company registered in Northern Ireland, trading as "Swingable" (the "Company", "we", "us"), processes personal data of Members and visitors of the Swingable platform (the "Platform"). It should be read alongside our Terms of Service and Cookie Policy. We act as the Controller of your personal data within the meaning of the UK GDPR and the Data Protection Act 2018.
Swingable is an adult social service. Much of what you choose to share on it will reveal information about your sex life or sexual orientation. Clause 6 explains exactly which lawful basis and which Article 9 condition we rely on, and clause 15 explains how to complain.
Controller identity & contact
The Controller is Entity Promotions LTD, a private limited company registered in Northern Ireland (company number NI721452) whose registered office is at 3 Wellington Park, Belfast, BT9 6DJ.
Privacy contact. Data-protection queries, rights requests and data-protection complaints should be sent to admin@swingable.co.uk.
Data Protection Officer. Given our size and processing operations, we are not required to and have not formally appointed a statutory Data Protection Officer under Article 37 UK GDPR. Overall responsibility sits with the directors of Entity Promotions LTD, and day-to-day matters are handled by our Trust & Safety lead, contactable at admin@swingable.co.uk.
No sale of personal data. We do not sell your personal data and we do not share it with data brokers for cross-context behavioural advertising.
Definitions
"Personal Data" has the meaning given in Article 4(1) of the UK GDPR. "Processing" has the meaning given in Article 4(2). "Special Category Data" has the meaning given in Article 9. "Member" means a person with an individual Member Account. "Shared Profile" means a shared identity that two or more Members act through. "Processor" means a third party processing Personal Data on our documented instructions.
Categories of personal data we collect
Account & identity data. Username, email address, date of birth, gender, orientation, relationship configuration, hashed password, and profile photographs.
Shared Profile data. Which individual Member Accounts belong to which Shared Profile, the relationship label chosen, join/leave events, and a record of which individual login performed each action taken through a Shared Profile (actor attribution). Some attribution is displayed publicly on Content. Where a Member leaves a Shared Profile, their individual membership of it ends, but the Shared Profile itself and its Content are not deleted as a result; the Shared Profile may instead be archived or continue to be used by its remaining Members.
Verification data. A selfie photograph of you holding a handwritten sign showing your username and today's date, submitted for photo verification. That single image is used both to check authenticity (that the person behind the account is a real, present person) and as part of our age assurance process. We apply a Challenge 25 approach: if the reviewer considers you may be under 25, or is not confident of your age from the photo alone, a government-issued identity document showing your date of birth is mandatory before the account can be approved. Images are reviewed visually by trained human moderators. We do not generate a biometric template from your face and we do not perform automated facial recognition or automated face-matching; the images are photographs assessed by people. We do not hold or claim any Ofcom certification in respect of this process.
Content data. Posts, comments, direct messages, group and event chats, stories, Vault uploads and their consent classifications, admin-operated live video broadcasts and any retained recordings of them, polls, reviews, and other Content submitted to the Platform. Live streaming on the Platform is currently operated by Swingable administrators only; Members do not currently have the ability to start their own live broadcasts.
Vault consent data. For each media item: your classification of who appears in it, the registered Members you tagged, and each tagged person's approval, decline or later withdrawal, with timestamps. Where you tag a registered Member, that item does not proceed to moderation review, and is not published, unless and until each tagged Member approves it; if a tagged Member declines, the item is deleted. Where a person shown in the media is not a Member or has not been tagged, we rely on your classification and the uploader's own consent declarations rather than a technical block, and such items may still be reported and actioned like any other Content.
Payment data. Where you subscribe or buy tickets or merchandise, payment details are collected and processed directly by Stripe. We receive tokenised references, limited card metadata (last four digits, brand, country), and the transaction outcome. For merchandise we also process the delivery name and address needed for fulfilment. Where you choose a charity allocation, we record that choice.
Device & technical data. IP address, a device fingerprint derived from browser and device characteristics, browser type, operating system, timezone, referral URL, app version, and error logs. Fingerprinting, account-linkage and ban-evasion signals derived from this data may be retained for safety and fraud-prevention purposes; see clause 12.
Location data. Coarse, area-level location you enter or that is derived from a postcode, and — only where you expressly opt in to Nearby or Meet Mode — device location used to calculate approximate distance. Your exact GPS coordinates are never shown to other Members. In Meet Mode, your location is stored server-side solely to run the session and calculate proximity to other participants; the session expires automatically and the underlying coordinates are cleaned up after the configured retention window. Nearby only ever shows other Members an approximate distance or proximity indicator, never coordinates.
NFC band data. Where you use a Swingable NFC band, the band identifier, its link to your account, and check-in or meet-verification events recorded when it is used.
Push notification data. Where you enable push notifications in the mobile app, a device push token issued by the operating-system push service (Apple Push Notification service on iOS, Firebase Cloud Messaging on Android), together with your notification preferences.
Telegram integration data. Where you choose to connect Telegram, we process your Telegram session and the identifiers and message content of the conversations you have opted to sync, so they can be shown in your Swingable inbox. You can disconnect at any time in Settings. Telegram is an independent service and its own terms and privacy policy apply to it.
Safety, moderation & enforcement data. Reports you make or that are made about you, moderator decisions and notes, appeals, risk signals used to prioritise review, multi-account and account-creation-limit signals derived from device fingerprints, ban and block records, and visibility restrictions applied to an account or item.
Security provenance data. Media shown on the Platform may carry a per-viewer, per-media pseudonymous provenance identifier, together with associated access records. These are used only to investigate leaks or misuse of private media and to support reports of non-consensual sharing. We do not publish the methods or algorithms involved. Access to this data is restricted to a small number of authorised staff.
Organiser, advertiser and ambassador data. Business and payout details, campaign and event records, and acceptance of the applicable agreement.
Legal acceptance records. The document and version you accepted, with a timestamp, so we can demonstrate what you agreed to.
Live Chat data. Where you use Live Chat we process the text you send in the room, presence information (that you are in the room, and whether your camera or microphone is on), and minimal session records. Room text is short-lived and held for operational safety and abuse reporting only. Where you switch on camera or microphone, the audio and video is processed in realtime by our media provider so that other Members in the room can see and hear you; it is not recorded by us by default and is not stored as a media file. This is distinct from verification photos, direct messages and Vault media, which are stored.
Special Category Data. Because the Platform is an adult social service, information you submit will reveal data concerning your sex life or sexual orientation within the meaning of Article 9(1) UK GDPR. Additional safeguards apply, described at clause 6.
Sources of personal data
From you. Directly during registration, verification, use of the Platform, or when contacting support.
From other Members. Where other Members mention you, tag you in Vault media, report you, verify you, or otherwise reference you.
From our processors. Payment outcomes from Stripe, email delivery and engagement status from Resend, media processing status from our video provider, and fulfilment status from our print partner.
Purposes of processing & Article 6 lawful bases
Provision of the service — Art. 6(1)(b) (contract). Creating and maintaining your account and any Shared Profile you join, delivering Platform features, Vault consent workflow, messaging, events and ticketing, merchandise fulfilment, subscriptions and support.
Safety, moderation and illegal-content duties — Art. 6(1)(c) (legal obligation) and Art. 6(1)(f) (legitimate interests). Complying with the Online Safety Act 2023, checking that Members are adults, detecting and removing illegal or harmful Content, handling reports and appeals, and protecting Members from harm. Our legitimate interest is running a safe service for adults; we balance it against your interests and provide the appeal route in the Terms.
Fraud prevention and account integrity — Art. 6(1)(f). Device fingerprinting to enforce account-creation limits and detect ban evasion, chargeback-abuse detection, and provenance tokens on media to investigate leaks.
Optional features — Art. 6(1)(a) (consent). Nearby and Meet Mode location, push notifications, non-essential cookies, Telegram integration, and optional marketing. You can withdraw any of these in Settings or by using the unsubscribe link, without losing access to the rest of the Platform.
Legal and accounting — Art. 6(1)(c). Retaining transaction records to meet tax and accounting duties and responding to lawful regulatory or law-enforcement requests.
Special category data — Article 9 condition
An Article 6 lawful basis is not enough on its own for data revealing sex life or sexual orientation. A separate Article 9 condition is also required, and we treat these as two distinct questions.
Explicit consent — Art. 9(2)(a). Where we have asked you for a specific, separate and affirmative statement of explicit consent to process information revealing your sex life or sexual orientation for the purpose of operating this adult social service, we rely on that consent. Explicit consent of this kind is not currently collected as a separate step at registration for all Members; we are introducing it, and where it has not been collected from you we rely on the conditions below instead.
Information you have manifestly made public — Art. 9(2)(e). Where you have deliberately published information to a genuinely public area of the Platform, we may rely on this condition for that published information only. We do not apply it to private messages, Vault content, group or event chats, or anything visible only to a restricted audience, merely because other parts of your profile are public.
Legal claims — Art. 9(2)(f). Where processing is necessary for the establishment, exercise or defence of legal claims, including defending moderation decisions and responding to complaints.
Safeguarding and substantial public interest — DPA 2018 Sch. 1. Where we process special category data to prevent or detect unlawful acts, protect the public against dishonesty or seriously improper conduct, or safeguard individuals at risk, we rely on the corresponding substantial- public-interest conditions in Schedule 1 to the Data Protection Act 2018 and maintain an appropriate policy document.
Withdrawing consent. Where we rely on your explicit consent you may withdraw it at any time by contacting admin@swingable.co.uk. Because this category of information is intrinsic to an adult social service, withdrawing it means we can no longer provide the Platform to you; we will explain that before acting, and you may instead pause your account or delete it from Settings. Withdrawal does not affect processing carried out before withdrawal, and does not remove records we must keep for safety, legal or accounting reasons.
Marketing & electronic messages
Consent. We only send electronic direct marketing where PECR permits it — either because you have given consent, or because a valid soft opt-in applies (clause 7.2) — and every marketing message includes a means of opting out. Opting in is separate from accepting the Terms and is never a condition of using the Platform.
Marketing preference setting. Your account's marketing preference toggle may default to enabled. That toggle only controls whether we will send you marketing if we are otherwise legally entitled to; the toggle itself is not, and is not treated by us as, your consent to receive marketing. Whether marketing may lawfully be sent to you still depends on satisfying a valid legal basis under clause 7.2 or 7.3. You can turn the preference off at any time in Settings.
Soft opt-in. Where you have bought or negotiated to buy a product from us, PECR permits us to email you about our own similar products and services, provided we gave you a simple means of refusing at the point your address was collected and in every message. We rely on this only within those limits.
Service messages. Transactional and safety messages (billing, verification outcomes, moderation decisions, security alerts) are not marketing and are sent for as long as you hold an account.
Opting out. Every marketing email contains an unsubscribe link, and you can change your preferences in Settings at any time.
Sharing with processors & third parties
We share Personal Data with the following recipients, each acting under a written data-processing agreement or, where indicated, as an independent controller. This list reflects the integrations actually implemented in the Platform.
Infrastructure & hosting. Our managed backend provider (database, authentication, storage and server functions) and our web hosting and content-delivery provider.
Payments. Stripe (independent controller for card-data purposes) for subscriptions, event ticketing and merchandise checkout.
Transactional and lifecycle email. Resend, for authentication, notification, billing and support emails, including delivery and engagement events.
Video. Cloudflare Stream, for encoding, storage and delivery of uploaded video and of admin-operated live streams (live streaming is currently run by Swingable administrators only, not by individual Members).
Realtime Live Chat audio and video. None. Where you switch on camera or microphone in Live Chat, that audio and video travels directly between your device and the devices of the Members watching you (peer‑to‑peer). It is not sent to, processed by or stored by us or by any third‑party media provider, and it is not recorded or turned into stored on-demand video. Our servers carry only the brief technical handshake that sets the connection up, which is deleted automatically within about two minutes. To make a direct connection possible, your device and the devices you connect with exchange network address information (including IP address, which can indicate an approximate location); we also use Google’s public STUN servers to help discover that address information. This is separate from Cloudflare Stream at clause 8.5, which encodes and stores uploaded video and admin-operated live streams.
Print-on-demand fulfilment. Printful, where you place a merchandise order (delivery details only).
Push notifications. Apple Push Notification service and Firebase Cloud Messaging, where you enable push in the mobile app.
Telegram. Where you connect the optional Telegram integration, message and account data passes between Swingable and Telegram. Telegram is an independent controller for its own service.
Analytics and advertising measurement. Google Analytics 4 and the Meta Pixel, loaded only after you consent to analytics or advertising cookies. See the Cookie Policy.
Moderators. Our internal moderation team and, where engaged, vetted external moderators bound by confidentiality obligations.
Organisers. Where you buy a ticket, the Organiser receives the attendee information needed to run the Event.
Regulators and law enforcement. Where required by lawful request, or where reporting is required or justified to protect people from serious harm, including reporting child sexual exploitation and abuse to the National Crime Agency where the statutory duty applies.
International transfers
Where Personal Data is transferred outside the United Kingdom, we rely on (a) an adequacy regulation of the UK Government, or (b) the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with supplementary technical and organisational measures.
Members located outside the UK. We accept Members who access the Platform from outside the United Kingdom. This Policy, and the Terms of Service, are nonetheless governed by the law of Northern Ireland, and the protections described in this Policy apply regardless of where you access the Platform from.
Retention
General approach. We do not keep Personal Data for longer than is necessary for the purpose it was collected for. Some categories of data are short-lived by design and are deleted quickly, on the schedule set out below; a smaller set of categories genuinely needs longer retention for legal, fraud-prevention, accounting, safety, dispute or audit reasons, and for those we retain records for no longer than seven (7) years, being the outer horizon we apply for compliance purposes. Nothing in this clause promises that deletion happens through fully automated purging alone; in some categories deletion happens on review by us.
Active accounts. Account and Content data is retained for as long as your Member Account remains active.
Ordinary content after account deletion. On account deletion, ordinary Content and account data is deleted or anonymised promptly, except for records we are justified in retaining under clause 10.4.
Long-retention categories (up to seven years). We retain, for no longer than is necessary and up to a maximum of seven (7) years: (a) financial and transaction records, for tax, accounting and payment-dispute purposes; (b) enforcement and safety decision records (moderator decisions, reports, appeals, and the reasoning for them), so we can defend our decisions, respond to regulators, and prevent repeat harm; and (c) evidence relevant to an actual or reasonably anticipated legal claim or dispute, for as long as that claim or dispute could reasonably be pursued. Minimal device, fingerprint and ban-evasion indicators may also be retained within this horizon for fraud prevention and to stop circumvention of enforcement.
Identity documents. Government-ID images are retained only for as long as it takes us to reach a verification decision. The image is deleted once the decision is made, whether the outcome is approval or rejection. If an application is rejected and you are invited to resubmit, the original image is deleted first, before you are asked to provide a new one. We keep only minimal decision audit metadata after that — the reviewer, the date, the outcome, the reason, and the verification method used — not the image itself. Selfie verification images are handled the same way once a decision on your verification has been reached.
Stories. Stories expire automatically 24 hours after posting, subject to a short hold where a moderation review or a legal hold is outstanding.
Location and Meet Mode. Nearby and Meet Mode location data is short-lived: it is used to compute proximity for the active session, the session expires automatically, and the underlying coordinates are cleaned up after the configured retention window. It is not kept as a long-term location history.
Live Chat. Live Chat room text is retained only briefly for operational safety and abuse reporting — currently a buffer of approximately fifteen (15) minutes — and then expires automatically. Where a report is made, a bounded amount of relevant context is preserved as moderation evidence and is then handled under the enforcement and safety retention rule at clause 10.4. Realtime Live Chat camera and microphone streams are not recorded by us by default and so are not retained as media. Aggregate room-health counts used to keep the feature working contain no message text and are kept briefly.
Other categories. Where a category is not listed above we keep it only for as long as it is needed for the purpose it was collected for, retained no longer than necessary, and we review retention periodically. If you want to know the position for a specific category, ask us at admin@swingable.co.uk.
Your rights
Under the UK GDPR you have the right to: (a) access your Personal Data; (b) request correction of inaccurate data; (c) request erasure; (d) restrict processing; (e) data portability; (f) object to processing based on legitimate interests or for direct marketing; and (g) withdraw consent where processing is based on consent.
How to exercise, and how long we take. Contact admin@swingable.co.uk. We will respond without undue delay and in any event within one month of receiving the request. Where a request is complex, or where you have made a number of requests, we may extend that period by up to a further two months and will tell you within the first month if we do. We may ask for information reasonably necessary to verify your identity. There is no fee unless a request is manifestly unfounded or excessive.
In-product tools. You can delete your account, or pause it temporarily, from Settings → Data. An in-product self-service data export is not currently available; ask us at admin@swingable.co.uk and we will provide a copy of your data.
Limits. Some rights are qualified. For example, we may decline erasure where retention is necessary for legal claims, accounting, or the protection of others.
Automated decision-making & profiling
The Platform uses automated tools to (a) rank feed and search results; (b) detect suspicious or fraudulent activity, including device fingerprinting for multi-account detection and risk scoring that prioritises accounts for review; and (c) triage Content for moderator review. Decisions with a legal or similarly significant effect — in particular permanent bans — involve human review and are subject to appeal, so they are not solely automated within the meaning of Article 22 UK GDPR.
Security
We maintain appropriate technical and organisational measures including encryption in transit and at rest, role-based access controls, row-level security on our database, signed time-limited URLs for private media, staff access controls, and security testing. No system is perfectly secure; please notify us immediately of any suspected breach at admin@swingable.co.uk.
Personal data breach notification. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within seventy-two (72) hours of becoming aware in accordance with Article 33 UK GDPR and, where the risk is high, notify affected Members without undue delay under Article 34.
Child sexual abuse material. Such material is prohibited absolutely. Where it is detected through reporting or moderator review it is preserved on legal hold, the account is terminated, and it is reported to the National Crime Agency where the statutory duty applies and, where appropriate, to the Internet Watch Foundation or the police.
Confidentiality of messages. Your direct messages and other private Content are not routinely browsed or read by our staff. Authorised staff access message content only where necessary: to investigate a report or safety concern, to respond to a valid lawful request, or to investigate an exceptional security or technical incident. Access is logged and limited to what is needed for that purpose.
Children
The Platform is strictly for adults aged 18 or over. We do not knowingly collect Personal Data from anyone under 18 and will delete any such data on becoming aware of it.
Data-protection complaints
How to complain to us. If you are unhappy with how we handle your personal data, send a data-protection complaint to admin@swingable.co.uk with the word "data protection" in the subject line. You can also raise it through the in-app contact form.
What we will do. In line with the Data (Use and Access) Act 2025 we will acknowledge your data-protection complaint within thirty (30) days of receiving it, take appropriate steps to investigate it without undue delay, and tell you the outcome.
Escalating to the regulator. You may complain to the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, website ico.org.uk. The ICO may ask whether you have raised the matter with us first.
Deceased Members
On satisfactory evidence of death we will memorialise, restrict or delete the account in line with the deceased Member's documented wishes or reasonable requests from their personal representative. We do not grant access to a deceased Member's private messages.
Changes to this Policy
We may amend this Policy from time to time. Each version carries a version number and date at the top of this page. Material amendments will be notified in-app or by email at least fourteen (14) days before they take effect.