Privacy policy

What we collect: name, shipping/billing address, email and/or phone, and order history, collected at checkout. We do not collect full payment card numbers — those are handled directly by our payment processor.

Why we collect it: to fulfil and ship your order, respond to support requests, process refunds, and meet our own legal/accounting record-keeping obligations. We do not sell your personal information to third parties.

Who we share it with: our fulfillment supplier (to ship your order), our payment processor (to process payment), and our storefront platform provider, each solely to perform their role in your order. We do not share your information for their independent marketing use.

Retention: order and contact records are kept for as long as needed to handle returns/refunds and to meet tax/accounting record-keeping obligations, then deleted or de-identified. You can request deletion of your data outside that retention need by contacting support.

Your rights: you can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it (subject to the retention need above) by contacting the storefront's support channel.

Data security & breach response: we take reasonable technical and organizational steps to protect your data. If we become aware of a data breach involving your personal information, we will (a) contain and assess the breach, (b) notify affected customers without undue delay once the scope is known, and (c) notify any regulator required by applicable law (e.g. state breach-notification statutes in the US; the OAIC under the Notifiable Data Breaches scheme if AU customers are ever affected).

Contact: privacy questions go through the storefront's official support channel (same as general customer service), or by emailing hello@myswift.store.

Jurisdiction notes: if California residents are customers, CCPA/CPRA rights — access, deletion, opt-out of "sale/sharing" — track closely with "Your rights" above; an explicit "Do Not Sell/Share My Info" reference will be added only if/when CA sales volume triggers CCPA applicability thresholds. If AU customers are ever added, the language above already tracks the APPs' core obligations — collection notice, use/disclosure limits, access/correction, and a breach-response path — closely enough to serve as a baseline; only the regulator-notification line would need updating to lead with the OAIC.