← Back to SwankflowTerms of Service

Privacy Policy

Last updated: May 12, 2026

This Privacy Policy explains how Swankflow ("we," "us," "our") collects, uses, shares, and protects information when you use the Swankflow platform ("Service"). By using the Service you agree to the practices described here.

1. Who This Policy Applies To

This policy covers two categories of people:

  • Tenants — home service businesses who sign up for Swankflow to build forms and sync to Jobber. You're a tenant if you've created a Swankflow account.
  • End customers — people who submit a tenant's signup form (typically homeowners or business customers buying services from one of our tenants).

For end-customer data, the tenant is the data controller and Swankflow acts as the data processor. End customers should direct privacy requests to the tenant whose form they submitted; if you don't know which tenant, contact us and we'll help you find them.

2. Information We Collect

From tenants

  • Account details: business name, email address, password (stored hashed, never in plain text).
  • Branding: logo, colors, custom email templates.
  • Integration credentials: OAuth tokens for Jobber (used to read and write your Jobber data on your behalf), optional Resend API keys, Stripe customer ID.
  • Billing information: handled directly by Stripe — Swankflow stores only the Stripe customer ID and subscription metadata, not credit card details.
  • Usage data: log entries, error messages, IP addresses, browser user agents, timestamps. Used for debugging, security monitoring, and abuse prevention.

From end customers (via tenant forms)

  • Information they provide to the tenant's form: name, email, phone, address, custom-question answers, service selections, etc.
  • Submission metadata: time of submission, IP address, browser user agent.

The specific fields collected depend on what the tenant's form asks. Swankflow stores this data on behalf of the tenant; the tenant determines what to collect and how to use it.

3. How We Use Information

We use the information we collect to:

  • Provide and operate the Service (host your forms, sync submissions to Jobber, send transactional emails, process billing).
  • Authenticate users and secure accounts.
  • Communicate with you about your account, security alerts, product updates, and support requests.
  • Monitor for abuse, fraud, and security incidents.
  • Improve the Service based on aggregated, anonymized usage patterns.
  • Comply with legal obligations.

We do not sell personal information. We do not use end-customer data for our own marketing.

4. Third-Party Services We Use

Swankflow relies on the following third-party processors to provide the service. Each is bound by its own privacy and security obligations:

  • Jobber — CRM integration. When you connect, we send relevant submission data into your Jobber account on your behalf.
  • Stripe — payment processing for paid subscriptions. Card data is handled directly by Stripe.
  • Resend — transactional email delivery (welcome emails, review requests, password resets).
  • Cloudflare — hosting, DNS, and DDoS protection. All Swankflow traffic and data are stored on Cloudflare's infrastructure.
  • Anthropic — AI features (form-builder assistance, in-app support chat). Messages sent to the assistant are processed by Anthropic but not used to train models.
  • Referly — affiliate-program tracking. If you arrived via an affiliate link, a referral cookie is set and shared with Referly to attribute the signup.

5. Data Storage and Security

Swankflow data is stored on Cloudflare's global infrastructure, primarily in their D1 database (SQLite) and R2 object storage. All data is encrypted in transit (TLS 1.2+) and at rest. Passwords are hashed using PBKDF2 with 100,000 iterations and a unique salt per password. Sessions use HMAC-SHA256 signatures with constant-time comparison.

We restrict internal access to personal data to authorized personnel who need it to operate the service. We log all admin actions for audit purposes.

6. Data Retention

  • Tenant account data is retained for as long as the account is active.
  • After account cancellation, we retain data for up to 30 days to allow account restoration, then it is deleted from active systems. Backups are deleted within an additional 60 days.
  • Tenants can archive (soft delete) and permanently delete their account from their admin panel at any time. Permanently deleted accounts have all associated data — submissions, products, fields, logos, custom domain configs, sender domain configs — erased immediately.
  • Submissions data is retained for as long as the tenant chooses; tenants can delete individual submissions from their dashboard.
  • Audit logs (admin actions) are retained for 12 months for security and compliance purposes.

7. Your Rights

Depending on where you live, you may have rights to:

  • Access your personal data and receive a copy.
  • Correct inaccurate or incomplete data.
  • Delete your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Portability — receive your data in a machine-readable format.
  • Withdraw consent where processing is based on consent.

To exercise any of these rights, email hello@swankflow.com. We will respond within 30 days. End customers should direct requests to the tenant whose form they submitted; if you need help identifying them, contact us.

8. International Transfers

Swankflow is hosted on Cloudflare's global infrastructure. Data may be processed in any country where Cloudflare operates, including the United States. Where applicable law (such as GDPR) requires additional safeguards, we rely on standard contractual clauses and the processor agreements offered by our subprocessors.

9. GDPR and CCPA

If you are in the European Economic Area, United Kingdom, or Switzerland, GDPR applies to our processing of your personal data. Swankflow acts as a data processor for end-customer data submitted through tenant forms, and as a data controller for tenant account data.

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you certain rights, including the right to know what personal information we collect and the right to delete personal information. We do not sell personal information.

10. Children's Privacy

Swankflow is not intended for use by children under 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will delete it promptly.

11. Cookies and Tracking

Swankflow uses essential cookies for authentication (session management) and CSRF protection. Tenants may optionally enable third-party tracking pixels (Google Analytics, GTM, Meta Pixel, TikTok, Snapchat) on their public forms — those are configured and controlled by the tenant. Affiliate-program cookies (Referly) are set when a visitor arrives via an affiliate link.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision.

13. Contact

Privacy questions or to exercise your rights: hello@swankflow.com.