Privacy Policy
How SWIRL collects, uses, and protects your information, and the control you have over it.
01 Introduction & scope
SWIRL ("SWIRL", "we", "us", or "our") is a swipe-based fashion discovery platform that helps you find products from Indian and global brands. This Privacy Policy applies to everyone who uses the SWIRL mobile application and related services, on both iOS and Android.
It is publicly accessible and applies wherever you use SWIRL. By using the app, you acknowledge the practices described here.
02 Who we are
SWIRL is operated from Hyderabad, Telangana, India. The founder acts as our Data Protection Officer and grievance contact. You can reach us at contact@swirl.style or through swirl.style. We aim to respond to privacy inquiries within 30 days.
03 Data we collect
3.1 Data you provide
- Account information. Your phone number, used to sign in, along with your name and, optionally, gender and date of birth.
- Profile and taste data. Your username, profile photo, and your Style DNA: preferred brands, budget range, sizes, and the style preferences you set.
- Content you create. Curations (product collections you assemble), wishlists, and anything you save or share. Curations you publish are visible to other users.
- Search and assistant input. The text you type into search and the AI stylist. See AI & personalization.
- Support messages. Anything you send us when you contact support.
3.2 Data collected automatically
- Device and identifiers. Device model, OS version, app version, and platform advertising identifiers. On Android, the Advertising ID; on iOS, an identifier is accessed only with your permission (see Permissions).
- Usage and behaviour. Your swipes (likes and dislikes), items viewed, time spent, features used, streaks, and the taste signals we infer from them to personalize your feed.
- Approximate location. City-level location derived from your IP address. We do not collect precise GPS location.
- Guest activity. If you browse without an account, we use a randomly generated guest identifier to remember what you have already seen in your session. It is not linked to your identity.
- Diagnostics. Crash reports and session data used to keep the app stable.
3.3 Data from integrations
We work with a small set of service providers to run SWIRL. The full list, and what each one receives, is in Data sharing.
04 How we use your data
- Core functionality. Signing you in, building and personalizing your feed, powering search and the AI stylist, and saving your curations.
- Improving SWIRL. Understanding how features are used, running A/B tests, and fixing bugs.
- Safety and security. Preventing fraud and abuse, verifying sign-in, and meeting legal obligations.
- Communications. Transactional messages such as sign-in codes, and, only if you opt in, updates and marketing. You can opt out at any time.
We do not sell your personal or sensitive data to any third party for monetary consideration, and we do not share it with advertising networks or data brokers.
05 AI & personalization
SWIRL uses AI to power search, the stylist ("Deep Search"), and outfit recommendations. When you use these features:
- The text of your query and relevant taste signals, such as your Style DNA and recent likes, are sent to a third-party large language model. We use Anthropic's Claude, accessed through Amazon Web Services (AWS Bedrock).
- This data is used to produce your result. We do not use it to build advertising profiles, and we do not sell it.
- Feed personalization based on your swipes is computed on our own infrastructure.
AI-generated recommendations are suggestions, not professional advice.
06 Affiliate links & how we earn
SWIRL is free to use. When you choose to buy a product, we may route you to the retailer through an affiliate network (Cuelinks) so that a resulting purchase can be attributed to SWIRL and we earn a commission.
- The outbound link includes a tracking identifier associated with your account, so a purchase can be reconciled to you for commission purposes. Cuelinks and the destination retailer receive this identifier and record the click and any resulting purchase.
- When you share a curation, the links inside carry an identifier that ties any resulting purchase back to that shared curation.
- Purchases are completed on the retailer's own site, under the retailer's terms and privacy policy. SWIRL is not the seller.
07 Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract. To provide your account and the core service.
- Consent. For personalized recommendations, optional permissions, and marketing.
- Legitimate interest. For analytics, security, and fraud prevention.
- Legal obligation. Where the law requires us to retain or disclose data.
08 Data sharing & disclosure
We share data only with the providers that operate SWIRL, under data-processing agreements, and only the data each one needs:
| Provider | Purpose | Data involved |
|---|---|---|
| Twilio | SMS one-time passcodes for sign-in | Phone number, verification code |
| Amazon Web Services (incl. Bedrock) | Cloud hosting and the AI stylist and search | App data at rest; search and taste input for AI features |
| Cuelinks | Affiliate link tracking | Click event and an account-linked tracking id |
| Shopify | Product catalog data, and order status where checkout runs through Shopify | Catalog data; order data and PII only if you check out through Shopify |
| Firebase (Google) | Push notifications and diagnostics | Device push token, crash and analytics data |
| CDN (CloudFront) | Serving product images | Standard request metadata |
We may also disclose data to comply with a valid legal request, in connection with a business transfer (with equivalent protection and notice to you), or where you have given explicit consent.
09 Data retention & deletion
| Category | Retention |
|---|---|
| Account data | Until deletion, plus 30 days |
| Transaction records, if any in-app | 7 years (tax and GST compliance) |
| Analytics and usage | Up to 24 months, rolling |
| Support communications | 2 years |
| Crash logs and diagnostics | 90 days |
| Marketing consent records | Until withdrawn, plus 3 years |
Deleting your account. You can delete your account in the app (Profile, then Settings, then Account, then Delete Account), at swirl.style/delete-account, or by emailing contact@swirl.style. We permanently delete your personal data within 30 days, except anonymized statistics and anything the law requires us to keep.
10 Permissions we request
SWIRL requests only what it needs, and most permissions are optional.
- Camera (optional). To take a profile photo or capture a style upload.
- Photos or storage (optional). To choose an image from your gallery, and to save a shared curation image.
- Notifications (optional). For updates and alerts.
- App tracking on iOS (optional). We ask through Apple's App Tracking Transparency prompt before accessing any advertising identifier. You can decline.
- Internet (required). The app cannot function offline.
SWIRL does not request contacts, SMS or call logs, precise GPS, microphone, or background location.
11 Analytics & tracking
- No third-party advertising. SWIRL currently shows no third-party ads. If that changes, we will update this policy and notify you.
- Advertising identifiers are used only for product analytics and fraud prevention, never for cross-app behavioural advertising. You can reset or limit them in your device settings.
- Firebase analytics data is aggregated and used to improve the app. You can opt out through contact@swirl.style or in-app settings.
- Affiliate tracking is described in Section 06.
12 Data security
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256) on our cloud infrastructure.
- Role-based access controls that limit who can access personal data.
- No storage of raw card numbers, CVVs, or passwords. Sign-in is by one-time passcode.
- Periodic security reviews.
No system is perfectly secure. If you believe your account or data is at risk, contact contact@swirl.style.
13 Children's privacy
SWIRL is not directed to children under 13, or under 16 in the EEA. We do not knowingly collect their data, and we will promptly delete it if we learn we have. For concerns, contact contact@swirl.style.
14 Your rights
14.1 India (DPDPA 2023)
You have the right to access, correct, and erase your personal data, and the right to grievance redressal, including escalation to the Data Protection Board.
14.2 GDPR & UK GDPR
You have the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, and the right to complain to your supervisory authority, such as the ICO in the UK.
14.3 How to exercise them
Email contact@swirl.style with the subject "Data Rights Request", and the type of request. We respond within 30 days, or within 72 hours for security matters, free of charge.
15 International data transfers
We are based in India and use cloud infrastructure that may process data in India, the United States, and other regions. For users in the EEA and UK, transfers are protected by Standard Contractual Clauses, the UK International Data Transfer Agreement, and the EU to U.S. Data Privacy Framework where applicable.
16 Third-party links & stores
SWIRL links out to retailer sites and brand stores. This policy does not cover those sites, so please review their own privacy policies. We are not responsible for third-party practices.
17 Changes to this policy
When we update this policy we will change the "Last updated" date. For material changes that affect your rights, we will show an in-app notice at least 14 days before they take effect, and significant changes to sensitive-data processing will ask for renewed consent. Continued use after an update means you accept it. If you disagree, you may delete your account.
18 Grievance & contact
In line with India's IT Rules 2021, you may contact our Grievance Officer for privacy complaints. We acknowledge within 48 hours and aim to resolve within 30 days.
We maintain adherence to the Apple App Store and Google Play developer policies, India's DPDPA 2023, the GDPR and UK GDPR, and India's IT Act 2000 and IT Rules 2011 and 2021.