Swift Pivot
  • Solutions
  • Pricing
Sign inRequest access

Legal

Privacy Policy

Effective September 22, 2026Last updated September 22, 2026
This policy explains what Swift Pivot does with personal information — both the information about you, as someone with an account, and the information about your contacts, which you upload and control. Those are different relationships with different rules, and §1 sets out which is which.

On this page

  1. 1Our two roles
  2. 2Information we collect
  3. 3Google sign-in data
  4. 4How we use information
  5. 5Contact data you upload
  6. 6Health information and HIPAA
  7. 7Sharing and subprocessors
  8. 8Storage, security and retention
  9. 9Your privacy rights
  10. 10Cookies and tracking
  11. 11Children's privacy
  12. 12Changes to this policy
  13. 13Contact us

01Our two roles

Swift Pivot (“Swift Pivot”, “we”, “us”) is operated by SWIFT-PIVOT LLC. We handle personal information in two distinct capacities, and the rest of this policy depends on the difference.

  • As a controller — for information about you as an account holder: your name, email address, organization and how you use the product. We decide why and how that information is processed.
  • As a processor (service provider) — for the contact data you upload or capture through Swift Pivot: your leads, patients, caregivers and prospects. You decide why and how that is processed; we act on your instructions. Your own privacy notice, not this one, governs your relationship with those people.

In plain English

We are responsible for the data about you. You are responsible for the data about the people you market to — we just hold it and send on your behalf.

02Information we collect

Information you give us

  • Account information — email address, password (stored only as a salted hash by our authentication provider), and full name.
  • Organization information — organization name, logo and brand settings you upload, and the email addresses of teammates you invite.
  • Content — post text, images and video you upload for publishing, and any campaign copy you write.
  • Credentials for connected services — if you supply your own social publishing API key, we store it encrypted (see §8).

Information we collect automatically

  • Authentication and session data — session tokens and their expiry, kept in cookies so you stay signed in.
  • Operational logs — request timestamps, error diagnostics and publishing outcomes, used to run and debug the service.
  • Publishing results — whether a post succeeded on each connected network, and the resulting public permalink.

What we do not collect

We do not run advertising networks, we do not sell personal information, and we do not use third-party behavioural advertising trackers on this site. We do not collect payment card numbers: services are invoiced, and payment is arranged directly with us.

03Google sign-in data

If you choose Sign in with Google, Google sends us a limited set of profile information so we can create and authenticate your account. We request only the standard openid, email and profile scopes.

Google user data we receive and how it is used
DataWhy we need itHow long we keep it
Email addressIdentifies your account and is where we send service noticesUntil you delete your account
Name and profile pictureDisplayed in the app so teammates can recognise youUntil you delete your account
Google account IDLinks your Google identity to your account so sign-in works next timeUntil you delete your account

We do not request access to Gmail, Google Drive, Contacts, Calendar or any other Google service, and we cannot read them. Google sign-in is used for authentication only.

Important

Swift Pivot’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to others except as necessary to provide the service, we do not use it for advertising, and we do not allow humans to read it except with your explicit consent, for security purposes, or as required by law.

You can revoke Swift Pivot’s access at any time from your Google account permissions page. Doing so prevents future Google sign-in but does not by itself delete your Swift Pivot account — use §10 for that.

04How we use information

We use personal information only for the following purposes:

  • To create your account, authenticate you and keep you signed in.
  • To provide the service — publishing posts, storing media, running your campaigns.
  • To send service messages: confirmation and password-reset emails, invitations you trigger, and notices about material changes to the service or these terms.
  • To detect, investigate and prevent abuse, fraud and security incidents.
  • To meet legal, tax and regulatory obligations.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy laws.

05Contact data you upload

When you import contacts, publish a lead form or connect a lead source, you are asking us to process personal information about other people on your behalf. In respect of that data:

  • We process it only to provide the service and on your documented instructions.
  • We do not use it to build our own profiles, train models, or market to your contacts.
  • We store the consent state, timestamp and source you record for each contact, because marketing law depends on it.
  • We return or delete it when you close your account, per §8.

Important

You are responsible for having a lawful basis to contact every person you upload. The Telephone Consumer Protection Act carries statutory damages of $500–$1,500 per message, and CAN-SPAM penalties run per email. Swift Pivot enforces consent and suppression checks at the point of sending, but it cannot verify that consent you recorded elsewhere was genuinely obtained. See the Terms of Service §6.

06Health information and HIPAA

Important

Swift Pivot is a marketing platform, not a clinical system. It is not designed for Protected Health Information (PHI), we do not act as a HIPAA Business Associate, and we do not enter into Business Associate Agreements. You must not upload diagnoses, treatment details, care plans, insurance or claims data, or any other PHI.

A name, phone number and email address for someone enquiring about services is contact information, and that is what the platform is built for. The moment a record describes somebody’s health condition or care, it does not belong here. If you need to market using PHI, you need a vendor that will sign a BAA — that is not us today.

In plain English

Names and contact details, yes. Anything about someone’s health or care, no.

07Sharing and subprocessors

We share personal information only with the service providers needed to run the platform, each bound by contract to protect it and use it only for the service they provide:

Subprocessors currently used
SubprocessorPurposeLocation
Vercel Inc.Application hosting and content deliveryUnited States
Supabase, Inc.Database, authentication and file storageUnited States
BlotatoSocial media publishing to connected accountsUnited States
cron-job.orgScheduled task trigger (carries no customer data)Germany
Amazon Web Services (SES)Bulk email deliveryUnited States
Twilio Inc.SMS delivery and carrier registration (A2P 10DLC and toll-free verification)United States

The following are used only once you enable the corresponding feature, and process nothing until then:

Subprocessors used when the corresponding feature is enabled
SubprocessorPurposeLocation
Anthropic, PBCAI generation of marketing copyUnited States

We also disclose information where required by law, to enforce our terms, or in connection with a merger or acquisition — in which case we will give notice before your information becomes subject to a different privacy policy.

Separately, when you publish a post, its content and media are sent to the social networks you selected. Those networks are independent controllers and their own policies govern what happens next; we cannot retract a post once it is live.

08Storage, security and retention

Data is stored in the United States. We apply technical and organizational safeguards appropriate to the risk, including:

  • Encryption in transit (TLS) and at rest for all databases and file storage.
  • Row-level security in the database, so an organization’s records are isolated at the storage layer rather than only in application code.
  • AES-256-GCM application-layer encryption for third-party API keys you supply, so they remain unreadable in a database backup.
  • Passwords stored only as salted hashes, never in plain text or a reversible form.

No system is perfectly secure, and we do not claim otherwise. An attacker with application-level access could reach data the application itself can reach.

Retention

  • Account and organization records: until you delete them, then removed within 30 days.
  • Uploaded media: retained after a post is deleted, because published posts may still reference the file; removed with the organization.
  • Suppression and opt-out records: retained after contact deletion, because we must not re-contact someone who opted out. This is the one case where deleting less protects people more.
  • Operational logs: retained for a limited period for security and debugging.

09Your privacy rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to opt out of its sale or sharing (we do neither), and not to be discriminated against for exercising these rights. Residents of California, Colorado, Connecticut, Virginia and other US states with comprehensive privacy laws have these rights by statute; we extend them to everyone.

Much of this is self-service: update your profile under Settings → Account, and delete your account there too. For anything else, write to contact@swift-pivot.com and we will respond within 45 days.

If you are one of our customers’ contacts and want your data removed, contact the organization that holds it — they control that record and we act on their instruction. If you reach us instead, we will forward your request to them.

10Cookies and tracking

We use a small number of first-party cookies, all strictly functional:

  • Authentication cookies — keep you signed in and refresh your session.
  • Active organization — remembers which organization you were last working in. It is a preference only, and is re-checked against your memberships on every request.
  • Theme and layout preferences — light or dark mode, sidebar state.

There are no advertising or analytics cookies, so there is no consent banner to dismiss. Blocking functional cookies will prevent sign-in from working.

11Children's privacy

Swift Pivot is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, write to contact@swift-pivot.com and we will delete it.

12Changes to this policy

We may update this policy as the product changes — new subprocessors appear here before they process anything. When a change is material we will notify account holders by email or in-product notice before it takes effect. The “last updated” date at the top always reflects the current version.

13Contact us

Privacy questions and rights requests:

SWIFT-PIVOT LLC1507 Central AvenueUnion City, NJ 07087United StatesEIN: 42-4932893Email: contact@swift-pivot.com
Swift Pivot

One workspace for home care agencies: capture leads, publish to every social channel, and run compliant bulk email and SMS campaigns.

contact@swift-pivot.com

Platform

  • Platform overview
  • Social publishing
  • Lead capture & contacts
  • Email & SMS campaigns
  • AI content studio

Company

  • About
  • Solutions
  • Pricing
  • FAQ
  • Contact

Trust

  • Compliance
  • Security
  • Subprocessors
  • Acceptable use

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Notice

© 2026 Swift Pivot

Operated by SWIFT-PIVOT LLC (EIN 42-4932893), 1507 Central Avenue, Union City, NJ 07087.

Publishes to Facebook, Instagram, LinkedIn, TikTok and X. Not affiliated with any of them.