Our two roles
Swift Pivot (“Swift Pivot”, “we”, “us”) is operated by SWIFT-PIVOT LLC. We handle personal information in two distinct capacities, and the rest of this policy depends on the difference.
- As a controller — for information about you as an account holder: your name, email address, organization and how you use the product. We decide why and how that information is processed.
- As a processor (service provider) — for the contact data you upload or capture through Swift Pivot: your leads, patients, caregivers and prospects. You decide why and how that is processed; we act on your instructions. Your own privacy notice, not this one, governs your relationship with those people.
Information we collect
Information you give us
- Account information — email address, password (stored only as a salted hash by our authentication provider), and full name.
- Organization information — organization name, logo and brand settings you upload, and the email addresses of teammates you invite.
- Content — post text, images and video you upload for publishing, and any campaign copy you write.
- Credentials for connected services — if you supply your own social publishing API key, we store it encrypted (see §8).
Information we collect automatically
- Authentication and session data — session tokens and their expiry, kept in cookies so you stay signed in.
- Operational logs — request timestamps, error diagnostics and publishing outcomes, used to run and debug the service.
- Publishing results — whether a post succeeded on each connected network, and the resulting public permalink.
What we do not collect
We do not run advertising networks, we do not sell personal information, and we do not use third-party behavioural advertising trackers on this site. We do not collect payment card numbers: services are invoiced, and payment is arranged directly with us.
Google sign-in data
If you choose Sign in with Google, Google sends us a limited set of profile information so we can create and authenticate your account. We request only the standard openid, email and profile scopes.
| Data | Why we need it | How long we keep it |
|---|---|---|
| Email address | Identifies your account and is where we send service notices | Until you delete your account |
| Name and profile picture | Displayed in the app so teammates can recognise you | Until you delete your account |
| Google account ID | Links your Google identity to your account so sign-in works next time | Until you delete your account |
We do not request access to Gmail, Google Drive, Contacts, Calendar or any other Google service, and we cannot read them. Google sign-in is used for authentication only.
You can revoke Swift Pivot’s access at any time from your Google account permissions page. Doing so prevents future Google sign-in but does not by itself delete your Swift Pivot account — use §10 for that.
How we use information
We use personal information only for the following purposes:
- To create your account, authenticate you and keep you signed in.
- To provide the service — publishing posts, storing media, running your campaigns.
- To send service messages: confirmation and password-reset emails, invitations you trigger, and notices about material changes to the service or these terms.
- To detect, investigate and prevent abuse, fraud and security incidents.
- To meet legal, tax and regulatory obligations.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy laws.
Contact data you upload
When you import contacts, publish a lead form or connect a lead source, you are asking us to process personal information about other people on your behalf. In respect of that data:
- We process it only to provide the service and on your documented instructions.
- We do not use it to build our own profiles, train models, or market to your contacts.
- We store the consent state, timestamp and source you record for each contact, because marketing law depends on it.
- We return or delete it when you close your account, per §8.
Health information and HIPAA
A name, phone number and email address for someone enquiring about services is contact information, and that is what the platform is built for. The moment a record describes somebody’s health condition or care, it does not belong here. If you need to market using PHI, you need a vendor that will sign a BAA — that is not us today.
Storage, security and retention
Data is stored in the United States. We apply technical and organizational safeguards appropriate to the risk, including:
- Encryption in transit (TLS) and at rest for all databases and file storage.
- Row-level security in the database, so an organization’s records are isolated at the storage layer rather than only in application code.
- AES-256-GCM application-layer encryption for third-party API keys you supply, so they remain unreadable in a database backup.
- Passwords stored only as salted hashes, never in plain text or a reversible form.
No system is perfectly secure, and we do not claim otherwise. An attacker with application-level access could reach data the application itself can reach.
Retention
- Account and organization records: until you delete them, then removed within 30 days.
- Uploaded media: retained after a post is deleted, because published posts may still reference the file; removed with the organization.
- Suppression and opt-out records: retained after contact deletion, because we must not re-contact someone who opted out. This is the one case where deleting less protects people more.
- Operational logs: retained for a limited period for security and debugging.
Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to opt out of its sale or sharing (we do neither), and not to be discriminated against for exercising these rights. Residents of California, Colorado, Connecticut, Virginia and other US states with comprehensive privacy laws have these rights by statute; we extend them to everyone.
Much of this is self-service: update your profile under Settings → Account, and delete your account there too. For anything else, write to contact@swift-pivot.com and we will respond within 45 days.
If you are one of our customers’ contacts and want your data removed, contact the organization that holds it — they control that record and we act on their instruction. If you reach us instead, we will forward your request to them.
Children's privacy
Swift Pivot is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, write to contact@swift-pivot.com and we will delete it.
Changes to this policy
We may update this policy as the product changes — new subprocessors appear here before they process anything. When a change is material we will notify account holders by email or in-product notice before it takes effect. The “last updated” date at the top always reflects the current version.
Contact us
Privacy questions and rights requests:
SWIFT-PIVOT LLC1507 Central AvenueUnion City, NJ 07087United StatesEIN: 42-4932893Email: contact@swift-pivot.com