Spontu (formerly UniSwipe) — Student Noticeboard
Last Updated: 18 August 2026 · Effective Date: 18 August 2026
Operated by: Serendipity Inc., registered in Japan
Spontu (formerly UniSwipe) ("we," "us," "our") is a student marketplace platform developed and operated by Serendipity Inc., a company incorporated in Japan. The Service is available as a web application and mobile application (collectively, the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and your rights regarding your data.
We are committed to protecting your privacy and complying with applicable data protection law. The Service is available worldwide, so more than one framework may apply to you at once — depending on where you live, where we are established, and where our infrastructure sits. Those that may apply include:
One standard, applied to everyone
Rather than promise different things to different people, we apply one set of practices to every user worldwide. The disclosures, retention limits, security measures, and rights described in this policy are available to you regardless of which country you are in and regardless of which of the laws above happens to reach you. Where your local law gives you more than what is described here, you get more — Section 8 lists the region-specific additions we are aware of.
By creating an account or using the Service, you agree to the collection and use of your data as described in this policy. If you do not agree, please do not use the Service.
This policy is provided for transparency. It is not legal advice. If you need advice about your specific situation (for example tax, immigration, or regulatory compliance), consult a qualified professional.
The data controller responsible for your personal data is:
Serendipity Inc.
Nishi-Shinjuku Mizuma Building 6F, 3-3-13 Nishi-Shinjuku, Shinjuku-ku, Tokyo 160-0023, Japan
Email: cwtros@gmail.com
As we are not established in the United Kingdom but process personal data of UK residents, we have appointed a representative in the UK in accordance with Article 27 of the UK General Data Protection Regulation (UK GDPR).
UK residents may contact our representative for any matters relating to the processing of their personal data, including Subject Access Requests and other data subject rights under UK GDPR:
Data Protection Representative (UK) Limited (trading as DataRep)
107–111 Fleet Street, London, EC4A 2AB, United Kingdom
Email: datarequest@datarep.com (quote “Spontu (formerly UniSwipe)” in the subject line)
Online form: www.datarep.com/data-request
When contacting by post, please address your letter to “DataRep” (not “Spontu (formerly UniSwipe)”) and refer clearly to Spontu (formerly UniSwipe) in your correspondence. DataRep acts as our representative point of contact and does not have independent decision-making authority over data processing activities.
If you are anywhere other than the United Kingdom, contact us directly at cwtros@gmail.com or at the postal address in Section 2 for any matter concerning your personal data, including a request to exercise the rights in Section 8.
We handle those requests on the same terms and to the same timescales for everyone, wherever you live — see Section 8.4 for how that works in practice. Contacting us is never a precondition to complaining about us: you can go straight to your own supervisory authority at any time, and Section 8.2 lists where to find yours.
When you create an account, we collect:
| Data | Purpose |
|---|---|
| Email address | Account creation, sign-in links, and login via Supabase Auth (any reachable email you choose; we do not require a specific school domain) |
| OAuth profile data (Google / Apple) | Optional sign-in: name and email supplied by the provider to Supabase Auth per their policies |
| Full name | Display on your profile and listings |
| Profile photo | Display on your profile, listings, and messages |
| Institution name and type (e.g. university or school) | Profile trust signal and feed filters (e.g. same institution) |
| Course / programme of study | Display on your profile for trust and context |
| Year of study | Display on your profile |
| Age | Collected at signup from individual accounts to confirm eligibility (18+). Organisation accounts are not asked for one. |
| Phone number (optional) | Stored on your profile if you provide it; visibility controlled in Settings |
| Bio and languages (optional) | Display on your profile |
| Notification preferences | In-app / email-style notification categories (bookings, messages, etc.) |
| Password (hashed) | Email/password sign-in only — stored by Supabase; we never see your plaintext password |
When you create a listing, we collect:
| Data | Purpose |
|---|---|
| Listing title and description | Display in the marketplace feed |
| Listing type (Time, Experience, Item) | Categorisation and filtering |
| Location label and meeting type (in person / online) | Display to bookers; in-person meetups may include a text address |
| Map coordinates (optional, in-person listings) | If you drop a pin on the map, we store latitude/longitude to show the listing on the map and compute distances when bookers opt in |
| Online meeting URL (optional) | Shared when the listing is online |
| Event timezone and event date/time (experiences) | Correct scheduling and display for bookers |
| Availability / calendar slots (time-based listings) | Allow bookers to select a time |
| Listing images (if uploaded) | Display in listing detail (including gallery photos) |
| Data | Purpose |
|---|---|
| Booking details (listing, date, time, participants) | Manage the booking lifecycle |
| Booking status (pending, confirmed, checked-in, completed, cancelled, disputed, expired) | Track booking progress and moderation states |
| Completion PIN and handover deadline | In-person completion: Booker shows PIN; Provider enters it to mark the booking complete |
| Reviews (1–5 stars + text, booker → provider) | Public reputation after completed bookings |
We do not collect payment data. Spontu (formerly UniSwipe) takes no payments: every listing is free, no card is ever requested, and no payment processor is connected to the Service. We hold no card numbers, CVVs or bank details, and never have.
Historical records. Before payments were switched off, a limited number of bookings recorded a payment reference and an amount. Those rows still exist in our database and are retained under Section 7 for the periods required by law. You can request a copy or erasure of them under Section 8 on the same basis as any other data we hold about you.
| Data | Purpose |
|---|---|
| Message content (text) | In-app communication via Supabase Realtime |
| Message timestamps | Display in chat interface |
| Read receipts | Show whether messages have been read |
We store message content in our database for as long as the conversation and accounts exist, or as required for safety, disputes, or law. We do not sell message content to third parties. We may review message content if a user reports a safety concern, or if required by law.
Reports and blocks: If you submit a report (listing, message, or profile) or block another user, we store the identifiers, reasons, and details you provide, plus related metadata, for moderation and safety.
| Data | Purpose |
|---|---|
| IP address | Security, fraud prevention, approximate location |
| Browser type and version | Compatibility and debugging |
| Device type (mobile/desktop) | Responsive design and analytics |
| Operating system | Compatibility and debugging |
| Approximate location you opt into (browser geolocation) | Only if you enable location for "nearest" sorting or the map view: coordinates may be sent with feed requests to sort or display distance—not stored as a permanent profile field |
| Pages visited and actions taken | Product improvement (limited to normal server logs where applicable) |
| Crash reports and error logs | Debugging and stability (if you or we attach them to support) |
Cookies and similar technologies are separately regulated in many countries — by the Privacy and Electronic Communications Regulations 2003 (PECR) in the UK, the ePrivacy Directive as implemented across the EEA, and comparable rules elsewhere. The common shape of those rules is:
| Type | Purpose | Required? |
|---|---|---|
| Essential | Supabase auth session cookies / storage | Yes — required to stay signed in |
We currently use essential cookies only. We do not use advertising cookies, third-party tracking pixels, or behavioural profiling cookies. We do not share cookie data with advertisers. If we introduce non-essential cookies in future, we will implement a consent banner that blocks those cookies until you actively accept them, meeting the PECR and ePrivacy standard for every user regardless of country.
Because we set no advertising or analytics cookies and share no data with advertisers, we do not engage in "targeted advertising" or the "sale" or "sharing" of personal information as those terms are defined under US state privacy laws, and there is no such processing for you to opt out of.
We send service-related communications (for example booking confirmations, account security notices, and policy updates) which do not require your separate consent as they are part of the service you signed up for.
We do not send marketing emails or push notifications without your explicit, separate consent. We apply the following rules to every user, wherever you are, because they are the strictest of those we are subject to (UK GDPR and PECR, EU GDPR and ePrivacy, and Japan's Act on Regulation of Transmission of Specified Electronic Mail):
| Data | Purpose |
|---|---|
| Device push token (if you enable push on a supported client) | May be stored on your profile for future mobile push delivery |
| In-app notification records | Notification inbox in the Service (bookings, messages, etc.) |
| Notification preferences | Respect your settings on your profile |
To provide the Service: Create and manage your account, display your profile and listings, process bookings, enable in-app messaging, send notifications, and display reviews and ratings.
To maintain trust and safety: Use profile and institution information you provide, investigate reports, enforce our Terms and Community Guidelines, and prevent fraud.
To improve the Service: Analyse usage patterns, debug errors, and understand which features are most used.
To comply with legal obligations: Respond to lawful requests, comply with tax reporting obligations, and maintain legally required records.
Communications: We send service-related emails or in-app messages (for example account security, bookings, and policy updates). We do not use your data to run third-party behavioural advertising. If we introduce optional marketing messages where consent is required, we will describe that separately.
Automated decisions: We do not use solely automated processing to make decisions about you that produce legal or similarly significant effects without human involvement.
We process personal data on the following legal bases under the UK GDPR and the EU GDPR. Where your own law uses a different framework (for example consent-led regimes such as Japan's APPI, or notice-and-opt-out regimes such as those in several US states), we still confine ourselves to the purposes listed below:
Your profile information and listing details are visible to other users. You control what you include in your profile and listings.
Because the Service is available worldwide, "other users" is not limited to your campus or your country: a profile, listing, or review is readable by signed-in Users anywhere, and once another User has seen something we cannot unsee it for them. Feed filters (such as same-institution) affect what is surfaced, not what is accessible. The one exception is blocking: a User you have blocked, or who has blocked you, cannot see your listings and you cannot see theirs. Do not put anything in a public field that you would not want read outside your own country.
| Provider | Data Shared | Purpose | Location |
|---|---|---|---|
| Supabase | All account, listing, booking, message data | Database, auth, realtime | United States (AWS) |
| Vercel | IP address, browser data, request logs | Web hosting (Next.js) | United States (Edge) |
| Account identifiers if you use "Sign in with Google" | Authentication (via Supabase) | United States / global | |
| Apple | Account identifiers if you use "Sign in with Apple" | Authentication (via Supabase) | United States / global |
| Map tile providers (e.g. CARTO / OpenStreetMap) | Standard HTTP requests when maps load (may include IP) | Map images in the browser | Varies (CDN) |
We report nothing to any tax authority. Platform reporting regimes — UK platform reporting rules, EU DAC7, and the national regimes based on the OECD Model Reporting Rules for Digital Platforms — require the reporting of consideration paid to sellers. Spontu (formerly UniSwipe) pays Providers nothing and processes no payments, so no such report is due in any country. If paid listings are ever reintroduced, this section would change and we would notify affected users and provide a copy of any data reported where permitted by law.
We may disclose your data if required by law, regulation, legal process, or governmental request. We will attempt to notify you before disclosure unless prohibited by law.
Your data leaves your country. This is true for every user, everywhere.
Spontu (formerly UniSwipe) runs on infrastructure in the United States and is operated from Japan. Wherever you live, using the Service means your personal data is transferred to, stored in, and processed in those countries — and, for content you post publicly, is visible to Users in other countries. If you are not comfortable with that, do not use the Service.
Specifically: our database is hosted by Supabase on AWS infrastructure in the United States. Our web hosting is provided by Vercel (United States, with edge nodes globally, which means a request from you may be served from a node in or near your own region). We are operated by Serendipity Inc., a Japanese entity.
The UK and the EU each operate an "adequacy" framework that allows personal data to flow freely to countries whose data protection standards have been approved. The position differs between them, and it matters:
Many countries restrict cross-border transfers of personal data in their own way — through consent requirements, contractual safeguards, adequacy-style listings, or in some cases data localisation rules that we cannot satisfy. By creating an account you consent, to the extent your law treats consent as the basis for such a transfer, to your personal data being transferred to and processed in the United States and Japan as described above.
Whatever the mechanism, the substance is the same for everyone: the same sub-processors, under the same contractual terms, with the protections described in Section 9 and the rights described in Section 8. If your country requires personal data about its residents to remain within its borders, the Service cannot meet that requirement and you should not use it.
| Data Type | Retention Period |
|---|---|
| Account and profile data | Until you delete your account (subject to legal retention below) |
| Listings | Until deleted or account deletion |
| Booking records | 3 years after completion |
| Transaction / payment records | 7 years (legal/tax requirements) — historical only; no new records are created |
| Messages | While accounts exist; deleted with account or as required by law |
| Reviews and ratings | Until account deletion (then anonymised) |
| Notification history | 12 months |
| Technical / analytics data | 12 months |
We extend the following rights to every user regardless of location, whether or not your national law requires it:
You can always complain to us first at cwtros@gmail.com. You are also entitled to complain to a regulator without going through us:
Contact us at cwtros@gmail.com. We respond within 30 days for everyone, wherever you live. Some laws allow longer (45 days in California, for example) and some allow an extension for complex requests; we aim for 30 days regardless and will tell you if we need more time and why. We may ask you to verify your identity before acting on a request, and we will not charge you for a first request.
You can delete your account through Settings. The Service first attempts to cancel open bookings, then removes your auth account and cascaded profile data from our database. Some records (for example reviews or bookkeeping) may be retained in anonymised or aggregate form, or longer where the law requires.
If you no longer have the app installed, or cannot sign in, email us at cwtros@gmail.com from the address on your account and we will delete it for you. The same 30-day response time in 8.4 applies.
If you discover a vulnerability, report it to cwtros@gmail.com.
No system is perfectly secure. We cannot guarantee that unauthorised access, hacking, data loss, or other breaches will never occur. You use the Service understanding that residual risk remains.
Under Article 33 of the UK and EU GDPR, we must notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it, where the breach is likely to result in a risk to individuals' rights and freedoms (for example, exposure of personal messages or identity information). Under Article 34, where the breach is likely to result in a high risk to individuals, we must also notify affected users directly without undue delay.
Other countries impose their own deadlines and thresholds — Japan's APPI, Australia's Notifiable Data Breaches scheme, Brazil's LGPD, and US state breach-notification statutes among them, several of which are shorter or stricter in particular respects.
We apply the 72-hour standard and notify affected users directly for any breach likely to pose a high risk to them, wherever they live, and we notify each regulator we are answerable to within the deadline that regulator sets.
We have internal procedures in place to identify, assess, and respond to data breaches. If you believe your data has been compromised, contact cwtros@gmail.com immediately. You may also report a concern directly to your own regulator — see Section 8.2 for where to go; UK users can complain to the ICO at ico.org.uk/make-a-complaint.
Spontu (formerly UniSwipe) is for users aged 18 and over, or the age of majority where you live if that is higher. We do not knowingly collect data from anyone below that age. If we learn we have, we will delete it promptly.
Because the minimum age is 18 everywhere, we do not rely on the lower digital-consent ages that some countries permit (13 to 16 across the EEA, 13 under the US COPPA regime), and no child-directed processing takes place. If you are a parent or guardian who believes a person under 18 has created an account, contact cwtros@gmail.com and we will remove it.
We may update this policy. Material changes will be communicated via email or in-app notification at least 14 days before taking effect.
Email: cwtros@gmail.com
Address: Serendipity Inc., Nishi-Shinjuku Mizuma Building 6F, 3-3-13 Nishi-Shinjuku, Shinjuku-ku, Tokyo 160-0023, Japan
This Privacy Policy was last reviewed on 18 August 2026.