Privacy Policy

UniSwipe — Student Marketplace

Last Updated: 13 April 2026 · Effective Date: 13 April 2026

Operated by: Serendipity Inc., registered in Japan

1. Introduction

UniSwipe ("we," "us," "our") is a student marketplace platform developed and operated by Serendipity Inc., a company incorporated in Japan. The Service is available as a web application and mobile application (collectively, the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and your rights regarding your data.

We are committed to protecting your privacy and complying with applicable data protection law. The Service is currently offered to users in the United Kingdom. The primary legal framework governing our processing of your personal data is:

  • United Kingdom: UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018

By creating an account or using the Service, you agree to the collection and use of your data as described in this policy. If you do not agree, please do not use the Service.

This policy is provided for transparency. It is not legal advice. If you need advice about your specific situation (for example tax, immigration, or regulatory compliance), consult a qualified professional.

2. Data Controller

The data controller responsible for your personal data is:

Serendipity Inc.
Nishi-Shinjuku Mizuma Building 6F, 3-3-13 Nishi-Shinjuku, Shinjuku-ku, Tokyo 160-0023, Japan
Email: cwtros@gmail.com

UK GDPR Article 27 Representative

As we are not established in the United Kingdom but process personal data of UK residents, we have appointed a representative in the UK in accordance with Article 27 of the UK General Data Protection Regulation (UK GDPR).

UK residents may contact our representative for any matters relating to the processing of their personal data, including Subject Access Requests and other data subject rights under UK GDPR:

Data Protection Representative (UK) Limited (trading as DataRep)
107–111 Fleet Street, London, EC4A 2AB, United Kingdom
Email: datarequest@datarep.com (quote “UniSwipe” in the subject line)
Online form: www.datarep.com/data-request

When contacting by post, please address your letter to “DataRep”(not “UniSwipe”) and refer clearly to UniSwipe in your correspondence. DataRep acts as our representative point of contact and does not have independent decision-making authority over data processing activities.

3. Data We Collect

3.1 Account & Profile Data

When you create an account, we collect:

DataPurpose
Email addressAccount creation, sign-in links, and login via Supabase Auth (any reachable email you choose; we do not require a specific school domain)
OAuth profile data (Google / Apple)Optional sign-in: name and email supplied by the provider to Supabase Auth per their policies
Full nameDisplay on your profile and listings
Profile photoDisplay on your profile, listings, and messages
Institution name and type (e.g. university or school)Profile trust signal and feed filters (e.g. same institution)
Course / programme of studyDisplay on your profile for trust and context
Year of studyDisplay on your profile
AgeCollected at signup to confirm eligibility (18+)
Phone number (optional)Stored on your profile if you provide it; visibility controlled in Settings
Bio and languages (optional)Display on your profile
Notification preferencesIn-app / email-style notification categories (bookings, messages, etc.)
Password (hashed)Email/password sign-in only — stored by Supabase; we never see your plaintext password

3.2 Listing Data

When you create a listing, we collect:

DataPurpose
Listing title and descriptionDisplay in the marketplace feed
Listing type (Time, Experience, Item)Categorisation and filtering
PriceDisplay to bookers and payment processing
Location label and meeting type (in person / online)Display to bookers; in-person meetups may include a text address
Map coordinates (optional, in-person listings)If you drop a pin on the map, we store latitude/longitude to show the listing on the map and compute distances when bookers opt in
Online meeting URL (optional)Shared when the listing is online
Event timezone and event date/time (experiences)Correct scheduling and display for bookers
Availability / calendar slots (time-based listings)Allow bookers to select a time
Listing images (if uploaded)Display in listing detail (including gallery photos)

3.3 Booking & Transaction Data

DataPurpose
Booking details (listing, date, time, participants)Manage the booking lifecycle
Booking status (pending, confirmed, checked-in, completed, cancelled, disputed, expired)Track booking progress and moderation states
Completion PIN and handover deadlineIn-person completion: Booker shows PIN; Provider enters it to trigger payment capture (paid) or completion (free) as implemented
Service fee, platform fee, provider payout amountsCheckout display, Stripe application fee, and earnings records
Reviews (1–5 stars + text, booker → provider)Public reputation after completed bookings
Transaction amount and commissionPayment processing and platform revenue

3.4 Payment Data

We use Stripe (including Stripe Connect) to process all payments. We do not store your full card number, CVV, or bank account details on our servers. Stripe handles this data directly under their own privacy policy.

DataWhere StoredPurpose
Stripe Connect Account IDOur database (Supabase)Link your provider account to receive payouts
Stripe PaymentIntent ID (per paid booking)Our database (Supabase) + StripeAuthorise, capture, cancel, or refund the correct charge
Transaction IDs and amountsOur database + StripeRecord of transactions, earnings tracking
Bank account details (for payouts)Stripe onlyProvider payouts — we never see full bank details

For Stripe's data handling practices, see: stripe.com/privacy

3.5 Messaging Data

DataPurpose
Message content (text)In-app communication via Supabase Realtime
Message timestampsDisplay in chat interface
Read receiptsShow whether messages have been read

We store message content in our database for as long as the conversation and accounts exist, or as required for safety, disputes, or law. We do not sell message content to third parties. We may review message content if a user reports a safety concern, or if required by law.

Reports and blocks: If you submit a report (listing, message, or profile) or block another user, we store the identifiers, reasons, and details you provide, plus related metadata, for moderation and safety.

3.6 Device & Technical Data

DataPurpose
IP addressSecurity, fraud prevention, approximate location
Browser type and versionCompatibility and debugging
Device type (mobile/desktop)Responsive design and analytics
Operating systemCompatibility and debugging
Approximate location you opt into (browser geolocation)Only if you enable location for "nearest" sorting or the map view: coordinates may be sent with feed requests to sort or display distance—not stored as a permanent profile field
Pages visited and actions takenProduct improvement (limited to normal server logs where applicable)
Crash reports and error logsDebugging and stability (if you or we attach them to support)

3.7 Cookies & Local Storage — PECR Compliance

In the United Kingdom, cookies and similar tracking technologies are governed by the Privacy and Electronic Communications Regulations 2003 (PECR) as well as UK GDPR. The rules are:

  • Essential cookies (session management, authentication): no consent required — these are necessary to provide the Service.
  • Analytics, marketing, or tracking cookies: require your explicit opt-in consent before being set. Pre-ticked boxes and "by continuing to browse you accept" are not valid consent under PECR.
  • You can withdraw consent for non-essential cookies at any time as easily as you gave it.
TypePurposeRequired?
EssentialSupabase auth session cookies / storageYes — required to stay signed in

We currently use essential cookies only. We do not use advertising cookies, third-party tracking pixels, or behavioural profiling cookies. We do not share cookie data with advertisers. If we introduce non-essential cookies in future, we will implement a PECR-compliant consent banner that blocks those cookies until you actively accept them.

3.8 Marketing Communications

We send service-related communications (for example booking confirmations, payment receipts, account security notices, and policy updates) which do not require your separate consent as they are part of the service you signed up for.

We do not send marketing emails or push notifications without your explicit, separate consent. Under UK GDPR and PECR:

  • Marketing opt-in is always presented as a separate, unticked checkbox — it is never bundled with account registration or these Terms.
  • Pre-ticked consent boxes for marketing are not used.
  • You can withdraw consent for marketing communications at any time by emailing cwtros@gmail.com or using the unsubscribe link in any marketing email.

3.9 Notifications Data

DataPurpose
Device push token (if you enable push on a supported client)May be stored on your profile for future mobile push delivery
In-app notification recordsNotification inbox in the Service (bookings, messages, etc.)
Notification preferencesRespect your settings on your profile

3.10 Data We Do NOT Collect

  • We do not track your live location in the background. Optional exact coordinates may exist when you place a listing map pin, and optional one-off geolocation when you choose nearest sorting or the map view.
  • We do not collect biometric data.
  • We do not collect government-issued ID numbers, passport numbers, or national insurance / social security numbers.
  • We do not collect health data.
  • We do not record audio or video through the app.
  • We do not access your contacts, camera roll, or files without explicit action from you.

4. How We Use Your Data

To provide the Service: Create and manage your account, display your profile and listings, process bookings and payments via Stripe, enable in-app messaging, send notifications, and display reviews and ratings.

To maintain trust and safety: Use profile and institution information you provide, investigate reports, enforce our Terms and Community Guidelines, and prevent fraud.

To improve the Service: Analyse usage patterns, debug errors, and understand which features are most used.

To comply with legal obligations: Respond to lawful requests, comply with tax reporting obligations, and maintain legally required records.

Communications: We send service-related emails or in-app messages (for example account security, bookings, payments, and policy updates). We do not use your data to run third-party behavioural advertising. If we introduce optional marketing messages where consent is required, we will describe that separately.

Automated decisions: We do not use solely automated processing to make decisions about you that produce legal or similarly significant effects without human involvement.

4.1 Legal bases (UK GDPR)

We process personal data on the following legal bases under UK GDPR:

  • Performance of a contract (Article 6(1)(b)): to provide the Service you signed up for—account, listings, bookings, messaging, payments facilitation, and related notifications.
  • Legitimate interests (Article 6(1)(f)): to keep the Service secure, prevent fraud and abuse, handle reports, improve and debug the product, and analyse usage in ways that do not override your rights; you may object where applicable.
  • Consent (Article 6(1)(a)): where we ask for optional consent (for example if we introduce optional marketing or non-essential cookies), you may withdraw it at any time.
  • Legal obligation (Article 6(1)(c)): where we must retain or disclose data for tax, accounting, or regulatory requirements.

5. Who We Share Your Data With

5.1 Other UniSwipe Users

Your profile information and listing details are visible to other users. You control what you include in your profile and listings.

5.2 Service Providers (Sub-processors)

ProviderData SharedPurposeLocation
SupabaseAll account, listing, booking, message dataDatabase, auth, realtimeUnited States (AWS)
StripeName, email, bank/card details, transactionsPayments, payouts, KYCUnited States
VercelIP address, browser data, request logsWeb hosting (Next.js)United States (Edge)
GoogleAccount identifiers if you use "Sign in with Google"Authentication (via Supabase)United States / global
AppleAccount identifiers if you use "Sign in with Apple"Authentication (via Supabase)United States / global
Map tile providers (e.g. CARTO / OpenStreetMap)Standard HTTP requests when maps load (may include IP)Map images in the browserVaries (CDN)

5.3 Tax Authorities

We may be required by law to report provider income data to tax authorities. This includes:

  • United Kingdom: HMRC (including under UK DAC7 / platform reporting rules)

We will notify affected users and provide a copy of any data reported where permitted by law.

5.4 Law Enforcement

We may disclose your data if required by law, regulation, legal process, or governmental request. We will attempt to notify you before disclosure unless prohibited by law.

5.5 We Do NOT Share Data With

  • Advertisers
  • Data brokers
  • Marketing companies

6. International Data Transfers

Our database is hosted by Supabase on AWS infrastructure in the United States. Payments are processed by Stripe in the United States. Our web hosting is provided by Vercel (United States, with edge nodes globally). We are operated by Serendipity Inc., a Japanese entity. Your personal data may therefore be transferred to, stored in, and processed in the United States and Japan.

Japan is not on the UK adequacy list

The UK operates an "adequacy" framework under UK GDPR that allows personal data to flow freely to countries whose data protection standards have been approved. Japan is not currently on the UK's adequacy list. This means that any transfer of your personal data to Japan requires a lawful transfer mechanism. We use the UK International Data Transfer Agreement (IDTA) between our UK-facing operations and our Japanese entity to ensure these transfers are lawful under UK GDPR Article 46.

We protect your data in cross-border transfers as follows:

  • Transfers to Japan: We rely on the UK International Data Transfer Agreement (IDTA), issued by the UK ICO, to lawfully transfer personal data from the UK to our Japanese entity. A copy of our IDTA framework is available on request from cwtros@gmail.com.
  • Transfers to the US (Supabase, Stripe, Vercel): We rely on the UK Addendum to the EU Standard Contractual Clauses(or the IDTA where applicable) and on our sub-processors' own compliance with UK GDPR transfer requirements (including their signed Data Processing Agreements).

7. Data Retention

Data TypeRetention Period
Account and profile dataUntil you delete your account (subject to legal retention below)
ListingsUntil deleted or account deletion
Booking records3 years after completion
Transaction / payment records7 years (legal/tax requirements)
MessagesWhile accounts exist; deleted with account or as required by law
Reviews and ratingsUntil account deletion (then anonymised)
Notification history12 months
Technical / analytics data12 months

8. Your Rights

8.1 All Users

Regardless of location, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and associated data
  • Withdraw consent for optional processing
  • Object to processing based on legitimate interests

8.2 Additional Rights (UK GDPR)

You also have the right to data portability, restriction of processing, and to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk.

8.3 How to Exercise Your Rights

Contact us at cwtros@gmail.com. We respond within 30 days.

8.4 Account Deletion

You can delete your account through Settings. The Service first attempts to cancel open bookings and release or refund payments via Stripe, then removes your auth account and cascaded profile data from our database. Some records (for example reviews or bookkeeping) may be retained in anonymised or aggregate form, or longer where the law requires. Stripe may retain payment records under its own policies.

9. Data Security

  • All data is encrypted in transit using TLS 1.2+ (HTTPS)
  • Passwords are hashed via Supabase Auth (bcrypt)
  • Database access controlled via Supabase Row Level Security (RLS)
  • Payment card data handled entirely by Stripe (PCI DSS Level 1)
  • Production access limited to authorised personnel only

If you discover a vulnerability, report it to cwtros@gmail.com.

No system is perfectly secure. We cannot guarantee that unauthorised access, hacking, data loss, or other breaches will never occur. You use the Service understanding that residual risk remains.

9.1 Data Breach Response — UK GDPR

Under UK GDPR Article 33, we are required to notify the UK Information Commissioner's Office (ICO) of a personal data breach within 72 hoursof becoming aware of it, where the breach is likely to result in a risk to individuals' rights and freedoms (for example, exposure of payment data, personal messages, or identity information).

Under UK GDPR Article 34, if the breach is likely to result in a high risk to individuals, we will also notify affected users directly without undue delay.

We have internal procedures in place to identify, assess, and respond to data breaches. If you believe your data has been compromised, contact cwtros@gmail.com immediately. You also have the right to report a concern directly to the ICO at ico.org.uk/make-a-complaint.

10. Children's Privacy

UniSwipe is for users aged 18+. We do not knowingly collect data from anyone under 18. If we learn we have, we will delete it promptly.

11. Changes to This Policy

We may update this policy. Material changes will be communicated via email or in-app notification at least 14 days before taking effect.

12. Contact Us

Email: cwtros@gmail.com
Address: Serendipity Inc., Nishi-Shinjuku Mizuma Building 6F, 3-3-13 Nishi-Shinjuku, Shinjuku-ku, Tokyo 160-0023, Japan


This Privacy Policy was last reviewed on 13 April 2026.