Privacy Policy

Spontu (formerly UniSwipe) — Student Noticeboard

Last Updated: 18 August 2026 · Effective Date: 18 August 2026

Operated by: Serendipity Inc., registered in Japan

1. Introduction

Spontu (formerly UniSwipe) ("we," "us," "our") is a student marketplace platform developed and operated by Serendipity Inc., a company incorporated in Japan. The Service is available as a web application and mobile application (collectively, the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and your rights regarding your data.

We are committed to protecting your privacy and complying with applicable data protection law. The Service is available worldwide, so more than one framework may apply to you at once — depending on where you live, where we are established, and where our infrastructure sits. Those that may apply include:

  • United Kingdom: UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
  • European Economic Area: EU General Data Protection Regulation (Regulation (EU) 2016/679)
  • Japan: Act on the Protection of Personal Information (APPI), which applies to us as a Japanese company wherever our users are
  • Other countries: including, as applicable, the California Consumer Privacy Act as amended (CCPA/CPRA) and other US state privacy laws, Canada's PIPEDA, Brazil's LGPD, Australia's Privacy Act 1988, South Korea's PIPA, and comparable laws elsewhere

One standard, applied to everyone

Rather than promise different things to different people, we apply one set of practices to every user worldwide. The disclosures, retention limits, security measures, and rights described in this policy are available to you regardless of which country you are in and regardless of which of the laws above happens to reach you. Where your local law gives you more than what is described here, you get more — Section 8 lists the region-specific additions we are aware of.

By creating an account or using the Service, you agree to the collection and use of your data as described in this policy. If you do not agree, please do not use the Service.

This policy is provided for transparency. It is not legal advice. If you need advice about your specific situation (for example tax, immigration, or regulatory compliance), consult a qualified professional.

2. Data Controller

The data controller responsible for your personal data is:

Serendipity Inc.
Nishi-Shinjuku Mizuma Building 6F, 3-3-13 Nishi-Shinjuku, Shinjuku-ku, Tokyo 160-0023, Japan
Email: cwtros@gmail.com

UK GDPR Article 27 Representative

As we are not established in the United Kingdom but process personal data of UK residents, we have appointed a representative in the UK in accordance with Article 27 of the UK General Data Protection Regulation (UK GDPR).

UK residents may contact our representative for any matters relating to the processing of their personal data, including Subject Access Requests and other data subject rights under UK GDPR:

Data Protection Representative (UK) Limited (trading as DataRep)
107–111 Fleet Street, London, EC4A 2AB, United Kingdom
Email: datarequest@datarep.com (quote “Spontu (formerly UniSwipe)” in the subject line)
Online form: www.datarep.com/data-request

When contacting by post, please address your letter to “DataRep” (not “Spontu (formerly UniSwipe)”) and refer clearly to Spontu (formerly UniSwipe) in your correspondence. DataRep acts as our representative point of contact and does not have independent decision-making authority over data processing activities.

Contacting us from outside the UK

If you are anywhere other than the United Kingdom, contact us directly at cwtros@gmail.com or at the postal address in Section 2 for any matter concerning your personal data, including a request to exercise the rights in Section 8.

We handle those requests on the same terms and to the same timescales for everyone, wherever you live — see Section 8.4 for how that works in practice. Contacting us is never a precondition to complaining about us: you can go straight to your own supervisory authority at any time, and Section 8.2 lists where to find yours.

3. Data We Collect

3.1 Account & Profile Data

When you create an account, we collect:

DataPurpose
Email addressAccount creation, sign-in links, and login via Supabase Auth (any reachable email you choose; we do not require a specific school domain)
OAuth profile data (Google / Apple)Optional sign-in: name and email supplied by the provider to Supabase Auth per their policies
Full nameDisplay on your profile and listings
Profile photoDisplay on your profile, listings, and messages
Institution name and type (e.g. university or school)Profile trust signal and feed filters (e.g. same institution)
Course / programme of studyDisplay on your profile for trust and context
Year of studyDisplay on your profile
AgeCollected at signup from individual accounts to confirm eligibility (18+). Organisation accounts are not asked for one.
Phone number (optional)Stored on your profile if you provide it; visibility controlled in Settings
Bio and languages (optional)Display on your profile
Notification preferencesIn-app / email-style notification categories (bookings, messages, etc.)
Password (hashed)Email/password sign-in only — stored by Supabase; we never see your plaintext password

3.2 Listing Data

When you create a listing, we collect:

DataPurpose
Listing title and descriptionDisplay in the marketplace feed
Listing type (Time, Experience, Item)Categorisation and filtering
Location label and meeting type (in person / online)Display to bookers; in-person meetups may include a text address
Map coordinates (optional, in-person listings)If you drop a pin on the map, we store latitude/longitude to show the listing on the map and compute distances when bookers opt in
Online meeting URL (optional)Shared when the listing is online
Event timezone and event date/time (experiences)Correct scheduling and display for bookers
Availability / calendar slots (time-based listings)Allow bookers to select a time
Listing images (if uploaded)Display in listing detail (including gallery photos)

3.3 Booking & Transaction Data

DataPurpose
Booking details (listing, date, time, participants)Manage the booking lifecycle
Booking status (pending, confirmed, checked-in, completed, cancelled, disputed, expired)Track booking progress and moderation states
Completion PIN and handover deadlineIn-person completion: Booker shows PIN; Provider enters it to mark the booking complete
Reviews (1–5 stars + text, booker → provider)Public reputation after completed bookings

3.4 Payment Data

We do not collect payment data. Spontu (formerly UniSwipe) takes no payments: every listing is free, no card is ever requested, and no payment processor is connected to the Service. We hold no card numbers, CVVs or bank details, and never have.

Historical records. Before payments were switched off, a limited number of bookings recorded a payment reference and an amount. Those rows still exist in our database and are retained under Section 7 for the periods required by law. You can request a copy or erasure of them under Section 8 on the same basis as any other data we hold about you.

3.5 Messaging Data

DataPurpose
Message content (text)In-app communication via Supabase Realtime
Message timestampsDisplay in chat interface
Read receiptsShow whether messages have been read

We store message content in our database for as long as the conversation and accounts exist, or as required for safety, disputes, or law. We do not sell message content to third parties. We may review message content if a user reports a safety concern, or if required by law.

Reports and blocks: If you submit a report (listing, message, or profile) or block another user, we store the identifiers, reasons, and details you provide, plus related metadata, for moderation and safety.

3.6 Device & Technical Data

DataPurpose
IP addressSecurity, fraud prevention, approximate location
Browser type and versionCompatibility and debugging
Device type (mobile/desktop)Responsive design and analytics
Operating systemCompatibility and debugging
Approximate location you opt into (browser geolocation)Only if you enable location for "nearest" sorting or the map view: coordinates may be sent with feed requests to sort or display distance—not stored as a permanent profile field
Pages visited and actions takenProduct improvement (limited to normal server logs where applicable)
Crash reports and error logsDebugging and stability (if you or we attach them to support)

3.7 Cookies & Local Storage

Cookies and similar technologies are separately regulated in many countries — by the Privacy and Electronic Communications Regulations 2003 (PECR) in the UK, the ePrivacy Directive as implemented across the EEA, and comparable rules elsewhere. The common shape of those rules is:

  • Essential cookies (session management, authentication): no consent required — these are necessary to provide the Service.
  • Analytics, marketing, or tracking cookies: require your explicit opt-in consent before being set. Pre-ticked boxes and "by continuing to browse you accept" are not valid consent under PECR, the ePrivacy Directive, or most equivalent regimes.
  • You can withdraw consent for non-essential cookies at any time as easily as you gave it.
TypePurposeRequired?
EssentialSupabase auth session cookies / storageYes — required to stay signed in

We currently use essential cookies only. We do not use advertising cookies, third-party tracking pixels, or behavioural profiling cookies. We do not share cookie data with advertisers. If we introduce non-essential cookies in future, we will implement a consent banner that blocks those cookies until you actively accept them, meeting the PECR and ePrivacy standard for every user regardless of country.

Because we set no advertising or analytics cookies and share no data with advertisers, we do not engage in "targeted advertising" or the "sale" or "sharing" of personal information as those terms are defined under US state privacy laws, and there is no such processing for you to opt out of.

3.8 Marketing Communications

We send service-related communications (for example booking confirmations, account security notices, and policy updates) which do not require your separate consent as they are part of the service you signed up for.

We do not send marketing emails or push notifications without your explicit, separate consent. We apply the following rules to every user, wherever you are, because they are the strictest of those we are subject to (UK GDPR and PECR, EU GDPR and ePrivacy, and Japan's Act on Regulation of Transmission of Specified Electronic Mail):

  • Marketing opt-in is always presented as a separate, unticked checkbox — it is never bundled with account registration or these Terms.
  • Pre-ticked consent boxes for marketing are not used.
  • You can withdraw consent for marketing communications at any time by emailing cwtros@gmail.com or using the unsubscribe link in any marketing email.

3.9 Notifications Data

DataPurpose
Device push token (if you enable push on a supported client)May be stored on your profile for future mobile push delivery
In-app notification recordsNotification inbox in the Service (bookings, messages, etc.)
Notification preferencesRespect your settings on your profile

3.10 Data We Do NOT Collect

  • We do not collect payment or card data of any kind. Spontu (formerly UniSwipe) takes no payments and has no payment processor connected to the Service.
  • We do not track your live location in the background. Optional exact coordinates may exist when you place a listing map pin, and optional one-off geolocation when you choose nearest sorting or the map view.
  • We do not collect biometric data.
  • We do not collect government-issued ID numbers, passport numbers, or national insurance / social security numbers.
  • We do not collect health data.
  • We do not record audio or video through the app.
  • We do not access your contacts, camera roll, or files without explicit action from you.

4. How We Use Your Data

To provide the Service: Create and manage your account, display your profile and listings, process bookings, enable in-app messaging, send notifications, and display reviews and ratings.

To maintain trust and safety: Use profile and institution information you provide, investigate reports, enforce our Terms and Community Guidelines, and prevent fraud.

To improve the Service: Analyse usage patterns, debug errors, and understand which features are most used.

To comply with legal obligations: Respond to lawful requests, comply with tax reporting obligations, and maintain legally required records.

Communications: We send service-related emails or in-app messages (for example account security, bookings, and policy updates). We do not use your data to run third-party behavioural advertising. If we introduce optional marketing messages where consent is required, we will describe that separately.

Automated decisions: We do not use solely automated processing to make decisions about you that produce legal or similarly significant effects without human involvement.

4.1 Legal bases (UK and EU GDPR)

We process personal data on the following legal bases under the UK GDPR and the EU GDPR. Where your own law uses a different framework (for example consent-led regimes such as Japan's APPI, or notice-and-opt-out regimes such as those in several US states), we still confine ourselves to the purposes listed below:

  • Performance of a contract (Article 6(1)(b)): to provide the Service you signed up for—account, listings, bookings, messaging, and related notifications.
  • Legitimate interests (Article 6(1)(f)): to keep the Service secure, prevent fraud and abuse, handle reports, improve and debug the product, and analyse usage in ways that do not override your rights; you may object where applicable.
  • Consent (Article 6(1)(a)): where we ask for optional consent (for example if we introduce optional marketing or non-essential cookies), you may withdraw it at any time.
  • Legal obligation (Article 6(1)(c)): where we must retain or disclose data for tax, accounting, or regulatory requirements.

5. Who We Share Your Data With

5.1 Other Spontu (formerly UniSwipe) Users

Your profile information and listing details are visible to other users. You control what you include in your profile and listings.

Because the Service is available worldwide, "other users" is not limited to your campus or your country: a profile, listing, or review is readable by signed-in Users anywhere, and once another User has seen something we cannot unsee it for them. Feed filters (such as same-institution) affect what is surfaced, not what is accessible. The one exception is blocking: a User you have blocked, or who has blocked you, cannot see your listings and you cannot see theirs. Do not put anything in a public field that you would not want read outside your own country.

5.2 Service Providers (Sub-processors)

ProviderData SharedPurposeLocation
SupabaseAll account, listing, booking, message dataDatabase, auth, realtimeUnited States (AWS)
VercelIP address, browser data, request logsWeb hosting (Next.js)United States (Edge)
GoogleAccount identifiers if you use "Sign in with Google"Authentication (via Supabase)United States / global
AppleAccount identifiers if you use "Sign in with Apple"Authentication (via Supabase)United States / global
Map tile providers (e.g. CARTO / OpenStreetMap)Standard HTTP requests when maps load (may include IP)Map images in the browserVaries (CDN)

5.3 Tax Authorities

We report nothing to any tax authority. Platform reporting regimes — UK platform reporting rules, EU DAC7, and the national regimes based on the OECD Model Reporting Rules for Digital Platforms — require the reporting of consideration paid to sellers. Spontu (formerly UniSwipe) pays Providers nothing and processes no payments, so no such report is due in any country. If paid listings are ever reintroduced, this section would change and we would notify affected users and provide a copy of any data reported where permitted by law.

5.4 Law Enforcement

We may disclose your data if required by law, regulation, legal process, or governmental request. We will attempt to notify you before disclosure unless prohibited by law.

5.5 We Do NOT Share Data With

  • Advertisers
  • Data brokers
  • Marketing companies

6. International Data Transfers

Your data leaves your country. This is true for every user, everywhere.

Spontu (formerly UniSwipe) runs on infrastructure in the United States and is operated from Japan. Wherever you live, using the Service means your personal data is transferred to, stored in, and processed in those countries — and, for content you post publicly, is visible to Users in other countries. If you are not comfortable with that, do not use the Service.

Specifically: our database is hosted by Supabase on AWS infrastructure in the United States. Our web hosting is provided by Vercel (United States, with edge nodes globally, which means a request from you may be served from a node in or near your own region). We are operated by Serendipity Inc., a Japanese entity.

6.1 If you are in the UK or the EEA

The UK and the EU each operate an "adequacy" framework that allows personal data to flow freely to countries whose data protection standards have been approved. The position differs between them, and it matters:

  • Transfers to Japan from the EEA: Japan has an EU adequacy decision (adopted 2019, extended in 2023), so transfers of your data from the EEA to our Japanese operations are lawful on that basis, subject to the supplementary rules that decision imposes.
  • Transfers to Japan from the UK: Japan is not currently on the UK's adequacy list, so these transfers need a separate safeguard. We rely on the UK International Data Transfer Agreement (IDTA), issued by the UK ICO, under UK GDPR Article 46. A copy of our IDTA framework is available on request from cwtros@gmail.com.
  • Transfers to the US (Supabase, Vercel): we rely on the EU Standard Contractual Clauses and the UK Addendum to them (or the IDTA where applicable), together with our sub-processors' own compliance with GDPR transfer requirements under their signed Data Processing Agreements.

6.2 If you are anywhere else

Many countries restrict cross-border transfers of personal data in their own way — through consent requirements, contractual safeguards, adequacy-style listings, or in some cases data localisation rules that we cannot satisfy. By creating an account you consent, to the extent your law treats consent as the basis for such a transfer, to your personal data being transferred to and processed in the United States and Japan as described above.

Whatever the mechanism, the substance is the same for everyone: the same sub-processors, under the same contractual terms, with the protections described in Section 9 and the rights described in Section 8. If your country requires personal data about its residents to remain within its borders, the Service cannot meet that requirement and you should not use it.

7. Data Retention

Data TypeRetention Period
Account and profile dataUntil you delete your account (subject to legal retention below)
ListingsUntil deleted or account deletion
Booking records3 years after completion
Transaction / payment records7 years (legal/tax requirements) — historical only; no new records are created
MessagesWhile accounts exist; deleted with account or as required by law
Reviews and ratingsUntil account deletion (then anonymised)
Notification history12 months
Technical / analytics data12 months

8. Your Rights

8.1 All Users, Everywhere

We extend the following rights to every user regardless of location, whether or not your national law requires it:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and associated data
  • Port your data — receive it in a structured, commonly used, machine-readable format
  • Restrict processing while a dispute about accuracy or lawfulness is resolved
  • Withdraw consent for optional processing
  • Object to processing based on legitimate interests
  • Be free from discrimination for exercising any of the above — we will not degrade or deny the Service because you made a request

8.2 Where to Complain

You can always complain to us first at cwtros@gmail.com. You are also entitled to complain to a regulator without going through us:

  • United Kingdom: the Information Commissioner's Office (ICO) at ico.org.uk. You may also contact our UK representative (Section 2A).
  • European Economic Area: the supervisory authority of your Member State — normally the one where you live, work, or where the issue arose. A directory is maintained by the European Data Protection Board at edpb.europa.eu.
  • Japan: the Personal Information Protection Commission (個人情報保護委員会).
  • Elsewhere: your national or state data protection authority, privacy commissioner, or equivalent body.

8.3 Additional Regional Rights

  • EEA and UK (GDPR): in addition to Section 8.1, you have the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects — we do not make such decisions (see Section 4).
  • California (CCPA/CPRA): you have the right to know the categories and specific pieces of personal information collected, the sources, and the purposes; to delete and to correct; to limit the use of sensitive personal information; and to opt out of "sale" or "sharing" and of targeted advertising. As set out in Section 3.7, we do not sell or share personal information and do not run targeted advertising, so there is nothing to opt out of. You may use an authorised agent to make a request. We do not knowingly process the data of anyone under 18 at all (Section 10).
  • Other US states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others as they take effect): equivalent access, correction, deletion, portability, and opt-out rights, exercised through the same contact route, plus the right to appeal a refused request — write to the same address and mark it "Appeal".
  • Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), South Korea (PIPA), and comparable regimes: the access, correction, deletion, portability, and objection rights in Section 8.1 cover the substance of what these laws grant; where yours goes further, tell us and we will honour it.

8.4 How to Exercise Your Rights

Contact us at cwtros@gmail.com. We respond within 30 days for everyone, wherever you live. Some laws allow longer (45 days in California, for example) and some allow an extension for complex requests; we aim for 30 days regardless and will tell you if we need more time and why. We may ask you to verify your identity before acting on a request, and we will not charge you for a first request.

8.5 Account Deletion

You can delete your account through Settings. The Service first attempts to cancel open bookings, then removes your auth account and cascaded profile data from our database. Some records (for example reviews or bookkeeping) may be retained in anonymised or aggregate form, or longer where the law requires.

If you no longer have the app installed, or cannot sign in, email us at cwtros@gmail.com from the address on your account and we will delete it for you. The same 30-day response time in 8.4 applies.

9. Data Security

  • All data is encrypted in transit using TLS 1.2+ (HTTPS)
  • Passwords are hashed via Supabase Auth (bcrypt)
  • Database access controlled via Supabase Row Level Security (RLS)
  • Production access limited to authorised personnel only

If you discover a vulnerability, report it to cwtros@gmail.com.

No system is perfectly secure. We cannot guarantee that unauthorised access, hacking, data loss, or other breaches will never occur. You use the Service understanding that residual risk remains.

9.1 Data Breach Response

Under Article 33 of the UK and EU GDPR, we must notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it, where the breach is likely to result in a risk to individuals' rights and freedoms (for example, exposure of personal messages or identity information). Under Article 34, where the breach is likely to result in a high risk to individuals, we must also notify affected users directly without undue delay.

Other countries impose their own deadlines and thresholds — Japan's APPI, Australia's Notifiable Data Breaches scheme, Brazil's LGPD, and US state breach-notification statutes among them, several of which are shorter or stricter in particular respects.

We apply the 72-hour standard and notify affected users directly for any breach likely to pose a high risk to them, wherever they live, and we notify each regulator we are answerable to within the deadline that regulator sets.

We have internal procedures in place to identify, assess, and respond to data breaches. If you believe your data has been compromised, contact cwtros@gmail.com immediately. You may also report a concern directly to your own regulator — see Section 8.2 for where to go; UK users can complain to the ICO at ico.org.uk/make-a-complaint.

10. Children's Privacy

Spontu (formerly UniSwipe) is for users aged 18 and over, or the age of majority where you live if that is higher. We do not knowingly collect data from anyone below that age. If we learn we have, we will delete it promptly.

Because the minimum age is 18 everywhere, we do not rely on the lower digital-consent ages that some countries permit (13 to 16 across the EEA, 13 under the US COPPA regime), and no child-directed processing takes place. If you are a parent or guardian who believes a person under 18 has created an account, contact cwtros@gmail.com and we will remove it.

11. Changes to This Policy

We may update this policy. Material changes will be communicated via email or in-app notification at least 14 days before taking effect.

12. Contact Us

Email: cwtros@gmail.com
Address: Serendipity Inc., Nishi-Shinjuku Mizuma Building 6F, 3-3-13 Nishi-Shinjuku, Shinjuku-ku, Tokyo 160-0023, Japan


This Privacy Policy was last reviewed on 18 August 2026.