SongSwipeSongSwıpe

Privacy Policy

Last updated: March 2026

1. Who We Are

SongSwipe ("we", "us", "our") is a personalised AI song creation service. We are the data controller responsible for your personal data. If you have any questions about this policy or your data, contact us at privacy@songswipe.io.

2. What Data We Collect

Account data: Your name and email address when you sign up (via email/password or Google OAuth).

Song personalisation data: Recipient names, special memories, occasion details, and any other information you provide to personalise your song.

Payment data: Payment transactions are processed by Stripe. We do not store your card number, expiry date, or CVV. We receive a transaction reference and payment status from Stripe.

Song audio files: The AI-generated songs created for you, stored securely so you can access and download them.

Technical data: Your browser type, IP address, and how you interact with our site (e.g. pages visited). This is collected automatically by our hosting provider.

3. Why We Collect It

To deliver our service: We need your personalisation details to generate your song, your email to create your account, and payment information to process your order.

To improve our service: We may analyse usage patterns (in aggregate, not individually) to make SongSwipe better.

To communicate with you: Order confirmations, gift delivery notifications, and essential service updates.

4. Legal Basis for Processing

Contract performance: Processing your data is necessary to fulfil your song order and deliver the service you paid for.

Legitimate interest: Improving our service, preventing fraud, and ensuring security.

Consent: We use analytics cookies only when you give explicit consent via our cookie banner. You can withdraw consent at any time in Cookie Settings.

Legal obligation: We retain payment records for 6 years as required by HMRC.

5. Who We Share Data With

We share your data only with the service providers necessary to run SongSwipe:

ProviderPurposeLocation
SupabaseDatabase, authenticationUS (EU SCCs)
StripePayment processingUS (EU SCCs)
ElevenLabsAI song generationUS (EU SCCs)
VercelWebsite hosting, anonymous page view analyticsUS (EU SCCs)
ResendTransactional emailsUS (EU SCCs)
PendoProduct analytics (with your consent)US (EU SCCs)

Where data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place (Standard Contractual Clauses). We do not sell your data to anyone.

6. How Long We Keep Your Data

Account data: Kept until you request deletion of your account.

Song audio files: Kept for 12 months after creation, then automatically deleted.

Song personalisation data: Kept for 12 months after creation alongside the song.

Payment records: Kept for 6 years as required by HMRC for tax purposes.

Technical logs: Kept for up to 30 days by our hosting provider.

7. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data (request a copy of what we hold)
  • Rectification of inaccurate data
  • Erasure of your data ("right to be forgotten")
  • Data portability (receive your data in a machine-readable format)
  • Object to processing based on legitimate interest
  • Restrict processing in certain circumstances

To exercise any of these rights, email us at privacy@songswipe.io. We will respond within 30 days.

If you are unsatisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO).

8. Cookies

We use cookies to operate and improve SongSwipe. Some are strictly necessary; others require your consent.

Strictly necessary cookies

Authentication cookie: Session token from Supabase to keep you signed in.

Stripe cookies: Set during checkout for secure payment processing.

Cookie consent preference (songswipe_analytics_consent): Stores your cookie choice so we do not ask repeatedly.

Analytics cookies (optional, requires your consent)

Pendo analytics: Helps us understand how visitors use SongSwipe so we can improve the product.

Tracks page views, feature usage, and user journeys.

Does NOT track personal conversations, song personalisation data, or payment details.

Data stored in US with Standard Contractual Clauses (EU GDPR compliant).

You can accept or decline analytics cookies when you first visit SongSwipe. You can change your preference at any time on our Cookie Settings page.

NamePurposeTypeExpiry
sb-*-auth-tokenAuthenticationStrictly necessarySession
songswipe_analytics_consentYour cookie preferenceStrictly necessary1 year
_pendo_*Product analyticsAnalytics (optional)Varies

For more about Pendo's data handling: Pendo Privacy Policy

9. Cookieless Analytics

In addition to the optional cookie-based analytics described above, we use Vercel Web Analytics to collect anonymous page view data. This operates without setting any cookies or storing any data on your device.

How it works: Each page view is counted using a daily-rotating hash that cannot be used to identify you as an individual. No personal data is collected, no tracking cookies are set, and no cross-site tracking occurs.

Referral sources: We also detect which website linked you to SongSwipe (e.g. a search engine or social media platform) using standard HTTP referrer headers sent by your browser. This is built into how the web works and does not involve cookies or additional tracking.

What we learn: Aggregate information such as which pages are most visited, how visitors arrive at our site, and general usage trends. This data is used solely to understand how the site is used and make improvements.

Legal basis: Because Vercel Web Analytics does not store any data on your device and cannot identify individuals, it does not require cookie consent under UK GDPR or the Privacy and Electronic Communications Regulations (PECR). We process this anonymous data under our legitimate interest in understanding and improving our service.

10. Children

SongSwipe is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make significant changes, we will notify you by email or by placing a notice on our website. The "last updated" date at the top of this page shows when the policy was last revised.

11. Contact Us

For any questions about this Privacy Policy or to exercise your data rights, contact us at: privacy@songswipe.io