Swift legal
Privacy Policy
- Effective
- Version
- 2026-09-24
This policy explains what personal data Swift collects, why, on what legal basis, who it is shared with, how long it is kept, and the rights you have — written to meet Guyana's Data Protection Act 2023. We collect the minimum needed to run a delivery, ride and marketplace platform, and we never sell your data.
Who is responsible (data controller)
Swift is the data controller for the personal data described here, operated in and from Guyana. Our full registered business name and postal address are available on request from the contact below. For anything about your privacy — access, correction, deletion or a complaint — email privacy@swiftgy.com. This inbox reaches us even if you can no longer sign in to the app, so you are never locked out of your rights. This policy covers customers, Partners (businesses and movers), advertiser contacts, and visitors to our websites.
1. What we collect
- Account: your phone number (verified by SMS code), name, and optional email.
- A registration selfie to deter account fraud; it becomes your in-app photo.
- Orders, rides and bookings: what you ordered, addresses you save or enter, delivery instructions, and the trip/delivery history tied to your account.
- Location: your device location while you use the app to set pickup/delivery points. For movers, live location while online — that is what powers dispatch and customer tracking. Background collection for movers happens only after a separate, explicit in-app consent, and stops when you go offline.
- Verification documents (partners and, where required, customers): government ID and, for movers, licence, insurance and related documents. These are stored privately; in the app they are viewable only by our verification team through short-lived signed links, each access logged. To confirm a document and selfie match, they are also processed by our identity-verification provider (see the provider list below).
- Messages, ratings and reports: order-scoped chat messages, the ratings and review tags you give and receive, reports you file, and your block list.
- Emergency contacts: if you add one, their name and phone number. We text them a verification code immediately, use the number only for your safety alerts, and never for marketing. If someone added you and you want the number removed, email privacy@swiftgy.com.
- Support and consent records: your Help & Support tickets, and the consent ledger — a tamper-evident record of each policy version you agreed to, when, and on what surface. At consent we may also store a keyed cryptographic digest of your network address as evidence of the event; the address itself cannot be read back from it.
- Device and diagnostics: a push-notification token, app version, and crash/error reports.
- Partner records (partners only): subscription and payment-confirmation history for the weekly fee, earnings summaries, and operational quality metrics.
2. What we do NOT collect
Swift never holds your order money, so we do not collect card numbers or wallet credentials. If you pay a business through MMG, that payment happens in MMG's own flow under MMG's terms — we only record that the business confirmed receiving it. Our websites and app carry no third-party advertising or cross-site tracking pixels.
3. Why we use it — and the legal bases
Under the Data Protection Act 2023, each use of your data rests on a legal basis:
- To perform our contract with you: running your account; transmitting orders; matching deliveries and rides; live tracking; receipts; order-scoped chat; Partner subscription administration.
- To meet legal obligations: identity and document verification where required; keeping transaction, consent and audit records; responding to lawful demands.
- For legitimate interests, balanced against your rights: preventing fraud and abuse (strikes, collusion checks, GPS-plausibility and account-security signals), keeping the platform safe and available, and producing aggregated, de-identified statistics (e.g. orders per day) that carry no personal data. You may object — see section 9.
- With your consent, separately asked and freely refusable: marketing messages; background location for movers; the optional email on your profile. Consent can be withdrawn at any time without affecting the service.
4. Automated systems and human review
Swift uses automated systems to match orders to movers, estimate times, and flag possible fraud or account-takeover risk. Flags lead to review, not to automatic punishment: no decision that produces a legal or similarly significant effect on you — losing your account, a penalty, a withheld payment confirmation — is taken by a machine alone; a human reviews the record first, and security holds (such as a staged change to where a Partner is paid) are announced to the account owner with a way to cancel them. You can contest any such decision through Help & Support.
5. Sharing
A business sees what it needs to fulfil your order (items, first name, delivery address). A mover sees pickup/drop-off details and your first name. Movers and customers see each other's first names, photos and ratings. Your verified emergency contacts receive your live location if you raise an SOS. We share data with authorities only where the law requires it, and we document every such demand.
Technical service providers (processors): to run Swift we use a small number of providers, each bound to process only what its function needs, on our instructions: Twilio (delivers your SMS verification codes — your phone number), Expo (delivers push notifications — a device token), an identity-verification provider — Didit or ID Analyzer — (receives the verification document and matching selfie to perform the identity check), Sentry (crash and error reports; we attach route templates rather than full URLs, drop request query strings, headers, cookies and bodies, and run an automated filter that reduces tokens and signed links across the report — a report is diagnostic context, not your account records), encrypted cloud object storage (verification documents and images), and Google Maps (addresses and coordinates for map display and travel estimates). Some of these providers process data on infrastructure outside Guyana; where that happens, the transfer is made under the Act's conditions with contractual safeguards and the minimisation described here.
AI processing: Swift sends nothing you write to an artificial-intelligence service. Search terms, store menus and your messages are handled by our own software and by people; no model reads them, and none is used to decide anything about you. There is one exception, and it is not text you write: the identity-verification provider named above (Didit or ID Analyzer) runs automated document-reading and face-matching checks on the verification document and selfie you submit, because that is what an identity check is. That check can accept the document, reject it, or refer it to a person for review. If it is rejected you are told and can submit it again, or raise it through Help & Support. Swift sends no other document, message or account record to any automated-analysis service.
Business changes: if Swift's business is transferred to a successor, your data moves with it under this policy's protections, and you are told before any materially different use begins.
6. Retention and deletion
We keep personal data only as long as its purpose or a legal duty requires. Verification documents are purged on a schedule after they stop being needed, with the purge itself logged; purged documents are irrecoverable. Order, ride and settlement history is retained for the period required for disputes, guarantees, tax and legal obligations, and order-scoped chat is retained with its order's record. The consent ledger is retained as legal evidence of what was agreed — it is append-only by design and is kept even after account deletion, holding only what it must. You can delete your account from inside the app — Profile → Personal data → Delete my account — which permanently destroys your documents, revokes every signed-in session, and deletes or de-identifies personal data not subject to a legal retention duty. Business, driver and advertiser accounts are closed through Help & Support instead, so outstanding listings and settlement records are handled correctly first.
7. Security
Data in transit is encrypted (the app pins Swift's certificates), access to production data is restricted and audit-logged, verification documents are encrypted at rest and readable only through short-lived signed links, security-sensitive account changes require step-up confirmation, and administrative actions on your account leave a permanent trail. No system is perfectly secure; if a breach creates a risk to you, we will notify the Data Protection Commissioner and affected users as the Act requires.
8. Children
Swift is for adults: you must be 18 to hold an account, and we do not knowingly process children's data. Our published Child Safety Standards state our zero-tolerance rules and the dedicated reporting channel; anything reported there is prioritised, removed, and reported to the authorities as the law requires.
9. Your rights under the Data Protection Act 2023
You have the right to: access the personal data we hold about you; have it corrected; request its deletion; restrict processing; object to processing based on legitimate interests and to any direct marketing; withdraw a consent at any time; receive a copy of your data in a portable form (the app's "Download my data" does this instantly); and not be subject to a solely automated decision with legal or similarly significant effect — section 4 describes how we already work that way. Exercise any of these by email to privacy@swiftgy.com or through Help & Support; we respond within the timeframes the Act sets, and identity is verified before data is released. Each right is subject to the legal retention duties described above, and exercising them never costs you the service. If you believe we have mishandled your data, you have the right to complain to the Data Protection Commissioner of Guyana.
10. Changes to this policy
Material changes are announced in the app before they take effect, and where the law requires fresh consent we ask for it. Every version of this policy is recorded with its date and an integrity hash, so the exact words that applied to you at any time are provable.