Privacy Policy
Operated by Southern Technology Partners LLC
Effective Date: August 26, 2026 Last Updated: August 26, 2026
1. Introduction
This Privacy Policy explains how Southern Technology Partners LLC (“STP,” “we,” “us”) collects, uses, shares, and protects information in connection with the Swivl application and related services (the “Service”). It applies to our subscribing customers and their authorized users, to individuals who book appointments through a Swivl-powered booking page or use the Swivl client portal, and to visitors of our websites, including swivl.app and app.swivl.app.
By using the Service, you acknowledge the practices described here. Capitalized terms not defined here have the meaning given in the Swivl Terms of Service.
2. Our Role: Controller vs. Processor
Swivl is software for appointment-based businesses — salons, barbershops, nail and lash studios, spas, and massage practices. Our role depends on the data:
As a processor / service provider. Most of the information in the Service — client records, appointments, service notes, photographs, sales and financial records, inventory, and similar content (collectively “Customer Data”) — is submitted by our subscribing customers (each, a “Customer Organization”) and processed by us on their behalf and under their instructions. For that Customer Data, the Customer Organization is the controller and is responsible for providing its own privacy notices to, and obtaining any required consents from, its staff and clients (each, an “End Client”). If you are an End Client, please contact the Customer Organization you booked with regarding its handling of your data; we will also assist, as described in §14.
As a controller. For information we collect about our direct relationship with a Customer Organization and its authorized users — account registration, billing, support, security, and website usage — STP acts as a controller, and this Policy governs.
Note on consumer-facing surfaces. Unlike a purely internal business tool, parts of the Service are used directly by End Clients: the public booking page, booking confirmation and reminder messages, and the client portal. We operate those surfaces on behalf of the Customer Organization, but their design, consent language, and security are ours, and this Policy describes them so End Clients can understand what happens to their information.
Third-party providers as independent parties. Certain providers integrated with the Service — including Stripe, Plaid, SurePayroll, and Telnyx — collect and process information under their own privacy policies as independent businesses, not merely as our subprocessors. Those practices are governed by their policies, not this one (see §§5, 6, 7, and 8).
3. Information We Collect
Account and registration data. Name, display name, business name, email address, phone number, role and employment type (owner, administrator, provider, employee, commission-based, booth renter), profile photograph, booking handle, and authentication credentials.
Business profile data. Business name and type, address, hours, time zone, logo and branding images, service catalog and pricing, and tax settings.
Customer Data processed on behalf of Customer Organizations. Records the Customer Organization and its users create or upload, including:
- client name, email address, phone number, mailing address, and (where recorded) date of birth;
- appointment history, cancellations and no-shows, visit and spend totals, referral source, tags, and preferences;
- service records that may be sensitive, including allergies, hair type, and chemical or color formula history, and free-text notes staff write about a visit (see §15);
- photographs, including inspiration photographs an End Client uploads while booking and reference or before/after photographs staff attach to a client record;
- waitlist entries, appointment messages, and consent records;
- sales transactions, tips, commissions, booth-rent agreements, inventory, purchase orders, vendors, expenses, receipt images, general-ledger entries, and bank-reconciliation records.
Financial account data (via Plaid). When a user connects a financial account, we receive bank account and transaction information through Plaid to support features such as transaction import and reconciliation. See §5.
Payment data (via Stripe). Payments are processed by Stripe. We do not collect or store full payment card numbers, magnetic-stripe data, or CVV codes; card data is captured by Stripe’s hardware and libraries and transmitted directly to Stripe. We may receive limited transaction metadata (for example, amount, status, card brand, last four digits, expiration date, and a token) to reflect payments, tips, and saved cards in the Service. See §6.
Payroll data (via SurePayroll). If you use the payroll functionality, payroll information — which may include employer and employee names, addresses, Social Security or taxpayer identification numbers, compensation and hours, bank account and routing numbers for direct deposit, and tax-withholding details — is collected and processed by SurePayroll to provide payroll services. See §7.
Taxpayer identification data held in the Service. Where a Customer Organization uses the 1099 features for booth renters or contractors, the Service collects legal name, address, and taxpayer identification number (TIN/SSN/EIN). TINs are stored encrypted and are decrypted server-side only to generate tax exports; the application displays only the last four digits.
Consent records. Whether an End Client agreed to transactional text messages, marketing text messages, and marketing email; when each consent was given; and the source of each consent (booking page, client portal, or staff entry).
Usage, device, and log data. IP address, browser and device type, user agent, operating system, pages and features used, timestamps, approximate location derived from IP, audit-log events, and diagnostic information. IP addresses are recorded on public booking uploads and rate-limiting records to prevent abuse.
Error and diagnostic data. Application errors, including route, message, and stack trace. Before an error is stored, an automated redaction pass strips email addresses, phone numbers, card-like digit sequences, tokens, API keys, and secret URL segments. Users on public pages see only an opaque reference code, never raw error text.
Communications. Records of support requests, emails and text messages sent through the Service (including a send log showing recipient, subject, timestamp, and delivery result), and browser push-notification subscriptions (endpoint, encryption keys, and user agent) where a user enables them.
Cookies and local storage. We use only what the Service needs to work. Swivl does not run advertising, cross-site tracking, or third-party analytics pixels.
| Name / key | Type | Purpose |
|---|---|---|
swivl.theme |
Cookie, 1 year | Remembers light/dark mode so the page does not flash on load |
sidebar_state |
Cookie | Remembers whether the application sidebar is collapsed |
Session tokens (sb-*) |
Browser local storage | Keeps you signed in; staff and client-portal sessions are stored separately |
| Form drafts and UI preferences | Browser local storage | Prevents work loss and remembers view settings; treated as display-only cache and never used for access control |
Because these are strictly necessary or purely functional, we do not present a consent banner.
4. How We Use Information
We use information to:
provide, operate, maintain, secure, and improve the Service;
create, confirm, remind about, reschedule, and cancel appointments, and manage waitlists;
authenticate users and protect against fraud, unauthorized access, and abuse, including rate limiting of booking verification, portal sign-in, and password reset;
process and reflect payments, deposits, no-show fees, tips, and refunds, and reconcile financial and bank transaction data;
enable and route you to payroll services provided by SurePayroll;
produce a Customer Organization’s own reports, including sales, inventory, commission, and 1099 exports;
read uploaded receipt photographs to suggest a vendor, date, total, and category (see §10);
send service, security, and transactional communications, and marketing communications only where the recipient has opted in (see §§8 and 9);
provide customer support and respond to requests;
monitor performance, debug, and develop new features;
maintain audit logs and records; and
comply with legal obligations and enforce our agreements.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use Customer Data to train external or third-party advertising or unrelated commercial models. We do not market to End Clients on our own behalf. We process Customer Data only to provide the Service and as instructed by the Customer Organization, except as required by law.
5. Bank Account Data and Plaid
The Service uses Plaid Inc. (“Plaid”) to enable users to connect financial accounts and to retrieve bank account and transaction data used for features such as transaction import and reconciliation.
When you connect an account, you enter your credentials and authorize the connection through Plaid’s interface. By using these features, you grant Plaid the right to access, transmit, store, and use your financial data in accordance with the Plaid End User Privacy Policy, available at https://plaid.com/legal/#end-user-privacy-policy, which is incorporated into this Policy by reference. We encourage you to review it to understand how Plaid collects and handles your data.
We use the financial data retrieved through Plaid only to provide the features you request within the Service (such as importing and reconciling transactions) and as described in this Policy. We do not use it for advertising and do not sell it.
You represent that you have the authority to connect each account and to authorize this access, and that you have obtained any consents required from other account holders. You may disconnect a linked account at any time through the Service or via Plaid; disconnecting stops future data retrieval but does not delete data already imported into your records.
We retain bank transaction data imported into the Service as part of your financial records, subject to §12 (Retention) and your instructions.
6. Payments and Stripe
Payment processing is provided by Stripe, Inc. (“Stripe”) using Stripe Connect, under which each Customer Organization operates as a connected account. This includes in-person payments through Stripe Terminal card readers. When you make or receive a payment through the Service, your payment information is collected and processed by Stripe under the Stripe Privacy Policy and the Stripe Services Agreement. We do not store full card numbers. Stripe may use payment and device information for fraud prevention, identity verification, and connected-account onboarding as described in its policies. We receive limited transaction information from Stripe to record and display payment status, tips, deposits, and saved cards within the Service.
Saved cards (“card on file”) are stored as Stripe payment-method tokens tied to a Customer Organization’s client record and can be removed at any time.
7. Payroll and SurePayroll
Payroll functionality in the Service is powered by SurePayroll, Inc., a Paychex company (“SurePayroll”), and is offered on a white-labeled and/or referral basis, which may include Swivl branding or a co-branded or affiliate link.
SurePayroll processes your payroll data. When you use payroll, the payroll information described in §3 (including Social Security/taxpayer identification numbers, wages, and bank details) is collected and processed by SurePayroll to calculate wages, process direct deposits, and calculate, deposit, and file payroll taxes. SurePayroll handles this data under its own Terms of Use and Privacy Policy (available at SurePayroll’s Privacy Policy (https://www.surepayroll.com/legal/privacy-policy) and Terms of Use (https://www.surepayroll.com/legal/terms-of-use)), which are incorporated by reference. We encourage you to review them.
STP’s role is limited. SurePayroll is an independent provider, not merely our subprocessor, and we do not control its data practices. To the extent STP receives or transmits any payroll data to enable the service — for example, to pre-fill or synchronize hours, tips, commissions, or booth-rent figures calculated in the Service — we use it only for that purpose and protect it consistent with §13 (Security). We do not use payroll data for advertising and do not sell it.
Requests may come to us first. Because payroll may be presented under Swivl branding, you or your employees may direct privacy or consumer-rights requests relating to payroll to us first. We will verify such requests and coordinate with SurePayroll to help fulfill them, and we may direct you to submit certain requests to SurePayroll directly.
Affiliate/compensation disclosure. STP may receive compensation (such as referral awards, reseller revenue, or commissions) when you enroll in or use SurePayroll through the Service.
8. Text Messaging (SMS) and Telnyx
Text messaging is a core function of the Service and is governed by federal law (including the Telephone Consumer Protection Act), state analogues, and carrier and CTIA messaging rules. Messages are delivered by Telnyx LLC (“Telnyx”) from a verified toll-free number operated by STP on behalf of the sending business, or from the Customer Organization’s own Telnyx configuration where it has one.
Transactional messages (booking confirmations, reminders, schedule changes, verification codes, waitlist openings) are sent only to an End Client who has affirmatively consented — by checking the transactional-consent box on a booking page or in the client portal, or by giving consent to staff, which the Service records with a timestamp and source. Staff cannot save a phone number in Swivl without recording that consent.
Marketing messages require a separate, additional opt-in that is unchecked by default. Consenting to transactional messages never enrolls anyone in marketing messages.
Every message identifies the sending business and includes opt-out language. Reply STOP to opt out; reply HELP for help. Message frequency varies. Message and data rates may apply. Consent is not a condition of purchase.
Opting out of marketing messages does not stop transactional messages about an appointment you booked, and opting out with one business does not affect another.
No mobile information — including phone numbers, opt-in records, and consent data — is sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes. Phone numbers are disclosed only to Telnyx and the delivering carriers, solely to transmit the message the sending business initiated.
To opt out, reply STOP to any message, update your preferences in the client portal, or contact the business directly.
9. Email and Push Notifications
Transactional email (confirmations, receipts, verification and password-reset links, staff invitations) is sent to the address supplied at booking or sign-up. Email is delivered through SMTP credentials the Customer Organization configures, or through STP’s platform sender where the Customer Organization has not configured its own.
Marketing email is sent only with consent and always includes an unsubscribe link. Unsubscribe requests are recorded in a suppression list that persists even if a contact list is re-imported.
We maintain a send log (recipient, subject, timestamp, delivery result) so Customer Organizations can troubleshoot delivery.
Push notifications are opt-in per device and can be revoked at any time in your browser settings.
10. Automated Receipt Scanning
The Service includes one feature that sends data to a third-party model provider. When a user photographs an expense receipt, the image is uploaded to private storage and also sent to a Google Gemini model through our AI gateway, which returns a suggested vendor, date, total, tax, and category. A human always confirms the result before it is saved. Low-confidence results are flagged, and manual entry is always available.
Receipt images may contain personal information if a user photographs something other than a business receipt. Users should not upload documents containing client health information, government identifiers, or full payment card numbers.
We do not use an AI model to read client notes, photographs, or messages, and no Swivl customer data is used to train third-party models.
11. How We Share Information
We share information only as described here:
Service providers / subprocessors. With vendors that help us operate the Service, under contracts limiting their use of the information. These currently include: Supabase (cloud hosting, database, authentication, and file storage), Cloudflare (hosting, edge delivery, and DDoS protection), Telnyx (SMS messaging), our email-delivery provider or the Customer Organization’s own SMTP provider, Inngest (background job processing), and our AI gateway provider (receipt scanning). We update this list as our service providers change.
Independent integrated providers. With Stripe (payments), Plaid (financial-account connectivity), and SurePayroll (payroll), which process information as independent businesses under their own policies as described in §§5–7.
Customer Organizations. Where you are an End Client or an authorized user, information is accessible to the Customer Organization that controls the account, according to the permissions that organization configures. Customer Organizations are isolated from one another at the database level; one Customer Organization cannot access another’s data.
Legal and safety. When required by law, subpoena, or legal process, or to protect the rights, safety, security, or property of STP, our users, or others, or to investigate fraud or security incidents.
Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
With your direction or consent. As you otherwise authorize.
We do not sell personal information, share it for cross-context behavioral advertising, or provide it to data brokers or advertising networks.
12. Data Retention
We retain personal information for as long as needed to provide the Service, maintain your records, comply with legal, tax, accounting, and audit obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to the Customer Organization’s instructions and our Terms of Service. Payroll data retained by SurePayroll is subject to SurePayroll’s policies. In particular:
Customer Organization account data is retained while the account is active.
Client records are retained until the Customer Organization deletes them or closes its account. Some deletions are recorded as soft deletions first — hidden from use but recoverable — and then purged.
Financial and tax records, including sales, ledger entries, imported bank transactions, commission settlements, and 1099 data, are retained as long as the Customer Organization needs them for its own tax and accounting obligations — typically at least seven years — even where a related client record has been removed.
Verification tokens, pending bookings, and signed file links expire automatically, generally within hours.
Error logs and audit logs are retained for 12 months for security and troubleshooting.
When a Customer Organization closes its account, we delete or de-identify its data within 90 days, subject to any legal hold or retention requirement.
13. Data Security
We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect personal information, including:
encryption in transit (TLS) and encryption at rest by our infrastructure providers;
tenant isolation enforced in the database itself through row-level security rather than application code alone; the anonymous database role has no direct table privileges, and every public surface is served through a controlled server function;
encryption of taxpayer identification numbers held in the Service, which are decrypted server-side only for tax exports;
storage of private files (receipts, notes attachments, and private business content) in private buckets served only through short-lived signed links;
separate authentication sessions for the staff application and the client portal, so a client login cannot reach staff data;
redaction of email addresses, phone numbers, card-like digits, tokens, and keys from error text before it is stored or displayed;
rate limiting on booking verification, portal sign-in, and password reset; and
role-based permissions and audit logging of business and financial changes.
However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and for configuring access within the Service appropriately. If we become aware of a security incident affecting your information, we will notify you and applicable authorities as required by law. Where a Customer Organization is the controller of affected data, that organization is responsible for any notification obligation the law places on it.
14. Your Rights and Choices
Depending on your location and your relationship with us, you may have rights to:
access the personal information we hold about you;
correct inaccurate information;
delete your information;
port a copy of certain information;
limit the use of sensitive personal information;
opt out of certain processing; and
withdraw consent where processing is based on consent.
If you are an End Client, the Customer Organization you booked with controls your record and can view, correct, or delete it directly in the Service — contacting that business is the fastest route. If you contact us instead, we will verify your request, forward it to the relevant Customer Organization, and assist it in fulfilling the request as its processor.
If you are a Customer Organization or an authorized user, contact us at admin@southerntechpartners.net. We will verify your request and respond within the timeframes required by applicable law (generally 45 days under U.S. state privacy laws, extendable once where permitted). We verify identity by confirming control of the email address or phone number on the record, and we accept requests from an authorized agent with written proof of authorization.
You may also at any time reply STOP to any text message, use the unsubscribe link in any marketing email, update notification preferences in the client portal, or revoke push notifications in your browser settings.
State privacy rights (U.S.). Residents of certain states (for example, California under the CCPA/CPRA, and other states with comprehensive privacy laws) may have additional rights, including the right to know the categories of personal information collected and the purposes of use, the right to delete, the right to correct, the right to limit the use of sensitive personal information, and the right to opt out of “sale” or “sharing” (we do neither) and of certain profiling. We do not discriminate against you for exercising these rights. If we decline a request, you may appeal by replying to our decision, and you may contact your state attorney general if you remain unsatisfied.
Financial-data rights. For data accessed through Plaid, you may also exercise rights directly with Plaid as described in the Plaid End User Privacy Policy, and you may disconnect linked accounts at any time. For payroll data, you may exercise rights with SurePayroll as described in its privacy policy, and we will coordinate as described in §7.
15. Sensitive Client Information
Some information the Service stores about End Clients may qualify as sensitive personal information under state privacy laws, including allergies and other health-related notes, date of birth, precise service records such as chemical formula history, and photographs.
We use this information only to provide the Service and to enable the Customer Organization to serve its clients. We do not use it to infer characteristics about any individual, and we never use it for advertising.
Customer Organizations are responsible for limiting what they record. Staff should record only what the service requires, should not enter payment card numbers or government identification numbers in free-text fields, and should obtain any consent their own profession or jurisdiction requires before recording health-related information or photographing a client.
Swivl is not a HIPAA-covered entity and the Service is not designed to store protected health information as defined by HIPAA. Do not use the Service as a medical record system.
16. Children’s Privacy
The Service is intended for business use and for adults booking appointments, and is not directed to children under 13 (or the minimum age in your jurisdiction). Accounts may only be created by individuals 18 or older. A parent or guardian may book an appointment on behalf of a minor; in that case the parent or guardian is responsible for the information provided, and the Customer Organization should collect no more information about the minor than the service requires. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us at admin@southerntechpartners.net and we will take appropriate action.
17. Data Location and International Users
The Service is operated in the United States, and information is processed and stored in the United States. The Service is offered to businesses and clients in the United States. If you access the Service from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your jurisdiction.
18. Third-Party Services and Links
The Service integrates with and may link to third-party services (including Stripe, Plaid, SurePayroll, and Telnyx). Their handling of your information is governed by their own privacy policies, not this one. We encourage you to review them. If a Customer Organization connects its own provider accounts (for example, its own SMTP or Telnyx account), that organization’s relationship with those providers is governed by its agreements with them.
19. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by updating the “Last Updated” date or notifying you in the Service). Your continued use of the Service after the changes take effect constitutes acknowledgment of the updated Policy.
20. Contact Us
Questions or requests regarding this Policy or your information:
Southern Technology Partners LLC 15 Latimer Street, Hazlehurst, GA 31539 admin@southerntechpartners.net 912-209-4804 southerntechpartners.net

