Privacy at SwayRadar
Privacy notice
Last updated: 24 August 2026
This notice explains how SwayRadar handles information when you visit the service, submit a hotel website, review an extracted profile, or request an audit.
Who is responsible
Cyril Gabathuler
Riedmühlestrasse 16a
8306 Brüttisellen
Switzerland
privacy@swayradar.com
Information we process
- Request and security data, such as IP address, request time, URL, browser or device information, referrer, and security signals processed by Cloudflare.
- The hotel website URL you submit, the selected interface language, and the public audit token stored only as a cryptographic hash.
- The contact email you provide for audit status, report delivery, and service-related follow-up about that audit. It is not enrolled in marketing by submitting an audit.
- If you explicitly select the Founding Hotel interest button, we store that request with the audit and use its contact email to follow up about that offer. This does not enroll you in unrelated marketing.
- If paid Checkout is enabled and you subscribe, we process the selected plan, Stripe customer, Checkout and subscription identifiers, status, billing period, and a webhook ledger. Stripe processes the audit contact email, hotel name, billing address, optional tax identifier, and payment details. SwayRadar never receives your full card number.
- Public hotel-page content used to extract business facts, including source URLs, page titles, timestamps, content hashes, short excerpts, normalized page-language evidence, and public links between language versions. Public pages can incidentally contain names or business contact details.
- Hotel facts you confirm or correct, competitor and question-relevance responses, action usefulness and completion events, and an optional public link showing where an action was implemented. Responses submitted through an audit report link remain pending until hotel ownership is verified.
- Product feedback you choose to send: a category, an optional note, language, the type of page and section, and a broad device category. Private report tokens are removed from the stored page path. When feedback is sent from a report, it can be linked to that audit without storing the token itself.
- For founder-reviewed OpenAI and Gemini pilots: the same 30 frozen German or English guest questions, generated answers, citations, model/request metadata, timing, and token usage. The audit contact email, access token, completion URL, and correction text are not sent to either provider.
- For named-hotel fact checks, SwayRadar may retrieve up to two cited public third-party pages per answer. It stores only an exact relevant passage together with the final URL, retrieval time, and content hash. This check does not affect the Sway Score.
- For external hotel profiles found in named-hotel answers, SwayRadar may check up to five public pages per scan. It stores the source and final URL, page title, retrieval time, content hash, check state, and normalized positive topic signals, but not the page body. These checks do not change verified hotel facts or the Sway Score.
- When you mark a pilot action complete: only the affected frozen questions are measured again with OpenAI, and the before/after recommendation counts are stored. The completion URL and your report responses are not sent to OpenAI.
Purposes and legal grounds
- Provide the audit you request and take steps toward offering the service (GDPR Article 6(1)(b)).
- Send audit status, deliver the report, and answer or follow up on service questions connected to that audit (GDPR Article 6(1)(b)).
- Respond when you explicitly ask to be contacted about the Founding Hotel offer (steps requested before a possible contract under GDPR Article 6(1)(b)).
- Create and administer a requested paid subscription, invoices, payment status, and cancellation (contract performance under GDPR Article 6(1)(b), plus legal obligations under Article 6(1)(c) where applicable).
- Operate, secure, troubleshoot, and prevent misuse of the service (legitimate interests under GDPR Article 6(1)(f)).
- Understand where the service is unclear, wrong, incomplete, or could be improved, using feedback you choose to submit (legitimate interests under GDPR Article 6(1)(f)).
- Create and explain hotel recommendation benchmarks using public business information and hotel-confirmed facts (legitimate interests under GDPR Article 6(1)(f)).
- Run explicitly requested, one-time OpenAI and Gemini pilot measurements and retain their evidence for review (steps requested to provide the service under GDPR Article 6(1)(b)).
- Meet legal obligations where applicable (GDPR Article 6(1)(c)).
Where information comes from
Information comes from you, from the public hotel website you ask us to review, from public third-party pages cited in a measured answer, from OpenAI and Gemini responses in founder-reviewed pilots, from OpenAI action verifications, and from technical request data generated when the service is used. Automatic public execution and the other two AI providers remain disabled.
Processors, recipients, and locations
Cloudflare provides the edge network, Worker runtime, security, observability, workflow orchestration, and D1 database. The D1 primary database currently runs in Western Europe without a jurisdiction restriction. Cloudflare may process limited request metadata in Europe, the United States, and other service locations under its data-processing terms and applicable transfer safeguards. OpenAI provides the search-backed Responses API. Google provides the paid Gemini API with Google Search grounding for founder-approved measurements. Google states that paid-service prompts and responses are not used to improve its products. Google additionally states that grounded prompts, contextual information, and output are stored for 30 days to create grounded results and for debugging and testing. SwayRadar stores the grounded answer, returned Search suggestions, citations, model and request metadata, and normalized measurement evidence for the audit retention period. These providers may process questions and generated answers in their service locations under their applicable data terms and safeguards. Resend delivers transactional email. If paid Checkout is enabled, Stripe provides hosted payment, recurring billing, invoices, and the customer portal in its service locations under its data-processing terms and transfer safeguards. The controller receives a private copy of each customer email for pilot support and delivery oversight; these copies are not used for marketing. No analytics, advertising, or session-replay provider is currently integrated.
Retention
The contact email, unclaimed free-audit access, profile drafts, crawled page excerpts, linked OpenAI and Gemini pilot answers/evidence, OpenAI verification answers/evidence, pending hotel-review responses, action events, verification results, and email-delivery records expire 90 days after the latest profile activity and are purged daily. Protected operator sample audits use fixed fixture data and expire after 24 hours or are deleted earlier with the reset control. Unlinked product feedback is also purged after 90 days; feedback linked to an audit is removed with that audit. OpenAI states that API data is not used to train its models unless the customer opts in; default abuse-monitoring logs can retain prompts and responses for up to 30 days unless a different approved control applies. Normalized public hotel facts, source hashes, and benchmark definitions may be kept while needed to explain the audit, validate the product, or establish and defend legal claims; they are reviewed and can be deleted earlier on a valid request where no overriding duty or interest applies. Security and platform logs follow the configured Cloudflare service retention periods.
Your rights
Depending on the law that applies, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may also complain to your local EU/EEA supervisory authority or to the Swiss Federal Data Protection and Information Commissioner. Identity may need to be verified before a request is fulfilled.
Automated decisions
SwayRadar creates measurements and recommendations about hotels. It does not currently make solely automated decisions about individuals that produce legal or similarly significant effects.
Cookies and analytics
The current application does not set optional analytics or marketing cookies and does not use browser storage for tracking. The hidden operator sample area uses a strictly necessary, signed, HttpOnly session cookie for two hours. See the cookie notice for the live inventory and the rule for future optional technology.
Related information
Cookie noticeLegal noticeCloudflare privacy policyGemini API termsSwiss FDPIC