SSwayRadarBack

Privacy at SwayRadar

Privacy notice

Last updated: 17 August 2026

This notice explains how SwayRadar handles information when you visit the service, submit a hotel website, review an extracted profile, or request an audit.

Who is responsible

Cyril Gabathuler
Riedmühlestrasse 16a
8306 Brüttisellen
Switzerland
privacy@swayradar.com

Information we process

  • Request and security data, such as IP address, request time, URL, browser or device information, referrer, and security signals processed by Cloudflare.
  • The hotel website URL you submit, the selected interface language, and the public audit token stored only as a cryptographic hash.
  • The contact email you provide for audit status, report delivery, and service-related follow-up about that audit. It is not enrolled in marketing by submitting an audit.
  • Public hotel-page content used to extract business facts, including source URLs, page titles, timestamps, content hashes, and short excerpts. Public pages can incidentally contain names or business contact details.
  • Hotel facts you confirm or correct, competitor and question-relevance responses, action usefulness and completion events, and an optional public link showing where an action was implemented. Responses submitted through an audit report link remain pending until hotel ownership is verified.
  • Product feedback you choose to send: a category, an optional note, language, the type of page and section, and a broad device category. Private report tokens are removed from the stored page path. When feedback is sent from a report, it can be linked to that audit without storing the token itself.
  • For controlled, exact-domain OpenAI and optional Gemini pilots: the same 30 frozen German or English guest questions, generated answers, citations, model/request metadata, timing, and token usage. The audit contact email, access token, completion URL, and correction text are not sent to either provider.
  • When you mark a pilot action complete: only the affected frozen questions are measured again with OpenAI, and the before/after recommendation counts are stored. The completion URL and your report responses are not sent to OpenAI.

Purposes and legal grounds

  • Provide the audit you request and take steps toward offering the service (GDPR Article 6(1)(b)).
  • Send audit status, deliver the report, and answer or follow up on service questions connected to that audit (GDPR Article 6(1)(b)).
  • Operate, secure, troubleshoot, and prevent misuse of the service (legitimate interests under GDPR Article 6(1)(f)).
  • Understand where the service is unclear, wrong, incomplete, or could be improved, using feedback you choose to submit (legitimate interests under GDPR Article 6(1)(f)).
  • Create and explain hotel recommendation benchmarks using public business information and hotel-confirmed facts (legitimate interests under GDPR Article 6(1)(f)).
  • Run explicitly requested, one-time OpenAI and Gemini pilot measurements and retain their evidence for review (steps requested to provide the service under GDPR Article 6(1)(b)).
  • Meet legal obligations where applicable (GDPR Article 6(1)(c)).

Where information comes from

Information comes from you, from the public hotel website you ask us to review, from OpenAI and optional Gemini responses in the controlled exact-domain pilots, from OpenAI action verifications, and from technical request data generated when the service is used. Automatic four-provider execution remains disabled.

Processors, recipients, and locations

Cloudflare provides the edge network, Worker runtime, security, observability, and D1 database. The D1 primary database currently runs in Western Europe without a jurisdiction restriction. Cloudflare may process limited request metadata in Europe, the United States, and other service locations under its data-processing terms and applicable transfer safeguards. OpenAI provides the search-backed Responses API for the restricted exact-domain pilots. Google provides the paid Gemini API without Google Search grounding for an optional comparison of the same frozen questions. These providers may process questions and generated answers in their service locations under their applicable data terms and safeguards. Google states that paid-service prompts and responses are processed under its processor data-processing addendum and are not used to improve its products. The Resend email adapter is present but no email is sent until a verified sender and the required runtime configuration exist. No analytics, advertising, or session-replay provider is currently integrated.

Retention

The contact email, unclaimed free-audit access, profile drafts, crawled page excerpts, linked OpenAI and Gemini pilot answers/evidence, OpenAI verification answers/evidence, pending hotel-review responses, action events, verification results, and email-delivery records expire 90 days after the latest profile activity and are purged daily. Unlinked product feedback is also purged after 90 days; feedback linked to an audit is removed with that audit. OpenAI states that API data is not used to train its models unless the customer opts in; default abuse-monitoring logs can retain prompts and responses for up to 30 days unless a different approved control applies. Normalized public hotel facts, source hashes, and benchmark definitions may be kept while needed to explain the audit, validate the product, or establish and defend legal claims; they are reviewed and can be deleted earlier on a valid request where no overriding duty or interest applies. Security and platform logs follow the configured Cloudflare service retention periods.

Your rights

Depending on the law that applies, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may also complain to your local EU/EEA supervisory authority or to the Swiss Federal Data Protection and Information Commissioner. Identity may need to be verified before a request is fulfilled.

Automated decisions

SwayRadar creates measurements and recommendations about hotels. It does not currently make solely automated decisions about individuals that produce legal or similarly significant effects.

Cookies and analytics

The current application does not set optional analytics or marketing cookies and does not use browser storage for tracking. See the cookie notice for the live inventory and the rule for future optional technology.

Related information

Cookie noticeLegal noticeCloudflare privacy policyGemini API termsSwiss FDPIC

SSwayRadar

We show independent hotels when AI recommends them and what they can improve.

PrivacyCookiesLegal notice
Privacy — SwayRadar