Privacy Policy
Effective Date: March 18, 2026 · Last Updated: March 27, 2026
1. Introduction
ServeSwift Incorporated (“ServeSwift,” “we,” “us,” or “our”) is a Delaware corporation that provides CRM, contract generation, and e-signature tools for small and medium-sized businesses. This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use our platform at serveswift.ai (the “Service”).
By using the Service, you agree to the terms of this Privacy Policy.
2. Information We Collect
Information You Provide
- Account information: When you register, we collect your email address.
- Business data: We store information you input about your clients, contacts, accounts, contracts, quotes, and projects as part of using the Service.
- Payment information: When you subscribe to a paid plan or purchase add-ons, payment details are collected and processed by Stripe. ServeSwift does not store your full card number.
Information Collected Automatically
- Usage and analytics data: We use PostHog to collect information about how you interact with the Service, including pages visited, features used, and actions taken.
- Session recordings: PostHog may record your sessions within the Service to help us understand user behavior and improve the product.
- Feature flags: We use PostHog's feature flag functionality to manage feature availability.
- Cookies and similar technologies: We use cookies and similar tracking technologies to operate the Service and support analytics and session recording. You may disable cookies through your browser settings, but some features of the Service may not function properly as a result.
Email Integration Data
If you choose to connect a Gmail or Microsoft 365 (Outlook) account, ServeSwift will access your email data via OAuth with the permissions you grant. Specifically, we may collect:
- Email metadata: sender, recipient(s), subject, and timestamp
- Email body content, for the purpose of logging emails as CRM activities
- OAuth access and refresh tokens, stored securely and used solely to maintain your connected account
We only access email data as permitted by the scopes you authorize during the OAuth connection flow. We do not use your email data for advertising, profiling, or any purpose other than providing the features you have enabled. You can revoke our access at any time by disconnecting the integration in Settings or revoking access through your Google or Microsoft account.
E-Signature Data
When a contract is sent for signature using ServeSwift's native e-sign feature, we collect the following information from the document signer:
- Name and email address of the signer (provided by the sender)
- Signature image (drawn, typed, or uploaded by the signer)
- IP address and browser user agent at the time of signing
- Timestamp of when the document was viewed and signed
This data is used to produce a signed document and audit trail. It is stored securely and is accessible only to the organization that sent the contract and, via their unique signing link, the signer.
3. How We Use Your Information
- Provide, operate, and maintain the Service
- Improve and personalize your experience
- Analyze usage patterns and product performance
- Communicate with you about your account or the Service
- Respond to support requests and inquiries
- Process payments and manage your subscription
- Deliver transactional emails (e.g., contract signing links, quote portals)
- Enforce our terms and comply with legal obligations
4. AI-Powered Features
ServeSwift uses Anthropic's AI API to power certain features of the Service. When you use these features, limited data — such as names associated with your clients or contracts — may be transmitted to Anthropic for processing. Email addresses and other sensitive identifiers are not sent to Anthropic. Anthropic's use of this data is governed by their own privacy policy and data processing terms.
5. How We Share Your Information
We do not sell your personal information. We do not share your data with third parties except as follows:
- Service providers: We share data with the following sub-processors to operate the Service:
- Supabase — database and authentication infrastructure
- PostHog — product analytics, session recording, and feature flags
- Anthropic — AI processing for applicable features (limited data, as described above)
- Stripe — payment processing and subscription management
- Resend — transactional email delivery (e.g., signing links, portal invitations)
- Dropbox Sign (HelloSign) — third-party e-signature processing, when you choose to send contracts via Dropbox Sign. Contract content and signer information are transmitted to Dropbox Sign for this purpose.
- Third-party integrations you authorize: When you connect a Gmail, Outlook, or Dropbox Sign account, data may flow to and from those services as described in Section 2. You control these connections and can revoke them at any time.
- Legal requirements: We may disclose information if required by law, court order, or governmental authority.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Service.
6. Data Retention
We retain your data indefinitely while your account is active, or until you request deletion. E-signature audit trail data (IP addresses, timestamps, signed documents) is retained to support the legal validity of executed contracts and may be retained for a longer period even after account deletion. If you would like your data deleted, please contact us at admin@serveswift.ai. We will process deletion requests in a reasonable timeframe and confirm once complete. Note that we may retain certain data as required by law or for legitimate business purposes such as fraud prevention.
7. Data Security
We implement reasonable technical and organizational measures to protect your information from unauthorized access, disclosure, alteration, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
8. Your Rights
Depending on your state of residence, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Opt out of certain data uses
To exercise any of these rights, contact us at admin@serveswift.ai.
9. Children's Privacy
The Service is intended for use by businesses and professionals. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that a minor has provided us with personal information, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the “Last Updated” date above. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
ServeSwift Incorporated
admin@serveswift.ai