Draft. Not yet in force. This policy is awaiting review by a solicitor.

Privacy Policy

Last updated: 8 October 2026

The short version. We collect what we need to run GaffSwipe and keep people safe, and nothing more. We never ask for your nationality, ethnicity, religion or health. We never track your phone's location. We don't sell your data. Your data is stored in the UK, and you can download or delete it from inside the app.

1. Who is responsible for your data

GaffSwipe Ltd (company number 17390238, [registered address]) is the data controller for personal data processed through GaffSwipe. Our registration with the Information Commissioner's Office is in progress, and we'll publish our registration number here once it's issued: [ICO number].

Questions or requests: privacy@gaffswipe.co.uk.

2. What we collect

DataFromWhy
Name, email address, sign-in identifiers (Apple, Google or email)YouTo create and secure your account
Date of birthYouOnly to confirm you are 18 or over. Other users see your age, never your date of birth.
Profile photoYou, optional for studentsSo other users know who they're talking to. Required to post in Social.
University email addressYou, optionalTo give you a Verified Student badge
Phone numberLandlords and agentsVerification and fraud prevention
Business details: company name and number, redress scheme, client money protection referenceLetting agentsLegal requirements for agents letting in England
Ownership or management documentsLandlords who choose higher verificationTo verify you can let the property. Stored in a private, access-logged store.
Search preferences: university, area, budget, room countYouTo show you relevant places and walk times to campus
Swipes, saved places, notes, enquiriesYour use of the appTo run your watchlist and improve which places we show you
Listings and photosLandlordsTo publish them. We remove location data (EXIF) from every photo.
Roommate posts and messagesYouTo deliver them, and to detect scams and abuse
Reports and moderation recordsYou, other users, usSafety and our Online Safety Act duties
Device and app data: device type, OS version, app version, push token, crash reports, device identifierYour deviceTo send notifications, fix bugs, and stop banned users from coming back
Usage events: screens viewed, features usedYour deviceTo understand how the app is used. Events never contain names, emails, phone numbers, addresses or full postcodes.

What we don't collect: your phone's location, nationality, immigration status, ethnicity, religion, health, or any other special category data. We don't record your screen or sessions.

3. Our lawful bases

  • Contract: running your account, showing listings, delivering messages and enquiries.
  • Legitimate interests: fraud prevention, scam detection in messages, moderation, security, product analytics and improving the feed. We have balanced these against your rights, and you can object at any time.
  • Legal obligation: responding to lawful requests, keeping records we are required to keep, and our Online Safety Act duties.
  • Consent: marketing notifications and optional analytics. You can withdraw consent at any time in Settings.

4. Who can see your data

Other users

  • Students see listings with an approximate area. A property's exact address is shared only with a student whose enquiry the landlord has accepted.
  • Landlords see the name, photo, age and verification status of students who enquire, and can see that a student saved their listing.
  • In Social, other students see your post, first name, photo, age, university and verification badge.
  • Messages are visible to the people in the conversation, and to our moderators if a message is reported or flagged.

Service providers

We use these providers to run GaffSwipe. They process data only on our instructions.

ProviderPurposeLocation
SupabaseDatabase, sign-in, file storage, messagingUK (London)
Expo (650 Industries)Push notification delivery, app updatesUSA
Apple, GoogleSign in with Apple and Google, push notifications (APNs, FCM)USA
PostHogProduct analyticsEU
SentryCrash and error reportsEU
TwilioPhone verification codesUSA
ResendSign-in codes and account emailUSA

Where data leaves the UK, we rely on UK adequacy regulations or the International Data Transfer Agreement / Addendum to protect it.

Others

We share data with the police, regulators or courts only when the law requires it, or when it's needed to protect someone from serious harm or to prevent fraud. We report child sexual abuse material to the relevant authorities. We will never sell your personal data.

5. How long we keep it

DataKept for
Account and profileUntil you delete your account
Swipes24 months
Messages24 months after the conversation's last activity
Listings24 months after the property is marked as let
Reports and moderation records6 years, for legal claims and to stop repeat offenders
Crash reports90 days

When you delete your account, we delete your profile, photos and files. Messages you sent stay in the other person's conversation but are no longer linked to you. Moderation records about your account are kept as above.

6. Your rights

Under UK data protection law, you have the right to:

  • access your data. In the app: Profile → Privacy → Export my data;
  • delete your data. In the app: Profile → Privacy → Delete account;
  • correct inaccurate data. Most of it can be edited in your profile;
  • object to or restrict processing based on legitimate interests;
  • data portability. Your export is in a machine-readable format (JSON);
  • withdraw consent at any time, without affecting earlier processing.

We'll respond within one month. If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office, but please contact us first so we can try to put it right.

7. Age

GaffSwipe is only for people aged 18 and over. If we find out that an account belongs to someone under 18, we will close it and delete their data.

8. Security

Data is encrypted in transit and at rest. Access is restricted row by row at the database level, so users can only read what they're entitled to see. Sign-in tokens are kept in your device's secure storage. Staff access to personal data is limited, logged and protected by two-factor authentication. If a breach is likely to put you at risk, we will tell you and the ICO.

9. Cookies and this website

This website uses no cookies, analytics or tracking, and it doesn't collect any personal data. Our hosting provider may keep standard server logs, such as IP addresses, for a short time for security.

The GaffSwipe app doesn't use cookies. It does use analytics events, as described above, and you can turn off optional analytics in the app's Settings.

10. Changes

We'll update this policy when how we use data changes, and we'll tell you in the app before any significant change takes effect.