PromptSwing

Legal

Privacy Policy

Effective Date: September 11, 2026

1. Who We Are and What This Covers

PromptSwing is operated by Bergen Ridge LLC. You can reach us at [email protected].

This policy covers:

  • our website, www.promptswing.com, and its support assistant;
  • the PromptSwing dashboard at app.promptswing.com, including Captain;
  • PromptSwing hosting and the website builder, including the stores we host on promptswing.io addresses and on merchants' own domains;
  • our Shopify app, PromptSwing Profit Analytics; and
  • the PromptSwing connector, which lets an AI assistant a merchant chooses work with their store.

2. Our Role

For merchant account and billing information, we decide how it is used.

For information about a merchant's own customers — collected by a store we host or received through our Shopify app — we process it on that merchant's behalf, to provide the services they turned on. The merchant is responsible for telling their customers how their information is used. If you shop with a store that uses PromptSwing, please contact that store first; we will help them answer you.

3. Information We Collect

Merchant accounts. Name, email address, password (stored only as a one-way hash), and, if you turn on two-factor sign-in, its secret and your recovery codes (the recovery codes are stored as hashes). We keep a record of sign-ins for security.

Billing. Subscriptions are sold by Paddle, which receives your payment details. Prepaid time bought through an AI assistant is paid through Stripe and approved in your own payment wallet. We receive the purchase record, never your card number.

Stores you build or host with us. Store content, products and prices, images you upload, your conversations with Captain and the website builder, domain settings, and a copy of each version of your store you publish.

Your customers, on stores we host. Depending on what your store offers: carts, checkouts and orders (items, totals, the email address a shopper gives at checkout and whether they agreed to marketing emails, shipping destination details where the store collects them, and the page the shopper arrived from); reviews; messages sent through a contact form (name, email, message); bookings (name, email, phone, requested time); event replies (name, email, attendance, party size and message); and membership access. Store payments are processed by the merchant's own connected Stripe account; we do not receive card numbers.

Our Shopify app. The shop's domain and the access token Shopify issues; order and checkout notifications Shopify sends us, which can include customer details Shopify includes in them; each product's unit cost and the Shopify Payments fees on each order, read from the store when the merchant opens the Profit page; and checkout steps recorded by a Shopify web pixel. The pixel runs only when Shopify reports that the shopper allows analytics — in some regions that is the default unless the shopper opts out in the store's cookie choices. It records the step reached, the time, a scrambled (hashed) checkout identifier, and the text of any error message shown with the form field it relates to. It does not record names, email addresses, street addresses, phone numbers, card details, or what a shopper typed.

Tracked links. When someone clicks a short link a merchant shares through PromptSwing, we log the time, the referring page, the browser type and a scrambled (hashed) form of the IP address — never the address itself — so the merchant can see which links bring visitors and sales.

Businesses we may contact. To find new businesses that may want a store, we collect information about companies from public company registers and, at most, the company's own website: company name, registration details and location, website, whether it already sells online, and a contact email address only if the company publishes one on its site. These records are deleted after about 90 days. If we write to a business, it receives at most one message and one follow-up, the message says where we found it, and any reply or unsubscribe stops all further messages permanently; we keep a minimal record of that choice so we never write again.

AI assistant connector. Which AI app a merchant approved, the permissions they granted, and a log of each action that app takes on their store, so the merchant can see what it did.

Our website and support assistant. Messages you send to the assistant, and standard server logs such as IP address and browser type, which we use for security and to keep the service running.

4. How We Use It

We use information only to provide the services a merchant uses: building and hosting stores, showing store readings and insights, recording orders, and sending the emails described below. We also use it to secure accounts, prevent abuse, and meet legal obligations.

Emails. Account and billing emails, and notices about a store's plan — reminders before prepaid time ends, and a notice if a store is taken offline. On stores we host, where the merchant turns them on: one reminder about an unfinished checkout, sent only if the shopper agreed to marketing emails, and one review request per order.

Within one merchant account, our tools read each other's data — for example, insights look at orders, carts and reviews together. Between merchants, private data is never shared. The one exception is public product information already shown on a store we host (product name, description, image, price and whether it is in stock), which may appear in a combined product search across those stores; a merchant can ask us to remove their store from it.

We do not sell personal information, and we do not use or share it for advertising.

Legal bases (European Economic Area and UK). We process information to perform our contract with merchants, for our legitimate interests in running, securing and promoting a business service (including contacting businesses as described above), with consent where it is required (such as marketing emails to shoppers and the checkout pixel where analytics consent applies), and to meet legal obligations.

5. Service Providers

These companies process information for us, only to provide our services:

  • Hetzner — servers and encrypted backups, in Europe.
  • Cloudflare — delivering traffic to our sites and stores, security, and domain name services.
  • Anthropic — AI processing, in the United States. When a store or page is generated, when Captain or an automated agent replies, or when a written insight is produced, the relevant text is sent to Anthropic. This can include messages a shopper sends to a merchant's agent. Under Anthropic's commercial terms this data is not used to train its models. Our Shopify app's profit and checkout readings are calculated without AI.
  • Paddle — sells our subscriptions as merchant of record and handles payment details, VAT and sales tax. Billing questions: [email protected].
  • Stripe — processes prepaid plan purchases, and payments on stores we host through each merchant's own connected account.
  • USPS — when a store we host has shipping set up, the origin and destination postal details of a parcel are sent to USPS to get a shipping rate.
  • Shopify — for merchants using our Shopify app, Shopify sends us store data as described above.
  • Services a merchant chooses to connect, such as a GitHub repository or an advertising account — we exchange data with them only as needed for the feature the merchant turned on, for example reporting a store release back to the repository.
  • Google Fonts — stores we host load their typefaces from Google, so a visitor's browser connects to Google's servers when a store page opens.

Our email is sent from our own mail server (mail.promptswing.com), not through an email marketing company.

6. How Long We Keep It

Accounts. For as long as the account is open. When you ask us to delete your account, we remove its data from our live systems within 30 days.

Hosted stores after a plan ends. A store is taken offline three days after payment was due. Its content is kept for 90 days so it can be brought back; after that, the store's files and saved versions are deleted. The account, its order records and a record of past releases remain until the account is deleted.

Our Shopify app. While the app is installed. When a merchant uninstalls it, we discard the shop's access token at once. Shopify then sends us a deletion request for the shop, 48 hours later, and we delete the shop's stored order, checkout and profit data when it arrives. When Shopify asks us to remove a customer's data, we remove that customer's personal details from the orders we hold.

Backups. Our databases are backed up every six hours, encrypted, and the backups are kept for about 14 days. Deleted data can remain in a backup until that backup is removed.

7. Security

Traffic to our sites, stores and services uses HTTPS. Webhooks from Shopify and payment providers are checked with their signatures. Passwords and recovery codes are stored only as hashes, two-factor sign-in is available, sign-in attempts are rate-limited, backups are encrypted, and access to our servers requires an SSH key. No system is perfectly secure; if you believe you have found a vulnerability, write to [email protected].

8. Your Choices and Rights

Merchants can ask to see, correct, export or delete their data, and can disconnect a store or uninstall our Shopify app at any time, which stops future collection. Shoppers can decline analytics in a Shopify store's cookie choices, which stops our checkout pixel for them, and can leave the marketing-email box unticked at checkout on stores we host.

Depending on where you live, you may have further rights, such as to object to or restrict certain processing. To make a request, write to [email protected]. We respond within 30 days.

9. Cookies and Local Storage

The PromptSwing dashboard uses cookies needed to keep you signed in. Stores we host use the browser's local storage to remember a shopper's cart. We do not place advertising cookies.

10. Where Data Is Processed

Our servers and backups are in Europe. Some of our service providers, including Anthropic and Stripe, process data in the United States, and Cloudflare operates worldwide.

11. Children

PromptSwing is a service for businesses and is not directed at children. We do not knowingly collect personal information from children under 13.

12. Changes to This Policy

Updates will be posted at promptswing.com/privacy with a revised effective date.

13. Contact

[email protected]

PromptSwing Support
Typically replies instantly
Hi there! How can we help you today?