Privacy Policy

Effective Date: March 18, 2026  ·  Last Updated: July 27, 2026

1. Introduction

We are ServeSwift Incorporated (“ServeSwift,” “we,” “us,” or “our”), a Delaware corporation. We build CRM, contract, and e-signature tools for small and medium-sized businesses, all in one place at serveswift.ai (the “Service”). This policy lays out what we collect, why we collect it, and how we look after it. We have tried to keep it plain, because you should not need a lawyer to understand what happens to your data.

When you use the Service, you are agreeing to what follows.

2. Information We Collect

Information You Provide

  • Account information: When you register, we collect your email address.
  • Business data: We store information you input about your clients, contacts, accounts, contracts, quotes, and projects as part of using the Service.
  • Payment information: When you subscribe to a paid plan or purchase add-ons, payment details are collected and processed by Stripe. ServeSwift does not store your full card number.

Information Collected Automatically

  • Usage and analytics data: We use PostHog to collect information about how you interact with the Service, including pages visited, features used, and actions taken.
  • Session recordings: PostHog may record your sessions within the Service to help us understand user behavior and improve the product.
  • Feature flags: We use PostHog's feature flag functionality to manage feature availability.
  • Cookies and similar technologies: We use cookies and similar tracking technologies to operate the Service and support analytics and session recording. You may disable cookies through your browser settings, but some features of the Service may not function properly as a result.

Email Integration Data

If you decide to connect a Gmail or Microsoft 365 (Outlook) account, we access your email through OAuth using only the permissions you hand us. Here is what that can include:

  • Email metadata: sender, recipient(s), subject, and timestamp
  • Email body content, for the purpose of logging emails as CRM activities
  • OAuth access and refresh tokens, stored securely and used solely to maintain your connected account

We only ever touch email data within the scopes you granted during that connection. We do not use it for advertising, we do not build profiles from it, and we do not use it for anything beyond the features you turned on. You can cut off our access whenever you want, either by disconnecting the integration in Settings or by revoking access from your Google or Microsoft account directly.

E-Signature Data

When someone signs a contract through our native e-sign feature, we collect a few things from the signer:

  • Name and email address of the signer (provided by the sender)
  • Signature image (drawn, typed, or uploaded by the signer)
  • IP address and browser user agent at the time of signing
  • Timestamp of when the document was viewed and signed

We use this to produce the signed document and its audit trail. It is stored securely, and the only people who can see it are the organization that sent the contract and the signer, through their unique signing link.

3. How We Use Your Information

  • Provide, operate, and maintain the Service
  • Improve and personalize your experience
  • Analyze usage patterns and product performance
  • Communicate with you about your account or the Service
  • Respond to support requests and inquiries
  • Process payments and manage your subscription
  • Deliver transactional emails (e.g., contract signing links, quote portals)
  • Enforce our terms and comply with legal obligations

4. AI-Powered Features

Some features run on Anthropic's AI API. When you use them, a limited amount of data (things like the names tied to your clients or contracts) may be sent to Anthropic to do the work. We do not send email addresses or other sensitive identifiers. Once it reaches Anthropic, their own privacy policy and data processing terms govern how they handle it.

5. How We Share Your Information

We do not sell your personal information, full stop. The only times your data leaves our hands are these:

  • Service providers: We share data with the following sub-processors to operate the Service:
    • Supabase: database and authentication infrastructure
    • PostHog: product analytics, session recording, and feature flags
    • Anthropic: AI processing for applicable features (limited data, as described above)
    • Stripe: payment processing and subscription management
    • Resend: transactional email delivery (e.g., signing links, portal invitations)
    • Dropbox Sign (HelloSign): third-party e-signature processing, when you choose to send contracts via Dropbox Sign. Contract content and signer information are transmitted to Dropbox Sign for this purpose.
  • Third-party integrations you authorize: When you connect a Gmail, Outlook, or Dropbox Sign account, data may flow to and from those services as described in Section 2. You control these connections and can revoke them at any time.
  • Legal requirements: We may disclose information if required by law, court order, or governmental authority.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Service.

6. Data Retention

We hold onto your data for as long as your account is active, or until you ask us to delete it. E-signature audit trail data (IP addresses, timestamps, signed documents) is one exception: we keep it to protect the legal validity of contracts you have already executed, and that can outlast your account. If you want your data deleted, email us at admin@serveswift.ai. We will handle it in a reasonable timeframe and let you know once it is done. A caveat: we may keep certain records where the law requires it, or for legitimate reasons like preventing fraud.

7. Data Security

We put reasonable technical and organizational safeguards in place to keep your information from being accessed, shared, changed, or destroyed without authorization. That said, no method of sending data over the Internet or storing it electronically is ever completely secure, so we cannot guarantee absolute security.

8. Your Rights

Depending on your state of residence, you may have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Opt out of certain data uses

To exercise any of these rights, contact us at admin@serveswift.ai.

9. Children's Privacy

The Service is built for businesses and professionals. We do not knowingly collect personal information from anyone under 18. If we find out a minor has given us their information, we will delete it right away.

10. Changes to This Policy

We will update this policy now and then. When something material changes, we will post the new version here and update the “Last Updated” date at the top. If you keep using the Service after that, you are accepting the updated policy.

11. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

ServeSwift Incorporated
admin@serveswift.ai