Legal — Document 01
Privacy Policy
Contents
1. Who We Are
Aged Science LLC (“Aged Science,” “we,” “us,” or “our”) is a limited liability company organised under the laws of the State of Texas, United States, filing number 806026211, with its principal office at 1888 Brittmoore Road, Houston, TX 77043.
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit agedscience.com or use the Swappr mobile application and related services (together, the “Services”).
For the purposes of the EU and UK General Data Protection Regulation (“GDPR”), Aged Science LLC is the data controller of the personal data described in this policy. You can reach us at any time at infra@swappr.biz.
2. Data We Collect
We collect the following categories of personal data:
2.1 Data You Provide
- Account data — name, username, email address, password hash, phone number, and date of birth where required for age verification.
- Profile data — display name, avatar, biography, sizes, and preferences you choose to add.
- Seller verification data — legal name, address, government identification document, and the verification result returned by our payment processor. We receive the outcome and limited metadata; we do not store full identification document images on our own systems.
- Listing and transaction data — items you list, prices, offers, trades, orders, shipping addresses, tracking numbers, and dispute records.
- Communications — in-app messages between users, and any support correspondence you send to us.
2.2 Data Collected Automatically
- Device and technical data — device model, operating system version, app version, language, time zone, IP address, and crash diagnostics.
- Usage data — screens viewed, features used, searches run, session timestamps, and interaction events.
- Push notification identifiers — the device token required to deliver notifications you have opted into.
2.3 Data We Do Not Collect
We do not collect or store full payment card numbers. Card data is entered directly into our payment processor’s secure fields and never reaches our servers. We do not collect precise geolocation, and we do not purchase personal data from data brokers.
3. How We Use Data
- Create and administer your account and authenticate your sessions.
- Operate the marketplace — publish listings, process orders, execute trades, and manage escrow, payouts, and refunds.
- Verify seller identity and reduce fraud, counterfeiting, and abuse.
- Deliver transactional messages — order confirmations, shipping updates, dispute notices, and security alerts.
- Send price alerts and product notifications you have enabled.
- Provide customer support and resolve disputes between users.
- Analyse aggregate usage to diagnose faults, improve performance, and prioritise product work.
- Comply with legal obligations, including tax, anti-money-laundering, and record-keeping requirements, and enforce our Terms of Service.
We do not sell personal data, and we do not use your data to serve third-party behavioural advertising.
4. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases under Article 6:
- Contract (Art. 6(1)(b)) — account creation, order processing, escrow, trades, payouts, and support.
- Legal obligation (Art. 6(1)(c)) — tax records, fraud reporting, and responses to lawful requests.
- Legitimate interests (Art. 6(1)(f)) — fraud prevention, platform security, service analytics, and protecting our users and business. We balance these interests against your rights and freedoms.
- Consent (Art. 6(1)(a)) — optional marketing messages, push notifications, and any non-essential analytics where consent is required. You may withdraw consent at any time.
Where identity documents are processed for verification, that processing is carried out by our payment processor as part of regulated financial-services obligations.
5. Third Parties and Processors
We share personal data only with service providers that process it on our instructions under a written data processing agreement, with other users where the transaction requires it (for example, sharing a shipping address with a seller), and with authorities where the law requires it. Our current processors are:
- Stripe
- Payment processing, escrow, seller identity verification, and payouts. Receives name, email, address, identification data, and transaction details. Acts as an independent controller for its regulated activities.
- Supabase
- Primary database, authentication, and file storage. Hosts account, listing, order, and message data.
- Railway
- Application and API hosting. Processes request data and server logs, including IP addresses.
- Resend
- Transactional email delivery. Receives email address, name, and message content.
- Expo
- Mobile application delivery, over-the-air updates, and push notification routing. Receives device tokens and crash diagnostics.
- PostHog
- Product analytics. Receives pseudonymous usage events, device metadata, and a hashed user identifier. Used for product improvement only.
We may also disclose personal data in connection with a merger, acquisition, financing, or sale of assets, in which case we will notify affected users before their data becomes subject to a different privacy policy.
6. Data Retention
We keep personal data only as long as we need it:
- Account data — for the life of your account, then deleted or anonymised within 30 days of account closure, subject to the exceptions below.
- Transaction and financial records — retained for 7 years to meet United States tax and accounting requirements.
- Dispute and fraud records — retained for 3 years after resolution to protect against repeat abuse and to defend legal claims.
- In-app messages — retained for 2 years from the date sent, or longer where linked to an open dispute.
- Server and security logs — retained for 90 days.
- Analytics events — retained in pseudonymous form for 14 months.
- Marketing consent records — retained for 3 years after withdrawal, as evidence that consent was properly obtained.
Where an account is closed while a transaction, payout, or dispute is still open, we retain the related records until that matter is fully resolved.
7. International Data Transfers
We operate from the United States, and our servers and processors are located in the United States. If you access the Services from the European Economic Area, the United Kingdom, or Switzerland, your personal data is transferred to and processed in the United States.
For those transfers we rely on the European Commission’s Standard Contractual Clauses (SCCs), together with the UK International Data Transfer Addendum where applicable. We carry out transfer impact assessments and apply supplementary measures including encryption in transit and at rest, access controls, and data minimisation. A copy of the relevant transfer safeguards is available on request from infra@swappr.biz.
8. Your Rights
8.1 Rights Under the GDPR
If you are in the EEA, the UK, or Switzerland, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data where no overriding obligation applies.
- Restrict processing while a dispute about accuracy is resolved.
- Port your data — receive it in a structured, machine-readable format.
- Object to processing based on legitimate interests, including profiling.
- Withdraw consent at any time, without affecting past processing.
- Lodge a complaint with your local supervisory authority.
To exercise a right, email infra@swappr.biz with the subject line “Data Subject Request.” We respond within 30 days and may extend by a further two months for complex requests, telling you why. We may ask you to verify your identity before we act. Exercising your rights is free unless a request is manifestly unfounded or excessive.
8.2 Automated Decision-Making
We use automated checks to flag suspected fraud and policy abuse. Where an automated check materially affects your account, you may request human review by contacting us.
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to:
- Know the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties we disclose it to.
- Delete personal information we hold, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding 12 months.
- Limit the use of sensitive personal information. We use sensitive personal information only to provide the Services and to meet verification and legal obligations.
- Non-discrimination — we will not deny service, charge different prices, or provide a lower quality of service because you exercised your rights.
Submit a request by emailing infra@swappr.biz with the subject line “California Privacy Request.” We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days. An authorised agent may submit a request on your behalf with written proof of authorisation.
10. Cookies and Similar Technologies
This website uses only what is strictly necessary to serve pages. We do not set advertising or cross-site tracking cookies, and we do not run third-party ad networks on agedscience.com.
- Strictly necessary — session and security cookies needed to load the site and keep it secure. These cannot be switched off.
- Analytics — within the Swappr application, pseudonymous product analytics help us find faults and improve features. Where consent is legally required, we ask for it before analytics start.
- Local storage — the app stores your session token and preferences on your device so you stay signed in.
You can clear cookies and site data through your browser settings, and you can reset or disable the advertising identifier in your device settings. Blocking strictly necessary cookies may stop parts of the Services from working.
11. Children’s Privacy
The Services are not directed to children. You must be at least 18 years old to hold an account and transact on Swappr. We do not knowingly collect personal data from anyone under 18.
If we learn that we have collected personal data from a person under 18, we delete the account and associated data promptly. If you believe a minor has provided us with personal data, contact infra@swappr.biz and we will act within 7 days.
12. Security
We protect personal data with encryption in transit (TLS) and at rest, hashed credentials, role-based access controls, least-privilege service accounts, audit logging, and regular dependency and infrastructure review. Access to production data is restricted to personnel who need it to operate the Services.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify affected users without undue delay where the risk is high.
13. Changes to This Policy
We may update this Privacy Policy as the Services develop or the law changes. The “Last Updated” date at the top of this page always reflects the current version.
For material changes — a new processing purpose, a new category of data, or a change to your rights — we give at least 30 days’ notice by email and in-app notice before the change takes effect. Continuing to use the Services after the effective date means you accept the updated policy.
14. Contact Us
Questions, requests, and complaints about this policy or about how we handle personal data go to:
- Entity
- Aged Science LLC
- infra@swappr.biz
- Post
- 1888 Brittmoore Road, Houston, TX 77043, USA
- Response Time
- Within 2 business days for general enquiries
If you are in the EEA or the UK and are not satisfied with our response, you may complain to your national data protection authority. See the Legal Center for our EU representative status and for data deletion requests.