What we collect
To run the service, we collect:
- Account info. Email, name, optional phone, company name and address for corporate accounts. Provided by you at signup.
- Order info. Shipping addresses, billing addresses, items ordered, payment metadata (last 4 digits of card, ACH last 4 — never the full card number; that's tokenized by our payment processor).
- Designs + artwork. Files you upload to the customizer, design versions, mockup screenshots, share links you mint.
- Usage data. Pages viewed, designer actions, browser + device metadata, anonymous session id (sb_anon cookie) for guest checkout.
- Support communications. Anything you send us via email, the help center, or in-product chat.
How we use it
We use the data above to:
- Produce, ship, and bill your orders.
- Show you your designs + order history when you sign in.
- Send transactional emails (confirmations, tracking, invoices).
- Improve the product (aggregate analytics, A/B tests).
- Investigate fraud, abuse, and platform health issues.
- Comply with legal obligations (tax records, court orders).
Who we share it with
We share data with service providers who help us run SwagByte:
- Payment processor (Helcim) for card + ACH capture.
- Shipping carriers (UPS, FedEx, USPS) for delivery.
- Email infrastructure (transactional + marketing send).
- Cloud + analytics infrastructure (hosting, error tracking).
We don't sell your personal data. We don't share it with advertising networks for cross-site tracking. Corporate-account designs may be visible to teammates on the same company.
Cookies
We use a small number of cookies:
- Session cookie (httpOnly): keeps you signed in.
- sb_anon: anonymous identifier so guests can save designs + carts across page loads. Cleared on signup so your guest data migrates to your account.
- Analytics: page-view + funnel telemetry. No cross-site tracking.
Your rights
You can:
- Access your data via account settings (profile, orders, designs, addresses).
- Export your data via account settings → export (JSON archive).
- Delete your account via account settings → delete account. We hard- delete designs + carts + addresses; orders retained for tax/legal compliance (typically 7 years).
- Opt out of marketing emails via the unsubscribe link in any marketing email. Transactional emails (order updates) continue regardless.
Security
Passwords are hashed with industry-standard algorithms. Payment data never touches our servers — Helcim tokenizes at the browser. All traffic is HTTPS. Designs are encrypted at rest. We have an internal incident response plan and will notify affected users in case of a confirmed breach.
Children
SwagByte is not intended for users under 13. We don't knowingly collect data from children. Contact us to delete an underage account.
Changes
We'll post material changes to this policy 30 days before they take effect and notify account holders by email.
Questions: privacy@swagbyte.com.