Privacy Policy

Swift Flow Privacy Policy

Last updated: July 13, 2026

Swift Flow ("we", "us", or "our") operates the Swift Flow field service management platform, including the Swift Flow web application, technician mobile application, client portal, and public website (collectively, the "Service"). This page informs you of our policies regarding the collection, use, storage, processing, and disclosure of personal data when you use our Service.

1. Information We Collect

Personal and Account Information

Account Data: Name, email address, password or authentication credentials, phone number, home or business address, profile photo, account status, and account identifiers

Role and Organization Data: Company or organization name, user role, company authority, specialties, property manager or building engineer designation, custom role designation, and primary, secondary, or read-only client-contact status

Company and Client Data: Company and building names, addresses, contact persons, email addresses, phone numbers, industries, logos, service-provider relationships, invitation and linking records, and company subscription, trial, billing-cycle, and storage-usage information

Preference and Activity Data: Notification preferences, onboarding and product-tour progress, selected theme and Rhea voice, last-seen status, presence, and feature usage

Location, Time, and Dispatch Information

Location Data: GPS coordinates, last known technician location, job-site and building coordinates, geocoded addresses, and location accuracy when available

Time and Attendance Data: Clock-in and clock-out times, active shifts, time-entry locations, job start and end times, route or dispatch status, and GPS-gate results or administrator override reasons and notes

Job and Scheduling Data: Projects, one-time and recurring jobs, job descriptions, equipment types, assigned technicians, priorities, schedules, service locations, emergency status, progress, and completion history

Service, Client Portal, and Business Records

Service Requests: Requested service type, issue description, urgency, location, preferred date and time, administrator notes, and related quotation, job, and project records

Service Reports: Client and site details, technician details, faults, findings, actions taken, parts and materials, readings, equipment and device checklist results, maintenance history, remarks, recommendations, acknowledgements, ratings, feedback, photos, and signatures

Equipment Inventory: Device codes and types, subtype, floor, area, room, location, zone, loop and address numbers, brand, model, serial number, installation and replacement dates, active status, and other imported or custom metadata

Commercial Records: Quotations, line items, prices, taxes, terms, billing statements and invoices, due and paid dates, statuses, and related client, project, request, job, and report references. Swift Flow does not currently collect payment-card, bank-account, or e-wallet credentials because no online payment processor is integrated into the current Service.

Communications: Direct, group, building-team, operations-team, and company-client messages; message edits, replies, reactions, read status, typing and presence indicators; images, documents, spreadsheets, archives, and other message attachments; and recorded voice messages that a user chooses to send

Call Data: Voice or video call participants, call type, conversation and channel identifiers, call status, start and end times, duration, end reason, and call-log messages. Live call audio and video are transmitted through Agora. Swift Flow does not currently record or store the content of live calls.

Photos, Signatures, Documents, and Files

Report Photos: Images selected or captured for a service or preventive-maintenance report, together with timestamps and captions when provided. In the current report workflow, these images are encoded in the report record stored in Supabase.

Signatures: Observer or client signatures included in submitted reports, and a technician's optional saved drawn or typed signature. Saved technician signatures are stored in the private Supabase signatures bucket; signature type, path, update time, and related audit information such as user agent are stored in the database.

Message Files and Voice Messages: Files and recorded voice messages sent through messaging are stored in Supabase Storage in the message-attachments or chat-attachments bucket and referenced by a file URL in the message. These attachment URLs are currently generated as public URLs, so anyone who obtains the exact URL may be able to access the file.

Company Logos: Company logos are stored in the Supabase company-logos bucket and may be publicly displayed in the Service and generated documents.

PDFs: Service reports, quotations, and invoices may be rendered as PDFs for preview, printing, or download. The current web application generally generates these PDFs in the user's browser; generating or downloading a PDF does not by itself upload a separate PDF copy to Swift Flow. Supabase storage categories also exist for report, quotation, and invoice PDFs when a workflow saves a server-side copy.

Check-In Photos: The current application verifies job check-in primarily through GPS and time-entry data and does not automatically capture a separate check-in photo. A designated Supabase storage category exists for check-in photos if that upload workflow is enabled or used.

AI and Voice Information

Voice Analyst: When a technician uses Voice Analyst, the microphone recording and its audio content are sent through a Supabase Edge Function to the Google Gemini API to extract report details. Swift Flow does not write the Voice Analyst audio file to its database or storage buckets. The recording remains temporarily in the current app session until it is discarded, replaced, or the session is closed, and no Swift Flow server-side audio copy is intentionally retained after processing. Google's processing and retention practices may apply while the data is handled by Gemini.

Rhea Text Assistant: Messages sent to Rhea, recent conversation history, user role, and relevant workspace or report context may be sent through a Supabase Edge Function to the Google Gemini API. For supported admin sessions, up to the most recent ten Rhea text messages may also be stored in browser local storage until the chat or browser storage is cleared.

Rhea Voice Assistant: When a user starts a Rhea voice session, microphone audio is streamed to the OpenAI Realtime API, and generated audio is streamed back. Relevant role and workspace context may be included. Swift Flow does not create or retain a separate recording of the live Rhea voice stream in its database or storage buckets. OpenAI's processing and retention practices may apply while the stream is handled by its API.

AI Equipment Import: When a user chooses AI Import for a CSV or Excel equipment file, the file is read in the browser and converted into CSV data batches. Those equipment rows and values are sent through a Supabase Edge Function to the OpenAI API for structured parsing. Confirmed parsed records are stored in Supabase. The original spreadsheet file is not automatically stored as part of the import.

Marketing Rhea: Questions and recent chat history entered in the public website's Rhea widget are sent to the Google Gemini API. The marketing assistant does not have access to authenticated company or user records.

Generated Voice Output: When a Rhea voice preview is requested, the selected text and voice setting may be sent to the OpenAI text-to-speech API, and the generated audio is returned without being intentionally stored by Swift Flow.

Device, Notification, Website, and Technical Information

Push Notification Data: Mobile push-notification permission status, Firebase Cloud Messaging (FCM) device token, user identifier, notification title and body, delivery data, notification channel, and navigation or call identifiers

Device and Usage Data: Device or browser type, operating environment, IP address and request logs available to hosting and infrastructure providers, user agent where recorded, login and session activity, errors, and feature interactions

Public Website Contact Data: Name, email address, company name, and message submitted through the website contact form

Browser and On-Device Storage: Local and session storage are used for authentication sessions, invitations and onboarding, preferences, report and maintenance drafts, navigation state, limited Rhea history, and continuity features. IndexedDB stores offline copies of projects, clients, reports and drafts, assigned technician jobs, active time entries, limited session data, synchronization metadata, and queued changes. The current Swift Flow application and website code does not set advertising or analytics cookies.

Offline Data and Synchronization

When offline features are used, data may be stored locally through IndexedDB. Offline-created or updated reports, jobs, projects, clients, time entries, and permitted profile changes may be queued. When connectivity returns, queued changes are sent to Supabase and reconciled with server records. Cached data remains on the device until refreshed, cleared by the Service, removed through browser or app settings, or the application is uninstalled. Anyone with access to an unlocked device or browser profile may be able to access locally stored data.

How We Collect Data

  • Directly from you when you register, complete onboarding, submit a form, upload a file, record audio, communicate, make a call, or use the Service
  • Automatically through your browser or device when using authentication, location, offline, notification, calling, camera, microphone, mapping, or usage features
  • From your employer, service company, company administrator, client-organization primary contact, or another authorized user who creates, imports, invites, assigns, links, or manages records involving you
  • From authorized users within the same company, building, project, job, conversation, or client account

2. How We Use Your Data

We use collected data to:

  • Create, authenticate, secure, and administer user, company, technician, and client-portal accounts
  • Provide job scheduling, dispatch, recurring work, technician assignment, project tracking, and emergency-service workflows
  • Verify technician arrival and job eligibility, record time entries, support background location tracking during active jobs, and provide authorized dispatch or en-route visibility
  • Create, complete, share, rate, export, and retain reports, including photos, signatures, device results, and PDFs
  • Maintain equipment inventories and parse user-selected CSV or Excel imports
  • Manage client requests, quotations, approvals, invoices, billing statements, and related notifications
  • Enable messages, attachments, voice messages, presence, reactions, and live voice or video calls
  • Provide building-team and multi-contact client portals, including primary-contact administration, invitations, service-provider links, and role-based access
  • Provide Rhea AI, Voice Analyst, AI equipment parsing, generated voice output, and the informational marketing assistant
  • Cache selected data for offline work and synchronize queued changes when connectivity returns
  • Send verification, invitations, reminders, job and call alerts, transactional emails, and support or contact-form responses
  • Generate maps, geocode addresses, calculate job-site distances, and display service or technician locations
  • Monitor storage, troubleshoot errors, maintain security, prevent abuse, and improve and personalize the Service
  • Enforce subscription limits and manage trials and billing status. We do not currently process online payments or store payment credentials.
  • Respond to support inquiries and comply with legal obligations

3. Data Sharing

We do NOT sell your personal data. We may share data with:

  • Your Employer or Service Company: Authorized administrators and team members may view technician profiles, assignments, schedules, location and time data, reports, messages, performance information, and other operational records according to their access.
  • Clients and Service Providers: Authorized service-company users and linked client contacts may view shared building, equipment, request, project, job, quotation, invoice, report, dispatch, and communication records as needed to provide and receive services.
  • Other Contacts in Your Client Organization: Primary, secondary, and read-only contacts linked to the same building or client account may access shared portal records according to their permissions. Primary contacts may invite or manage contacts and transfer primary-contact status. Building-team conversations are shared with authorized participants. Contact-specific service conversations are limited by conversation membership and may also be visible to authorized service-company administrators and the primary client contact where access rules require it.
  • Supabase: Database hosting, authentication, realtime updates, Edge Functions, and file storage
  • Vercel: Hosting and server-side processing for the public website and scheduled web functions, including requests and technical logs
  • Google: Gemini for Voice Analyst, Rhea text, and marketing Rhea; Google Maps Platform for maps, places, geocoding, addresses, and coordinates; and Firebase Cloud Messaging for device tokens and push delivery
  • OpenAI: Rhea realtime voice streaming and voice generation, and AI parsing of equipment CSV or Excel data
  • Agora: Realtime transport of live voice and video calls and technical channel data needed to connect participants. Swift Flow does not currently ask Agora to record live calls.
  • Resend: Transactional emails, invitations, reminders, website contact messages, recipient addresses, email content, and delivery metadata
  • Cloudflare CDN: Certain font assets used by quotation and invoice templates; standard request information such as IP address, browser information, and requested asset may be processed when loaded
  • Legal Requirements: Government authorities, regulators, courts, or other parties when required by Philippine law, valid legal process, or protection of users, the Service, or legal rights

Swift Flow does not currently integrate PayMongo, Stripe, or another online payment processor. If one is added, this policy will be updated before payment data is collected through it.

4. Data Security

We implement security measures including:

  • Encrypted connections (HTTPS/TLS)
  • Password hashing and managed authentication through Supabase
  • Role-based access controls, row-level security, tenant and conversation access rules, and time-limited signed URLs for private saved signatures
  • Secure cloud infrastructure, server-side API credentials, and authenticated Edge Function requests for protected features
  • Local cache clearing and session controls for supported offline and browser data

Some content is accessible through public URLs, including company logos and current message-attachment and voice-message file URLs. Users should share those URLs carefully and not upload material they are not authorized to disclose.

No method of transmission over the Internet, cloud storage, or on-device storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

5. Data Retention

We retain account and Service data for as long as the relevant account, company, client relationship, or operational record is active, and as reasonably necessary to provide the Service, maintain audit and transaction history, resolve disputes, enforce agreements, meet security requirements, or comply with law.

Voice Analyst recordings and live Rhea voice audio are not intentionally stored by Swift Flow as server-side audio files after processing. Live Agora call content is not recorded, but call logs and messages may be retained as operational history. Voice messages users intentionally send, attachments, report photos, signatures, and submitted business records remain until deleted through an available feature, removed following a valid request, or retained for a business or legal reason.

Local-storage, session-storage, and IndexedDB data remains on the device until cleared by the Service, user, browser or operating system, or application removal. Third-party providers may retain request, security, abuse-monitoring, or service data under their own terms.

Upon account deletion or a valid erasure request, we will delete or anonymize eligible personal data within 30 days where reasonably practicable. Deletion may be limited or delayed when the account is the last company administrator or when records remain connected to messages, reports, time entries, assigned jobs, calls, invitations, billing, safety, audit, or other operational history that must be preserved, reassigned, anonymized, or retained by law.

6. Your Rights (Philippine Data Privacy Act)

Under Republic Act No. 10173 (Data Privacy Act of 2012), you have the right to:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate or incomplete data
  • Erasure or Blocking: Request deletion, removal, or blocking of eligible personal data
  • Data Portability: Receive eligible data in a portable format
  • Object: Object to certain processing of your data
  • Withdraw Consent: Withdraw consent for optional processing, including location, camera, microphone, calling, or notification permissions, subject to limitations in Service functionality
  • File a Complaint: Raise a concern with us or the National Privacy Commission when appropriate

To exercise these rights, contact us at: support@swiftflow.pro

We may need to verify your identity and authority. Some requests may be limited by another person's rights, company ownership of business records, contractual obligations, or legal retention requirements.

7. Location Tracking

Our technician application and web features may collect GPS location data to:

  • Verify technician arrival at job sites and enforce the job GPS gate
  • Record location with time entries and clock-in or clock-out events
  • Provide live dispatch and last-known-location visibility to authorized administrators
  • Provide en-route or service-progress visibility to authorized linked clients
  • Geocode company, client, project, recurring-job, and job addresses and calculate job-site distance

Continuous or background technician location tracking occurs only when the feature is enabled for the applicable account and a technician has an active job or tracking session. The Service may update the last known location periodically while tracking is active. A one-time location check may also occur when a technician attempts to start or clock into a job.

Technicians can disable location permissions, but this may prevent check-in, GPS verification, live dispatch visibility, or other Service functionality. Administrators may disable the GPS gate or record an override reason where permitted.

8. Children's Privacy

The Service is intended for business use and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If we learn that a child's data was collected without appropriate authorization, we will take reasonable steps to delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the Service, data practices, providers, or legal requirements. We will notify you of material changes by posting the new policy on this page, updating the "Last Updated" date, or providing another appropriate notice through the Service.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Swift Flow

Email: support@swiftflow.pro