📍 This service primarily serves users in Taiwan
Overseas use is governed by Taiwan law. If your jurisdiction requires additional terms, contact support@swayfoodapp.com.
This page is a machine translation. The Traditional Chinese version is authoritative.
Important Notice and Consent: Downloading, registering, using, or continuing to use the SWAY App (iOS / Android), the official website (swayfoodapp.com), the Merchant Portal, or any service of the Company shall be deemed your complete reading, understanding, and unconditional agreement to this Privacy Policy (the "Policy"). We are committed to protecting your personal data while delivering quality services, operating the Platform, optimizing recommendations, preventing fraud, and developing our business, in accordance with the Personal Data Protection Act of the Republic of China (Taiwan), the EU General Data Protection Regulation (GDPR), Apple App Store privacy standards, and Google Play Data Safety standards.
1. Operator and Data Processor
1.1 Data Controller
SWAY CO., LTD. is the data controller of this Service and bears the responsibility of a non-government agency for the collection, processing, and use of data under the Personal Data Protection Act. However, with respect to customer rosters uploaded or created by merchants under Section 5.6 of the Merchant Service Agreement, the Company stands in the position of a fiduciary processor, and the collector is that merchant; see §2.6 of this Policy for details.
This Policy also applies to customer rosters that the Company processes on merchants' instructions in its position as a fiduciary processor (see §2.6 for details); with respect to such data, the Company's obligations are not conditional on the existence of a membership relationship between the data subject and the Company.
- Name: SWAY CO., LTD. (registered in Taiwan as 隨食有限公司; brand name "Sui Shi SWAY")
- Responsible Person: Yang Da-Wei (楊大為)
- Unified Business Number: 62153228
- Registered Address: 4F., No. 158, Sec. 1, Xinsheng S. Rd., Zhongzheng Dist., Taipei City, Taiwan (臺北市中正區新生南路1段158號4樓)
- Primary Contact: support@swayfoodapp.com
- Business Scope: food and beverage discovery app, merchant backend management system, advertising services, member CRM
- Place of Registration: Republic of China (Taiwan)
1.2 Privacy Contact Points
1.3 Scope of Application
This Policy applies to all products and services offered by the Company, including but not limited to: (a) SWAY App (iOS, Android); (b) official website (swayfoodapp.com and its subdomains); (c) Merchant Portal; (d) push notification service; (e) email communications; (f) customer service systems; (g) API services; (h) marketing campaigns; (i) physical membership cards (where available). This Policy does not apply to third-party websites, apps, or services linked or redirected from the service (such as Google Maps, Apple Maps, Uber, food delivery platforms), which are governed by their own privacy policies.
1.4 Legal Basis
The Company processes your personal data on one or more of the following legal bases:
- Performance of Contract: providing core services you have requested, member entitlements, subscription billing, merchant binding;
- Consent: obtaining your express consent for specific processing purposes (such as marketing pushes, cross-border transfer of special category data, AI training of specific data); whether the Google ads shown in the App are personalized is determined by the settings of your device operating system (App Tracking Transparency (ATT) on iOS; the advertising ID on Android), as described in §8.3; if you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the Company additionally obtains your choice through Google’s consent management tool (User Messaging Platform, UMP) before displaying advertising;
- Legal Obligations: compliance with tax, accounting, anti-money laundering, consumer protection, and criminal judicial assistance requirements;
- Legitimate Interest: processing necessary for service optimization, fraud prevention, platform security, business development, business intelligence, business cooperation, and reputation protection of the Company; unless your interests or fundamental rights clearly outweigh the Company's legitimate interest.
2. Categories of Personal Data We Collect
2.1 Data You Actively Provide
- Account identification: email address, name / nickname, profile photo, password hash (provided through Google / Apple / Facebook OAuth login or self-registration via email);
- Contact information: phone number (for verification), email, optional address;
- Personal preferences: birthday (for age determination and birthday benefits), gender, dietary preferences, language settings, location preferences, push preferences;
- City / district of residence: the city of residence or city/district of address you provide at registration or in personal settings. The Company uses this field to determine your area in order to provide localized content and send local push notifications (e.g., "a new store has opened nearby").
- User-Generated Content (UGC): articles, comments, ratings, photos, videos, audio, reports, favorites, likes/dislikes posted by you;
- Merchant data (Merchant users only): merchant name, business identification number, registered address, business address, principal's name, food business operator registration number, tax registration, bank account, employee account information, brand / trademark ownership proof (such as a copy of the trademark registration certificate, only for applicants to a Chain Plan);
- Payment information: processed by the Company's third-party payment providers (ECPay); the Company only retains transaction codes, order numbers, last 4 digits of credit card, and does not directly store full credit card numbers or CVV;
- E-invoice data: the optional invoice carrier (mobile barcode) or donation code you provide, a business tax ID (merchants), and the invoice number, line items and amounts we are required by law to issue. The mobile barcode is a personal carrier identifier issued by Taiwan's Ministry of Finance; we use it solely to issue cloud invoices and transmit it to our e-invoice value-added service centre. Invoices and related vouchers are retained under the Tax Collection Act and the Business Entity Accounting Act — see §5.3;
- Customer service interactions: problem descriptions, screenshots, attachments, chat logs you provide via email, in-app customer service, or forms;
- Reports and dispute data: documents and supporting evidence you provide in reports, complaints, or refund requests;
- Identity verification data: ID document photocopies provided during KYC, age verification, parental consent for minors, or identity dispute verification (Merchant or special circumstances only).
2.2 Data Automatically Collected
- Location data: GPS location, IP-estimated location, Wi-Fi base station signals (limited to authorized scope) obtained when opening the App or performing specific operations (random recommendation, search, nearby restaurants, reservation, check-in). The Company does not continuously track location in the background; you may disable location permission in device settings at any time, but some core functions will be limited.
- Behavioral data: search records, browsing paths, click events, dwell time, favorites, push opens, ad impressions and clicks, conversion events, A/B testing groupings, recommendation result interactions, social interaction patterns;
- Device information: OS version, app version, device model, CPU, language, time zone, advertising identifier (IDFA / GAID, only if you have not opted out), push token, app installation source;
- Network information: IP address, ISP, connection type (Wi-Fi / 4G / 5G), browser type and version (website only);
- Device fingerprint and anti-fraud data: hardware fingerprint, Canvas fingerprint, font list, simulator detection, VPN / Proxy detection, behavioral biometrics (such as typing rhythm, swipe patterns) — used to prevent account fraud, false identity, cross-border location forgery;
- Event logs: API call records, error logs, performance metrics, security events;
- Cookies and similar technologies: see Section 8;
- Offline cache data: the App caches recent browsing records, favorites, personal preferences locally on your device. This data is stored on your device and managed automatically by the App.
2.3 Data from Third-Party Sources
- OAuth login providers: basic personal information obtained through Google, Apple, Facebook, X (Twitter) OAuth login (name, email, email verification status, profile photo, provider ID, OpenID identifier), used for account verification, single sign-on, and fraud prevention;
- Geographic data sources: Google Maps Platform, OpenStreetMap (subject to ODbL license), Apple Maps, and other public restaurant data sources; the Company's collection and processing of such data complies with the terms of service of each respective service;
- Payment service providers: ECPay, Apple, and Google provide transaction results, payment status, and chargeback notifications;
- Merchant-provided: data merchants provide on the Platform regarding their members' point accumulation, consumption, and redemption records;
- Anti-fraud and credit data: the Company may, based on legitimate interest, obtain data from anti-fraud databases, sanctions lists (OFAC, UN), and public credit information for verifying merchant identity and preventing illegal activity;
- Referrers and referral codes: when you register through someone else's referral code, the referrer's identification information.
2.4 Special Category Personal Data
The Company generally does not actively collect the following special category personal data: medical records, genetic data, sex life, criminal record, religious beliefs, political views, biometrics (fingerprints, iris). However, if you actively disclose such data in UGC, customer service messages, or report documents, the Company may process within the necessary scope and shall handle in accordance with Article 6 of the Personal Data Protection Act.
2.5 Children's Data
The minimum age for this service is 13 years old. The Company does not deliberately collect personal data of children under 13; if the Company becomes aware of inadvertent collection, it shall delete within a reasonable time. See Section 9.
Customer rosters uploaded by merchants: customer names or forms of address, telephone numbers, and merchant notes and tags collected by the merchant itself, uploaded by the merchant or created in the back office, for its use in identifying customers in reservation, waitlist, and seating on the Platform; see §2.6 for details.
3. How We Use Your Data
The Company collects, processes, and uses your personal data for the following specific purposes. Each item may use your data alone or in combination:
3.1 Core Service Provision (Performance of Contract)
- Random recommendations, search, favorites, map navigation, parking lot search, reservations, queueing, sharing;
- Member tier management (Free / Plus), entitlement activation, quota calculation, cross-country location unlock, ad-free experience;
- Merchant member binding, point accumulation, coupon redemption, QR code identification;
- Paid subscription order processing, invoice issuance, tax certificates, auto-renewal;
- Community discussion posting, commenting, liking, reporting, replying, abuse handling;
- Multi-language interface, localized content;
- Push notifications (system announcements, order status, merchant offers, membership expiry reminders, and local notifications based on your stated city of residence/address, such as promotional notifications for newly opened stores nearby). You may disable push notifications or adjust push/marketing preferences (opt-out) at any time in App "Settings"; opting out does not affect essential security and billing notifications.
3.2 Personalized Recommendations and Algorithms (Legitimate Interest + Consent)
- Building personalized recommendation models based on your usage records, preferences, location, and social interactions;
- Real-time computation and optimization of ranking, filtering, and recommendation results;
- Building or updating user profiles / segments for: precise recommendations, personalized ranking, personalized advertising, merchant matching;
- A/B testing, gradual rollout, new feature validation;
- Post-evaluation and performance tracking of recommendation results.
3.3 Service Optimization and Machine Learning (Legitimate Interest)
- Analyzing usage behavior, retention rate, conversion rate, bounce rate as a basis for product decisions;
- Using your personal data, UGC, and behavioral data to train and validate the Company's internal algorithms, recommendation systems, AI models, quality moderation systems, anti-fraud models, and customer service automation models;
- For product development, version iteration, and new feature design;
- Detecting and fixing performance bottlenecks, errors, and failures;
- Conducting de-identified or anonymized statistics, research, and academic uses.
3.4 Advertising and Commercial Promotion (Legitimate Interest / Consent)
- Merchant ads within the SWAY platform (full-screen launch ad, top banner, scrolling carousel): whether such an ad is displayed is decided by the city in which your current location falls, the time of day, and the conditions set by the merchant (distance from the store, the cuisines you selected as preferences in the App, and whether you have previously earned loyalty points at that merchant). Your precise coordinates are used only to determine the city and the distance for that single request and are not written into the advertising records. Ad impression and click records are stored on the Company's servers together with your member ID (if you are signed in) and your IP address, and are used to avoid repeated exposure, to prevent click fraud, and to bill merchants. Such records are retained until the foregoing purposes cease to exist; the Company does not set an automatic de-identification or automatic deletion period for them, and you may exercise your right of deletion or of cessation of use under §6.1;
- Google AdMob advertising (free members only): served by Google using the data described in §4.4. Whether it is personalized depends on the settings of your device operating system and on your choice in the ad consent options, as described in §8.3. SWAY Plus paying members are not shown any advertising, including Google AdMob ads and ad slots purchased by merchants within the platform;
- Building advertising segments, lookalike audiences, retargeting audiences;
- Tracking ad impressions, clicks, conversions for settlement with advertisers;
- Per agreements with advertisers, providing performance reports in de-identified or aggregated form;
- Marketing of the Company's or partners' products / activities (you may unsubscribe from marketing pushes at any time);
- Notifications of partner merchant promotions, time-limited offers, member-exclusive rights.
3.5 Account Management, Security, and Fraud Prevention (Legitimate Interest + Legal Obligations)
- Login verification, two-factor authentication, password reset, account recovery assistance;
- Anomaly detection: cross-region login, device anomaly, IP anomaly, location forgery, simulator, bot;
- Account abuse, multi-account detection, false identity determination;
- Detection and handling of credit card fraud, chargebacks, money laundering, false invoicing;
- Detection, investigation, and evidence-gathering for violations of Community Guidelines, Merchant Service Agreement;
- Protecting the lawful rights of the Company, other users, Merchants, and third parties from infringement.
3.6 Legal Compliance and Dispute Handling (Legal Obligations)
- Performing obligations under the Personal Data Protection Act, Electronic Signature Act, Electronic Invoice Implementation Regulations, Income Tax Act, Business Tax Act, Fair Trade Act, Consumer Protection Act, Criminal Code, Code of Criminal Procedure, Money Laundering Control Act, Children and Youth Protection Act;
- Cooperating with lawful requests from courts, prosecutors, police, Investigation Bureau, tax authorities, Personal Data Protection Commission, Fair Trade Commission, consumer protection agencies, Ministry of Labor, Ministry of Health and Welfare, Ministry of Finance, Financial Supervisory Commission, etc.;
- Where the Company deems necessary, providing necessary data to judicial authorities under the Communications Protection and Surveillance Act, Domestic Violence Prevention Act, Sexual Assault Prevention Act, etc.;
- Handling refund disputes, consumer disputes, merchant disputes, advertiser disputes, IP infringement disputes, labor disputes;
- Retaining transaction records, invoices, KYC documents, dispute documents for regulatory inspections or future evidence by the Company;
- Verifying merchant identity and brand ownership: for applications to the chain-brand plan, verifying the authenticity of the trademark / brand-ownership proof provided by the merchant, and where applicable cross-checking with the Taiwan Intellectual Property Office (TIPO) of the Ministry of Economic Affairs or the equivalent competent authority of the place of application, in order to prevent fraudulent chain claims and protect genuine brand-rights holders;
- Preparation for litigation, arbitration, administrative proceedings, and legal opinions.
3.7 Business Development and Commercial Intelligence (Legitimate Interest)
- Market research, consumption trend analysis, geographic heat analysis;
- Aggregated data needed for commercial presentations, pitching materials, press releases, media interviews;
- De-identified data shared with potential investors, strategic partners, partner media, research institutions;
- Due diligence for partnership / merger / investment / business transfer;
- Service statistics needed for grants, accelerator entry, government project applications.
3.8 Third-Party Service Integration (Performance of Contract / Legitimate Interest)
- Necessary transmissions for connecting Google Maps Platform, Apple Maps, food delivery platforms, taxi apps, parking apps, reservation platforms;
- Identification information exchange required for OAuth login to third-party services;
- Necessary exchanges with payment service providers to complete transactions;
- Data transmission and processing required with cloud infrastructure service providers (Cloudflare, Supabase, Railway, etc.);
- Reasonable data integration with the Company's partner content creators or marketing partners, advertising agencies, and brand partners (limited to de-identified or aggregated form).
3.9 Communications and Customer Service (Performance of Contract)
- Replies to customer service inquiries, complaints, refund requests, and report handling;
- System notifications, policy change notifications, security warnings;
- Surveys, feedback, user research interviews (with your participation consent);
- Customer service AI auto-reply and classification (including automated processing by AI service providers such as Anthropic / OpenAI / Google).
3.10 Other Purposes Authorized by Your Consent
Where express consent is required by law (such as for marketing pushes, cross-border transfer of special category data, AI training of specific data), the Company shall obtain your consent through checkbox at checkout, settings panel toggle, or separate consent form. You may withdraw consent at any time, but withdrawal of consent only affects future processing and does not affect the legality of processing already performed based on your consent.
📌 Our Commitment and Limitation: The Company will not directly sell your raw personally identifiable information (PII) to third-party advertisers or data brokers. Advertising delivery, business intelligence, and media sharing are conducted in de-identified, aggregated, or group-characteristic form. This commitment does not restrict the Company from: (a) using de-identified or aggregated data for advertising delivery and commercial cooperation; (b) sharing personal data with necessary third parties listed in Section 4; (c) disclosing data based on legal obligations; (d) transferring data in case of business transfer, merger, investment, or acquisition.
4. Data Sharing Recipients
The Company may share, disclose, or transmit your personal data to the following recipients in necessary circumstances. All external sharing follows the "minimization principle" and requires recipients to provide data protection standards equivalent to or higher than this Policy.
4.1 Technical Service Providers (Data Processors)
The following third-party service providers process your data as "Data Processors," only on the Company's instructions, and bound by individually signed or publicly available Data Processing Agreements (DPAs):
- Cloud infrastructure: Cloudflare (CDN, security, WAF, DNS), Supabase (database, account verification, storage), Railway (application servers), GitHub (source code version control);
- Maps and location: Google Maps Platform, Apple MapKit, OpenStreetMap;
- OAuth and identity: Google, Apple, Meta (Facebook), X (Twitter), LINE;
- Email and communications: Resend, Twilio, Zoho Mail (corporate email);
- Push services: Apple Push Notification Service (APNs), Google Firebase Cloud Messaging (FCM), Web Push;
- Analytics and monitoring: Sentry (error tracking and performance monitoring; when an error occurs in the SWAY App (including its web version), a sample of screen replays of that session is kept, with on-screen text and images masked, used only for debugging and not for advertising or marketing);
- AI service providers: Anthropic (Claude), OpenAI, Google AI for customer service automation, content moderation, recommendation assistance, email classification, translation processing;
- Customer service and ticketing systems: self-hosted by the Company or provided by third parties.
4.2 Payment and Financial Service Providers
Payment-related processing is delegated to the following licensed payment providers: ECPay (credit card), Apple App Store IAP, Google Play Billing. The Company does not directly store full credit card numbers or CVV; only transaction codes, order numbers, and last 4 digits of cards are retained.
4.3 Merchants and Member Binding
When you actively bind your membership to a specific merchant via QR code or member ID, that merchant may view within the Platform interface: (a) your member ID / QR code; (b) consumption / point / redemption records with that merchant; (c) reviews you submitted to that merchant. Merchants are in the position of fiduciary processors of such data, bearing protection obligations under Article 5 of the Merchant Service Agreement and Article 8 of the Personal Data Protection Act, and shall not use such data outside the Platform.
4.4 Advertisers, Partners, and Marketing Agencies
- The Company provides ad performance reports to advertisers and agencies in de-identified or aggregated form (impressions, clicks, conversion rates, demographic distribution);
- Tracking data automatically triggered by Cookies / Pixels / SDKs is processed per the policies of each third-party advertising platform;
- Where the Company's lookalike audience and retargeting audience building is conducted through third-party advertising platforms, such platforms may, per their own policies, incorporate the data into their global audience systems.
- Google AdMob (Google LLC): the App displays third-party advertising provided by Google AdMob to free members. The Google Mobile Ads SDK contained in the App automatically collects and transmits the following data to Google: advertising identifiers (the IDFA on iOS, only if you allowed tracking at the system prompt; the advertising ID on Android, unless you have deleted it in your system settings), IP address (which may be used to estimate approximate location), device and operating system information, ad interaction data such as impressions and clicks, and diagnostic data such as crashes and performance. Google uses such data to serve advertising, personalize advertising, measure performance, perform data analysis, and prevent fraud and abuse, and processes it under its own privacy policy. See "How Google uses information from sites or apps that use our services". SWAY Plus paying members are not shown any advertising, including Google AdMob ads and ad slots purchased by merchants within the platform.
4.5 Legal Authorities and Judicial Cooperation
The Company may disclose your personal data in the following circumstances (potentially without prior notice) under applicable law:
- Court rulings, judgments, orders;
- Lawful search warrants, subpoenas, or executive orders from prosecutors, police, Investigation Bureau, Ministry of Justice, customs;
- Lawful administrative dispositions from tax authorities, Personal Data Protection Commission, Fair Trade Commission, consumer protection agencies, Financial Supervisory Commission, etc.;
- Necessary cooperation under the Communications Protection and Surveillance Act, Money Laundering Control Act, Children and Youth Welfare and Rights Protection Act, Domestic Violence Prevention Act, Sexual Assault Prevention Act;
- To protect the life, body, property, and lawful rights of the Company, its employees, other users, Merchants, and third parties from infringement;
- For investigation, evidence, and defense of the Company's legal position (including litigation, arbitration, administrative proceedings, settlement negotiations);
- Lawful requests from foreign judicial authorities through the Mutual Legal Assistance Act in Criminal Matters, INTERPOL, or bilateral judicial assistance treaties;
- Necessary use by the Company's internal audit, external accountants, legal counsel, outside counsel, and insurance companies.
4.6 Corporate Group, Successors, and Business Transfer
- In business development, merger, acquisition, asset transfer, division, liquidation, IPO, business transfer, capital increase, investment, debt assignment, bankruptcy, or similar circumstances, the Company may transfer your personal data along with the business to successors, buyers, new shareholders, creditors, or their advisors;
- During due diligence (DD) of potential transactions, the Company may, under confidentiality protections, disclose your data to potential transaction counterparties, their advisors, accountants, lawyers, and valuation institutions;
- Necessary internal sharing with the Company's affiliates, parent company, subsidiaries, holding structure;
- Upon occurrence of the foregoing transfer, the Company shall announce in the App, on the official website, and via email; successors shall comply with protection standards at least equivalent to this Policy.
4.7 Your Instructions and Authorizations
- When you actively click "Share," "Navigate," "Parking," "Delivery," "Ride," or "Reservation" within the App to redirect to third-party services, the Company may transmit necessary information to such third parties per your instructions;
- When you click ads, partner links, or social sharing buttons within the App, the Company may transmit necessary data per your click behavior;
- When you authorize third-party applications to access your data via API (if any), processing shall be within the scope of your authorization.
5. Data Retention Period and Deletion Mechanism
5.1 Retention Period (by Data Category)
- Account core data (name, email, phone, password hash): retained during the account's existence; processed per §5.2 after account deletion;
- Location data (GPS coordinates): used for real-time request processing; de-identified location data in server-side logs retained up to 90 days (for recommendation optimization, fraud prevention, legal evidence);
- UGC (comments, photos, videos): immediately removed from public display upon your deletion; retained in the Company's backup system for 90 days for restoration and legal evidence; may continue to be retained in the following circumstances: (a) already cited, shared, or republished by others; (b) already incorporated into training datasets; (c) involved in reports, complaints, disputes, or judicial proceedings; (d) content the Company deems necessary to retain;
- Behavioral logs (search, click, favorite, interaction records): retained for 180 days for recommendation algorithms, A/B testing, fraud prevention; after 180 days, processed for de-identification and may continue to be retained for statistical analysis (the retention of ad impression and click records is governed separately by §3.4 and is not subject to the 180-day period in this item);
- Device and anti-fraud data (device fingerprint, IP, login records, anomaly events): retained for 24 months for security analysis; if disputes or reports arise, retained until 5 years after dispute conclusion (the IP addresses contained in ad impression and click records are retained separately under §3.4 and are not subject to the 24-month period in this item);
- Transaction and payment data: retained for at least 7 years per the Business Accounting Act, Income Tax Act, Business Tax Act; if disputes arise, retained until conclusion;
- KYC document files (Merchant or special verification only): contract term + 7 years after termination;
- Customer service interaction records, tickets, refund application documents: retained for at least 5 years;
- Legal-related documents (contract consent records, policy version records, judicial request records): retained for at least 10 years;
- Merchant operational data: retained during the merchant account's existence; retained for 7 years after account termination for financial settlement, audit, and commercial analysis;
- Offline cache data: stored on your device, automatically managed by the App; you may clear App cache at any time.
5.2 Account Deletion Process
Application Method: You may execute self-service deletion in the App: "Profile" (bottom navigation bar) → "Settings" → scroll to "Danger zone" at the bottom → red "Delete account" button → confirmation dialog "Delete your account?" → "Confirm delete", or submit a written application by email to support@swayfoodapp.com (Members) / merchant@swayfoodapp.com (Merchants).
Processing Flow:
- T+0 (Day of Application): The account is immediately disabled; publicly displayed reviews, posts, profile photos and other personally identifiable fields are marked as "Anonymous User"; paid entitlements, accumulated points, coupons, physical benefits, merchant binding relationships are immediately lost (processed per the Refund and Cancellation Policy; in principle non-refundable and not compensable);
- T+7 days: The account’s core identifying data (name, email, telephone number) is deleted from or encrypted in the main database; the Company will at the same time match your telephone number against the customer rosters uploaded by merchants (§2.6) and delete or de-identify any matching data together with it.
- T+30 days: Identifiable data in backup systems gradually de-identified or deleted;
- T+90 days: Data not subject to legal retention is cleared within reasonable scope; confirmation email sent.
5.3 Legal and Legitimate Interest Retention Exceptions
Notwithstanding your exercise of the right to deletion, the Company may continue to retain all or part of relevant data in the following circumstances to perform legal obligations or protect legitimate interests:
- Transaction, invoice, financial vouchers required to be retained under the Business Accounting Act, Income Tax Act, Business Tax Act, Electronic Invoice Implementation Regulations;
- Lawful requests from courts, prosecutors, police, regulatory authorities;
- Existing or reasonably anticipated litigation, arbitration, administrative proceedings, reports, complaints;
- Existing or reasonably anticipated chargebacks, payment disputes, refund applications;
- Records of violations of the Community Guidelines, Merchant Service Agreement, Refund Policy by the Company; re-cooperation restriction lists for serious violations (pursuant to Article 11.5 of the Merchant Service Agreement, for a reasonable and necessary period, in principle not exceeding 2 years, limited to the same business entity in breach);
- Identifiable information necessary for anti-fraud, anti-money laundering, sanctions evasion prevention;
- Historical records that have been incorporated into backups, logs, training datasets, audit trails and cannot be immediately deleted;
- UGC lawfully cited, republished, or shared by others;
- Necessary retention for the Company's legitimate interests (including IP protection, reputation protection, partnership maintenance).
Data retained under the above exceptions shall be processed on the minimization principle, used only to the necessary extent, and does not affect the Company's lawful retention status of such data.
5.4 Restoration Window
Within 30 days of account deletion, you may apply for restoration by emailing the Company's customer service; after 30 days, restoration is not possible because the data has been progressively deleted at the technical level. With respect to your restoration request, the Company shall consider it in good faith in accordance with the Personal Data Protection Act, and shall not refuse it absent a statutory or legitimate ground (such as the data being irrecoverable, the rights of third parties, or a legal retention exception); if refused, the Company shall notify you in writing or by email with specific reasons, and you may file a complaint with the Personal Data Protection Commission or the relevant competent authority under the Personal Data Protection Act, or seek remedies in accordance with law.
5.5 User Block Records
Records of you blocking other users in the App are part of your personal preferences, stored only in your account, and not publicly displayed or shared with the blocked third party. The retention period of block records is consistent with the lifecycle of your account; you may unblock at any time in Settings → Blocked List. See Community Guidelines Article 10 for the detailed mechanism.
Customer rosters uploaded by merchants: deleted immediately when the merchant deletes them itself; where a merchant account is suspended, rejected, or terminated, deleted after notice and an export period of not less than 30 days; where a merchant account is deleted, purged after the 30-day restoration window has expired. Audit records of import operations (not containing the content of the roster) are retained for 5 years.
6. Your Rights
6.1 Rights under the Personal Data Protection Act and GDPR
Under Article 3 of the Personal Data Protection Act and (where applicable) the GDPR, you may exercise the following rights regarding your personal data:
- Right of inquiry / access: inquire which of your personal data the Company holds;
- Right of rectification: request correction of inaccurate or incomplete data (most fields can be self-modified in the App);
- Right of deletion: request deletion of account and related data, subject to statutory requirements;
- Right to cease collection, processing, or use: request the Company to cease specific-purpose processing;
- Right of data portability (GDPR): obtain a machine-readable copy of your personal data held by the Company;
- Right to object (GDPR): object to automated decision-making or marketing pushes based on legitimate interest. As regards the personalization of Google ads in the App, you may refuse or change your choice at any time by the methods listed in §8.3; you may also email support@swayfoodapp.com to object, and we will explain the options and assist you in completing the settings;
- Right to withdraw consent: withdraw consent-based processing at any time; withdrawal only affects future processing;
- Right to file a complaint: file a complaint with the Personal Data Protection Commission, consumer protection authorities, or local competent authorities.
6.2 Limitations on Exercise of Rights (Important)
Your above rights may be limited or refused in the following circumstances; the Company has reasonable discretion over the decision to limit / refuse:
- The Company may refuse or limit exercise of rights based on legal grounds under Articles 11, 19-21 of the Personal Data Protection Act, or Articles 15-22 of the GDPR; any extension of the processing period may be made only under §6.4;
- Data the Company is required to retain by legal obligations (including tax law, accounting law, criminal procedure, money laundering control) is not subject to the right of deletion;
- Historical records that have been incorporated into backups, logs, training datasets, audit trails cannot be processed within a reasonable time;
- Requests that are clearly unmeritorious, excessively frequent, harassing, or malicious — the Company may refuse or charge reasonable administrative costs (NT$500 minimum per request);
- Where exercise of rights involves third-party rights (such as other users' UGC, merchant data), the Company may limit the scope of provision;
- Where the Company cannot verify your identity, additional verification data may be required; if verification fails, the Company may refuse to process;
- Requests for data involving the Company's trade secrets, intellectual property, business secrets, internal review standards, recommendation algorithms, anti-fraud mechanisms, or commercial cooperation relationships — the Company may not disclose;
- Where force majeure, third-party service provider limitations, or technical difficulties prevent processing within the applicable period, the Company may extend that period only once under §6.4 and shall notify you of the reason in writing; if the request still cannot be fully fulfilled after the extension, the Company may fulfil it in part and explain why.
6.3 Method of Exercise
You may exercise your rights through any of the following methods:
- Self-service operations in App Settings (fastest; for rectification, deletion, push / marketing preferences);
- Email to support@swayfoodapp.com, with subject:
[Personal Data Rights] Request Type - Account ID, and provide: identity verification information, specific request scope, and desired processing outcome.
6.4 Processing Timeline
The Company handles your requests in accordance with Article 13 of the Personal Data Protection Act and, where applicable, Article 12(3) of the GDPR, and the periods in items (1) and (2) below are counted in calendar days: (1) for requests under Article 10 of that Act to inquire about or review your personal data or to be provided with copies of it, the Company shall decide whether to grant or deny the request within 15 days of accepting it; where necessary, this period may be extended once by no more than 15 days, and the Company shall notify you of the reason for the extension in writing; (2) for requests under Article 11 of that Act to supplement or correct your personal data, to stop its collection, processing or use, or to delete it, the Company shall decide whether to grant or deny the request within 30 days of accepting it; where necessary, this period may be extended once by no more than 30 days, and the Company shall notify you of the reason for the extension in writing; (3) for requests under the GDPR for data portability, objection to processing, or withdrawal of consent in writing, the Company shall handle the request within one month of receiving it; where necessary, this period may be extended once by no more than one month, and the Company shall notify you in writing of the reason for the extension within one month of receiving the request. If you withdraw consent or refuse personalised advertising yourself in the App under "Settings" or by the methods in §8.3, this takes effect immediately. The Company's response may be in the form of providing data, refusal with stated reason, or request for additional verification.
If you are not a SWAY member but find that a merchant has uploaded your data to the Platform, please write to support@swayfoodapp.com with the subject line: [Roster Inquiry / Deletion] Restaurant Name - Last Four Digits of Your Telephone Number. Because the collector of such data is that merchant, the Company will forward the matter to that merchant for handling within 3 business days and cooperate in carrying it out; we will first confirm by SMS verification code that the number is held by you before accepting the request.
7. Data Security Measures
The Company adopts reasonable technical and organizational security measures appropriate to data risks to protect your personal data:
- Transmission encryption: all data transmission uses TLS 1.2 or above encryption;
- Password protection: passwords are hashed with PBKDF2-SHA512 (100,000 iterations) plus random salt, irreversibly;
- Access control: the database employs strict role-based permission control (RLS), least-privilege principle, employee duty separation;
- Audit and monitoring: regular security audits, vulnerability scans, penetration tests, SIEM monitoring;
- Input sanitization: all user inputs sanitized to prevent injection attacks (SQL Injection, XSS, CSRF);
- WAF and DDoS protection: application-layer protection through Cloudflare and other infrastructure providers;
- Backup and disaster recovery: regular encrypted backups, geographically distributed storage, automatic anomaly switching;
- Employee confidentiality: all employees sign non-disclosure agreements; access to sensitive data requires authorization with audit trail;
- Incident response: a data breach response procedure is in place. The Company’s central competent authority is the Ministry of Digital Affairs of Taiwan, and the Company is subject to that Ministry’s Regulations Governing Security Measures for Personal Data Files in Digital Economy-Related Industries. Where a personal data security incident endangers the Company’s normal operations or the rights of a large number of data subjects, the Company must notify the Ministry of Digital Affairs within 72 hours of becoming aware of the incident, or notify the municipal or county (city) government with a copy to the Ministry.
Despite the Company's best efforts to protect your data, network transmission and electronic storage cannot guarantee 100% security. You shall safeguard your account password, third-party OAuth credentials, and QR codes, and not share with others. Losses caused by your account management failures shall be borne by you (see Terms of Service §3.3).
8. Cookies, Tracking Technologies, and Device Identifiers
8.1 Cookie Categories
The Company's official website and App WebView components use the following Cookies and similar technologies:
- Necessary Cookies (cannot be refused): website operation, login session management, CSRF protection, language preference, Cookie consent status records;
- Functional Cookies: remembering your settings, layout preferences, recent browsing history;
- Analytics Cookies: this website does not currently use any third-party website analytics Cookies;
- Advertising and Marketing Cookies: this website does not currently use any third-party advertising tracking Cookies;
- Third-Party Cookies: Cookies that may be set by Google, Apple, Meta, X, LINE, Cloudflare, ECPay, embedded content (YouTube, maps), and other service providers.
8.2 In-App Tracking Identifiers
Within the SWAY App, the Company also uses the following identification technologies:
- Advertising identifiers (the IDFA on iOS; the advertising ID (GAID) on Android): on iOS, only if you chose to allow tracking at the system "Allow tracking" prompt; on Android, unless you have deleted it in your system settings. This identifier is read by the Google Mobile Ads SDK contained in the App and transmitted to Google, and is used to serve and personalize advertising, to measure performance, for frequency capping, and for fraud prevention (see §4.4); the Company's servers do not store your advertising identifier;
- Device identifiers: device IDs, push tokens (APNs / FCM token) provided by the system;
- SDK and Pixels: event tracking via analytics, push, anti-fraud, and advertising SDKs;
- Device fingerprint: for preventing account fraud, cross-border location forgery, and simulator use;
- Local storage: localStorage, IndexedDB, Cache API for offline cache, preference memory, and ad frequency capping (timestamps only, no identifiers).
8.3 Your Choices
- You may manage or refuse non-essential Cookies through browser settings; you may also toggle analytics / marketing Cookies at the website's Cookie consent banner;
- iOS: the App may ask, through the system prompt, whether you allow tracking; you may turn it off at any time under "Settings → Privacy & Security → Tracking". If you refuse, Google cannot obtain your IDFA, and you may still see non-personalized advertising;
- Android: you may delete or reset your advertising ID under "Settings → Google → Ads" (menu names may differ slightly depending on the device model);
- Google Account: you may manage Google's personalized advertising settings in Google My Ad Center (https://myadcenter.google.com);
- European Economic Area (EEA) / United Kingdom / Switzerland: before displaying advertising, the Company obtains and records your choice regarding the use of advertising through Google’s consent management tool (User Messaging Platform, UMP); you may reopen that form at any time in the App under "Settings → Privacy settings → Ad privacy options" to change or withdraw your choice, and the change takes effect immediately;
- Paying members: after upgrading to SWAY Plus, you will no longer see any advertising, including Google AdMob ads and ad slots purchased by merchants within the platform;
- Refusing analytics or advertising Cookies / identifiers will not affect the Service's basic functions but may affect personalized experience, ad relevance, and recommendation accuracy.
8.4 "Do Not Track" Signal
The Company's website currently does not respond to the browser Do Not Track (DNT) signal, as the industry has no unified standard. You may exercise your preferences through the methods in §8.3.
9. Protection of Children and Minors
9.1 Minimum Age
The minimum age for use of the Service is 13 years old. The Company does not deliberately collect personal data of children under 13. Upon discovery of inadvertent collection, the Company shall delete and terminate the account within a reasonable time. Parents / guardians who discover that a child under 13 is using the Service should immediately contact support@swayfoodapp.com to report.
9.2 Minors Aged 13 to 18
Minors aged 13 (inclusive) to 18 (exclusive) using the Service (especially for posting UGC, binding merchants, paid purchases, push subscriptions, social interaction) shall obtain prior consent from the legal representative. The act of registration shall be deemed consent obtained. The legal representative shall, within the scope of the supervisory duty owed under Article 187 of the Civil Code, be jointly and severally liable with the minor for damages (involving payment disputes, UGC legal liability, disputes with other users, disputes with merchants, etc.). However, if the legal representative has exercised reasonable supervision, or if the damage would have occurred notwithstanding the exercise of reasonable supervision, the legal representative may be relieved of liability for damages pursuant to Article 187, Paragraph 2 of the Civil Code.
9.3 Rights of Parents / Guardians
- May request the Company to provide a summary of their minor child's data on the Service;
- May request deletion of the minor child's account (proof of relationship and identity required);
- Refund applications by minors are processed under the strict requirements of §2.8 of the Refund and Cancellation Policy;
- The Company may require parents / guardians to sign a 90-day no re-registration undertaking; violation shall be deemed malicious repeat application.
9.4 Expedited Deletion
Deletion requests by minors or their legal representatives shall be prioritized within 7 working days, but still subject to the legal and legitimate interest retention exceptions in §5.3 (such as payment disputes, litigation, report cases).
10. Cross-Border Data Transfer
10.1 Cross-Border Transfer Regions
Due to the global distribution of data centers of the technical service providers the Company relies on, your personal data may be stored, processed, and transmitted in the following regions (including but not limited to):
- Asia-Pacific: Taiwan (primary operating location), Japan (Supabase pooler primary node), Singapore, Korea, Hong Kong;
- North America: United States (location of Cloudflare, Anthropic, OpenAI, Google AI, and other service providers);
- Europe: Ireland, United Kingdom, Germany (EU nodes of certain service providers);
- Other: other regions where the Company's service providers' global CDN and backup nodes are located.
10.2 Legal Basis for Cross-Border Transfer
The Company adopts the following safeguards for cross-border transfer:
- Transfers to regions such as the United States are conducted under each service provider's Data Processing Agreement (DPA), Standard Contractual Clauses (SCCs), and applicable certification mechanisms (such as the EU-US Data Privacy Framework, where applicable);
- For data subjects within the GDPR scope, processed under appropriate safeguards under GDPR Art. 46;
- For data subjects within the Republic of China (Taiwan) Personal Data Protection Act scope, conducted under Article 21, where the National Development Council has not announced restrictions;
- Recipients are required to provide data protection standards equivalent to or higher than this Policy.
10.3 Data Subject's Consent
By using the Service, you consent to the Company's cross-border transfer for the above purposes. You may withdraw such consent at any time in accordance with the Personal Data Protection Act; however, transfers lawfully conducted prior to withdrawal shall not be affected. If you do not consent to cross-border transfer, you may cease use of the Service and exercise your right of deletion under Section 6.
11. Policy Updates
11.1 The Company reserves the right to amend this Policy at any time. Amended versions shall be published on this page with updated "Last Updated date."
11.2 Material Changes (including substantial expansion of data collection scope, addition of sharing recipient categories, change of cross-border transfer regions) shall be announced 7 days before effective date by the methods of notice in §8 of the Terms of Service. Non-Material Changes (including text refinement, section number adjustments, typo corrections, supplements consistent with the spirit of this Policy) may take effect immediately upon publication, without prior notice obligation.
11.3 After the amended version takes effect, your continued use shall be deemed agreement to the amended content. If you do not agree, your sole remedy is to immediately cease use of the Service and exercise the right of deletion under §6.3.
11.4 Version Application: for the handling of specific disputes or complaints, the version of the policy at the time of the event or application date shall apply; not the version at the time of registration or earliest use.
12. Contact Us
For any privacy-related inquiries, complaints, or data rights exercise requests, please contact:
The Company's privacy team shall provide initial reply within 5 working days, and process rights exercise requests within the timelines in §6.4.
If you have concerns about the Company's privacy processing, after first contacting the Company without satisfactory response, you may further file complaints with the Personal Data Protection Commission, Consumer Protection Authority, or (for GDPR-applicable data subjects) the Data Protection Authority of your jurisdiction.
v3 Supplemental Clauses (V1 Launch Edition)
The following clauses are added at SWAY V1's official launch (May 2026) and have legal effect equivalent to all other clauses of this Policy; in case of conflict between this section and any preceding section, this section shall prevail.
Supplementary Article 1 QR Code Scan Data
- Purpose of Collection: When you scan a SWAY QR code at a partner merchant's premises, the Service collects the following data for review-authenticity verification:
- Scan time (hour, minute, second)
- Your device's GPS location at the time (used to verify in-store scanning)
- The scanning device's IP address and device fingerprint (used to prevent fraudulent activity)
- Scope of Use:
- The above data is used solely for: (a) verifying review authenticity; (b) preventing fraud; (c) anonymized merchant statistics (not traceable to individuals).
- With respect to the foregoing scan data, merchants cannot see your personal data; they can only see aggregate figures such as "14 genuine customers left reviews." (Customer rosters uploaded by merchants themselves are not covered by this; see Supplementary Article 5.)
- Retention Period: 90 days, after which the data is automatically anonymized. Anonymization is irreversible.
- Opt-out: You may request immediate deletion of your scan records at "Personal Settings → Privacy → Scan Records."
Supplementary Article 2 Behavioral Retargeting Push Notifications
- What is Behavioral Retargeting: When you have scanned a QR code at a SWAY partner merchant's premises but have not yet bound as a member of that merchant, the merchant may push coupons or promotional messages to you through the SWAY system.
- Off by Default: This feature is set to "Off" by default, and becomes effective only after you explicitly opt in at "Personal Settings → Privacy → Behavioral Retargeting."
- Data Isolation: Even when you opt in, the merchant still cannot obtain your personal data, contact information, or user ID. The merchant can only set targeting conditions (e.g., "non-members who scanned the QR within the last 30 days"), and the message is delivered by the SWAY system on the merchant's behalf.
- Frequency Cap: The same merchant is limited to at most 1 behavioral retargeting push per user per month.
- Consent Withdrawal: You may turn off this feature in the settings page at any time; withdrawal takes effect immediately.
Supplementary Article 3 Advertising-Related Data
- To provide a precise and fair advertising experience, the Service collects your ad-impression and click behavior within SWAY for:
- Calculating merchant ad Quality Score (CTR, rating, and other components)
- Avoiding repeated exposure to the same ad
- Statistical analysis (aggregated level, no personal identification)
- Preventing click fraud and billing merchants (see §3.4)
- Such data will not be sold or disclosed to merchants; merchants receive only aggregated statistical reports.
- SWAY Plus paying members are not shown any advertising, including Google AdMob ads and ad slots purchased by merchants within the platform (full-screen launch ad, top banner, scrolling carousel). The in-platform merchant ads seen by free members are sold under publicly disclosed auction rules and are labeled "#Sponsored". Google AdMob's data processing is described in §4.4.
Supplementary Article 4 Recommendation Algorithm Disclosure
- SWAY's "Random Restaurant Pick," "Search Result Ranking," and "Personalized Recommendations" are computed based on the following publicly disclosed factors:
- Merchant rating and review count
- Distance
- Your past preferences (favorites, reviews, QR verification history)
- Whether the merchant subscribes to Plus Merchant (a small boost is applied: a 0.1-star increment added to the ranking score; this boost is publicly disclosed)
- Ad slots and natural recommendation results are clearly distinguished in the UI; ads are always labeled "#Sponsored" or "Advertisement."
- In the natural recommendation ranking, paid plans receive only the small, publicly disclosed boost described above (a 0.1-star increment added to the ranking score for Plus Merchant and above); the ranking is otherwise driven primarily by organic factors such as merchant rating, review count, and distance. Merchants cannot obtain, through payment, any ranking preference beyond that boost. The ranking of separate ad slots is governed by the auction rules.
Supplementary Article 5 Customer Lists Uploaded by Merchants
Some partner merchants upload the customer rosters they have collected themselves to the Platform, or add them record by record in the merchant back office, so that they can identify their own customers within SWAY's reservation, waitlist, and seating functions. These customers do not need to have, and will not thereby obtain, a SWAY account.
・Data categories: the customer's name or form of address, contact telephone number, the notes and tags entered by that merchant itself (for example: regular, vegetarian, no peanuts), and the creation and update times.
・Data source: uploaded by that merchant from its existing customer records (such as a previous reservation system or in-store paper records), or entered by that merchant itself in the back office.
・Status of the parties: with respect to this category of data, the collector is that merchant, and the Company merely stores it as entrusted by that merchant and makes it available to that merchant for inquiry in its own back office. The Company will not provide this data to other merchants, will not merge it into SWAY's member database, will not match it against or identity-link it to SWAY member data, will not use it for any marketing or push notifications, and will not use it for model training or statistical analysis.
・Representations of the uploading merchant: the uploading merchant must represent to the Company that such data was lawfully collected by it directly from customers in the course of its business, that it has performed its statutory notification duty toward the data subjects and obtained their consent or has other statutory grounds, and that the data does not contain special categories of personal data such as medical records, medical treatment, or health examinations.
・Storage and outsourcing: such data is stored in the facilities of the Company's cloud service providers, which may be located outside the Republic of China, currently including Japan, the United States, and the service providers' global redundancy nodes. The categories of sub-processors used by the Company are: cloud database and authentication services, application server hosting services, and network and information security services.
・Retention period: the same as the period during which that merchant's account subsists. The data is purged as soon as the merchant deletes it itself; where a merchant account is suspended, rejected, or terminated, the Company deletes it after giving notice and providing an export period of not less than 30 days, with one further reminder 7 days before deletion; where a merchant account is deleted in its entirety, the data is purged after the 30-day restoration window has expired.
・Operation records: the Company additionally records the operation record of each import, addition, and deletion (the merchant employee account performing the operation, the time, the number of records, the version of the statement consented to, and the source IP address), for audit and evidentiary purposes, with a retention period of 5 years. Such records do not contain the content of the roster.
・Your rights: if you find that a restaurant has uploaded your data to SWAY, you may contact that restaurant directly, or write to support@swayfoodapp.com. Because the collector of such data is that merchant, we will forward the matter to that merchant within 3 business days and cooperate in handling it, and will at the same time tell you which merchant uploaded it; where that merchant takes no action within 7 days after we forward the matter, we may cease processing or delete that record directly. To protect your data, we will first confirm by SMS verification code that the telephone number is held by you before accepting the request; before verification is complete, we will neither confirm nor deny to any person whether a given number exists in any merchant's list.
・Please note: reservation and waitlist records you previously completed through SWAY or that restaurant are data separately collected by the Company under this Policy, and their deletion is handled per Sections 5 and 6. When we respond to you, we will explain what has been deleted, what is retained as required by law, and the reasons therefor.
Appendix: Template for Merchants to Post or Notify Customers (Not Part of This Policy)
This restaurant, in order to provide reservation and seating services, uses the customer management system provided by "SWAY CO., LTD. (SWAY)" to hold your name, telephone number, and the service notes and tags recorded by this restaurant. That data is collected by this restaurant and this restaurant is responsible for it; SWAY merely holds it as entrusted by this restaurant, will not use it for marketing, and will not provide it to other stores. The data may be stored in the facilities of this restaurant's outsourced service providers located outside the country (Japan, the United States). You may at any time inquire of, correct, or request deletion from this restaurant; contact: [restaurant telephone number].
Recurring Auto-Renewal Notice
When you upgrade to Plus Members in the SWAY App, billing shall be processed through ECPay's recurring billing service; for purchases through Apple App Store / Google Play, IAP auto-renewal is also used. The system shall automatically charge per the contract on a monthly, semi-annual, or annual basis; you may cancel at any time in the App, with current entitlements continuing to expiration and no charge for the next period.
Refund Policy: Refunds for the Service are governed entirely by the Refund and Cancellation Policy. Please read the full Policy before purchase. In conflicts between this Policy and that Policy, that Policy shall prevail.
This Policy Version 2.3, effective September 20, 2026; prior Version 2.2 effective September 1, 2026.
Correction within the same version on September 13, 2026: now that the App’s "Ad privacy options" entry point is live, the wording in §1.4, §3.4 and §8.3 has been restored, covering the collection of consent from users in the European Economic Area (EEA) / United Kingdom / Switzerland through Google’s consent management tool (User Messaging Platform, UMP) and the ability to change that choice at any time in the App under "Settings → Privacy settings → Ad privacy options". The version number (2.3) and the effective date (September 20, 2026) remain unchanged.
Correction within the same version on September 15, 2026: in §6.4, the processing period for personal data rights requests has been corrected from "30 working days, extendable to 60 working days" to the calendar-day periods under Article 13 of the Personal Data Protection Act (requests to inquire, review or be provided with copies: decision to grant or deny within 15 days of accepting the request; requests to supplement or correct, to stop collection / processing / use, or to delete: decision within 30 days of accepting the request; where necessary, each period may be extended once by no more than 15 days and 30 days respectively, with written notice of the reason); §6.2 has been corrected accordingly, removing the wording that allowed requests to be postponed because of force majeure, third-party service provider limitations or technical difficulties, so that any extension of the processing period may be made only under §6.4. The version number (2.3) and the effective date (September 20, 2026) remain unchanged.
Correction within the same version on September 16, 2026: (1) in §3.8, the wording for the parties with whom data may be integrated has been corrected to "partner content creators or marketing partners", and such integration remains limited to de-identified or aggregated form; (2) §4.1 now explains that, when an error occurs in the SWAY App, Sentry error monitoring keeps a sample of screen replays of that session with on-screen text and images masked, used only for debugging; (3) §5.2 corrects the in-App path for deleting your account yourself; (4) a new item (3) in §6.4 sets the processing period for GDPR requests for data portability, objection to processing, or withdrawal of consent; (5) the reference to a "shopping cart", which this website does not use, has been removed from §8.1; (6) §9.3 corrects the cross-reference to the Refund and Cancellation Policy (§2.7 corrected to §2.8). The version number (2.3) and the effective date (September 20, 2026) remain unchanged.
Operating Entity: SWAY CO., LTD. (registered in Taiwan as 隨食有限公司; brand name "Sui Shi SWAY")
This Policy is officially in Traditional Chinese; in case of discrepancy with any translated version, the Traditional Chinese version shall prevail.