1. Scope and operator
This Privacy Policy applies to haveswap.com, related Haveswap pages, and the marketplace, listing, matching, barcode, market-comparison, and Flip Check features made available through the site (collectively, the “Service”). “Haveswap,” “we,” “us,” and “our” refer to the operator of the Service.
This Policy does not govern another user’s handling of information you choose to share with them, third-party websites you visit, payment services you use directly, shipping carriers, or any transaction conducted outside Haveswap.
2. Information we collect
Information you submit
When you post or edit a listing, Haveswap may collect the item description and category, photo, condition, working status, asking price, sale or trade preference, wanted item, broad location, shipping preference, notes, public contact handle or email address, and listing status or outcome.
When you use Flip Check, barcode lookup, market comparisons, or listing-generation tools, we may process an item description, barcode, photo, condition, verification details, asking price, direct costs, feedback, and the results generated for you.
Device ownership credentials and preferences
Haveswap does not currently require a conventional account. The site creates a random owner identifier and high-entropy owner token in your browser so that the same browser, or someone with your private manage link, can edit or close your listing. The raw owner token is stored locally on your device; a one-way hash is stored with the listing. We may also store interface preferences such as your selected appearance, contact preference, broad location, and shipping preference in browser local storage. Browser local storage is convenience state only and is not treated as proof of legal acceptance.
Optional listing recovery email
When you create a listing you may optionally provide a private recovery email. It is not required to post. It is not displayed on the public listing, is not included in public listing APIs, and does not create a Haveswap account. The address is used only to verify that recovery method, to restore listing-management access if you lose the private manage link, and for security or abuse handling associated with recovery. Knowing the email address alone is not enough to control a listing.
A recovery email becomes active only after you confirm a single-use verification link sent to that inbox. Until then it cannot recover the listing. Haveswap stores a keyed one-way value derived from the normalized address rather than publishing or returning the address. We do not claim that value is encryption. The raw owner token is never emailed and is never recovered; successful recovery issues a new owner capability.
Usage, assent, and diagnostic information
When you post a listing, Haveswap records an immutable legal-assent row bound to that listing. The row stores the Terms version, Privacy Policy version, assent schema version, the posting surface, the creation time, and the same one-way owner-token hash used to control the listing. The raw owner token is not stored. That record is created in the same database transaction as the listing. Listings created before this assent table exists are not backfilled with a historical acceptance record; they remain readable and can still be hidden or closed by the original owner.
We may also collect interaction events such as listing creation or edits, contact and share clicks, surfaced trade matches, Flip Check usage, product category, generated decision, confidence indicators, and voluntary feedback. These events help operate, secure, debug, enforce, and improve the Service. Legal acceptance is not stored as a detached telemetry event.
Technical information
Our hosting and security systems may receive IP address, request time, requested URL, browser or device information, referrer, and similar server-log data. Haveswap uses IP address in short-lived application rate-limit buckets and, for listing create/edit protection, stores a salted one-way hash of the requesting IP in short-lived database rate-limit records. The raw IP is not stored in that database rate-limit table. Hosting and infrastructure providers may maintain their own security and access logs under their policies.
Cookies and local storage
Haveswap primarily uses browser local storage rather than an account cookie to remember ownership credentials and interface preferences. Browser storage is not proof of legal acceptance. Our hosting, security, or embedded-service providers may use cookies, headers, or similar technologies necessary to deliver and protect their services.
3. Information that becomes public
Live listings are public and may include the listing photo, item details, price or trade terms, condition, broad location, notes, public contact information, relative posting time, and seller-provided claims. Other users may copy, screenshot, index, repost, or retain public information outside Haveswap’s control.
Closing, hiding, or removing a listing from the live marketplace stops ordinary public display on Haveswap, but it does not guarantee deletion from search-engine caches, screenshots, third-party archives, messages already sent, backups, security records, or copies held by other people.
Private owner tokens and private manage links are not intended to be public. Anyone who obtains a valid private manage link may be able to edit or close the associated listing. You are responsible for keeping it confidential. Optional recovery email addresses are not part of the public listing.
4. How we use information
We use information to:
- publish, organize, search, filter, match, edit, hide, and close listings;
- connect interested users directly through the public contact method supplied by a seller;
- produce item identification, listing suggestions, market evidence, risk flags, and Flip Check results;
- remember ownership credentials and user-selected preferences on a device;
- record the version of legal terms accepted during listing submission and enforce our agreements;
- verify an optional recovery email and restore listing-management access when that method is used;
- measure use, diagnose errors, prevent spam or abuse, enforce limits, and secure the Service;
- investigate suspected fraud, theft, counterfeiting, unlawful conduct, infringement, or violations of our Terms;
- comply with law, respond to valid legal process, and protect users, Haveswap, and the public;
- maintain, improve, and develop Haveswap.
We do not currently sell personal information, operate a data broker, or use personal information for cross-context behavioral advertising. If those practices materially change, we will update this Policy and provide legally required choices.
5. When information is disclosed
Public marketplace
Information you include in a live listing is disclosed publicly as described above.
Infrastructure and database providers
Haveswap uses service providers to host the website and serverless functions, store marketplace records and event data, deliver fonts and other assets, send optional recovery-related email, monitor availability, and protect the Service. Current infrastructure includes Vercel, Supabase, and Google-hosted font resources. Optional listing-recovery email is sent through Resend when that feature is configured.
AI and product-identification providers
When you invoke an AI-assisted feature, the item text, photo, and relevant facts you submit may be sent to Anthropic for processing. Barcode values may be sent to UPCitemdb. Item search terms, SKU, condition, and asking-price context may be sent to eBay to obtain active marketplace asking-price evidence. These providers process information under their own terms and privacy practices.
Legal, safety, and enforcement disclosures
We may preserve, review, or disclose information when reasonably necessary to comply with law or legal process; enforce our Terms; investigate fraud, theft, counterfeit goods, threats, abuse, or security incidents; protect rights or safety; or respond to a lawful request from a regulator, court, or law-enforcement agency.
Business changes
Information may be transferred as part of a merger, financing, acquisition, reorganization, asset sale, insolvency, or transfer of the Service, subject to applicable law and appropriate notice where required.
6. Retention
We retain information for as long as reasonably needed to provide and secure the Service, maintain marketplace integrity, comply with law, resolve disputes, investigate abuse, enforce agreements, and support legitimate business operations.
A live listing remains publicly available until it is hidden, closed, removed, or otherwise moderated. Closing a listing generally changes its status and removes it from the public feed; it may not immediately erase the underlying database record or associated event history. Legal-acceptance records, recovery-email records, recovery-token records, ownership-recovery audit records, security logs, rate-limit records, provider logs, backups, and de-identified or aggregated records may follow different retention periods.
We may delete or de-identify information when it is no longer reasonably needed. We may also retain information when deletion would interfere with fraud prevention, security, legal obligations, another person’s rights, or an ongoing dispute.
7. Your choices and privacy rights
You can avoid publishing optional listing fields, use a purpose-specific public contact method, close or hide your listing with the owner controls, clear Haveswap local storage in your browser, or stop using the Service.
Depending on where you live and subject to legal exceptions, you may have rights to request access, correction, deletion, portability, restriction, objection, or information about our handling of personal information. You may also have a right to appeal a denied request or complain to a regulator.
Submit a request to burnzzzstock@gmail.com with the subject “Haveswap Privacy Request.” Describe the request and identify the relevant listing or interaction. We may need to verify that you control the listing or information before acting. Never email us your raw owner token unless specifically requested through a secure process.
We do not currently sell personal information or share it for cross-context behavioral advertising, so there is no separate sale or targeted-advertising opt-out to exercise at this time. We will honor legally required browser-based preference signals where they apply to our practices.
8. Security and incident response
We use measures intended to reduce risk, including restricted server-side credentials, database access controls, hashed owner tokens, hashed recovery tokens, keyed recovery-email lookups, input validation, rate limiting, limited public database fields, and encrypted network transport provided by our infrastructure. No website, storage system, or transmission method is completely secure, and we cannot guarantee that information will never be accessed, lost, altered, or disclosed.
You are responsible for securing your device, browser profile, email account, public contact channel, private manage link, optional recovery email inbox, and any payment or shipping method used outside Haveswap. Do not use the same secret for Haveswap ownership and another service.
If we determine that an incident requires notice under applicable law, we will provide notice using available contact information or a conspicuous notice on the Service, as appropriate.
9. Children and age limits
Haveswap is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The Terms require users to be at least 18 years old and legally able to enter a binding agreement. If you believe a child has submitted personal information, contact us so we can review and remove it as appropriate.
10. International use
Haveswap is operated from the United States. If you access the Service from another country, your information may be processed and stored in the United States or other locations where our providers operate. Those locations may have privacy laws different from the laws where you live.
11. Changes to this Policy
We may update this Policy as the Service, vendors, or legal requirements change. The effective date and version at the top identify the current Policy. Material changes may be announced through the Service or another reasonable method. Your continued use after an updated Policy takes effect is subject to the updated Policy, except where additional consent is required by law.
12. Contact
Questions, privacy requests, and complaints may be sent to: