Information we collect
SlugSwap collects only the information needed to provide its student tools:
- Account information: your Google-provided name, email address, profile photo URL, and an internal user identifier.
- GET account information: an encrypted device credential, account names, balances, and barcode data when you choose to link UCSC GET.
- Point-sharing activity: donation preferences, claim codes, redemptions, allowances, and notification preferences.
- Device messaging data: an Expo push token and mobile platform when you enable notifications.
Map searches and your current location stay on your device. SlugSwap does not store precise or coarse location data.
How we use information
We use this information to:
- sign you in and maintain your SlugSwap profile;
- show GET balances and barcode tools you request;
- operate donations, weekly allowances, and short-lived claim codes;
- send point-sharing notifications you enable;
- protect the service, diagnose failures, and respond to support requests.
We do not sell personal information, run third-party advertising, or use your data to track you across apps or websites.
Services we rely on
SlugSwap uses Google for sign-in, Supabase for authentication, Neon for database hosting, Vercel for the web service, Expo for optional push notifications, and the CBORD GET service to provide features you explicitly request. These providers process information under their own terms and privacy policies. We share only what is needed to operate the relevant feature.
Retention and security
We retain account information while your SlugSwap account is active. GET credentials are encrypted at rest. Access is limited to the service components that need the data to fulfill your requests.
When you delete your account, we delete your profile, stored GET credential, donation settings, requests, push tokens, and other directly linked records. Transaction records involving another student may remain only after the link to you and any balance snapshot have been removed. Hosting providers may retain limited security and operational logs on their standard schedules.
Your choices
You can unlink GET, disable notifications, or sign out at any time.
To permanently delete your account, open More → Account → Delete accountin the SlugSwap app. This deletes your SlugSwap account; it does not delete your Google or UCSC GET account.
Questions and changes
SlugSwap is an independent student-built project and is not an official UCSC or CBORD service. It is intended for university students and is not directed to children under 13.
We may update this policy as the product changes. Material revisions will be reflected by the effective date below. For privacy questions or requests, open a support request through our contact link. Do not include GET credentials or claim codes.