GDPR & Data Processing
How SwiftMile complies with EU data protection regulations.
Last updated: September 2026
1. Introduction
This document describes how SwiftMile processes personal data in compliance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
SwiftMile is committed to protecting the privacy and personal data of all users of our platform.
2. Data Controller and Data Processor
SwiftMile acts as the Data Controller for personal data collected directly from users through our platform. We determine the purposes and means of processing this data.
For Business Users using our API, SwiftMile may act as a Data Processor for delivery-related data provided by the Business User, who acts as the Data Controller.
3. Lawful Basis for Processing
We process personal data under the following lawful bases: (a) Contract performance (Art. 6(1)(b)) — for processing orders and deliveries; (b) Legal obligation (Art. 6(1)(c)) — for maintaining tax and accounting records; (c) Legitimate interests (Art. 6(1)(f)) — for service improvement and fraud prevention; (d) Consent (Art. 6(1)(a)) — for marketing communications.
For special categories of data (e.g., rider verification documents), we rely on legal obligations and explicit consent.
4. Categories of Personal Data
We process the following categories of personal data: identification data (name, email, phone), location data (GPS coordinates, addresses), financial data (Stripe payment method references — we do not store card numbers), transactional data (order history, ratings), and verification data (rider ID documents, vehicle registration).
GPS location data is collected from riders only during active deliveries and is not continuously tracked when riders are offline.
5. Data Subject Rights
You have the right to: be informed about how your data is processed, access your personal data, rectify inaccurate data, erase your data, restrict processing, receive your data in a portable format, and object to processing.
To exercise any of these rights, contact our Data Protection Officer at dpo@swiftmile.se. We respond within 30 days of receiving your request.
6. Data Processing Operations
Location data: Rider GPS positions are collected during active deliveries and retained for 90 days for route optimization and dispute resolution. Location data is not used for behavioral profiling.
Payment data: All payment processing is handled by Stripe, a PCI-DSS compliant processor. SwiftMile receives only payment method references — never card numbers or CVVs.
Communication data: Chat messages between riders, dispatchers, and customers are retained for 6 months for support and dispute resolution.
Verification data: Rider documents (ID, vehicle registration, insurance) are retained for 3 years after account closure for legal compliance.
7. Data Security Measures
We implement appropriate technical and organizational measures: encryption in transit (TLS 1.2+) and at rest, role-based access controls with least-privilege principle, regular security audits, data minimization, and pseudonymization where possible.
Access to personal data is restricted to authorized personnel with a legitimate need. All staff are trained on GDPR compliance.
8. Data Retention
Account data: retained for the account lifetime plus 30 days after closure. Order data: 7 years (tax compliance). GPS logs: 90 days after delivery. Chat messages: 6 months. Rider verification documents: 3 years after account closure.
Anonymized, aggregated data may be retained indefinitely for analytics purposes.
9. International Data Transfers
Personal data may be transferred to third countries outside the EU/EEA, including the United States (for Stripe payment processing and Mapbox mapping services).
Such transfers are made under the protection of Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the EU-US Data Privacy Framework.
10. Data Protection Officer
Our Data Protection Officer (DPO) can be contacted at dpo@swiftmile.se for any questions regarding your personal data or to exercise your rights under GDPR.
You may also contact the Swedish Data Protection Authority (Integritetsskyddsmyndigheten, www.imy.se) to lodge a complaint.
11. Right to Complain
If you believe SwiftMile has not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the supervisory authority in your jurisdiction — in Sweden, the Integritetsskyddsmyndigheten (IMY).
You also have the right to an effective judicial remedy against SwiftMile before the Swedish courts.