OnceSwapOnceSwap
Legal framework

Privacy notice

What OnceSwap records about you, why it records it, who else sees it, and how long it is kept. Everything described here is something the platform actually does.

Last updated: September 2026

1. Who is responsible

OnceSwap is operated by Spiridon Iconomou, trading as OnceSwap, a sole trader (enskild firma) established in Varberg, Sweden. For the purposes of the General Data Protection Regulation, that is the data controller for everything described on this page.

Questions about this notice, or any request concerning your personal data, can be sent to hello@onceswap.com. The registered business number is available on request and appears on every invoice.

2. What is collected, and why

Account details. For creators: name, email address, and the identity and payout information you provide directly to Stripe. For clients: name, email address, and the organisation domain of that email address where it is not a personal mailbox. This is needed to operate your account and to identify the parties to a project.

Project details. The title and description of the work, the amount and currency, deadlines, delivery files, and the messages exchanged about revisions or disputes. This is needed to perform the agreement between you and the other party.

Payment records. When a project is funded, the amount, currency and payment method, the billing country, the cardholder name and email address where the card issuer supplies them, the card's brand, funding type and last four digits, the result of the 3-D Secure check, and a card fingerprint. The fingerprint is an identifier derived by Stripe that is the same for a given card across payments and from which the card number cannot be recovered. The full card number and security code are never transmitted to OnceSwap and are never stored by it.

Transaction history. Every step of a project is recorded as a dated entry: the project created, the funding request sent, funds received, work delivered, revisions requested, approval given or the review window elapsing, disputes raised and how they were decided, and funds released or refunded. This record is append-only. Entries are never edited or deleted, because a payment history that can be quietly rewritten is worth nothing to the party relying on it.

Technical records. Server logs, delivery status for the emails OnceSwap sends you, and basic security information. This is needed to keep the service running and to investigate faults.

3. Legal basis

Account, project and transaction data are processed to perform the contract you enter into when you create or fund a project, under Article 6(1)(b) of the GDPR.

Payment records beyond the transaction itself — the card fingerprint, billing country, 3-D Secure result and risk indicators — are processed on the basis of legitimate interests under Article 6(1)(f): confirming that the person who paid is the person who was invited, detecting fraud and duplicate accounts, and protecting creators from chargeback abuse. Payment providers require this of any platform that releases funds on their instruction.

Accounting records are kept to comply with a legal obligation under Article 6(1)(c), specifically the Swedish Bookkeeping Act.

4. How the transaction history is used

The record of how each party has acted — projects funded, how quickly funding arrived, deliveries made, approvals given, disputes raised and how they were decided — is part of the transaction record and is retained with it.

OnceSwap intends to use this history to set pricing: a reduced platform fee, or a lower dispute deposit, for parties with a record of completed projects. This is profiling within the meaning of the GDPR. It is used only to offer better terms, never to refuse service, and it produces no automated decision with legal or similarly significant effect. Any such pricing will be described on the payment terms page before it takes effect, and you may object to it under Article 21 by writing to the address in section 1.

OnceSwap's own conclusions about a party — how a dispute was decided — are held separately from the factual record of what occurred, and are not disclosed to other users of the platform.

5. Who else sees your data

The other party to a project sees what the project requires: your name, the project details, and the delivery and approval steps. Clients do not see other clients. Creators do not see other creators.

OnceSwap uses a small number of processors, each of which handles data only on documented instructions: Stripe (payment processing, identity and payout verification), Base44 (application hosting and the database), Resend (transactional email), and Telegram (operational alerts to the operator). Stripe acts as an independent controller for its own regulatory obligations.

Personal data is not sold, is not shared with advertisers, and is not disclosed to anyone else except where the law requires it.

6. How long it is kept

Accounting and transaction records are kept for seven years after the end of the financial year in which the project completed, as the Swedish Bookkeeping Act requires. Payment records used for fraud prevention are kept for the same period.

Delivery files are kept for as long as the project is active and for a limited period afterwards so that a completed project can be re-examined if a dispute or chargeback arises.

Account details are kept while the account is open. If you close an account, the account details are removed but the transaction records remain for the retention period above, because a completed payment cannot be unmade and the other party is entitled to their own record of it.

The transaction ledger is append-only and each entry carries a cryptographic hash of the entry before it, so no entry can be revised or removed without the change being detectable. This is a deliberate design choice and it has a consequence worth stating plainly: an individual ledger entry cannot be deleted on request during its retention period. The entries are accounting records that the Bookkeeping Act requires OnceSwap to keep, and they are also the other party's evidence of a payment they were part of — neither of which is OnceSwap's to erase. Section 7 sets out what this means for the right to erasure.

7. Your rights

You have the right to ask for a copy of the personal data held about you, to have inaccurate data corrected, to have data erased where no legal obligation requires it to be kept, to ask that processing be restricted, to object to processing carried out on the basis of legitimate interests, and to receive data you provided in a portable form.

How erasure applies here. Profile and account data — your name, email address, notification settings, saved details — is erased on request. Entries in the transaction ledger are not, for the period described in section 6: they are accounting records OnceSwap is required by the Bookkeeping Act to retain, and they are simultaneously the other party's record of a transaction they were part of. This is the exemption in Article 17(3)(b) and (e) of the GDPR, not a discretionary refusal. When the retention period ends, ledger entries relating to you are erased along with everything else. If a ledger entry about you is factually wrong, the correction right still applies in full: corrections are made by appending a corrected entry rather than by editing the original, so both the error and its correction remain visible.

Portability, concretely. Every party to a project can download that project's complete event record from the project page at any time, as a JSON file that includes the hash of each entry and the instructions to verify the chain independently. It is designed to be checked without OnceSwap's cooperation. A small number of entries carry operator-only content — payment-instrument details, internal notes — and are supplied with the content withheld but its hash included, so the record still verifies end to end and the withheld content remains fixed and checkable if it is ever disclosed.

Requests go to hello@onceswap.com and are answered within one month. There is no charge.

If you believe your data has been handled improperly you may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy@imy.se. You may also complain to the supervisory authority in your own country of residence.

8. Transfers outside the EEA

Some processors listed in section 5 operate infrastructure outside the European Economic Area. Where that occurs, the transfer is covered by the European Commission's standard contractual clauses, which form part of those providers' terms.

9. Changes to this notice

This notice changes whenever what OnceSwap records changes, and the date below is updated when it does. Material changes affecting how your data is used are notified by email before they take effect.