Privacy Policy
EFFECTIVE: 10 AUGUST 2026
Who We Are
The data controller is Artium Golztman. Contact: support@swingcommand.com. Our postal address appears in the Terms of Service.
What We Collect
Providing your data is voluntary: no law requires you to give it to us. An email address is a condition of having an account, because without one we cannot provide the Service.
- Account: your email address, and your Google account identifier if you sign in with Google. We never see or store passwords; sign-in uses Google or one-time emailed codes.
- Sessions: hashed session identifiers, creation and last-use times, and a coarse browser/device class.
- Devices: an opaque random device identifier stored in a cookie on devices you use.
- Access records: for each request class, timestamps, route class, and network values derived from your IP address (network operator (ASN) and country). IP addresses are used transiently for these derivations and stored only in hashed form.
- Billing state: your tier, subscription status and period end. Payment card data never reaches us: no payment provider is active today, and when checkout opens, payments will be processed by an external payment provider named at checkout and on your receipt.
- Email events: which service emails we sent you and their delivery state.
- Telegram: if you connect Telegram, your Telegram user id and channel membership state.
- Journal content you write, stored to provide the journal to you.
Why We Process It
- To provide the Service (contract): accounts, sessions, entitlements, journal, alerts, the Telegram channel, service email.
- To keep accounts secure and subscriptions honest (legitimate interests): the monitoring described in the next section. Our balancing summary: the interest is protecting subscriber-only content and preventing account sharing and abuse; the data points are minimal (no precise location, no biometrics, no cross-site tracking, no advertising profiles); restrictive decisions are made by people; you can object and appeal.
- To meet legal obligations (tax, accounting, responding to lawful requests).
- With your consent where the law requires it, which you can withdraw.
Account and Abuse Monitoring
We tell you exactly what we watch, before it runs:
- per sign-in and per request class we record session, device identifier, network (ASN) and country values;
- deterministic thresholds (for example, an unusual number of distinct devices in 30 days) put an account in a review queue for a person to look at;
- the only automated consequence is a re-verification prompt (a code to your account email); restriction, suspension and termination decisions are made by a human;
- we do not sell data, we do not run advertising or cross-site tracking, and we do not profile you beyond the security records above.
Retention
- Access records: 6 months.
- Enforcement records and their evidence: until the matter, and any dispute over it, is closed.
- Agreement records (your acceptance of terms, withdrawal-right acknowledgment): at least 3 years.
- Account data: for the life of the account plus applicable limitation periods.
- Journal content: until you delete it or the account closes.
Sharing and Processors
We share personal data only with the providers that run the Service: Cloudflare (infrastructure, edge hosting and transactional email delivery), Google (sign-in), and Telegram (channel membership operations). If we adopt a dedicated email provider, it will be named here before it processes personal data. No payment provider is active today; when checkout opens, the payment provider will be named at checkout, on your receipt, and in this list before it processes any payment. No sale of personal data, no data brokers, no ad networks.
International Transfers
We operate from Israel on global infrastructure. Transfers of EU and UK data to Israel are covered by the European Commission's adequacy decision for Israel (and the UK's equivalent finding); transfers to processors elsewhere (including the United States) ride standard contractual clauses or an applicable adequacy framework certification.
Your Rights
- EU, EEA and UK: access, rectification, erasure, restriction, portability, objection (including to legitimate-interest processing), and complaint to your supervisory authority. An EU representative under Article 27 GDPR will be appointed and named here before we open subscriptions to EU residents; once named, you can address them alongside or instead of us.
- Israel: the Privacy Protection Law 5741-1981 as amended (Amendment 13) applies to our subscriber database. You may inspect the personal data we hold about you, in Hebrew, Arabic or English, and ask for correction or deletion of data that is wrong or not lawfully held; if we accept a correction we notify recipients of the data, and if we refuse we give you a written notice you can challenge in court. Online identifiers, device identifiers and IP-derived data are personal data under the Law. We are not among the bodies required to appoint a privacy protection officer under section 17B1 of the Law, our database is not subject to the registration duty under section 8A(a), and we maintain the records and security documentation required at our database's security level under the Data Security Regulations 5777-2017.
- Everyone: write to support@swingcommand.com; we answer within 30 days.
Cookies
Essential cookies only: the session cookie, the device identifier cookie, and the security-challenge cookie on public forms. No analytics cookies, no advertising cookies.
Children
The Service is for adults 18 and over.
Changes
Material changes are announced by email at least 30 days before they take effect; the monitoring section never expands silently.
Contact
Artium Golztman. Write to support@swingcommand.com. Our postal address appears in the Terms of Service.