Privacy Policy
ErasmusSwap ("we", "our", "us") is a free, non-commercial platform run from the Netherlands that connects Erasmus and other exchange students so they can swap rooms or find an Exchange Buddy in their destination city. This Privacy Policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR / AVG) and its Dutch implementation, the Uitvoeringswet AVG (UAVG).
You have the right to know how we handle your data. If any part of this policy is unclear, please please use our contact form — we're happy to explain.
1. Data controller
ErasmusSwap is the data controller within the meaning of GDPR art. 4(7). We are a small student-run project based in the Netherlands and can be reached through the please use our contact form — this replaces publishing any personal email address online. Because we process only limited data on a small scale, we are not required to appoint a formal Data Protection Officer under GDPR art. 37, but privacy questions still receive a reply within 30 days.
2. What data we collect
We only collect data that is necessary to make the platform work:
- Account data: name, email address, hashed password.
- Profile data (optional): home city, home university, exchange destination, bio, avatar.
- Listing data: room title, description, city, country, university, rent, currency, available dates, destination city, amenities, photos you upload.
- Messages: the content of messages you send to other users through the in-app chat.
- Technical data: IP address at the time of login, browser type, device type — used for anti-abuse and security only.
- Cookies / local storage: an authentication token so you stay logged in, plus a small set of preference flags (e.g. whether you've seen the onboarding). These are strictly-necessary for the service to function and do not require prior consent under art. 11.7a Telecommunicatiewet.
- Analytics (optional, opt-in): aggregated, non-identifying page-view statistics via Google Analytics with IP anonymisation. This is only loaded after you actively accept on the cookie banner. If you reject or ignore the banner, no analytics scripts run and no analytics cookies are set. You can change your choice at any time — see section 12 below.
We do not collect passport numbers, dates of birth, payment information, or any special category data (health, religion, sexual orientation, ethnicity, etc.). We do not sell your data. We do not profile users for advertising purposes. We do not make automated decisions that produce legal or similarly significant effects on you (GDPR art. 22).
3. Why we use your data (legal bases)
- To provide the service — matching, chat, listings, account management (GDPR art. 6(1)(b): performance of a contract).
- To notify you about new matches, replies, and password resets (GDPR art. 6(1)(b): necessary to deliver the service you signed up for).
- To keep the platform safe — abuse prevention, spam blocking, admin moderation (GDPR art. 6(1)(f): our legitimate interest in a safe community).
- To comply with legal obligations when we receive a lawful request (GDPR art. 6(1)(c)).
- Analytics — only after you have opted in via the cookie banner, based on your consent (GDPR art. 6(1)(a)). You can withdraw consent at any time in section 12.
4. Who we share your data with
Your data is shared only with the following processors, each bound by a data processing agreement (verwerkersovereenkomst) under GDPR art. 28, and only for the purposes listed above:
- Resend — sends transactional emails (password reset, match notifications). Only your email address, name and the message body are transmitted.
- MongoDB Atlas / hosting provider — stores the database and uploaded photos.
- Emergent / Kubernetes hosting — runs the servers.
- Wikimedia Commons — we fetch public city photos through Wikipedia's API as fallbacks; no personal data is sent.
- Google Analytics — where enabled, aggregated page views only.
Other users of the platform can see the parts of your profile and listing that you have chosen to publish (name, city, destination, room details, photos). Your email address is never shown to other users — they contact you only via the in-app chat.
5. International transfers
Our servers are located in the European Economic Area whenever possible. Some processors (e.g. Google Analytics) may transfer data to the United States. In those cases we rely on the Standard Contractual Clauses approved by the European Commission (GDPR art. 46(2)(c)) or equivalent safeguards, and only the minimum necessary data is transferred.
6. How long we keep your data
- Account data: as long as your account is active. Delete your account at any time via Profile → Danger zone — this permanently removes your profile, rooms, messages, and uploaded photos.
- Listings: until you remove them or delete your account.
- Messages: until either party deletes their account.
- Server / login logs: max 30 days for security purposes, then automatically rotated out.
7. Your rights
Under the GDPR / AVG you have the right to:
- Access the personal data we hold about you (art. 15)
- Correct data that is inaccurate (art. 16) — edit it in your profile, or ask us via the contact form
- Delete your account and associated data ("right to be forgotten", art. 17)
- Restrict processing (art. 18)
- Object to processing based on our legitimate interest (art. 21)
- Data portability — request a copy of your data in a machine-readable format (art. 20)
- Withdraw any consent you gave earlier (art. 7(3))
- Not be subject to purely automated decision-making (art. 22)
- Lodge a complaint with the Dutch Data Protection Authority — Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl)
The fastest way to exercise most of these rights is inside the app: Profile lets you view and update your data; the Danger zone button deletes everything permanently. For anything else, please use our contact form and we'll reply within 30 days as required by GDPR art. 12(3).
8. Security
We take appropriate technical and organisational measures as required by GDPR art. 32:
- Passwords are stored hashed with bcrypt — plaintext is never stored or logged.
- All traffic between your device and our servers is encrypted with TLS (HTTPS).
- Uploaded photos are served over HTTPS and stored in access-controlled object storage.
- Principle of least privilege — only designated admins have direct database access, and access is logged.
- Automated rate-limiting protects against brute-force login attempts.
9. Data breaches
In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, as required by GDPR art. 33. If the breach is likely to result in a high risk to you, we will also notify you directly and without undue delay, as required by GDPR art. 34.
10. Children
ErasmusSwap is intended for university students, typically aged 18+. Under the UAVG, minors under 16 cannot give valid consent for online services without a parent or guardian, so we do not knowingly collect data from anyone under 16. If you believe we have data about a minor, please please use our contact form and we will delete it.
11. Changes to this policy
We may update this policy from time to time to reflect changes in the service or in the law. When we make a material change, we will note it here and — if it affects you meaningfully — send you a notification email. The date at the top of this page always reflects the most recent version.
12. Cookie preferences
You accepted or rejected our analytics cookies once via the banner at the bottom of the page. You can change that decision at any time — clicking the button below clears your saved choice and reloads the site so the banner appears again.
13. Contact
Questions, requests, or complaints about this policy or how we handle your data? Please use our contact form — we won't publish any personal email address here, but every message is read and replied to by a real person within 30 days.