Skip to main content
Swarmed logo

Privacy Policy

Last updated: August 14, 2026

This Privacy Policy explains how Swarmed ("Swarmed", "we", "us", or "our") collects, uses, shares, and protects personal information when you use the website at beeswarmed.org and any related services, features, or applications we provide (collectively, the "Service"). It applies to visitors, registered users, beekeepers, association members, and anyone who submits or interacts with a swarm report.

This policy is designed to comply with the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and other applicable privacy laws.

1. Who We Are (Data Controller)

The Service is operated by two affiliated entities, both trading as "Swarmed":

If you have any questions about this policy or how your personal data is handled, please contact us at the email above.

2. Personal Data We Collect

We collect the following categories of personal data:

You are not legally required to provide personal data, but some data (such as your email and password) is necessary to create an account or submit a swarm report. If you do not provide required data, we may be unable to deliver the relevant feature.

3. How We Use Personal Data and Legal Bases (GDPR Art. 6)

We process personal data for the purposes and on the legal bases below.

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms and concluded that the processing is necessary and proportionate. You may object to processing based on legitimate interests as explained in Section 9.

4. How We Share Personal Data

We do not sell personal information. We share it only in the following situations:

5. International Data Transfers

Swarmed operates from the United States, and some of our service providers process data outside the European Economic Area, United Kingdom, or your country of residence. Where personal data is transferred internationally, we rely on appropriate safeguards required by law, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision where one is in place. You can request a copy of these safeguards by contacting us.

6. Data Retention

We keep personal data only as long as needed for the purposes described in this policy:

7. Security

We implement reasonable administrative, technical, and physical safeguards designed to protect personal data — including encryption in transit (TLS), encryption at rest where supported by our providers, hashed passwords, access controls, and audit logging. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected users without undue delay.

Bot and abuse protection. To keep automated scripts from submitting fake swarm reports or claiming swarms ahead of real beekeepers, our forms are protected by Cloudflare Turnstile, a service provided by Cloudflare, Inc. Turnstile runs invisibly: there is no puzzle to solve and nothing appears on screen. To distinguish humans from bots, it processes a limited set of technical signals from your browser, including your IP address, TLS fingerprint, user-agent header, and the sitekey and associated origin of the page you are on. Turnstile is not used for advertising, profiling, or cross-site tracking. Your interaction with Turnstile on the Service is governed by the Cloudflare Turnstile Privacy Addendum, which supplements Cloudflare's own privacy policy. Our legal basis is our legitimate interest in keeping the Service secure (Art. 6(1)(f) GDPR).

8. Cookies, Analytics, and Similar Technologies

We use cookies, local storage, pixels, tags, and similar technologies. Our cookie banner organizes them into four categories:

Specific third-party tools currently in use:

Session replay. With your analytics consent, PostHog reconstructs a replay of your visit so we can see where the Service breaks or confuses people. This is not a video recording and we cannot see your screen or any other tab: it is a reconstruction built from the page's own structure plus your clicks, scrolling, and page changes. Anything you type into a form field is masked before it leaves your browser, so we do not receive it. Replay is switched off entirely in our admin area and on the pages where a reporter manages their own report. On the signed-in beekeeper dashboard replay does run, but every word of text on the page is replaced with asterisks inside your browser before anything is sent, and the web address is stripped of everything after the page name. So reporters' names, addresses, and phone numbers never reach our analytics provider: what we receive for that page is the layout and your interactions with it, not its contents. Replay follows the same analytics consent as everything else in this section: deny or later revoke analytics and no replay is recorded. Our legal basis is consent (Art. 6(1)(a) GDPR) where required, and our legitimate interest in a working service elsewhere (Art. 6(1)(f)).

How you found us. When you arrive at the Service we record, in your browser's temporary session storage, the campaign tags in the link you followed (if any), the website that linked to you, and the first page you landed on. We keep only the website's domain name and the page path, never the rest of the address, so nothing from a link's query string is retained. If you then submit a swarm report or create an account, that information is saved alongside it so we can tell which outreach actually helps people find us. It is not used to build a profile of you, is not shared with advertisers, and is discarded when you close the tab if you do not submit anything.

How consent is enforced. If we detect that you are accessing the Service from the EEA, the United Kingdom, Switzerland, or any country we cannot reliably identify, our banner appears on your first visit and all non-essential categories are denied by default until you choose. Until you accept a category, we use Google Consent Mode v2 to signal "denied" for analytics, advertising storage, ad personalization, ad user data, functionality storage, and personalization storage — so Google tags load in a privacy-preserving mode that does not set identifying cookies. Your saved choice is stored in a first-party cookie (swarmed_cookie_consent) for up to 6 months, after which we ask again. Outside the EEA/UK/Switzerland we apply a permissive default consistent with applicable law.

Legal basis. Strictly necessary cookies are used without consent because the Service cannot function without them (legitimate interests / contract). For functional, analytics, and marketing cookies in jurisdictions that require it (e.g. EEA, UK, Switzerland), we rely on consent (Art. 6(1)(a) GDPR and the ePrivacy Directive).

Changing your choice. You can re-open the banner and update or revoke your choices at any time using the "Cookie settings" link in the footer. Revoking analytics or marketing also clears Google, Meta, Microsoft, and Hotjar tracking cookies from your browser on the next page load.

9. Telephone and SMS Communications (U.S. TCPA Notice)

If you provide a phone number and consent to be contacted by phone or SMS, you expressly authorize Swarmed and our lead and outreach partners — including Instantly and Networx — to contact you at that number for purposes related to your swarm report, service request, or matching with a beekeeper or service professional. These contacts may be made using an automatic telephone dialing system, artificial or prerecorded voice, or SMS / text messages, in accordance with the U.S. Telephone Consumer Protection Act (TCPA), 47 U.S.C. § 227, and applicable state laws.

Revoking consent for telephone or SMS communications will not affect lawful processing carried out before the revocation and will not prevent us from sending you transactional or service-related communications that are not subject to TCPA consent requirements.

10. Your Rights

Depending on where you live, you have some or all of the following rights:

To exercise any of these rights, email [email protected]. We will respond within the timeframes required by law (generally within one month under the GDPR). We may need to verify your identity before acting on your request.

11. California Privacy Rights (CCPA/CPRA)

California residents have the right to know what personal information we collect, use, disclose, and (if applicable) sell or share; to delete personal information; to correct inaccurate personal information; to opt out of any "sale" or "sharing" of personal information; and to limit the use of sensitive personal information. We do not sell personal information and do not share it for cross-context behavioral advertising. We will not discriminate against you for exercising your rights. To submit a request, email [email protected].

12. Automated Decision-Making

We do not use personal data to make decisions that produce legal or similarly significant effects about you solely through automated means, and we do not engage in profiling of that kind.

13. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.

14. Third-Party Links

The Service may link to third-party websites or services that we do not control. This Privacy Policy does not apply to those third parties. We encourage you to review their privacy notices before sharing personal data with them.

15. EU / UK Users

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the GDPR (or UK GDPR / Swiss FADP) applies to the processing of your personal data, and the rights described in Section 10 apply to you. The legal bases on which we rely are set out in Section 3.

Our Dutch sole proprietorship (KvK 96813733, Anna Paulownastraat 9 B, 2518BA The Hague) is our EU establishment for GDPR purposes. As a result, our lead supervisory authority is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), and an Article 27 EU representative is not required. UK users may lodge complaints with the ICO (ico.org.uk).

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, for material changes, provide additional notice (e.g. in-app message or email). Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

17. Contact Us

For questions, complaints, or requests relating to your personal data, contact us at [email protected], or by post at either: