Swiftly Security Overview

Last Updated: September 17, 2025

Swiftly Security Overview

Last Updated: September 17, 2025

(Version 1.0 Effective September 1, 2026)

This overview is published by Swiftly Systems, Inc. (“Swiftly”) and is incorporated by reference into the reseller, wholesale-channel, or distribution agreement (the “Channel Agreement”) between Swiftly and an authorized reseller (the “Reseller”). It describes the security program Swiftly maintains for Retailer Data processed through the Swiftly Technology. Capitalized terms not defined here have the meanings given in the Channel Agreement.

1. Information security program

Swiftly maintains a written information security program that includes administrative, physical, and technical safeguards appropriate to the nature of the Retailer Data, designed to protect its security, confidentiality, integrity, and availability, and consistent with generally accepted industry standards for software-as-a-service providers.

The program includes, at a minimum:

•          encryption of Retailer Data in transit over public networks and at rest;

•          role-based access controls, unique credentials, and multi-factor authentication for administrative access;

•          logical separation of each Retailer’s data from that of every other Retailer;

•          logging and monitoring of access to Retailer Data;

•          secure software development, vulnerability management, and patching practices;

•          background screening and security-awareness training for personnel with access to Retailer Data;

•          business continuity and backup procedures; and

•          periodic testing and review of the program.

2. Tenant separation

Retailer Data belonging to one Retailer is logically separated from that of every other Retailer. Swiftly does not disclose the data or content of one Retailer to another Retailer.

3. Limits on Swiftly’s use of and access to data

Swiftly will not:

•          disclose Retailer Data except as compelled by law under the confidentiality terms of the Channel Agreement, to subcontractors and service providers as permitted in Section 5 below, to the Reseller or the Retailer to which the data relates, or as expressly permitted in writing;

•          access Retailer Data except to provide the Services, to address service or technical problems, at the request of the Reseller or the applicable Retailer in connection with support, or as otherwise expressly permitted; or

•          sell, share, rent, or license Retailer Data, or use it for any advertising, targeting, or monetization purpose other than as expressly set out in a Services Schedule.

4. Aggregate and Deidentified Data

“End User” means a Retailer’s consumers and shoppers and persons authorized to access or use the Swiftly Technology. “Aggregate Data” means information that relates to a group or category of End Users, or that is presented in aggregate across stores, banners, categories, or periods, from which individual End User identities have been removed and that is not linked or reasonably linkable to any End User or household. “Deidentified Data” means information that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular End User, and for which Swiftly: (i) has implemented technical safeguards that prohibit reidentification of the End User to whom the information pertains; (ii) has implemented business processes that specifically prohibit reidentification of the information; (iii) has implemented business processes to prevent inadvertent release of the information; and (iv) makes no attempt to reidentify the information. Neither includes Personal Information. These definitions are the same as those in the Channel Agreement.

Swiftly may create Aggregate Data and Deidentified Data from Retailer Data and may use it to operate, support, secure, improve, and develop its products and services, including research, analytics, statistical analysis, model development, and the construction of baselines, benchmarks, category and peer-group comparisons, and recommendations, and may make those comparisons and recommendations available to the Reseller, to Retailers, and to its other customers. In using and disclosing Aggregate Data and Deidentified Data, Swiftly will not identify, or permit a recipient to readily identify, the Reseller, any Retailer, or any enrolled store as the source; will not disclose the individual results of a Reseller, Retailer, or store to any other customer, or present data in a manner from which those individual results can readily be derived; and will not attempt to reidentify any individual. This paragraph is a covenant of Swiftly and does not qualify or condition the definitions above or the rights stated in them.

Swiftly’s rights in Aggregate Data and Deidentified Data, and in the baselines, benchmarks, models, and reporting derived from them, are perpetual. They survive expiration or termination of the Channel Agreement, the cessation of any Retailer’s enrollment, and any return or deletion of Retailer Data under Section 8, and Swiftly is not required to re-compute, unwind, or remove any baseline, benchmark, model, or report that incorporates data contributed before that time.

Swiftly will not use Retailer Data to train, fine-tune, or otherwise develop any AI system except as Aggregate Data or Deidentified Data, or to the extent necessary to configure, tune, and operate a Solution for the Reseller and the applicable Retailer. Swiftly will not permit any third-party AI provider to use Retailer Data to train, fine-tune, or improve any model or service made available to third parties, and contractually requires each such provider to process the data solely to provide services to Swiftly and to retain it no longer than necessary for that purpose.

5. Subcontractors and service providers

Swiftly may engage subcontractors, hosting providers, and other service providers, including providers of AI systems, to process Retailer Data in connection with the Services, provided that Swiftly imposes on each written obligations for confidentiality, data protection, and security no less protective than those in the Channel Agreement; permits each to process Retailer Data only as necessary to provide the Services; and remains fully responsible and liable for their acts and omissions as though they were Swiftly’s own. Swiftly will provide a list of the subcontractors and service providers then materially involved in processing Retailer Data on written request.

6. Security incidents

A “Security Incident” means a confirmed unauthorized access to, acquisition of, use of, or disclosure of Retailer Data in Swiftly’s possession or control that compromises its security, confidentiality, or integrity. Unsuccessful attempts and activities that do not compromise Retailer Data, including pings, port scans, denial-of-service attempts, and unsuccessful log-in attempts, are not Security Incidents.

Swiftly will notify the Reseller of any Security Incident without undue delay and in any event within seventy-two (72) hours after confirming it. The notice will describe, to the extent then known, the nature of the incident, the Retailer Data and Retailers affected, and the measures Swiftly has taken or plans to take to investigate, mitigate, and remediate it.

Swiftly will promptly investigate each Security Incident, take reasonable steps to mitigate and remediate it, and provide the Reseller with reasonable cooperation and information necessary for the Reseller and affected Retailers to satisfy their obligations under privacy laws.

As between Swiftly and the Reseller, the Reseller is responsible for notifying affected Retailers. Swiftly will not communicate directly with a Retailer regarding a Security Incident without first consulting the Reseller, except where required by law or where the Reseller has not responded within a reasonable period given the circumstances. Neither party will issue a public communication regarding a Security Incident that identifies the other party or a Retailer without prior written consent, except as required by law.

7. Assurance and audit materials

On the Reseller’s reasonable written request, and no more than once in any twelve (12) month period, Swiftly will provide a summary of its then-current security program and a copy of its most recent third-party security audit report or certification, if any, in each case subject to the confidentiality terms of the Channel Agreement. The Reseller may share those materials with a Retailer that is subject to written confidentiality obligations no less protective than those terms.

8. Return and deletion

Within thirty (30) days after a Retailer ceases to be enrolled, after expiration or termination of the applicable Services Schedule, or on the Reseller’s earlier written request, Swiftly will, at the Reseller’s election, return that Retailer’s Retailer Data to the Reseller or to the Retailer, or delete it, except to the extent retention is required by law, is necessary to document performance, or is contained in routine backups maintained in the ordinary course. Data in routine backups remains subject to the protections in this overview until deleted in the ordinary course. Swiftly’s rights in Aggregate Data and Deidentified Data under Section 4 are unaffected by this Section 8.

9. Prohibited data

The Solutions are not designed for, and must not receive, protected health information subject to HIPAA, payment card data subject to PCI DSS, government-issued identification numbers, biometric identifiers, precise geolocation of individuals, or information concerning any individual known to be under the age of sixteen.

10. Changes to this overview

Swiftly may update this overview from time to time and will give the Reseller at least thirty (30) days’ written notice before a change takes effect. Swiftly will not make a change that materially reduces its security or data-protection commitments during the then-current term without the Reseller’s written consent. Swiftly will keep the version in effect on the date of a Channel Agreement, and each later version, available to the Reseller on request.