Privacy policy
shwcs operates as a B2B directory and processes personal data in accordance with the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and, where applicable, the General Data Protection Regulation (GDPR). Data controller: shwcs, contact hola@shwcs.site.
Back to homeLegal bases and types of data
shwcs operates under the principles of data minimization and transparency. We process data under four legal bases: explicit consent (recorded digitally together with the version of the clause you accepted), contractual necessity (to provide the platform and the services you buy), compliance with legal obligations (such as tax obligations) and legitimate interest (to ensure the security and availability of the system).
We collect identity and access data through OAuth protocols (such as Google), limited strictly to your email address and a secure unique identifier. We do not store, process or have visibility into external credentials or any other services linked to your identity provider.
At an operational level, we collect the company information, descriptions and digital assets you choose to add to your profile, your saved lists, and metadata about your interaction with the system (declared role, sector, feature usage events).
Infrastructure and subprocessors
All information is processed on enterprise-grade infrastructure. We use hosting and file storage from Vercel (vercel.com), cloud databases (Neon, hosted on AWS us-east-1), the transactional email provider Resend and, for sponsored-slot payments, Stripe (stripe.com). These subprocessors meet encryption standards in transit (TLS 1.2+) and at rest (AES-256).
By using shwcs, you acknowledge that information may be routed, processed or stored on servers that our subprocessors distribute geographically. We require confidentiality agreements and strict security measures from our technology supply chain, but shwcs is not liable for force majeure events or breaches originating in the underlying infrastructure.
Transactional privacy and third parties
The shwcs architecture strictly separates public information from private information. Drafts, content under review, your analytical notes and your lists (unless you state otherwise) reside in silos accessible exclusively to your account.
The contact component is a passive conduit. When you start a connection request with a listed project, you give your explicit consent to transmit your profile information, email and the context of your message to the recipient. From delivery onward, processing is subject to the recipient's policies. shwcs has no authority to audit or revoke that subsequent use.
The reviews and comments you publish are public: they show the name you enter and, if you add them, your country and company size. To show a review's verification level ("Verified email" or "Company email") we use whether you confirmed your email and its domain; we never publish your email or its domain. You can edit or delete your reviews at any time, and they are included in your data export.
If you publish a solution you can declare its tax ID (in Mexico, the RFC). It stays private: we only use it to check public registries — in Mexico, the SAT's article 69-B list — and to show the result on your listing, never the ID itself. If you prove a purchase in a review, we send the SAT the fiscal folio, the RFCs and the total of the CFDI to check its status; we keep only the result, the date and an irreversible fingerprint of the folio that prevents the same receipt from being used twice.
Payments and sponsored slots
When you book a sponsored slot, you pay on Stripe’s secure page (stripe.com). Stripe receives your card or other payment details directly; shwcs never receives or stores them. During payment Stripe also collects your billing address and, if you provide it, your tax ID, to calculate taxes and issue the receipt.
shwcs keeps a record of each booking: the listing and slot booked, the dates, the amounts, taxes and refunds, the account email, the version of the conditions accepted and the transaction identifiers at Stripe. Purpose: to perform the contract, issue receipts, handle cancellations, refunds and disputes, and meet tax and accounting obligations. Legal bases: performance of a contract and compliance with legal obligations.
Stripe acts as a processor to handle the payment and, for fraud prevention and the regulatory compliance of financial services, as an independent controller under its own privacy policy (stripe.com/privacy). Its servers may be located outside your country, including in the United States.
Retention: booking and payment records are kept for as long as applicable tax and accounting law requires, even if you delete your listing or your account. In that case they are unlinked from your account and only what that obligation needs is kept.
Measuring sponsored slots: we count impressions and clicks as daily totals, without cookies or visitor identifiers, and we honor DNT and GPC signals. Advertisers see only those totals—never who saw or opened their ad, who saved their listing, or any data from your account.
Your ARCO and global rights
You may exercise at any time your rights of Access, Rectification, Cancellation and Opposition (ARCO) under the applicable data protection laws, as well as the extended GDPR rights (portability, restriction of processing, right to be forgotten). Write to us at hola@shwcs.site stating the right you wish to exercise and, if possible, the email associated with your account.
Response time: 20 business days to confirm receipt and resolve your request (extendable by 20 additional business days when its complexity justifies it). Some rights can be exercised directly from your account dashboard (profile editing, list deletion, request deletion). For complete technical deletion, a request by email guarantees erasure across all subsystems, including encrypted backups within their rotation cycles. Erasure does not reach the payment records we must keep by law, described in “Payments and sponsored slots”.
If you reside in the European Union and believe the processing infringes the GDPR, you have the right to lodge a complaint with the supervisory authority of your Member State. In Mexico, the competent authority is the Secretaría Anticorrupción y Buen Gobierno (Ministry of Anti-Corruption and Good Governance), which took over the functions of the former INAI under the LFPDPPP in force since 21 March 2025. If you reside in another country, you may contact the data protection authority of your jurisdiction.
shwcs is a B2B directory designed exclusively for professionals and business entities. The service is not intended for consumers or for anyone under 18 years of age. We will immediately delete any account or subscription that does not meet this requirement.
Auditing, telemetry and changes to this policy
We deploy telemetry instrumentation to ensure performance, prevent abuse (rate limiting) and generate visibility metrics for founders. This processing uses ephemeral counters and irreversible hash functions. We do not build individual profiles or use cross-site tracking cookies.
This policy may be updated. When changes are material, we will notify active newsletter subscribers at least 15 days in advance. The current version will always be available at shwcs.site/privacidad with its last-updated date. Last reviewed: October 2026.
