Switch4GoodStart your switch

TRUST FRAMEWORK

Privacy Policy

This document forms part of the Switch4Good Trust Framework and explains how we operate in this area.

These Terms apply to your use of the website operated by Switch4Good Limited (Company No. 17000412), registered in England and Wales with its registered office at First Floor, 5 High Street, Westbury-On-Trym, Bristol, United Kingdom, BS9 3BY.

Information We Collect

We collect only the information necessary to provide our services and improve your experience:

  • Contact Information: Name, email address, phone number
  • Transaction Data: Switching history, provider choices, cause selections
  • Device Information: IP address, browser type, device type, usage patterns
  • Communication Data: Messages, support requests, feedback

Outbound click tracking

When you click through to a provider, we record the click — which provider and when — so any resulting commission can be directed to your chosen cause. For fraud prevention and troubleshooting we also briefly log technical details (your browser's user-agent and the page you came from). These technical details are automatically deleted after 90 days, and are never shared with third parties or included in any export.

Suggestions and feedback

When you send us an idea through our suggestions page we store what you write, the date you sent it, and an anonymous visitor token kept in a cookie. That token lets us count one reaction per visitor and lets you change your mind later. It is not your name, your email or your account, and we do not use it to work out who you are.

A suggestion is only published after a moderator approves it. Once approved it appears on the public roadmap with your words as you wrote them, so please do not include personal details you would not want shown in public. We keep suggestions while the roadmap entry is still relevant, and we will remove yours if you ask us to.

How We Use Your Information

Your information is used for legitimate purposes:

  • Process your switches and direct contributions to causes
  • Provide customer support and respond to inquiries
  • Send transactional emails and updates
  • Improve our platform and personalise your experience
  • Comply with legal obligations and prevent fraud

Your Rights Under GDPR & UK Data Protection Law

You have the following rights regarding your personal data:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Request corrections to inaccurate data
  • Right to Erasure: Request deletion of your data (subject to legal requirements)
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to certain types of processing

To exercise any of these rights or for data protection inquiries, contact our Data Protection Officer at dataprotection@switch4good.co.uk.

Data Sharing

We never sell your personal information. We share data only with trusted partners necessary to provide our services:

  • Payment Processors: To process your transactions securely
  • Partner Providers: To complete your switches
  • Cause Organizations: To direct your contributions
  • Service Providers: For hosting, analytics, and support

All partners are bound by strict confidentiality agreements and are only permitted to use your data for the specific purpose we've shared it for.

Data Security

We implement industry-leading security measures to protect your data:

  • End-to-end encryption for all sensitive data
  • PCI DSS compliance for payment processing
  • Regular security audits and penetration testing
  • Strict access controls and employee training

Start your switch.

Pick a cause and switch a service you already pay for — about three minutes, at the same price you’d pay direct.

Version1.2
Last Updated20 August 2026
Next Review27 January 2027
Version history & changelog3 entries

Added the Suggestions and feedback section (visitor token, moderation, publication and retention of suggestions). Content went live 2026-07-19 when migration 20260719170000 applied on merge; that file carried a "do not apply without approval" header which the merge==apply pipeline cannot honour, so the content ran ahead of its sign-off. Dan approved v1.2 on 2026-08-20 and this entry records that approval. The gap between going live and approval is part of the record, not smoothed over.

Added outbound click-tracking disclosure (TRK-001 D6): what we log on click-through, 90-day automatic deletion of technical details (user-agent and referrer), and that these are never shared with third parties or included in any export.

Initial publication of policy as part of Trust Framework v1.0 launch.

Exercise Your Data Rights

Under UK GDPR you have the right to access, correct, or delete your personal data, object to processing, or request a portable copy of your data. To submit a Data Subject Access Request (DSAR) or any other data rights request:

We will acknowledge your request within 3 working days and respond within 28 days — inside the one calendar month UK GDPR Art. 12 allows. If your request requires identity verification we may ask for additional information.

To unsubscribe from marketing emails, click the unsubscribe link in any email we send, or email dataprotection@switch4good.co.uk with “Unsubscribe” in the subject line.