Privacy Policy
Last updated: June 1, 2026
Best Switching Games Ltd. ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect when you use https://www.bestswitchinggames.com (the "Site"), how we use it, the legal bases on which we rely, who we share it with, how long we keep it, and the rights you have under data-protection law, including the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
For the purposes of GDPR, Best Switching Games Ltd. is the data controller of personal data collected through the Site.
1. Data controller
- Company name
- Best Switching Games Ltd.
- Trading name
- Best Switching Games
- Registration no.
- [Company Registration Number]
- VAT number
- [VAT Number]
- Registered address
- [Registered Address Line 1], [City], [Postcode], United Kingdom
- Support email
- support@bestswitchinggames.com
- Phone
- +44 (0) 000 000 0000
- Business hours
- Customer support: 24/7 · Office: Mon–Fri 09:00–18:00 GMT
2. Information we collect
We collect the following categories of personal data:
- Account data: name, email address, password (hashed), country, preferred currency and language.
- Order data: products purchased, order history, invoice information, delivered keys (associated with your Account, not stored in plain text after delivery).
- Payment data: billing name and address, last four digits of the payment instrument, transaction reference. Full card numbers and CVVs are processed directly by our PCI-DSS Level 1 payment partners and never reach our servers.
- Communications: support tickets, live chat transcripts, emails, and reviews you submit.
- Device & usage data: IP address, browser type, device identifiers, operating system, referring URL, pages viewed, time spent, and interaction events collected via cookies and similar technologies.
- Fraud-prevention signals: device fingerprint, geolocation derived from IP, behavioural risk scores, and verification documents you may voluntarily provide.
3. How and why we use your data (legal bases)
- To perform our contract with you — process orders, deliver keys, manage your Account, provide customer support, and handle refunds (Art. 6(1)(b) GDPR).
- To comply with legal obligations — tax, accounting, anti-fraud, anti-money-laundering, and consumer-protection law (Art. 6(1)(c) GDPR).
- For our legitimate interests — preventing fraud and abuse, securing the Site, analysing usage to improve our service, and defending legal claims (Art. 6(1)(f) GDPR).
- With your consent — non-essential cookies, marketing emails, push notifications, and personalised advertising (Art. 6(1)(a) GDPR). You can withdraw consent at any time.
4. Payment data
Payments are processed by PCI-DSS compliant providers including Stripe, PayPal, and selected regional processors. They act as independent data controllers for the payment data they collect. We receive only the information required to confirm and reconcile your Order. Their privacy policies govern their processing of your payment data.
5. Cookies and analytics
We use first-party and third-party cookies to operate the Site, remember your preferences, secure your session, measure traffic, and (with your consent) deliver relevant marketing. We use privacy-friendly analytics tools such as Google Analytics 4 (with IP anonymization) and may use server-side conversion APIs. Full details, categories, and instructions for managing cookies are provided in our Cookie Policy.
6. Marketing communications
Where permitted by law and with your consent, we may send you email newsletters, deal alerts, and personalized recommendations. Every marketing email contains a one-click unsubscribe link, and you can also manage your preferences from your Account dashboard. Withdrawing consent does not affect transactional emails (Order confirmations, delivery notifications, security alerts), which are essential to the service.
7. Sharing your data
We do not sell your personal data. We share it only with:
- Payment processors and fraud-prevention partners (e.g. Stripe Radar, PayPal, Sift).
- Cloud hosting and email infrastructure providers (e.g. Cloudflare, AWS, Postmark/SendGrid).
- Customer-support tooling (e.g. Zendesk, Intercom).
- Analytics and marketing partners (only with your consent).
- Professional advisors (lawyers, auditors, accountants).
- Public authorities or law enforcement when legally required.
All processors are bound by written data-processing agreements requiring confidentiality, security, and GDPR-compliant safeguards.
8. International data transfers
Some of our service providers are located outside the European Economic Area or the United Kingdom. When we transfer personal data to such jurisdictions, we rely on adequacy decisions or implement the European Commission's Standard Contractual Clauses (SCCs) together with supplementary technical and organizational measures.
9. Data retention
We keep personal data only for as long as necessary to fulfil the purposes outlined in this Policy:
- Account data: while your Account is active, plus 24 months of inactivity.
- Order, invoicing, and tax records: 7 years, as required by accounting law.
- Support correspondence: 24 months from last contact.
- Fraud-prevention records: up to 5 years from the relevant event.
- Marketing data: until you withdraw consent.
10. Security
We protect your data with industry-standard technical and organizational measures, including TLS 1.3 encryption in transit, AES-256 encryption at rest, role-based access control, hashed passwords (bcrypt/argon2), multi-factor authentication for staff access, continuous monitoring, and regular penetration testing.
11. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your data ("right to be forgotten").
- Request restriction of processing or object to processing based on legitimate interests.
- Request portability of your data in a machine-readable format.
- Withdraw consent at any time for processing based on consent.
- Lodge a complaint with a supervisory authority (e.g. the UK ICO at ico.org.uk, or your local EU DPA).
- For California residents: opt-out of "sale" or "sharing" of personal information and request information about the categories of data collected and disclosed (CCPA/CPRA).
Exercise any of these rights by emailing privacy@bestswitchinggames.com. We respond within 30 days.
12. Children
The Site is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or via a prominent Site notice at least 14 days before they take effect. The "Last updated" date at the top reflects the current version.
14. Contact
Data-protection enquiries: privacy@bestswitchinggames.com
Postal: [Registered Address Line 1], [City], [Postcode], United Kingdom
