01Who we are
SwitchGauge (“SwitchGauge”, “we”, “us”) is a car-management service that lets you keep your vehicles, service history, running costs and reminders in one place. SwitchGauge is operated by Data Science London.
For the purposes of the UK GDPR and the EU GDPR we are the data controller for the personal data described in this notice. Our registered address is available on request while our company details are being finalised.
Questions, requests and complaints: admin@switchgauge.com.
02What we collect
We collect only what the service needs to work. In practice that is:
- Account data — your email address, display name, profile picture if you upload one, and your preferences (units, language, currency, theme). Passwords are handled by our authentication provider and are never visible to us.
- Security and session data — sign-in times, the authentication method used, IP address, browser and device description for each session. This is what powers the login-history screen and lets you revoke a session you do not recognise.
- Vehicle data — everything you record about your cars: make, model, year, registration and identification details, mileage, service visits, maintenance plans, parts and modifications, fault codes and issues, fuel and cost entries, plus any photos or documents you upload.
- Billing data — your subscription tier, trial and renewal status, and the customer and subscription identifiers issued by our payment processor. We never see or store your card number; that goes directly to Stripe.
- Location data — described separately in section 3, because it is the most sensitive thing here and it works differently from the rest.
- AI assistant and diagnosis data — if you use an AI feature, the text and vehicle context you submit is sent to the AI provider to generate a response. We log the time, model, token counts and estimated cost so you can see your usage against your plan. Chat conversations with the assistant and generated issue diagnosis advice are saved to your account so you can pick them up again on any device; you can delete any conversation at any time (which removes its messages immediately), and issue diagnosis advice is removed when its issue or your account is deleted.
- Support and email data — messages you send us, and delivery events for the reminder and notification emails we send you.
We do not use advertising trackers, third-party analytics, or behavioural profiling, and we do not sell personal data or share it with data brokers.
03Location data
SwitchGauge uses two very different kinds of location, and treats them differently.
Approximate location from your IP address
When your browser loads the dashboard, our hosting provider tells our server the approximate city your connection appears to come from, derived from your IP address. We use this for one thing: showing local weather on the dashboard when precise location is unavailable.
These coordinates are a city or network centroid — they identify roughly which city a connection is routed through, not where you are. They can be several kilometres out, and on mobile networks or a VPN they can name the wrong city entirely. We label anything derived this way as approximate. We do not store this location; it is used for the weather lookup and then discarded.
Precise location from your device (GPS)
Precise location is off unless you turn it on. Two independent things must both be true before we ever read it: you enable location in your SwitchGauge settings, and your browser or operating system grants permission when it asks.
With location enabled, we record a point only while the app is open, and only when both:
- at least 20 minutes have passed since the last recorded point, and
- you have moved more than 250 metres, or the accuracy of the reading has materially improved.
We never record a continuous track, never collect in the background, and stop immediately when you close the app or switch location off. A stationary session typically produces a single point. Each point stores the coordinates, an accuracy figure, the source, the time, the vehicle selected at the time, and the version of this notice you consented under.
Location history is kept for 90 days and then deleted automatically. You can view your history, delete it in full at any time, and withdraw consent from Settings. Withdrawing consent stops collection immediately.
When a map is displayed, Mapbox receives the browser request for the tiles needed to draw that map. This includes your IP address and the requested map area and zoom level. It does not receive your complete location history as a separate dataset, and showing a map does not collect a new GPS point.
If you deliberately request route guidance, we send Mapbox the exact origin and destination you chose to calculate that route. That disclosure is remembered on your account so we do not ask again until you switch it off in Settings or this notice changes. We do not store the route, its geometry, or its turn list on SwitchGauge servers. The last preview stays on this device until you tap Clear route or sign out. We do keep a no-coordinate route-usage record tied to your account (your plan, whether the request found a route, and its time) for 90 days to enforce the monthly allowance and investigate aggregate service use.
04Email you send us
If you email an address at switchgauge.com — for example replying to a reminder, or writing to admin@switchgauge.com — that message is delivered through our email provider and stored in our database so we can read it, reply to it and keep track of what was said. We store the sender and recipient addresses, the subject, the message itself, its technical headers, and any attachments.
This applies whether or not you have a SwitchGauge account: anyone can send us an email, and we hold what they sent. Where the sender’s address matches an account, we show that alongside the message as a possible match only — the sender address on an email is easily forged, so we treat it as a hint and never as proof of identity.
Only our administrators can read this correspondence. It is not shown to other users, and the messages you send us are not added to your account’s data in the app. Messages that fail sender-authentication checks are held separately as suspected forgeries and deleted sooner.
Legal basis: our legitimate interest in answering people who contact us and in keeping a record of what we were asked — and, where you are a customer, performance of our contract with you. How long: 24 months from the date we receive a message (90 days for messages held as suspected forgeries), after which it is deleted automatically, attachments included.
You can ask us to delete correspondence you sent us at any time. If you delete your account we remove the link between your account and any messages you sent us, but we may keep the messages themselves for the period above — a conversation involves both sides, and the record of what we were asked and what we answered is not solely your data to erase. Ask us and we will tell you what we hold.
05Why we use it, and our legal basis
- To provide the service — your account, garage, logs, reports and reminders. Legal basis: performance of our contract with you.
- To take payment and manage subscriptions — trials, renewals, invoices and failed-payment handling. Legal basis: performance of our contract, and legal obligation for keeping financial records.
- To keep accounts secure — session records, rate limiting, abuse prevention and our administrative audit log. Legal basis: our legitimate interest in protecting users and the service.
- To show local weather from approximate IP location. Legal basis: our legitimate interest in a useful dashboard, balanced by the fact that the data is coarse, is not linked to a stored location profile, and is not retained.
- To record precise location history. Legal basis: your consent, which you can withdraw at any time without affecting the rest of the service.
- To operate AI assistance where you choose to use it, and to meter it against your plan. Legal basis: performance of our contract.
- To send service email — reminders you asked for, security notices, and billing notifications. Legal basis: performance of our contract and our legitimate interest in operational communication.
07International transfers
Some of our providers process data outside the UK and EEA, including in the United States. Where they do, transfers are covered by appropriate safeguards — the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or the provider’s certification under the EU–US Data Privacy Framework. You can ask us for details of the safeguards applying to a specific provider.
08How long we keep it
- Account and vehicle data — while your account is open. When you delete your account we delete it within 30 days, except where we must keep records for the reasons below.
- Location history — 90 days, deleted automatically on a scheduled job, or immediately when you delete it yourself.
- Route-preview usage records — 90 days, then deleted automatically. These contain your account, plan, request outcome and time, but never route coordinates, geometry or directions.
- Session and login history — 12 months, then deleted automatically.
- Billing and tax records — six years after the transaction, as UK tax law requires.
- AI usage logs — retained for the life of the account for quota, billing and abuse-prevention purposes.
- AI chat conversations and diagnosis advice — chat conversations are kept until you delete them, so a conversation is there when you come back to it. Deleting a conversation removes it and its messages immediately. Generated issue diagnosis advice is saved to the relevant issue and kept until that issue or your account is deleted. Deleting your account removes all of them.
- API request records — if you use the developer API, we keep a record of each request (the method, the route, the response status and the calling IP address, but never the query or the body) for 90 days, then delete it automatically.
- Security and audit records — kept indefinitely. This covers occasions when a member of our staff accessed or changed an account, and operations through the developer API that deleted data. We keep these for as long as the service exists because they are the only record of who did what, and a trail that expires is not a trail. They are never edited or removed, including by us. See below for how this interacts with deletion.
- Email suppression list— if an email we send you bounces permanently, or you mark it as spam, we record that so we stop emailing that address. We store it as a one-way salted hash of the address — never the address itself — and keep it for as long as the service exists, including if you later delete your account: a bounce or complaint is a property of the address, not the account, and forgetting it would mean resuming mail that harms delivery for everyone else. Legal basis: our legitimate interest in protecting the deliverability of our email, and it is the minimum needed to honour a “stop emailing me” signal. You can ask us to remove an entry by contacting us.
- Email you send us — 24 months from the date we receive it, then deleted automatically along with any attachments. Messages held as suspected forgeries (they failed sender-authentication checks) are deleted after 90 days. See Email you send us above.
- Backups — deleted data may persist in encrypted backups for a short period before those backups rotate.
09Your rights
You can, free of charge:
- ask for a copy of the personal data we hold about you;
- correct anything inaccurate — most of it you can edit yourself in the app;
- delete your account and its data;
- ask us to restrict or stop a particular use;
- receive your data in a portable format;
- object to processing we base on legitimate interests;
- withdraw consent for location history, and for sending origin and destination to Mapbox for a route preview, at any time from Settings.
One limit on deletion, stated plainly: when you delete your account, the API request and API deletion records tied to your user are removed with it, but our record of administrative actions is not. Those entries identify the member of staff who acted, and may name the account they acted on. We keep them under our legitimate interest in being able to show who accessed an account, and because a security trail a subject could erase would not be worth keeping. Everything else is deleted as described above. For the same reason of a different lifecycle, our email suppression record — a one-way salted hash of an address that bounced or complained, never the address itself — is also kept past deletion: it belongs to the address, not the account, and protects email deliverability for everyone else.
Email admin@switchgauge.comand we will respond within one month. If you are unhappy with how we handled it, you can complain to the UK Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority in the EEA.
11Security
Data is encrypted in transit and at rest. Every table enforces row-level security, so one account’s data is not reachable from another’s session. Administrative actions are recorded in an audit log. API routes validate their input and are rate limited. No system is perfect: if a breach ever affects your rights, we will notify you and the relevant regulator as the law requires.
12Children's data
SwitchGauge is not intended for children. You must be at least 16 to hold an account. If we learn we have collected data from a child, we will delete it.
13Changes to this notice
If we change how we use your data we will update this page and its version number. For material changes — particularly anything affecting location — we will tell you in the app or by email before the change takes effect, and where the change relies on consent we will ask again rather than assume the old answer still stands.