Privacy
Last updated 9 August 2026
Plain version: SwitchLab stores the account you create and the test traffic you generate. It does not sell data, does not run advertising, and does not load third-party trackers.
What is collected
Account data — your organisation name, email address and a password. Passwords are hashed with argon2 and are never stored or logged in readable form. API keys are hashed at rest; the plaintext key is shown once, at creation.
Test traffic — the ISO 8583 messages your sandboxes send and receive, together with the sandbox configuration, scenario rules, message specs and conformance run results. This is the product: it is what the live log, the field decoder and the readiness report are built from.
Operational records — an audit log of significant account actions, and standard server logs (timestamp, request path, status, source IP) used to run and secure the service.
Analytics — aggregate page views for the public marketing pages: page, referrer, approximate country, device type. Collected by a self-hosted Umami instance running on the same server. It sets no cookies, does not track you across sites, and the data is never shared with anyone.
Do not send real cardholder data
SwitchLab is a simulator, not a payment processor. It is not a PCI-DSS certified environment, and it is not designed or approved to hold live cardholder data. Use test PANs and synthetic values. If you send real card or account numbers, you do so against this notice and at your own risk — and you should treat that data as disclosed and rotate it.
Where it runs, and how long it is kept
The service runs on a single server hosted with Amazon Web Services in the ap-south-1 (Mumbai) region, with data stored in PostgreSQL and Redis on that server. Traffic is served over HTTPS.
Message history is retained for a rolling window — 12 months by default — after which old records are dropped automatically. Delete your sandboxes, specs or account at any time and the associated records go with them. Ask us by email and we will delete an account and its data on request.
Who else sees it
No one, with two exceptions. Amazon Web Services hosts the server. If you subscribe to a paid plan, Stripeprocesses the payment — card details go to Stripe directly and never reach SwitchLab’s servers; we see only a subscription status.
Data is not sold, rented, or shared for advertising. There is no advertising on this site.
Your choices
You can export or delete your data from within the app, or ask by email. To opt out of the aggregate page-view analytics entirely, any content blocker or a browser “do not track” setting will stop it — nothing on the site depends on it.
Contact
Privacy questions, data deletion requests, or a security disclosure: hello@switchlabs.cloud. Who we are is on the about page.