Skip to content

Cart

Your cart is empty

Privacy policy

Last Updated: 4 May 2026

(Privacy inquiries: office@thechange.swiss)

We take the protection of your personal data seriously and handle your personal data confidentially and in accordance with applicable legal requirements, in particular the revised Swiss Federal Act on Data Protection (revFADP, in force since 1 September 2023) and — where applicable — the EU General Data Protection Regulation (GDPR). The use of our website is generally possible without providing personal data.

Controller

Responsible for data processing on this website is:

Swiss Health & Nutrition AG
Spühlstrasse 4
CH-9016 St. Gallen
Switzerland

Email: office@thechange.swiss
Phone: +41 71 877 10 68
UID: CHE-157.641.272

What personal data do we process?

Depending on how you interact with our services, where you reside, and as permitted or required by applicable law, we may collect or process the following categories of personal data:

  • Contact Details such as name, postal address, billing and delivery address, telephone number, and email address.
  • Financial Data such as credit/debit card and financial account numbers, payment card information, transaction details, payment method, and payment confirmation.
  • Account Information such as usernames, passwords, configurations, and settings.
  • Transaction Information viewed, added to cart, purchased, returned, exchanged, or cancelled items, and your past transactions.
  • Communication Data from your communications with us (e.g., customer support requests, chats, emails).
  • Device and Connection Data such as IP address, browser and device information, network connection, and other unique identifiers.
  • Usage Information about your interaction with our Services (e.g., when and how you browse our website).

Sources of Personal Data

We receive personal data from the following sources:

  • Directly from you: upon account creation, placing an order, newsletter sign-up, customer support inquiries, or other forms of communication.
  • Automatically via our services: about your end device when you visit our website, as well as about cookies and similar technologies.
  • From Our Service Providers: when they collect or process personal data on our behalf (e.g., payment, Shipping, and marketing service providers).
  • From our partners and other third-party providers: e.g. from marketing platforms, social networks, or advertising networks, to the extent permitted by law.

How do we use your personal data?

We process your personal data for the following purposes:

  • Provision and improvement of our services: contract fulfilment, payment processing, order execution, Shipping, returns, account management, personalisation, and improvement of the shopping experience.
  • Marketing and Advertising: sending marketing and promotional communications via email, SMS, or post, as well as placing online advertisements — always within the scope of your consent or our legitimate interests.
  • Security and Fraud Prevention: Authentication, protection against fraudulent or abusive activities, security of our services.
  • Customer Communication: Processing your requests, providing customer support, maintaining the customer relationship.
  • Fulfilment of legal obligations: Compliance with legal requirements, responding to official enquiries, asserting or defending legal claims.

Currency Conversion

By using our website, you (the visitor) consent to third parties processing your IP address in order to determine your location for the purpose of currency conversion. You also consent to this currency being stored in a session cookie in your browser (a temporary cookie that is automatically removed when you close your browser). We do this so that the selected currency remains consistent while you browse our website, enabling prices to be displayed in your local currency.

Cookies and Similar Technologies

Our website uses cookies to provide you with a better user experience. Cookies are small text files that are placed on your computer and stored by your browser. They cannot contain any malicious code.

We use the following cookie categories:

  • Technically necessary cookies: Required for the operation of the website (e.g. shopping cart, Login, language selection). Legal basis: Art. 6 para. 1 lit. b GDPR or Art. 31 para. 2 lit. a revFADP.
  • Functional Cookies: Enhance the user experience (e.g. currency selection, geo-localisation). Legal basis: Consent (Art. 6(1)(a) GDPR).
  • Analytics cookies: Allow us to analyse usage behaviour and improve the website. Legal basis: Consent.
  • Marketing Cookies: Used for personalised advertising. Legal basis: Consent.

You can give, adjust, or withdraw your consent at any time via our cookie banner.

Hosting Provider and Server Log Files

The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • IP Address
  • Browser type and browser version
  • Operating System Used
  • Referrer URL
  • Hostname of the accessing computer
  • Server request time

These data cannot be directly attributed to specific individuals. No merging of these data with other data sources is carried out. We reserve the right to review these data retrospectively should we become aware of concrete indications of unlawful use.

These data, as well as all data on this website, are stored with our hosting provider Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland, stored. Shopify's privacy policy can be found at https://www.shopify.com/legal/privacy.

Relationship with Shopify (shared responsibility)

The Services are hosted by Shopify, which collects and processes personal data regarding your access to and use of the Services in order to provide and improve the Services for us. Data you submit to the Services is shared with Shopify and with third parties who may be located in countries other than your country of residence.

To protect, expand, and improve our business, we also use certain advanced Shopify features (e.g., Shop Pay, Shopify Audiences, personalisation features) that incorporate data and information from your interactions with our store, with other Shopify merchants, and with Shopify itself. As part of these advanced features, Shopify processes personal data in part as Joint Controller within the meaning of Art. 26 GDPR. In these cases, Shopify is also the point of contact for requests to exercise your rights with regard to these processing activities.

For more information about how Shopify uses your personal data and what rights you have, please refer to the Shopify Consumer Privacy Policy at https://www.shopify.com/legal/privacy/app-users as well as in the Shopify Privacy Portal at https://privacy.shopify.com/en.

SSL/TLS Encryption

This website uses SSL/TLS encryption for security purposes and to protect the transmission of confidential content. You can identify an encrypted connection by the fact that the address bar of your browser changes from "http://" to "https://" and by the padlock icon in your browser bar. When SSL/TLS encryption is active, the data you transmit to us cannot be read by third parties.

Order Processing and Payment Service Providers

To process your order, we collect the data required for the fulfilment of the contract (name, delivery address, billing address, email, telephone, payment details). The legal basis is Art. 6(1)(b) GDPR and Art. 31(2)(a) revFADP (contractual performance).

Payment providers: Shopify Payments & Stripe

We use the service provider for processing payments Shopify Payments (provided by Shopify International Ltd., Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, Ireland).

Payment processing within Shopify Payments is handled by the service provider Stripe Payments Europe Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland).

  • Processed data: These include, but are not limited to, name, address, account number, bank sort code, credit card number, invoice amount, currency, and transaction number.
  • Purpose: The data is shared exclusively for the purpose of payment processing in accordance with Art. 6(1)(b) GDPR.
  • Fraud Prevention: Account data may also be used to employ services such as Sift for the purpose of reviewing accounts for fraud or other issues.

For more information on Shopify Payments' privacy policy, please visit: https://www.shopify.com/legal/privacy. For privacy-related information regarding Stripe Payments Europe Ltd., please refer to the following: https://stripe.com/de/privacy.

Purchase on Invoice / Instalment Payment (CembraPay)

Purchase on account (including instalment payments) is provided by CembraPay AG processed. The following apply: the T&Cs and the Privacy Policy of CembraPay AG.

Additional Payment Methods

TWINT, PostFinance, and other local payment methods: Processing is carried out directly by the respective provider in accordance with its privacy policy.

Shipping and Logistics

To process your shipment, we share your delivery address and contact details with our logistics partners:

  • The Swiss Post
  • DHL (DHL Express (Switzerland) AG, DHL Group or the responsible DHL entity in the country of destination)

Legal basis: Art. 6(1)(b) GDPR or Art. 31(2)(a) revFADP (performance of contract).

Shipping Software: ShippyPro

To create shipping labels, transmit shipment data to carriers, and provide shipment tracking and return processes, we use the software ShippyPro the Italian Valley S.r.l., Piazza Francesca Morvillo 15, 50144 Firenze (FI), Italy (P.IVA 06587610483).

As part of order processing, shipping data (name, delivery address, email address, phone number for delivery notification, order details) is transmitted to ShippyPro and forwarded to the respective shipping service provider. Processing is carried out exclusively for the purpose of shipping and shipment tracking.

We have entered into a data processing agreement (DPA) with ShippyPro. Legal basis: Art. 6(1)(b) GDPR and Art. 31(2)(a) revFADP. Privacy policy: https://www.shippypro.com/en/privacy-policy.

Newsletter data and email marketing (Klaviyo)

If you wish to subscribe to our newsletter, we require your email address and your consent to receive the newsletter. We use this data exclusively for the purpose of sending the newsletter and related marketing communications. You may revoke your consent to the storage of your email address and its use for sending the newsletter at any time, for example via the "Unsubscribe" link in the newsletter.

Subscribing to our newsletter is carried out using a so-called Double opt-in process. This means that after registering, you will receive an email asking you to confirm your registration. This confirmation is necessary to prevent anyone from registering with someone else's email address.

Newsletter sign-ups are logged so that we can demonstrate that the registration process took place in accordance with legal requirements. This includes storing both the sign-up and confirmation timestamps, as well as the IP address.

Klaviyo

The newsletter is sent using Klaviyo, a newsletter distribution platform of the Klaviyo, Inc., 125 Summer Street, Boston, MA 02110, USA. Both the email addresses of our newsletter recipients and their additional data described in the context of these notices are processed on Klaviyo's servers. Klaviyo uses this information to send and evaluate the newsletters on our behalf.

Klaviyo may use this data to optimise or improve its own services, for example to technically optimise the delivery and display of newsletters. However, Klaviyo does not use the data of our newsletter recipients to contact them directly or to share it with third parties.

We have entered into a Data Processing Agreement with Klaviyo. The transfer to the United States is carried out on the basis of the EU-U.S. Data Privacy Framework, which Klaviyo has joined as a certified member, as well as supplementary Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR. Klaviyo's privacy policy can be found at https://www.klaviyo.com/legal/privacy-notice.

Statistical surveys and analyses in the newsletter

The newsletters contain what is known as a web beacon — a pixel-sized file that is retrieved from Klaviyo's server when the newsletter is opened. In the course of this retrieval, both technical information, such as details about your browser and system, as well as your IP address and the time of retrieval are collected. This information is used to technically improve the services — whether through technical data or through analyses of target audiences and their reading behaviour, based on retrieval locations or access times.

The statistical surveys also include determining whether newsletters are opened, when they are opened, and which links are clicked.

Cancellation / Revocation

You may cancel your subscription to our newsletter at any time, meaning you may withdraw your consent. This simultaneously extinguishes your consent to the Shipping of the newsletter via Klaviyo and to the statistical analyses. A link to unsubscribe from the newsletter can be found at the end of each newsletter.

Legal Bases

Consent to the Shipping of newsletters is granted on the basis of Art. 6(1)(a) and Art. 7 GDPR, or Art. 6(6) revDSG respectively. The use of the Shipping service provider Klaviyo, the conduct of statistical surveys and analyses, and the logging of the registration process are carried out on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR or Art. 31(2)(d) revDSG respectively.

Subscription Management (Zubs)

To the extent that you take out a subscription with us, this shall be processed via Zubs GmbH, Am Stein 6, 34327 Körle, Germany (Commercial Register Frankfurt am Main, HRB 136694, VAT ID No. DE449884692). Zubs processes your order, account, and delivery data to fulfil recurring deliveries, including the management of your subscription settings (e.g. delivery intervals, pauses, adjustments, cancellations).

As Zubs is based in Germany and data processing takes place within the European Union, No third-country transfer place. We have entered into a data processing agreement (DPA) with Zubs in accordance with Art. 28 GDPR.

Legal basis: Art. 6(1)(b) GDPR or Art. 31(2)(a) revFADP (performance of contract). Contact for data protection inquiries to Zubs: info@zubs.app. Privacy policy: https://zubs.app/legal-notices.

Web Analytics and Advertising

Google Analytics 4

This website uses Google Analytics 4 (GA4), a web analytics service of the Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. GA4 uses cookies and similar technologies that enable analysis of your use of the website. The information generated by the cookie about your use of this website is generally transmitted to and stored on Google's servers; a transfer to the USA may occur.

GA4 anonymises IP addresses by default and does not store them. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide the website operator with further services associated with website and internet usage.

Legal basis: Consent via the cookie banner (Art. 6(1)(a) GDPR). The transfer to the USA is carried out on the basis of the EU-U.S. Data Privacy Framework and standard contractual clauses. You may withdraw your consent at any time via the cookie settings.

Additional information: https://policies.google.com/privacy.

Google Ads and Conversion Tracking

We use Google Ads to promote our products. In this context, conversion tracking cookies are used to measure the effectiveness of our advertising campaigns. The provider is Google Ireland Limited. Legal basis: Consent via the cookie banner.

Meta Pixel (Facebook/Instagram) and Conversion API

We use the Meta Pixel as well as the Conversion API the Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. We use this to measure the effectiveness of our advertisements on Facebook and Instagram and to define target audiences for advertising purposes (Custom Audiences, Lookalike Audiences).

The transmission of server-side conversion data is carried out via Stape.io (Stape Solutions LLC, USA) as a server-side tagging provider on our behalf.

Legal basis: Consent via the cookie banner (Art. 6(1)(a) GDPR). Transfer to the USA on the basis of the EU–U.S. Data Privacy Framework and standard contractual clauses. Meta Privacy Policy: https://www.facebook.com/privacy/policy. Privacy Policy Stape: https://stape.io/privacy-policy.

Google Shopping / Multifeeds (WoolyTech)

To provide our product catalogue on Google Shopping, Meta platforms, and other marketing channels, we use the app Multiple Google Shopping Feeds (Multifeeds) the WoolyTech Pty Ltd, Australia. The app generates and transmits our product catalogue in the form of structured product data feeds to the respective platforms (Google Merchant Center, Meta Commerce Manager, etc.).

As part of this service, product-related data (product titles, descriptions, prices, availability, image URLs, etc.) are processed, but no direct personal data of end customers. Where the app delivers pixel-based marketing tags in users' browsers (e.g., Meta Pixel events), the respective notices of those third-party providers apply.

Legal basis: legitimate interest in effective product marketing (Art. 6(1)(f) GDPR) or consent via the cookie banner, where marketing pixels are deployed. WoolyTech Privacy Policy: https://woolytech.com/privacy-policy/.

Fonts (Google Fonts / locally embedded)

This website uses fonts that — where technically feasible — are hosted locally on our server, so that no connection to Google's servers is established. In individual cases where fonts are loaded dynamically from Google, your browser will transmit your IP address to Google Ireland Limited. Further information: https://developers.google.com/fonts/faq/privacy.

Social Media Links

Our website contains links to our profiles on social networks (Facebook/Meta, Instagram, LinkedIn, YouTube, Vimeo). These are pure Links, not embedded plug-ins. Data is only transmitted to the respective providers when you actively click on the corresponding link and are redirected to the platform. The privacy policy of the respective provider then applies on that platform:

Embedded Videos (Vimeo / YouTube)

Where we embed videos from the Vimeo or YouTube platforms, this is done in Privacy Enhanced Mode or only with your consent via the cookie banner. When playing a video, data (including your IP address) is transmitted to the respective platform. Legal basis: Consent (Art. 6(1)(a) GDPR).

Customer Communication (Superchat)

For communicating with our customers across various messaging and chat channels (e.g., website chat, WhatsApp Business, email, Instagram Direct Messenger, Facebook Messenger, SMS), we use the service Superchat the SuperX GmbH, Oranienburger Strasse 91, 10178 Berlin, Germany.

When you contact us via one of the connected channels, the data you submit (including name, contact details, message content, and technical connection data) will be processed on Superchat's servers in Germany on our behalf. We have entered into a data processing agreement (DPA) with Superchat in accordance with Art. 28 GDPR. Superchat Privacy Policy: https://www.superchat.com/de/datenschutz.

WhatsApp

If you use WhatsApp to contact us, we process your telephone number, your name, and any other data you provide in order to respond to your enquiry or, if you have given your express consent, to send you promotional messages.

The operator of the WhatsApp service is the WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, a corporate affiliate of Meta Platforms, Inc. (formerly Facebook). WhatsApp processes data in accordance with its privacy policy. Communication content is end-to-end encrypted. Where applicable, WhatsApp also collects so-called "metadata", which may contain information about the identity of senders and recipients, as well as phone numbers, device information, and information regarding the use of WhatsApp (e.g. duration and frequency). WhatsApp also uses this data for its own purposes, such as improving the WhatsApp service. We have no knowledge of the details of this data processing and no influence over it. We cannot rule out the disclosure of data to additional recipients within the Meta group of companies in countries outside the EU that do not offer an adequate level of data protection (in particular the United States).

You may withdraw your consent at any time by sending a message containing "Stop" in the chat or by sending an email to office@thechange.swiss Send.

Instagram Direct Messenger

If you use Instagram Direct Messenger to contact us, we process personal data that is required for establishing and maintaining communication. Instagram grants us access to the username you have chosen as well as the content of your messages.

Instagram is a service of Meta Platforms Ireland Limited (formerly Facebook Ireland Ltd.), 4 Grand Canal Square, Dublin 2, Ireland. Instagram processes data in accordance with its privacy policy. According to the information set out in the Instagram Privacy Policy, Instagram collects content provided by its users, including communications content, as well as additional information such as location, device information, and usage data. Instagram also uses this data for its own purposes. We cannot exclude the possibility that data may be shared with other recipients within the Meta group of companies (e.g., Facebook) as well as external third parties (e.g., advertising partners and analytics services) in countries outside the EU that do not offer an adequate level of data protection (in particular the United States).

You may withdraw your consent at any time by sending a message containing "Stop" in the chat or by sending an email to office@thechange.swiss send.

Legal Basis and Storage

The legal basis for data processing by us is:

  • Art. 6(1)(b) GDPR or Art. 31(2)(a) revFADP, where the communication serves to initiate or execute a contractual relationship;
  • Your consent pursuant to Art. 6(1)(a) GDPR or Art. 6(6) revFADP, if you have subscribed to promotional messages;
  • Our legitimate interest in efficient customer communication pursuant to Art. 6(1)(f) GDPR or Art. 31(2)(d) revFADP in all other cases.

Where processing is based on your consent, the data will be deleted once you withdraw your consent. Otherwise, we will delete your data as soon as the purpose of the processing no longer applies (e.g., once your enquiry has been conclusively answered). Should statutory retention periods preclude deletion, the data will be blocked from further use until the retention period has expired.

Content Delivery Network (Cloudflare)

For the delivery of static content and protection against attacks, we partially use Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. When you access our website, connection data (including IP address) is transmitted to Cloudflare. Legal basis: legitimate interest in security and performance (Art. 6 para. 1 lit. f GDPR). Transfer to the USA on the basis of the EU-U.S. Data Privacy Framework and standard contractual clauses. Privacy policy: https://www.cloudflare.com/privacypolicy/.

Translation and Multilingualism (Hextom)

Our website is available in multiple languages. For this purpose, we use the app Hextom Translate & Adapt the Hextom Inc., USA. Hextom does not process any personal data of end customers, but exclusively content and configuration data of our shop.

Third-Country Transfers

Some of the services mentioned above are based or process data in countries outside Switzerland and the EU/EEA, in particular in the United States. In these cases, we base the transfer on:

  • Adequacy decision the European Commission or Federal Council Recognition Resolution (e.g. EU-U.S. Data Privacy Framework / Swiss-U.S. Data Privacy Framework, to the extent that the provider is certified), or
  • Standard Contractual Clauses (SCC) of the EU Commission pursuant to Art. 46 GDPR or the standard contractual clauses recognised by the FDPIC, or
  • Your explicit consent pursuant to Art. 49 Para. 1 lit. a GDPR or Art. 17 Para. 1 lit. a revFADP.

Children's Data

Our services are not directed at Children. We do not knowingly collect personal data from Children who are minors in their country or under the age of 16. If you are a parent or guardian of a Child who has provided us with personal data, please contact us at office@thechange.swiss so that we may delete the data.

We do not knowingly "sell" or "share" the personal data of individuals under the age of 16 within the meaning of applicable data protection laws.

Security of Your Data

We employ technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, or alteration (including SSL/TLS encryption, access controls, and data processing agreements with our service providers). Please note, however, that no security measure can guarantee absolute protection. Residual risks exist in particular when transmitting data over the internet. Please refrain from sending sensitive or confidential information via unsecured communication channels.

Storage duration

We retain personal data only for as long as necessary for the respective purposes, or as required by statutory retention obligations (in particular commercial and tax retention periods of up to 10 years pursuant to CO Art. 958f). Newsletter data is retained until consent is withdrawn.

Your Rights

Under the Swiss revFADP and EU GDPR, you have the following rights with regard to your personal data:

  • Right to Access (Art. 25 revDSG / Art. 15 GDPR): You have the right at any time to gratuitous Information about your stored personal data, their Origin, recipient, and purpose of data processing.
  • Right of Rectification (Art. 32 revFADP / Art. 16 GDPR)
  • Right to Erasure (Art. 32 revFADP / Art. 17 GDPR)
  • Right to Restriction of Processing (Art. 18 GDPR)
  • Right to Data Portability (Art. 28 revFADP / Art. 20 GDPR)
  • Right of Objection against processing (Art. 30 revFADP / Art. 21 GDPR)
  • Withdrawal of Granted Consents with effect for the future

To exercise your rights, please contact office@thechange.swiss. We may request additional information for identity verification purposes.

Opt Out of Sale/Sharing for Targeted Advertising

Depending on where you reside, you may have the right to opt out of the "sale" or "sharing" of your personal data for the purposes of targeted advertising. You may exercise this right via the following Page.

Global Privacy Control (GPC)

When you visit our website with Global Privacy Control (GPC)-Signal in your browser, we will treat this — to the extent applicable based on your location — as an opt-out request for the device and browser you are using to visit the website. If we are able to associate the signal with an existing account, we will also apply the opt-out request to that account. For more information about Global Privacy Control, please visit https://globalprivacycontrol.org. We do not evaluate any other "Do Not Track" signals.

Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority:

Changes to This Privacy Policy

We reserve the right to amend this Privacy Policy in order to reflect changes in applicable law or in our services and data processing practices. The current version is available on this page.

 

Contact

Should you have any questions regarding our data protection practices or this Privacy Policy, or if you wish to exercise any of the rights available to you, please contact:

Swiss Health & Nutrition AG
Spühlstrasse 4
CH-9016 St. Gallen
Switzerland

Email: office@thechange.swiss
Phone: +41 71 877 10 68

In accordance with applicable data protection laws, we are the controller of your personal data.