Financial security & how RIFT protects your data

When you trust RIFT with your tax affairs, you are also trusting us with personal and financial information. That responsibility matters to us.

Whether you are already a customer or considering choosing us as your tax agent, you should feel confident that your details are handled responsibly, securely and in line with UK data-protection laws.

This guide explains how RIFT protects your data, why we use secure systems instead of email wherever possible, what information we collect and why, and how you can help keep your information safe.

How RIFT complies with data protection laws

RIFT operates in line with the UK General Data Protection Regulation and the Data Protection Act. In practical terms, this means we are clear about what data we collect, why we collect it and how it is protected.

RIFT acts as a data controller. That means we are responsible for deciding how your information is used and for keeping it secure.

We do this by:

  • Collecting only the information needed to prepare tax refunds or tax returns
  • Using your data for clear and lawful purposes, such as providing a service or meeting legal obligations
  • Keeping information accurate and up to date
  • Retaining records only for as long as required by tax and accounting rules
  • Respecting your rights, including access to your data and control over marketing preferences

If you ever have questions or concerns about how your data is handled, our team is here to help. You also have the right to raise concerns with the Information Commissioner’s Office, the UK regulator for data protection.

What information RIFT collects and why

As a tax agent, RIFT must collect enough information to prepare accurate claims and meet legal obligations.

Depending on the service you use, this may include:

  • Personal and contact details
  • Employment history and travel information
  • Income details, pensions, savings or benefits where relevant
  • Records of payments made to or from RIFT
  • Limited website usage data for security and performance monitoring

We collect only what is necessary to deliver our services properly. We do not sell personal data, and information is shared with third parties only where required to provide services or meet regulatory requirements.

How we keep your information secure

Protecting your data is just as important as collecting it, so RIFT uses multiple layers of security across its systems, website and mobile app to reduce the risk of unauthorised access, loss or misuse.

These measures include restricted system access, encrypted data storage and transfer, secure cloud backups and password-protected devices. Physical data, such as removable media, is stored securely when not in use.

Together, these controls help ensure your information remains protected, even if a device is lost or a system fails.

27 years of tax refunds

  • over £430m claimed in refunds
  • more than 160,000 customers helped
  • paid more than £100,000 in referrals each year

Secure accounts and the MyRIFT portal

When you use MyRIFT or the RIFT app, you access your information through a secure online account.

You are responsible for keeping your login details private, but we support this with secure systems, encrypted data transfer and device-level protections such as fingerprint or Face ID authentication on supported devices.

Uploading documents directly through MyRIFT helps prevent paperwork being misplaced, intercepted or sent to the wrong place. Your documents are immediately linked to your claim and visible to the specialist handling it, which also helps avoid delays. Our daily backups and restore points mean your information remains safe even if you lose your phone or computer.

Why we recommend secure upload instead of email

Email is convenient, but it is not always secure. Messages can be sent to the wrong address, intercepted or caught in pesky spam filters.

For that reason, we encourage customers to upload documents through MyRIFT or the RIFT app wherever possible. This includes payslips, P60s, receipts, mileage records and other supporting paperwork.

Some forms, such as HMRC authorisations that require a physical signature, still need to be posted. Where this applies, we explain what is required and why.

Using secure upload helps protect your data and keeps your claim moving smoothly.

How our team's access to data is controlled

Protecting your information also means making sure it is only accessible to the right people.

At RIFT, access to customer data is limited to authorised team members who need it to do their job. Systems are protected by passwords, encryption and access controls, and staff are trained in their data-protection responsibilities.

These safeguards reduce the risk of accidental access or misuse and help maintain accountability across the business.

While we invest heavily in security, our customers also play an important part.

To reduce risk and avoid delays, we recommend:

  • Uploading documents through MyRIFT rather than email
  • Using strong, unique passwords and keeping them private
  • Securing your phone, laptop and email account
  • Staying alert to phishing messages claiming to be from HMRC or tax providers
  • Keeping your contact details up to date

If you are ever unsure whether a message is genuine, contact us directly.

RIFT has been helping customers with tax refunds and returns since 1999. Over that time, we have processed hundreds of thousands of claims and reclaimed hundreds of millions of pounds for clients.

Our systems and processes are designed to protect customer information while keeping things as straightforward as possible. Most delays are linked to missing paperwork rather than security issues, which is why using secure upload and following guidance helps keep claims on track.

At RIFT, we make it our mission to always go above and beyond UK data-protection laws and remain accountable for how customer data is handled. Secure systems, encryption and access controls protect your information across our website, app and internal systems.

MyRIFT and the RIFT app provide safe ways to upload documents and track your claim. We collect only the information needed to deliver our services and meet legal requirements.

By using our secure systems and following simple security steps, you can feel confident that your data is treated with care and your claim is managed responsibly.

If you have any questions about data security or your account, our team is always happy to help.

Why people love us

Since 1999, we've helped over 160,000 people claim back more than £400m.

Aat Logo 677E5c5203691 Acca Logo 677E5c31c9db2
Start now

RIFTPROD2 - Subscriber