LEGAL
Privacy Policy
Last updated: 14 July 2026
This Privacy Policy explains how GifCard ("we", "us", "our") collects, uses, discloses, and protects personal information when you use our websites, apps, and services at https://gifcard.shop (the "Service").
We design GifCard for people sending personal digital greetings and optional gift cards — often last-minute birthdays, thank-yous, and congratulations. We try to collect only what we need to run that product.
1. Who we are
GifCard is operated as a consumer digital greeting and gift product. For privacy questions, contact us at support@gifcard.shop.
2. Information we collect
Depending on how you use the Service, we may collect:
- Card content you provide — occasion, tone, recipient name, sender name, message text, GIF selection (including Giphy media URLs/IDs), style choices, and optional uploaded images.
- Gift and payment data — selected gift product, face amount, currency, and checkout status. Card payments are processed by Stripe; we do not store full card numbers on our servers. Gift fulfilment may use Tremendous (or similar partners).
- Account data — if you create an account: name, email, and password (stored hashed by our auth provider), plus session tokens.
- Technical and usage data — IP address, device/browser type, approximate location derived from IP, pages viewed, referrers, and product events (for example card created, viewed, claimed). We use cookies and similar technologies, including via PostHog for product analytics.
- Anonymous session identifiers — stored in local storage or cookies to apply rate limits and connect events even without an account.
- Reports and safety signals — if someone reports a card, we retain that report and related content for review.
3. How we use information
- Provide, operate, and improve the Service (compose, preview, share, claim gifts).
- Process payments and issue digital gifts through payment and gift partners.
- Authenticate users and show sender dashboards (open / claim status).
- Prevent abuse, spam, fraud, and illegal content (rate limits, filters, reports).
- Measure product performance and fix bugs (analytics and error reporting).
- Communicate about the Service (transactional messages, security notices).
- Comply with law and enforce our Terms of Service.
We do not sell your personal information. We do not use card messages to train public AI models for unrelated products.
4. Public card links
Share links use unguessable IDs, but anyone with the link can view the card content you chose to include (names, message, GIF, gift badge). Cards are generally not listed in search engines (noindex), but treat links as secret URLs — only send them to people you trust. Do not put highly sensitive personal data in a card.
5. Sharing with service providers
We share data with processors who help us run GifCard, for example:
- Hosting & storage — e.g. Vercel, Postgres (Neon or similar), object storage for images.
- Payments — Stripe (checkout, webhooks, fraud tools).
- Gift cards — Tremendous (or successor partners) to issue redeemable rewards.
- GIFs — Giphy (search/display; subject to Giphy's terms and attribution).
- Auth — Better Auth (email/password sessions). We may send transactional emails (password reset, verification) via Resend when configured.
- Analytics — PostHog (product analytics; may use a first-party proxy path on our domain).
Providers only receive what they need to perform their services. We may also disclose information if required by law, to protect rights and safety, or in connection with a merger or asset sale (with notice where required).
6. International transfers
We may process data in Australia and other countries where our providers operate (for example the United States or EU). Where required, we use appropriate safeguards for cross-border transfers.
7. Retention
We keep card and account data for as long as needed to provide the Service, honour gift claims, resolve disputes, and meet legal or accounting requirements. You may request deletion of account-linked data where applicable; some records (payments, fraud, legal holds) may need to be retained longer.
8. Security
We use industry-standard measures such as HTTPS, access controls, and secret management. No method of transmission or storage is 100% secure. Protect your share links and account access.
9. Children
The Service is not directed to children under 16 (or the minimum age required in your region). We do not knowingly collect personal information from children. If you believe a child has provided data, contact us and we will take appropriate steps.
10. Your rights
Depending on where you live (including Australia's Privacy Act and, where applicable, GDPR/CCPA-style regimes), you may have rights to access, correct, delete, or export personal information, object to certain processing, or withdraw consent. Contact support@gifcard.shop. You may also have the right to lodge a complaint with your local privacy regulator (in Australia, the OAIC).
11. Cookies and similar technologies
We use essential cookies/storage for sessions, security, and rate limits, and analytics tools to understand product usage. You can control cookies through your browser settings; disabling some cookies may break sign-in or checkout.
12. Pricing context (not advertising tracking)
When you attach a gift, checkout may include a platform service fee (defaults A$8.99 / US$8.99) plus gift face value and payment processing. Fee amounts may be adjusted via remote configuration; the amount shown at checkout controls. See our Terms for commercial terms.
13. Changes
We may update this policy from time to time. We will post the new version with an updated "Last updated" date. Continued use of the Service after changes means you accept the revised policy where permitted by law.
14. Contact
Privacy requests: support@gifcard.shop