Privacy Policy

Last updated: December 21, 2025

1. Introduction

Gift Whisper ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our gift exchange platform at https://giftwhisper.app (the "Service").

Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: Email address for authentication and account recovery
  • Profile Information: Display name and profile picture (optional)
  • Circle Data: Circle names, descriptions, dates, budget ranges, and settings
  • Wishlist Data: Items, descriptions, links, and prices you add to wishlists
  • Communications: Secret notes and messages exchanged with other participants
  • Media: Photos and images you upload to share moments

2.2 Information Collected Automatically

  • Device Information: Browser type, operating system, and device identifiers
  • Usage Data: Pages visited, features used, and interaction patterns
  • Log Data: IP address, access times, and referring URLs
  • Cookies: Essential session cookies for authentication (see Section 7)

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, maintain, and operate our gift exchange platform
  • Authentication: To verify your identity and secure your account
  • Communications: To send authentication codes, notifications about your circles, and service-related updates
  • Matching: To facilitate anonymous gift exchange matching between participants
  • Improvements: To analyze usage patterns and improve our Service internally
  • Security: To detect, prevent, and address fraud, abuse, and security issues
  • Legal Compliance: To comply with applicable laws and legal obligations

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for marketing purposes. Your data is not for sale.

We may share your information only in the following limited circumstances:

  • With Circle Participants: Information necessary for the gift exchange (e.g., your name, wishlist items shared with your gifter)
  • Service Providers: Trusted third parties who assist in operating our Service (hosting, email delivery, file storage)
  • Legal Requirements: When required by law, court order, or governmental authority
  • Protection of Rights: To protect our rights, privacy, safety, or property, and that of our users
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to you

5. Third-Party Service Providers

We use the following categories of service providers to operate our Service:

  • Cloud Infrastructure: For hosting and data storage
  • Email Services: For sending authentication codes and notifications
  • File Storage: For storing uploaded images and media

These providers are contractually obligated to protect your data and use it only for the purposes we specify.

6. Data Security

We implement appropriate technical and organizational security measures to protect your personal information, including:

  • Encryption of data in transit using TLS/SSL
  • Secure data storage
  • Passwordless authentication (no passwords stored)
  • Regular security assessments and updates
  • Access controls and authentication for our systems

While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

7. Cookies and Similar Technologies

We use only essential cookies necessary to:

  • Maintain your authenticated session
  • Remember your preferences (such as dark mode)
  • Ensure the security of your account

We do not use tracking cookies, advertising cookies, or third-party analytics that collect personal information.

8. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes described in this policy:

  • Active Accounts: Data is retained while your account is active
  • Circle Data: Deleted when a circle is deleted by the Circle Keeper
  • Account Deletion: All personal data is permanently deleted upon account deletion request
  • Legal Requirements: Some data may be retained longer if required by law

9. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data
  • Portability: Request a copy of your data in a portable format
  • Opt-Out: Unsubscribe from non-essential email communications
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time

To exercise these rights, please contact us at privacy@giftwhisper.app.

10. Children's Privacy

Our Service is not directed to children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer data internationally, we implement appropriate safeguards to protect your information.

12. Additional Disclosures

For European Users (GDPR)

If you are in the European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with a supervisory authority. Our legal basis for processing your information is typically your consent, the performance of our contract with you, or our legitimate interests in operating the Service.

For California Residents (CCPA)

California residents have additional rights under the California Consumer Privacy Act (CCPA). We do not sell personal information. You have the right to know what personal information we collect, request deletion, and not be discriminated against for exercising your privacy rights.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of material changes by updating the "Last updated" date and, where appropriate, providing additional notice (such as via email or in-app notification). We encourage you to review this policy periodically.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email:privacy@giftwhisper.app