Privacy Policy
Last updated: October 2026
Gifty (“we”, “our”, “us”) is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding your data. By using Gifty you agree to this policy.
1. Information We Collect
When you create an account, we collect your name and email address. If you choose to connect calendars in My Calendar (Google, Microsoft Outlook, iCloud, or a calendar link), we hold a read-only connection to each one you add. When you send a gift card, we collect the recipient's name and delivery address solely to fulfil the physical card order. If you join our early-access list, we keep your email address (and your name, if you give it) to tell you when a feature launches, and nothing else. If you give us your email in the card designer to unlock another go, we keep it for that; we only send you occasional reminders and offers if you tick the box to say yes (it starts unticked), and you can ask us to stop, or to delete your email, at any time at privacy@cardsbygifty.co.uk. We do not sell your personal data.
2. How We Use Your Information
We use your information to: create and manage your Gifty account; deliver physical gift cards to recipients; sync your calendar occasions (birthdays, anniversaries, etc.) so they appear in My Calendar; send you transactional emails (order confirmation, dispatch notification); send you occasion reminder emails if you have separately opted in (see Section 3); and improve our service through anonymised analytics.
3. Calendar Data and Reminder Emails
You can connect as many calendar sources as you like — Google accounts, Microsoft Outlook accounts, iCloud accounts and calendar links (.ics) — and choose which calendars inside each one Gifty may read. Access is read-only. We store only each event's title, date, whether it is all-day, the name of the calendar it came from, and the occasion type we detect (birthday, anniversary…). We do not store event descriptions, locations, attendees or contacts. Google and Microsoft tokens and iCloud app-specific passwords are encrypted at rest using AES-256-CBC and are used solely to fetch your calendar data. Switching a calendar off, or removing a source, deletes its synced events immediately; "Disconnect everything" deletes every synced event, every stored credential and the reminder log.
Separately from calendar sync, you may opt in to email reminders before your upcoming occasions. The toggle in My Calendar → Reminders defaults to OFF; nothing is sent until you turn it on. Once enabled, we send a transactional email a configurable number of days (1–30, default 7) before each matched event. Each email includes a one-click unsubscribe link (cryptographically signed). You can withdraw consent at any time — either via the same toggle or any email's unsubscribe link. Both actions take effect immediately. We keep a small log of which reminders have been sent (user ID + event ID + timestamp, no email content) to guarantee no reminder is ever sent twice. The log is deleted when you disconnect your calendar or delete your account.
4. Sharing with Third Parties
We share data with third parties only where necessary to run the service: our printing and postal partner, to print and deliver cards; Stripe, which processes payments as our payment processor (your card details go to Stripe directly, and we never see or store them); and the providers that host the site, store uploaded videos and send our emails. Experience redemption links are generated by our partners (Ticketmaster, Experience Days, etc.) and are subject to their own privacy policies. We do not share your data with advertisers.
5. Cookies
We use strictly necessary cookies to keep you signed in, to protect forms from spam, and to count your goes in the card designer (and remember that you've unlocked more). We do not use tracking or advertising cookies. You can manage cookies in your browser settings at any time.
6. Data Retention
We retain your account data for as long as your account is active. Completed order records are retained for 7 years for legal and accounting purposes. You may request deletion of your account and associated personal data by contacting us at privacy@cardsbygifty.co.uk.
7. Your Rights
Under UK GDPR and the Data Protection Act 2018, you have the right to: access the personal data we hold about you; correct inaccurate data; request erasure of your data; object to processing; and data portability. To exercise any of these rights, please contact privacy@cardsbygifty.co.uk.
8. Security
We use industry-standard security measures including TLS encryption in transit, AES-256 encryption for sensitive credentials at rest, and access controls limiting who can view personal data. We conduct regular security reviews. To stop abuse of public forms, sign-up links and payments, we count requests from each IP address over short time windows; those counts are used for nothing else.
9. Contact
If you have any questions about this Privacy Policy or how we handle your data, please email privacy@cardsbygifty.co.uk or write to: Gifty, Data Protection, United Kingdom.