Privacy Policy
Last Updated: October 2025
Introduction
This Privacy Policy describes how Giftastic ("we," "our," or "us") collects, uses, and handles your information when you use our gift list management application. We are committed to protecting your privacy and ensuring you understand how your data is managed.
Information We Collect
Account Information
- Email address and password (for account creation)
- Display name (optional)
- Profile information
- Authentication tokens
Usage Information
We collect data about how you interact with Giftastic, including:
- Gift list creation and management
- Items added to gift lists
- Sharing interactions and link usage
- View and engagement statistics on shared lists
- Purchase tracking data (items marked as purchased)
- Device and platform information
Content Information
- Gift list names, descriptions, and icons
- Gift item details (name, description, price, URL, images)
- Cover images for gift lists
- Sharing preferences and tokens
How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve our services
- Create and manage your account
- Enable gift list creation, management, and sharing
- Track purchases to prevent duplicate gifts
- Facilitate sharing of lists via unique links
- Send service-related communications
- Analyze app usage and improve user experience
- Ensure security and prevent fraud
Information Sharing
We do not sell your personal information. We may share information in these situations:
With Your Consent
When you share a gift list, the recipients can view the list details you choose to share.
Service Providers
We use Firebase (Google) for backend services including authentication, database, and file storage.
Legal Requirements
We may disclose information if required by law or to protect our rights and users' safety.
Data Storage and Security
- Your data is stored on secure Firebase (Google Cloud) servers
- We use industry-standard encryption for data transmission
- Authentication is handled securely through Firebase Auth
- We implement appropriate security measures to protect your data
- However, no method of transmission over the internet is 100% secure
Your Rights and Choices
You have the right to:
- Access your personal information
- Correct inaccurate data
- Delete your account and associated data
- Export your data
- Control sharing settings for your lists
- Opt out of non-essential communications
To exercise these rights, contact us at support@giftastic.app
Children's Privacy
Giftastic is not intended for children under 13. We do not knowingly collect information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Authentication and security
- Remembering your preferences
- Analytics and performance monitoring
- Improving user experience
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last Updated" date. Continued use of Giftastic after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: support@giftastic.app
- Website: https://giftastic.app
Data Retention
We retain your information for as long as your account is active or as needed to provide services. When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal obligations.
Third-Party Links
Gift lists may contain links to third-party websites (e.g., product links). We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
International Users
Your information may be transferred to and processed in countries other than your own. By using Giftastic, you consent to the transfer of information to countries outside of your country of residence, which may have different data protection rules.