Privacy Policy

Last Updated: October 2025

Introduction

This Privacy Policy describes how Giftastic ("we," "our," or "us") collects, uses, and handles your information when you use our gift list management application. We are committed to protecting your privacy and ensuring you understand how your data is managed.

Information We Collect

Account Information

  • Email address and password (for account creation)
  • Display name (optional)
  • Profile information
  • Authentication tokens

Usage Information

We collect data about how you interact with Giftastic, including:

  • Gift list creation and management
  • Items added to gift lists
  • Sharing interactions and link usage
  • View and engagement statistics on shared lists
  • Purchase tracking data (items marked as purchased)
  • Device and platform information

Content Information

  • Gift list names, descriptions, and icons
  • Gift item details (name, description, price, URL, images)
  • Cover images for gift lists
  • Sharing preferences and tokens

How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve our services
  • Create and manage your account
  • Enable gift list creation, management, and sharing
  • Track purchases to prevent duplicate gifts
  • Facilitate sharing of lists via unique links
  • Send service-related communications
  • Analyze app usage and improve user experience
  • Ensure security and prevent fraud

Information Sharing

We do not sell your personal information. We may share information in these situations:

With Your Consent

When you share a gift list, the recipients can view the list details you choose to share.

Service Providers

We use Firebase (Google) for backend services including authentication, database, and file storage.

Legal Requirements

We may disclose information if required by law or to protect our rights and users' safety.

Data Storage and Security

  • Your data is stored on secure Firebase (Google Cloud) servers
  • We use industry-standard encryption for data transmission
  • Authentication is handled securely through Firebase Auth
  • We implement appropriate security measures to protect your data
  • However, no method of transmission over the internet is 100% secure

Your Rights and Choices

You have the right to:

  • Access your personal information
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your data
  • Control sharing settings for your lists
  • Opt out of non-essential communications

To exercise these rights, contact us at support@giftastic.app

Children's Privacy

Giftastic is not intended for children under 13. We do not knowingly collect information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • Authentication and security
  • Remembering your preferences
  • Analytics and performance monitoring
  • Improving user experience

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last Updated" date. Continued use of Giftastic after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Data Retention

We retain your information for as long as your account is active or as needed to provide services. When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal obligations.

Third-Party Links

Gift lists may contain links to third-party websites (e.g., product links). We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.

International Users

Your information may be transferred to and processed in countries other than your own. By using Giftastic, you consent to the transfer of information to countries outside of your country of residence, which may have different data protection rules.