Last updated: April 2026

Privacy Policy

1. Data Controller

The data controller for personal data is GiftWave. For any requests related to the processing of your personal data, you can contact us through the contact page.

2. Data collected

We collect the following data: email address, display name, avatar (if provided), authentication data through third-party providers (Google), data related to gift lists created (titles, descriptions, product links), shipping addresses (if entered by the user), and technical navigation data (IP address, browser type, access timestamps).

3. Purpose of processing

Your data is processed for: providing the gift list creation and sharing service, authentication and account management, sending service-related communications (registration confirmation, password recovery), service improvement and anonymized aggregate analysis, and compliance with legal obligations.

4. Legal basis

Data processing is based on: user consent at registration, execution of the service contract, legitimate interest for security and fraud prevention, and applicable legal obligations.

5. Data retention

Personal data is retained for the duration of the active account. Upon account deletion, data will be removed within 30 days, unless legal obligations require further retention. Contact message data is retained for a maximum of 12 months.

6. Data subject rights

Under the GDPR (EU Regulation 2016/679), you have the right to: access your personal data, request correction of inaccurate data, request deletion ('right to be forgotten'), request processing restriction, object to processing, request data portability, and withdraw consent at any time. To exercise these rights, contact us through the contact page.

7. Sub-processors and data transfers

Personal data is stored on servers under our management and may be processed by the following sub-processors: Resend Inc. (transactional email delivery — USA, Standard Contractual Clauses under Art. 46 GDPR); Google LLC (OAuth authentication and anonymous traffic analytics — USA, Standard Contractual Clauses). None of these providers sell your data to third parties. We do not share your personal data with third parties for marketing purposes.

8. Complaints

You have the right to lodge a complaint with the competent supervisory authority if you believe that the processing of your data violates the GDPR.