Privacy Policy
Last updated: 2026-07-31. Questions: privacy@giftdesk.app.
Who we are
GiftDesk (`giftdesk.app` and the Shopify app) provides shared gift-campaign desks for merchants (stores) and gift teams. Recipients may open a branded gift page; they do not need an account for delivery confirmation.
Data we process
- Gift team accounts — Google SSO identity, workspace membership, seats, alert preferences
- People / roster — recipient names, emails, phones, shipping addresses, notes, CRM/CSV source metadata
- Merchant Shopify data — shop domain, orders tagged into campaigns, fulfilment and tracking fields, campaign settings
- Messages & delivery — ticket content, outbound email/Slack metadata needed to send alerts
- Technical logs — access timestamps, error logs for reliability (see Security)
Why we process it
To match recipients to orders, show live fulfilment on the shared desk, send scoped alerts on delivery and exceptions, render recipient gift pages, and bill via Shopify / seat plans.
Sharing
We do not sell personal data. Data is shared with subprocessors required to run the product (hosting, database, email delivery, Shopify, optional Slack/CRM OAuth providers the customer connects). Merchants and gift teams only see data scoped to their campaigns and seats.
Retention
Campaign history is retained up to 24 months on Pro and above. Plus includes GDPR-aware retention controls in product. When retention expires or a deletion request is fulfilled, recipient PII is deleted or anonymized so it can no longer identify the person.
Your rights & deletion
Gift teams and merchants may request access, correction, or deletion of recipient PII they control via product Settings (Plus deletion path) or privacy@giftdesk.app. We acknowledge privacy requests within two business days. Recipients may contact the gift team or merchant who sent the gift, or email us with enough context to locate the record.
International transfers
Depending on hosting region, data may be processed in the EU and/or US. Formal transfer mechanisms will be stated in the counsel-approved policy.
GDPR / CCPA
We intend to support data-subject requests consistent with GDPR and CCPA/CPRA for personal information we process as a service provider / processor for customer workspaces. Roles (controller vs processor) will be clarified in the counsel-approved version.