Security
GiftDesk asks gift teams and stores to centralize recipient addresses and fulfilment status. This page describes what we store, who can see it, and how we are building toward formal compliance — without claiming certifications we do not hold yet.
Data we handle
- Gift team People list — names, emails, phones, shipping addresses, notes, and assignment ownership
- Shopify order & fulfilment data — order names, tags, tracking, and normalized delivery status for campaign members
- Accounts & sessions — Google SSO for gift teams; Shopify Admin auth for merchants; desk session grants
- Messages & alerts — ticket threads, outbound email metadata, optional Slack channel assignments
Who can see what
- Store (A) — full ops data for their shop’s campaigns
- Gift team (B) — desks and people scoped to campaigns shared with them; assign limits alerts to relationship owners
- Recipient (C) — branded gift page for their shipment only; no account required for confirmation
Hosting & transport
Application traffic is served over HTTPS. Merchant system of record and portal data live in managed Postgres / hosting providers documented in our internal security program. Tokens for desk links can be rotated; optional desk password is available on Pro.
Retention & deletion
Campaign history is retained up to 24 months on Pro and above. Plus plans include GDPR-aware retention controls. Deletion or anonymization requests for recipient PII can be opened from Settings (Plus) or emailed to privacy@giftdesk.app. See Privacy for the product-fact draft.
Support response targets
- Security incidents: acknowledge within 1 business day
- Privacy / deletion requests: acknowledge within 2 business days
- General support: support@giftdesk.app
Compliance roadmap
We are preparing a SOC 2 Type I program (data inventory, subprocessors, access control, incident response). We do not claim SOC 2 or ISO 27001 certification today. Program notes live in-repo for the team; buyers can request a current status summary via security@giftdesk.app.
International fulfilment
GiftDesk syncs Shopify fulfilment and carrier tracking as the merchant provides it. We do not operate a customs, duties, or multi-currency engine — those remain with the shop and their carriers. See Integrations.