StackGiftBuy a gift card

Privacy policy

Last updated: 2026-05-20

1. Data controller

StackGift Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, is the data controller for personal data processed on this site. Contact for any privacy request: [email protected].

2. Data we collect

We collect the minimum data necessary to deliver our service:
  • Email: required to deliver the gift card code.
  • Postal address: only for physical cards.
  • Blockchain transaction hash: to verify payment.
  • Server logs: IP address, user agent, timestamp (retained 30 days for security).
  • KYC data: only above regulatory thresholds (typically €1,000), via Sumsub.
We do not collect: banking data, advertising cookies, behavioral tracking.

3. Why we process it

  • Order fulfillment (legal basis: contract performance).
  • Invoicing and accounting (legal basis: legal obligation).
  • Anti-fraud and AML (legal basis: legal obligation).
  • Customer support (legal basis: legitimate interest).

4. How long we keep it

  • Order data: 18 months for customer support.
  • Invoices: 10 years (accounting obligation).
  • KYC data: 5 years after end of relationship (AML obligation).
  • Card codes: deleted within 7 days after delivery confirmation.
  • Server logs: 30 days.

5. Who we share it with

  • OxaPay: processes crypto payments (their privacy policy applies).
  • Resend: delivers transactional emails.
  • Card suppliers: receive minimum data to fulfill the order.
  • Sumsub: processes KYC data when triggered.
All processors are bound by data processing agreements under GDPR article 28.

6. Your rights

You have the right to access, rectify, erase, port, and object to the processing of your personal data, and to lodge a complaint with your local data protection authority. Send requests to [email protected].

7. International transfers

Where data is transferred outside the EEA, we rely on Standard Contractual Clauses or adequacy decisions issued by the European Commission.

8. Security

Data in transit is encrypted with TLS 1.3. Data at rest is encrypted on managed databases. Access is restricted to authenticated staff and protected by 2FA.

Placeholder draft. This privacy policy must be reviewed by a qualified DPO or lawyer before any public launch.