Privacy Policy

Last updated: 27 March 2026

1. Who We Are

GiftStack (hereinafter "we", "us", or "our") is the data controller within the meaning of the General Data Protection Regulation (GDPR / AVG). You can reach us at contact@giftstack.eu.

2. What Personal Data We Collect and Why

Data Purpose Legal basis (Art. 6 GDPR)
E-mail address & hashed password Account creation, authentication, and account recovery Performance of a contract (Art. 6(1)(b))
Names of gift recipients you add (Receivers) Core application functionality — tracking gift ideas per person Performance of a contract (Art. 6(1)(b))
Gift names, prices, and event information you enter Core application functionality Performance of a contract (Art. 6(1)(b))
Your user ID, error context, and technical diagnostics Error tracking and application stability (Sentry) Legitimate interest (Art. 6(1)(f)) — maintaining a secure and stable service

We do not use your personal data for advertising, profiling, or automated decision-making.

3. Data Retention

We retain your account data for as long as your account is active. If you request deletion of your account, we will erase your personal data within 30 days, except where a longer retention period is required by law. Error-tracking data in Sentry is retained for 90 days.

4. Third-Party Processors

We use the following sub-processors, all bound by a data processing agreement or equivalent safeguards for international transfers (Standard Contractual Clauses):

Processor Purpose Location
Fly.io, Inc. Cloud hosting & infrastructure (servers run in Frankfurt, Germany) United States
Tigris Data (via Fly.io) Encrypted database backup storage United States
Sentry, Inc. Application error tracking and diagnostics United States

Where processors are located outside the European Economic Area (EEA), the transfers take place under Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent safeguards.

5. Your Rights

Under the AVG/GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — request deletion of your data ("right to be forgotten").
  • Restriction — ask us to restrict processing of your data.
  • Data portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interest.
  • Withdraw consent — where processing is based on consent, you may withdraw at any time.

To exercise any of these rights, please email us at contact@giftstack.eu. We will respond within one month.

6. Right to Lodge a Complaint

You have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (AP): www.autoriteitpersoonsgegevens.nl.

7. Cookies

GiftStack uses only a single, strictly necessary session cookie to keep you logged in and a CSRF token cookie to protect form submissions. No tracking, analytics, or advertising cookies are used. No cookie consent banner is required for strictly necessary cookies.

8. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the service after a material change constitutes acceptance of the revised policy.

9. Contact

contact@giftstack.eu