Privacy Policy
Last Updated: November 15, 2025
1. Introduction
This Privacy Policy explains how GiftFinderAI.co ("we," "us," or "our") collects, uses, stores, and protects your information when you use our website at www.giftfinderai.co (the "Service").
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
2. Information We Collect
2.1 Information You Provide Directly
For Users Without Accounts:
- Gift queries and search parameters you enter
- Information submitted through contact forms
For Users With Accounts:
- Email address (required for account creation)
- Profile information you choose to provide
- Gift ideas and lists you save to your account
- Account preferences and settings
We recommend that you do not provide sensitive personal information such as birthdates, physical addresses, or payment information, as these are not required to use the Service.
2.2 Automatically Collected Information
When you use the Service, we automatically collect:
- Usage Data: Pages visited, features used, time spent on the Service, clicks, and user interactions
- Device Information: Browser type, operating system, device type, screen resolution
- Technical Data: IP address, approximate location (city/country level), referring website
- Cookies and Similar Technologies: See Section 4 for details
2.3 Third-Party Service Data
We use third-party services that may collect information:
- OpenAI: Your gift queries are processed by OpenAI's API to generate recommendations
- Amazon Product Advertising API: Product search queries to retrieve gift suggestions
- PostHog: Analytics data about how you use the Service
- Vercel: Hosting and delivery of the Service
- Supabase: Account data storage and management
3. How We Use Your Information
We use the collected information for the following purposes:
- Provide the Service: Generate AI-powered gift recommendations based on your queries
- Account Management: Create, maintain, and secure user accounts
- Service Improvement: Analyze usage patterns to improve features and user experience
- Communication: Send service-related emails, respond to inquiries, and provide customer support
- Marketing (with consent): Send newsletters or promotional content (you can opt-out at any time)
- Legal Compliance: Comply with applicable laws and legal obligations
- Security: Detect, prevent, and address technical issues, fraud, or abuse
4. Cookies and Tracking Technologies
4.1 What Are Cookies?
Cookies are small text files stored on your device that help us provide and improve the Service.
4.2 Types of Cookies We Use
Essential Cookies (Required for Service Operation):
- Authentication cookies for logged-in users
- Security and fraud prevention
- Service functionality
Analytics Cookies (PostHog):
- Track page views and user interactions
- Analyze user behavior and service performance
- Measure feature effectiveness
- Identify technical issues
Hosting Cookies (Vercel):
- Enable proper website delivery
- Load balancing and performance optimization
4.3 Managing Cookies
You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of the Service. Most browsers accept cookies automatically, but you can modify your browser settings to decline cookies if you prefer.
Note for EU/UK Visitors: We use analytics cookies that may require your consent under GDPR. By continuing to use the Service, you acknowledge our use of cookies as described in this policy.
5. How We Share Your Information
We do not sell your personal information. We share information only in the following circumstances:
5.1 Service Providers
We share information with trusted third-party service providers:
- OpenAI: Gift queries are sent to OpenAI's API for AI processing. OpenAI retains API data for up to 30 days for abuse monitoring, then deletes it (unless you've opted into data training, which we have not). See OpenAI's privacy policy for details.
- Amazon: Product search queries are sent to Amazon Product Advertising API to retrieve gift suggestions
- PostHog: Usage and analytics data for service improvement
- Vercel: Hosting provider that processes technical data to deliver the Service
- Supabase: Database provider that stores account information
These providers are contractually obligated to protect your information and use it only for providing services to us.
5.2 Legal Requirements
We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to:
- Comply with legal obligations
- Protect our rights, property, or safety
- Prevent fraud or illegal activity
- Protect the safety of our users or the public
5.3 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.
5.4 Affiliate Links
When you click on Amazon affiliate links, Amazon may collect information about your visit and purchase according to their privacy policy. We receive aggregated commission data but do not receive your personal purchase information.
6. Data Retention
6.1 Account Data
- With Account: Your email, profile, and saved gifts are retained until you delete your account
- Without Account: Gift queries are processed but not permanently stored to a user profile
6.2 Analytics Data
Analytics data collected by PostHog is retained until you request deletion or as needed for service improvement purposes.
6.3 AI Processing
Gift queries sent to OpenAI are retained by OpenAI for up to 30 days for abuse monitoring, then automatically deleted.
6.4 Deletion Requests
You can request deletion of your data at any time by emailing info@giftfinderai.co or through your account settings (for account holders).
7. Data Security
We implement reasonable security measures to protect your information from unauthorized access, disclosure, alteration, or destruction, including:
- Encryption: Secure data transmission using HTTPS
- Password Protection: Passwords are hashed and not stored in retrievable formats
- Access Controls: Limited access to personal information
- Secure Infrastructure: Hosting on secure, reputable platforms
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
8. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from anyone under 18. If we discover that a user is under 18, we will immediately delete their account and all associated information.
If you are a parent or guardian and believe your child under 18 has provided us with personal information, please contact us at info@giftfinderai.co so we can take appropriate action.
9. International Data Transfers
The Service is hosted and operated from servers that may be located in different countries. By using the Service, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection laws.
Our third-party service providers may process data in various locations:
- OpenAI (United States)
- Amazon Web Services (various regions)
- Vercel (global network)
- Supabase (various regions)
10. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information:
10.1 General Rights
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Objection: Object to processing of your information
- Data Portability: Request transfer of your data to another service
10.2 Marketing Communications
You can opt-out of marketing emails by:
- Clicking the unsubscribe link in any marketing email
- Adjusting your preferences in account settings
- Emailing info@giftfinderai.co
10.3 Cookie Management
You can control cookies through your browser settings (see Section 4.3).
10.4 EU/UK Residents (GDPR)
If you are located in the European Union or United Kingdom, you have additional rights under GDPR:
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority
- Right to restriction of processing
- Right to object to automated decision-making
10.5 California Residents (CCPA)
If you are a California resident, you have rights under CCPA:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt-out of sale of personal information (Note: We do not sell personal information)
- Right to non-discrimination for exercising your rights
10.6 Exercising Your Rights
To exercise any of these rights, contact us at info@giftfinderai.co. We will respond to your request within a reasonable timeframe as required by applicable law.
11. Third-Party Links
The Service contains links to third-party websites, including Amazon and other retailers. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- Posting the updated Privacy Policy on this page
- Updating the "Last Updated" date
- Sending an email notification (for significant changes, if you have an account)
Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.
13. Data Protection Officer
For privacy-related inquiries or to exercise your privacy rights, please contact us:
Email: info@giftfinderai.co
We will respond to all legitimate requests within 30 days (or as required by applicable law).
14. Automated Decision-Making
The Service uses AI (OpenAI) to generate gift recommendations. This is an automated process that does not produce legal or similarly significant effects. You are free to ignore AI recommendations and are not obligated to act on any suggestions provided.
15. Do Not Track Signals
Some browsers support "Do Not Track" (DNT) signals. Currently, we do not respond to DNT signals, as there is no industry standard for how to interpret them. We will update this policy if we implement DNT support in the future.
16. Australian Privacy Principles
While we may not be subject to the Australian Privacy Act 1988 (depending on our turnover and operations), we strive to align with the Australian Privacy Principles (APPs) as best practice for transparency and data protection.
17. Questions and Complaints
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us at:
Email: info@giftfinderai.co
We will investigate and respond to all complaints in a timely manner.
By using GiftFinderAI.co, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.