Privacy Policy
Last updated: February 2026
Giftles (“we”, “our”, “us”) is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal data when you use our website at giftles-production.up.railway.app (the “Service”).
1. Data We Collect
Account Information
When you create an account or sign in with Google, we collect your email address and display name. This data is stored securely by our authentication provider, Supabase.
Gift Search Data
When you use our gift discovery service, we collect information you provide about the gift recipient, including: name, age range, gender, occasion, budget range, and interests. We also record your voting choices during the product selection process. This data is used to generate personalised gift recommendations.
Feedback Data
If you submit feedback after viewing recommendations, we collect your satisfaction rating, purchase intent, and any comments you provide. This helps us improve our recommendation quality.
Automatically Collected Data
We may use privacy-friendly analytics to collect anonymous usage data such as pages visited and general geographic region. We do not use tracking cookies for advertising purposes.
2. How We Use Your Data
- To provide personalised gift recommendations based on your preferences
- To save your gift search history and recipient profiles (if signed in)
- To improve our recommendation algorithms and product selection
- To communicate with you about your account (e.g. email verification)
- To detect and prevent abuse of the Service
3. Third-Party Services
We use the following third-party services to operate Giftles:
- Supabase — Database hosting and user authentication. Your account data and session history are stored on Supabase servers. Supabase Privacy Policy
- Google — If you sign in with Google, your basic profile information (name and email) is shared with us via Google OAuth. Google Privacy Policy
- Amazon — Product data (names, prices, images, ratings) is sourced from Amazon. When you click “View on Amazon”, you are redirected to Amazon's website, which is subject to Amazon's Privacy Notice.
- Railway — Our application is hosted on Railway's infrastructure. Railway Privacy Policy
4. Amazon Affiliate Disclosure
Giftles is a participant in the Amazon Associates Programme, an affiliate advertising programme designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon.co.uk. When you click on product links and make a purchase, we may earn a commission at no additional cost to you. Product prices and availability are subject to change.
5. Cookies and Local Storage
We use the following types of browser storage:
- Essential cookies — Required for authentication and session management. These cannot be disabled.
- Local storage — Used to save your voting session progress, recipient profiles, and feedback history locally on your device.
- Analytics cookies — Used only with your consent to collect anonymous usage statistics. You can manage your preferences via the cookie consent banner.
6. Data Retention
Your account data is retained for as long as your account is active. Gift search sessions are retained for up to 12 months to provide search history functionality. Local storage data on your device is retained until you clear your browser data. You may request deletion of your account and associated data at any time.
7. Your Rights (GDPR)
Under UK and EU data protection law, you have the right to:
- Access — Request a copy of the personal data we hold about you
- Rectification — Ask us to correct inaccurate data
- Erasure — Ask us to delete your personal data
- Portability — Request your data in a machine-readable format
- Objection — Object to processing of your data
- Withdraw consent — Withdraw consent for analytics cookies at any time
To exercise any of these rights, please contact us at pysior25@gmail.com.
8. Children's Privacy
Giftles is not directed at children under 13. We do not knowingly collect personal data from children. The recipient information you provide (such as a child's age and interests for gift selection) is associated with your account, not the child's.
9. Changes to This Policy
We may update this policy from time to time. Any changes will be posted on this page with an updated revision date. Continued use of the Service after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this privacy policy or our data practices, please contact us at pysior25@gmail.com.