Legal
Privacy Policy
Last updated: June 2, 2026 · Opengift Group LLC · Wyoming, USA
At Opengift, operated under the corporate registration of Opengift Group LLC (Filing No. 2026-001993757 · 30 N Gould St Ste N, Sheridan, WY 82801, USA), ensuring data confidentiality, secure digital storage and structural transparency toward the user is an absolute priority. This Privacy Policy details the strict cryptographic measures and processing frameworks we apply so that your personal life remains completely private. By using the Services, you accept the practices described in this Policy.
1. The Zero-Knowledge Cryptographic Mandate
Unlike standard cloud hosting companies, Opengift Group LLC enforces a strict Zero-Knowledge Privacy Architecture.
- Browser-level encryption: Before your images, text or any other content leave your device, they are compiled into encrypted payloads using local hardware-accelerated AES-GCM 256-bit encryption via the browser's native Web Crypto API.
- Server blindness: Our databases and cloud servers only receive, store and transmit completely unreadable data (ciphertext) and initialization vectors (IVs). Our infrastructure cannot read the personal content of your gift.
- Key exclusivity: The secret cryptographic key needed to unlock and read your data is derived from the security PIN you create at the time of purchase. That PIN is delivered to you by email and is never stored in plaintext. Our engineering team has no technical ability to view, scan or recover your personal content.
2. Categories of Information We Process
2.1 Data you provide directly
- Gift content: Uploaded photos, written messages, geographic coordinates and any other content you enter when creating a gift — encrypted client-side before reaching our servers.
- Identity data: Names (sender and recipient), email address provided at checkout, and language preferences.
- Payment data: Processed entirely by our PCI-DSS-compliant external processor (Stripe, Inc.). We never store unencrypted credit card numbers, CVV codes or banking credentials in plaintext on our servers.
- Security PIN: If you choose to protect your gift with a PIN, a PBKDF2-derived key is used for AES-GCM encryption. The PIN itself is transmitted to you by email at the time of purchase and is never stored in plaintext on our servers.
2.2 Automatically collected data
- Network metrics: IP address, browser fingerprint, operating system, referrer URL, pages visited and timestamps — collected by our hosting provider (Vercel) for security and performance purposes.
- Encrypted blobs: Encrypted binary fragments representing photos, maps and dedications — unreadable without the user's PIN.
- Session cookies: Essential cookies required to manage payment sessions. We do not use advertising cookies, tracking pixels or behavioral analytics scripts.
3. Processing Purposes and Legal Basis
- Create, store and deliver your digital gift via a unique URL and email confirmation.
- Verify payment status through the Stripe API and issue transaction records.
- Detect and prevent fraud, abuse, bot injection and technical errors.
- Monitor system performance and fix platform errors.
- Comply with applicable legal, tax and regulatory obligations in Wyoming, United States.
- Content moderation: Before storage, uploaded images are analyzed by an automated content moderation system (Sightengine, Inc.) to detect and block nudity, explicit content and offensive material. This analysis processes image data in transit and does not store it on the provider's servers beyond the duration of the API call. Images that pass moderation are encrypted and stored under our Zero-Knowledge architecture.
We do not use your data for advertising, profiling, automated decision-making, AI training or any purpose not listed above.
GDPR legal bases (EEA / UK users)
- Contract performance (Art. 6(1)(b)): Processing necessary to fulfill your order and provide the Services.
- Legitimate interests (Art. 6(1)(f)): Security, fraud prevention and service improvement.
- Legal obligation (Art. 6(1)(c)): Compliance with tax, financial and regulatory requirements.
4. Third-Party Data Processors
We share data with the following sub-processors exclusively to operate the Services:
| Provider |
Purpose |
Data shared |
Location |
| Stripe, Inc. |
Payment processing |
Payment amount, email, billing data |
USA (EU SCCs available) |
| Vercel, Inc. |
Hosting and serverless functions |
IP address, server request logs |
USA (global CDN) |
| GitHub, Inc. |
Gift data storage (private repository) |
Encrypted gift blobs (ciphertext) |
USA |
| Resend, Inc. |
Transactional email delivery |
Recipient email address, order data |
USA |
| Sightengine, Inc. |
Automated image content moderation (nudity and offensive content detection) |
Uploaded image data (processed in transit, not retained by Sightengine) |
USA |
| Supabase, Inc. |
Backend database and authentication services |
User account data, session tokens |
USA |
| Cloudflare, Inc. |
DNS, DDoS protection and CDN |
IP address, request metadata (no content) |
USA (global) |
| Namecheap, Inc. |
Domain name registration and management |
Registrant contact data (domain WHOIS) |
USA |
| Hostinger, UAB |
Web hosting and infrastructure |
IP address, server access logs |
Lithuania (EU) |
We enforce a categorical No-Sale Policy — we do not commercialize, monetize, lease or distribute your data to advertising companies or external intermediaries. As your personal media files and text notes are fully encrypted before reaching our servers, Opengift Group LLC strictly guarantees that your content can never be scanned, extracted, analyzed or used to train commercial Artificial Intelligence systems or large language models.
5. Data Storage and Security
- Gift data is stored as encrypted JSON files in a private GitHub repository, accessible only via authenticated API calls from our serverless functions.
- Gift URLs use cryptographically random identifiers (128-bit entropy) generated at the time of purchase — not guessable by brute force.
- All data in transit is protected by TLS 1.2 / 1.3 (HTTPS). Unencrypted HTTP connections are automatically redirected.
- Access to our infrastructure is restricted to authorized personnel only.
6. Data Retention
- Gift content: Stored indefinitely to ensure the gift remains accessible at its URL. You may request deletion at any time.
- Email addresses: Retained for the duration of the service relationship and as required by applicable law.
- Payment records: Retained for a minimum of 7 years as required by US financial regulations.
- Server logs: Retained up to 90 days by Vercel for security purposes.
7. International Data Transfers
Opengift Group LLC maintains its primary administrative books and legal registration in Wyoming, United States. International users, including those from the EEA, UK or Latin America, expressly acknowledge and consent that their account parameters and encrypted data blobs will be routed, written and stored in secure cloud instances physically located in the United States.
For transfers from the EEA or UK, we rely on Standard Contractual Clauses (SCCs) with our data processors where applicable.
8. Your Rights
All users
- Right to erasure: Request the complete deletion of your account records and uploaded data from our active servers.
- Right of access and portability: Request a copy of the personal data we hold about you in a structured, machine-readable format.
- Right to rectification: Request the correction of inaccurate, outdated or incomplete data.
EEA / UK residents (GDPR / UK GDPR)
- All of the above rights, plus the right to restrict processing and to object to processing based on legitimate interests.
- Right to lodge a complaint with your local supervisory authority (e.g. CNIL, ICO, AEPD).
California residents (CCPA / CPRA)
- Right to know what personal information is collected, disclosed or sold.
- Right to delete personal information.
- Right to opt out of the sale of personal information. We do not sell personal information.
- Right not to be discriminated against for exercising CCPA rights.
Please note that since we do not store your private keys or security PINs, we can completely delete your encrypted database records but cannot recover them for you. To exercise any of these rights, send a written request to our privacy department. We will respond within 30 days.
9. Cookies
Our application uses essential session cookies required to manage payment processes and maintain user preferences during active sessions. We do not use advertising cookies, tracking pixels or third-party analytics scripts. You may block or reject non-essential cookies from your browser settings; however, doing so may affect payment functionality. For more details see our Cookie Policy.
10. Children's Privacy
The Services are not directed at children under 13 years of age (or under 16 in the EEA). We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us at legal@opengift.llc and we will delete it immediately.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be indicated by updating the "Last updated" date at the top of this page. Continued use of the Services after changes constitutes acceptance of the revised Policy.
12. Privacy and Data Protection Directory
For data audits, deletion requests or general privacy compliance inquiries, use the appropriate contact: