Privacy Policy

European Union / EEA Privacy Addendum (GDPR)

This addendum supplements the eGifter Global Privacy Policy and applies to residents of the European Union and European Economic Area. It is provided in accordance with the General Data Protection Regulation (EU) 2016/679 ("EU GDPR") and the Privacy and Electronic Communications Directive 2002/58/EC ("ePrivacy Directive"). UK residents are covered by a separate UK Privacy Addendum addressing the UK GDPR and the Data Protection Act 2018.

This addendum should be read together with the eGifter Global Privacy Policy, which describes our general data practices, categories of personal information, and sources of data.

Last Updated: July 9, 2026

A. Data Controller Information

I. Data Controller

GroupGifting.com, Inc. d/b/a eGifter, 315 Main Street, 2nd Floor, Huntington, NY 11743, USA, is the data controller for personal data processed in connection with the eGifter gift card platform and storefront services.

For data protection enquiries: privacy@egifter.com

II. Data Protection Contact

eGifter has designated a data protection contact responsible for overseeing GDPR compliance. To exercise your data subject rights or raise a data protection concern, please contact: privacy@egifter.com with the subject line "GDPR Data Subject Request."

III. Relationship Between eGifter and Merchants

When you purchase a gift card directly from eGifter through an eGifter-operated storefront, eGifter processes your personal data in connection with providing the Services and acts as a data controller for those processing activities under the GDPR.

When you purchase a gift card through a merchant-branded storefront powered by eGifter, both eGifter and the applicable merchant generally process personal data. The respective roles and responsibilities of each party depend on the context of the transaction, the services provided, and applicable law. In many circumstances, eGifter and the merchant act as independent controllers with respect to their own processing activities. In limited circumstances, such as shared fraud prevention, security monitoring, or compliance-related activities, eGifter and the merchant may be considered joint controllers for specific processing activities, as required under the GDPR.

B. Your Rights as a Data Subject

As an EEA resident, you have the following rights under the GDPR, subject to applicable conditions and exceptions:

Right Description
Right of Access (Art. 15) Obtain confirmation of whether we process your personal data and receive a copy of that data.
Right to Rectification (Art. 16) Request correction of inaccurate or incomplete personal data.
Right to Erasure (Art. 17) Request deletion of your personal data where it is no longer necessary, consent is withdrawn, or processing is unlawful.
Right to Restriction (Art. 18) Request that we restrict processing of your data in certain circumstances.
Right to Data Portability (Art. 20) Receive your personal data in a structured, commonly used, machine-readable format.
Right to Object (Art. 21) Object to processing based on legitimate interests or for direct marketing purposes, including profiling.
Right to Withdraw Consent (Art. 7(3)) Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
Right to Lodge a Complaint (Art. 77) Lodge a complaint with the supervisory authority in your EU member state of residence.

To exercise any of these rights, please contact privacy@egifter.com. We will respond within the timeframe required by applicable law.

C. Legal Bases and Processing Activities

We process personal data on the legal bases permitted under Article 6 GDPR, including where processing is necessary to perform a contract with you, to comply with legal obligations, to protect our legitimate interests (such as fraud prevention and platform security), or where you have provided consent. More information about our processing activities, categories of data, and retention criteria is described in the eGifter Global Privacy Policy.

D. International Data Transfers

Your personal data may be transferred to and processed in jurisdictions outside the EEA, including the United States and other countries where our service providers or merchant partners are located.

Where personal data is transferred outside the EEA to countries that may not provide an equivalent level of data protection, we implement appropriate safeguards in accordance with Chapter V of the GDPR to ensure that personal data remains protected.

E. Cookies and ePrivacy

In accordance with the ePrivacy Directive and applicable national implementing legislation, we obtain your consent before placing non-essential cookies on your device. Cookies are categorized as follows:

Category Purpose Legal Basis Consent Required
Necessary Essential platform functionality, security, session management ePrivacy: strictly necessary exemption / Art. 6(1)(b) or 6(1)(f) GDPR No
Functional Remembering preferences, language and currency settings Consent (Art. 6(1)(a)) Yes
Analytics Understanding platform usage, improving services Consent (Art. 6(1)(a)) Yes
Marketing Targeted advertising, retargeting, social media tracking Consent (Art. 6(1)(a)) Yes

You can manage your cookie preferences at any time through the cookie preference tool. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal (Art. 7(3) GDPR).

F. Automated Decision-Making

We use automated processing to support fraud prevention and transaction security, including where necessary to perform a contract with you. Where required by applicable law and where automated decision-making produces legal or similarly significant effects, you may have the right to request information about such processing and applicable safeguards.

To exercise these rights, contact privacy@egifter.com. We will respond within the timeframe required by applicable law.

G. Data Security

We maintain appropriate technical and organizational measures designed to protect personal data against unauthorized access, use, or disclosure. Despite these safeguards, no system is completely secure.

H. Supervisory Authority

You have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement. Where eGifter has identified a lead supervisory authority for cross-border processing under Article 56 GDPR, that authority is currently:

Data Protection Commission (DPC) — Ireland
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: www.dataprotection.ie
Phone: +353 (0)57 868 4800

You may also contact the supervisory authority in your own EU member state.

I. Contact

For all GDPR-related enquiries and data subject requests:
Email: privacy@egifter.com
Subject line: "GDPR Data Subject Request" or "GDPR Enquiry"