Privacy Policy

eGifter Global Privacy Policy

Last Updated: July 9, 2026

Introduction

This Privacy Policy sets out how GroupGifting.com, Inc. d/b/a eGifter ("eGifter", "us", "our" or "we") collects, uses, stores, and discloses information about you when you use or interact with any of our websites, mobile applications, or services, including when you purchase gift cards through any merchant storefront powered by the eGifter Platform ("Services").

We take our privacy obligations seriously and want to ensure you are fully informed about how your information is collected and used. This Policy applies globally. If you reside in a jurisdiction with specific privacy laws, please review the applicable addendum below for additional rights and information specific to your location.

By using our Services, you acknowledge that you have read and understood this Privacy Policy. Where applicable law requires consent for specific processing activities (such as marketing communications or non-essential cookies), we will obtain that consent separately.

If you have questions about this Privacy Policy, please contact us at privacy@egifter.com.

1. Who We Are and How We Work with Merchants

eGifter operates a gift card solutions platform that supports multiple use cases and deployment models. These include direct-to-consumer sales through eGifter-operated storefronts, rewards and incentive programs through which businesses deliver gift cards to designated recipients, and white-label or merchant-branded versions of the platform that merchants and other business clients (collectively, "Merchants") use to sell gift cards to consumers or administer their own rewards and incentive programs.

When gift cards are purchased through a Merchant's storefront powered by the eGifter Platform, both eGifter and the Merchant generally process certain personal information. The respective roles and responsibilities of each party depend on the context of the transaction, the services provided, and applicable law. In many situations, eGifter and other parties act as independent controllers with respect to their own processing of personal information. In limited circumstances, such as shared fraud prevention, security monitoring, or compliance-related activities, eGifter and another party may be considered joint controllers for specific processing activities, as required under applicable law.

Depending on the specific gift card program and merchant arrangement, eGifter may act as the merchant of record for certain transactions. In other cases, the merchant may be the merchant of record. The applicable merchant of record is determined by the structure of the program and the customer experience presented at the point of purchase.

2. Information We Collect

Information You Provide Directly

When you use our Services, we collect the following categories of personal information:

  • Identifiers: name, email address, postal address, phone number
  • Payment information: when eGifter acts as the merchant of record, we process payment card or other payment instrument details directly through our payment processors. In other cases, payment processing is handled by the merchant or its designated payment service providers, and eGifter processes personal information only as necessary to facilitate the transaction and delivery of the digital gift card.
  • Commercial information: gift cards purchased, order history, recipient details
  • Account information: username, password, account preferences
  • Sensitive personal information: we do not knowingly collect sensitive personal information (such as government IDs, precise geolocation, or financial account login credentials) except as necessary for fraud prevention or where required by law
Information Collected Automatically

When you visit our websites or mobile applications, we automatically collect:

  • Technical data: IP address, browser type and version, device type, operating system
  • Usage data: pages accessed, date and time of visits, referring URLs, interactions with our Services
  • Cookie and tracking data: as described in the Cookies section below
Information Received from Third Parties

We may receive information about you from fraud detection and prevention services, payment processors, and other third parties as necessary to provide our Services and protect against fraudulent activity.

3. How We Use Your Information

We use personal information to operate our Services, fulfill transactions, administer programs, provide customer support, communicate with users, comply with legal obligations, and prevent fraud.

We also use technical and security-related information, including system and network logs, to protect the security and integrity of our Services, detect and prevent unauthorized access and malicious activity, and improve the performance and reliability of our platform.

We do not use such technical information to identify individual users except where necessary to investigate suspected fraud, security incidents, or other unlawful activity.

4. Cookies and Tracking Technologies

We use cookies and similar technologies, such as tracking pixels, web beacons, and local storage mechanisms, to support essential platform functionality, analyze usage of our Services, and, where applicable, support targeted advertising.

You can manage your cookie preferences through our cookie control tool or by adjusting your browser settings. Please note that disabling certain cookies may affect your ability to use some features of our Services.

We also honor Global Privacy Control (GPC) signals. If your browser or browser extension sends a GPC signal, we will treat it as a request to opt out of the sale or sharing of your personal information for targeted advertising purposes, as required by applicable law.

5. How We Share Your Information

We share personal information only as necessary to provide our Services, operate our platform, comply with applicable law, and protect our legal rights.

Categories of recipients may include:

  • Service providers that perform services on our behalf, such as hosting, payment processing, communications delivery, gift card fulfillment, customer support, analytics, and fraud prevention
  • Merchant and business partners, where information is necessary to fulfill gift card orders, administer rewards or incentive programs, or support merchant-branded implementations of our platform
  • Fraud detection and security partners, to help prevent and investigate fraudulent or suspicious activity
  • Law enforcement, regulatory, or judicial authorities, where required by law or to protect our rights
  • Business successors, in connection with a merger, acquisition, or sale of all or substantially all of our assets

When eGifter acts as Merchant of Record for a gift card purchase, eGifter is the seller of the gift card to you. Your payment information is processed by our third-party payment processor to complete the transaction, and certain transaction information is processed by our third-party fraud prevention provider to detect and prevent fraudulent activity. The Merchant whose gift card you purchased is the issuer of the gift card and the supplier of the underlying goods or services, and processes your information in accordance with its own privacy notice.

We do not sell personal information for monetary consideration. Certain disclosures may constitute a "sale" or "sharing" of personal information for targeted advertising purposes under applicable state privacy laws. Where required, you may opt out of such disclosures as described in Your Privacy Rights below.

6. Data Retention

We retain your personal information for as long as necessary to provide our Services, comply with our legal obligations, resolve disputes, and enforce our agreements. If you submit a verified request to delete your personal information, we will honor that request to the extent permitted by applicable law. Please note that certain information may be retained where required by law or where we have a legitimate business purpose for doing so, such as fraud prevention, financial record-keeping, or the resolution of pending transactions or disputes. To submit a deletion request, please contact us via the support link on the Platform Service or at privacy@egifter.com.

7. How We Secure Your Information

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These measures are designed to reflect the sensitivity of the information and the nature of our Services.

Our information security program includes appropriate access controls, encryption, monitoring, and incident response processes, and is periodically reviewed and assessed. Where applicable, we align our practices with recognized security standards and regulatory requirements, including those applicable to payment card data.

Despite these safeguards, no system or transmission over the internet is completely secure, and we cannot guarantee the absolute security of personal information.

8. Government Access Requests

If we receive a legally binding request from a government or law enforcement authority for access to your personal information, we will, unless prohibited by law and where reasonably practicable, notify you of such request. We will challenge any request we have reasonable grounds to believe is unlawful. We will provide only the information reasonably necessary to comply with any lawful request.

9. Your Privacy Rights

Depending on your location, you may have the following rights with respect to your personal information:

  • Right to know or access: request information about the personal data we hold about you
  • Right to correct: request correction of inaccurate personal information
  • Right to delete: request deletion of your personal information, subject to legal exceptions
  • Right to data portability: receive a copy of your data in a structured, commonly used format
  • Right to opt out: opt out of the sale or sharing of your personal information for targeted advertising
  • Right to limit: limit the use of sensitive personal information
  • Right to non-discrimination: we will not discriminate against you for exercising your privacy rights

To exercise any of these rights, please contact us at privacy@egifter.com or via the support link on the Platform Service. We will respond to your request within the timeframe required by applicable law. If we are unable to fulfill your request, we will explain why.

If you are unsatisfied with our response, you have the right to appeal our decision by contacting privacy@egifter.com with the subject line "Privacy Request Appeal." We will review your appeal and respond within the timeframe required by applicable law. You may also have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.

10. Automated Decision-Making

We use automated decision-making technology for fraud detection and prevention purposes. Automated systems analyze transaction characteristics (such as purchase amount, payment method, device and network signals, and order history) against risk models, which may result in a transaction being flagged, held, or declined. The consequence of an adverse automated decision is that the specific transaction will not be completed; it does not affect your ability to attempt future transactions or use other aspects of our Services.

Where automated decision-making produces legal or similarly significant effects on you, we will inform you of the logic involved, the significance, and the envisaged consequences. You have the right to obtain human intervention, to express your point of view, and to contest the decision. To exercise these rights, contact privacy@egifter.com.

We do not use automated decision-making for purposes that produce significant legal effects on you beyond fraud prevention and transaction security without providing you an opportunity for human review.

11. Children's Privacy

Our Services are not directed to children under the age of 13 (or the higher minimum age that applies in your jurisdiction), and we do not knowingly collect personal information from children. To the extent we do collect personal information from a child where permitted, we will obtain verifiable parental or guardian consent as required by applicable law. If we become aware that we have collected personal information from a child without appropriate authorization, we will take steps to delete such information. If you believe we have collected information from a child, please contact us at privacy@egifter.com

12. Marketing Communications

We may send you marketing communications where you have opted in or where otherwise permitted by applicable law. You can opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at privacy@egifter.com. Please note that opting out of marketing communications does not opt you out of service-related communications such as order confirmations and receipts.

13. Third-Party Websites

Our Services may contain links to third-party websites. We are not responsible for the privacy practices of those websites. We encourage you to review the privacy policies of any third-party websites you visit.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on our website and updating the "Last Updated" date. Your continued use of our Services after any update constitutes your acceptance of the revised Policy.

15. Jurisdiction-Specific Rights

Depending on where you reside, you may have additional privacy rights under applicable local law. Please review the relevant addendum for your jurisdiction:

16. International Users

If you access our Services from outside the United States and your jurisdiction is not covered by one of the specific addenda listed above, your personal information may be transferred to and processed in the United States. We will ensure that any such transfer is carried out in compliance with applicable data protection laws. If you have questions about how your information is handled, please contact us at privacy@egifter.com.

17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:

GroupGifting.com, Inc. d/b/a eGifter
315 Main Street, 2nd Floor
Huntington, NY 11743
Email: privacy@egifter.com

For residents of the European Union, European Economic Area, and United Kingdom: eGifter has designated a data protection contact responsible for overseeing compliance with the GDPR and UK GDPR. To submit a data subject rights request or raise a data protection concern, please contact privacy@egifter.com with the subject line "GDPR Data Subject Request" (for EU/EEA residents) or "UK GDPR Data Subject Request" (for UK residents). We will respond within one month of receiving your verified request.

For residents of Australia: To submit a privacy request or complaint under the Privacy Act 1988, please contact privacy@egifter.com with the subject line "Australia Privacy Request." We will respond within 30 days.

For residents of Canada: To submit a privacy request under PIPEDA or Quebec Law 25, please contact privacy@egifter.com with the subject line "Canada Privacy Request." We will respond within 30 days.