PRIVACY

Privacy policy

What we store

We support email codes and Google sign-in, storing account identifiers, names, email addresses, verification and session records, and information submitted for stores, orders and support. Email codes and application session tokens are stored as verification hashes. We do not store account passwords.

Google sign-in data

Google sign-in requests only your account identifier, name and verified email to create and protect your account. We do not access Gmail, Drive, contacts or calendars, retain Google access tokens, use this data for advertising or sell it. You can revoke access in your Google Account third-party connections and request removal of associated site data through our support service.

How information is used

Information is used for verification emails, account security, fulfillment, order lookup, support and store reporting. Verification emails use the configured provider, Brevo or Resend, which processes the recipient email and message content. Sign-in cookies maintain account state. Agents cannot access other stores' customer data or delivery codes.

Delivery content

Cards are encrypted in storage. Sealed codes and ciphertext are not sent to pages. Store owners must explicitly reveal eligible cards they own. Delivered cards require separate authorization by the buyer, valid lookup credentials, or a main store administrator. Once displayed, codes can be read by the current browser; this does not mean redemption or activation. Never send third-party passwords or session credentials in support messages.

Corrections and deletion

When you use the wallet, we store financial movements, reviews, and payout details you submit. Legal names, account numbers, and authenticator secrets are encrypted. Payout details are masked by default; an administrator must verify a one-time code to reveal them for review, and access is logged. We do not store bank card passwords.

Manage your nickname, sign-in email and devices in Account & security, and your store in the dashboard. Submit account deletion or other data requests through support; the operator will consider outstanding orders and required transaction records.