Privacy Policy

Last updated: August 2026

This Privacy Policy describes how CuraGift collects, uses, discloses, and protects your personal information when you use our website. We are committed to protecting your privacy and complying with the GDPR, CCPA, and other applicable privacy laws.

1. Data Controller

  • CuraGift acts as the Data Controller as defined in GDPR Article 4(7).
  • Contact: privacy@curagift.com

2. Information We Collect

  • Account information: Name, email, password — for account creation and management.
  • Recipient profiles: Recipient name, relationship, interests — for AI gift recommendation.
  • Gifting calendar: Birthdays, anniversaries — for reminders and recommendations.
  • AI conversation history: Your messages to our AI assistant — for recommendations.
  • Customization details: Engraving text, card messages — for fulfilling custom orders.
  • Shipping address: Recipient name, address — for order delivery.
  • Payment information: Handled entirely by Shopify (PCI-DSS compliant). We do not store payment data.
  • Device and usage data: IP address, browser type, pages visited — for analytics and fraud prevention.

3. How We Use Your Information

  • Provide AI gift recommendations based on recipient profiles and conversation inputs.
  • Process and fulfill orders including custom engravings and packaging.
  • Send gifting reminders 30 days before each occasion.
  • Customer support and fraud prevention.
  • Improve our AI recommendations using aggregated and anonymized data.

4. Automated Decision-Making (GDPR Art. 22)

  • We use AI-powered systems to generate gift recommendations. Under GDPR Article 22, you have the right to:
  • Object to automated profiling — request human review of recommendations.
  • Receive information about the logic involved — we explain why each product was recommended.
  • Opt out of personalized recommendations — browse without AI personalization.
  • To exercise these rights, contact privacy@curagift.com.

5. Data Sharing

  • We do NOT sell your personal data.
  • Shopify: Order details, customer email — for e-commerce and payments.
  • LLM Provider: Anonymized conversation text — for AI recommendation engine.
  • Supabase: All user data — for database storage.
  • Vercel: Front-end application data — for website hosting.
  • Shipping partners: Recipient name, address, phone — for delivery.
  • Manufacturing partners: Customization details, shipping address — for product fulfillment.

6. Cross-Border Data Transfers

  • Your data may be transferred outside your country of residence. We ensure appropriate safeguards:
  • EU/UK to USA: EU-US Data Privacy Framework (DPF) certifications.
  • USA to China (manufacturing, shipping): Standard Contractual Clauses (SCC).
  • All transfers: Data Processing Agreements (DPA) with all processors.

7. Cookies

  • Strictly necessary: Enable core functionality (session, cart, security). No consent required.
  • Functional: Enhanced features (language, saved profiles). Consent required.
  • Analytics: Understand usage patterns. Consent required.
  • Advertising: Show relevant ads. Consent required.
  • EU/UK users: Non-essential cookies are blocked until you actively consent.
  • California users: "Do Not Sell or Share My Personal Information" link available in footer.

8. Data Retention

  • Account data: While account is active + 30 days after deletion request.
  • Order data: 7 years (or as required by tax law).
  • AI conversation history: 2 years from last interaction (anonymized).
  • Recipient profiles: While account is active or until user deletes.
  • Server logs: 90 days.

9. Your Rights

  • GDPR (EU/UK): Access, rectification, erasure, restriction, portability, object, withdraw consent.
  • CCPA/CPRA (California): Know, delete, correct, opt-out of sale/sharing, non-discrimination.
  • Other US states: VA, CT, CO, UT have similar rights.
  • Response time: 30 days (GDPR), 45 days (CCPA), may extend with notice.
  • Contact: privacy@curagift.com to exercise any right.

10. Data Security

  • All data transmitted via HTTPS/TLS 1.3.
  • Database encrypted at rest (Supabase).
  • Row-Level Security: Users can only access their own data.
  • Rate limiting and input validation on all API routes.
  • Payment processing handled by Shopify (PCI-DSS Level 1 certified).
  • 72-hour breach notification procedure (GDPR Art. 33).

11. Children's Privacy

  • Our Service is not directed to children under 16. We do not knowingly collect personal information from children.

12. Changes to This Policy

  • We may update this Privacy Policy from time to time. We will notify you of material changes via email and post a notice on our website at least 30 days before changes take effect.

Questions about your privacy?

We are committed to transparency and your rights.

Contact Our DPO →