Privacy Policy

Last updated: 28 September 2026

1. Who is responsible

Gifty Code LLC operates giftycode.com and the GiftyCode applications. Our registered address is Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, United Arab Emirates (Formation No. 2324397). Contact the privacy team at [email protected], using “Privacy” in the subject.

This notice explains our handling of personal information. It is not a blanket consent to optional analytics or marketing. Our services are intended for people aged 18 or older.

2. Information we use and why

  • Account and sign-in: email, name and other profile details you provide, hashed password, login-provider identifiers, authentication/session records, language and currency preferences. These let us authenticate you, protect your account and provide the service.
  • Orders and payments: purchased products, invoices, amounts, currencies, payment status, cryptocurrency transaction references and internal balance entries. These support delivery, reconciliation, refunds, fraud review and required accounting. We do not currently offer credit/debit-card checkout.
  • Delivery: recipient phone number for airtime; eSIM activation credentials, usage and expiry; and information needed by the chosen fulfillment provider. Enter only a recipient number you are authorised to use. Available products differ between application versions and markets.
  • Identity verification, where required: identity-document images and details, selfie images and biometric face-verification information and results submitted through the hosted Shufti verification flow. The current Canadian app verification flow uses a document and selfie/face check, not residential-address verification. Other services may separately request address evidence when required. This is separate from ordinary registration. Canadian app features that do not require this information do not initiate those verification flows.
  • Support: messages, attachments, order references and contact details you send. Avoid sending passwords, private keys, full payment-card credentials or unrelated identity documents.
  • How you found us (visit source): campaign tags in the link you followed (utm_source, utm_medium, utm_campaign, utm_term, utm_content), advertising click identifiers (gclid, yclid, fbclid, ttclid, msclkid), the domain of the referring website (not the full address), the first public page you opened and the visit time; in the Telegram mini app, the bot that opened it and its start parameter. This is kept in a first-party cookie for up to 90 days and, when you register or place an order, stored with that account or order. We use it to understand which channels bring customers and orders; we do not sell it or send it to advertising networks. It stays with the order or account record for the retention period of that record.
  • Security and operation: IP address, IP-derived country, request/access records, device/browser information and service errors. These help prevent abuse and operate the service. Public search terms may occur in request logs.

We process information to provide requested services, comply with applicable legal obligations, and protect the service; consent is used where required, including for optional website analytics. The applicable legal basis and available rights depend on your jurisdiction. We do not treat use of the service as permission for unrelated purposes.

3. Sign-in and notifications in the app

Optional Apple, Google and Telegram sign-in sends authentication requests to the selected provider and returns the identity information permitted by that flow. We do not receive your provider password. The Google Sign-In SDK declares contact, identifier, approximate-location, usage and other data for functionality and certain analytics purposes; its provider policy also applies.

With your permission, Apple Push Notification service receives a device token and notification payload. We associate the token with your account/session and preferences. Notification previews can display message contents; the full app can include 3DS codes, while the Canadian configuration provides eSIM reminders. You control permission and Lock Screen previews in iOS Settings. Disabling push does not delete your account.

The native app does not request GPS location, contacts or the advertising identifier. This does not mean that no personal information is collected.

4. Website cookies and optional analytics

Essential cookies and browser storage support sign-in, security, cart, preferences and the first-party visit-source record described in section 2. Where configured, optional Google Analytics and PostHog measurements are enabled only after analytics consent. They process public-page visits and technical/browser identifiers. PostHog additionally receives the steps of a purchase — product viewed, added to cart, checkout started, payment method chosen and order created — with product, quantity, amount, currency and order-number details, but not your email, phone number, delivered codes or guest order links. Addresses of account, authentication and checkout pages are excluded from these measurements.

If you consented and sign in, PostHog links these events to your account identifier together with your language, country, registration date and sign-up channel (a person profile); it does not receive your email or phone number. For orders placed with analytics consent, our servers send PostHog a purchase event (order number, amount, items and visit source) so that completed purchases are measured even when a browser blocks analytics. PostHog session recording and automatic click capture are disabled. Your consent choice is also kept in a cookie so our servers can respect it. You can change the website analytics choice at any time; withdrawing it stops new events and removes the analytics identifier cookies. These website analytics libraries are not embedded in the native iOS interface.

Where displayed, Trustpilot widgets receive network/browser information, including your IP address, when loaded. A delivered-order email may contain a review link; following it opens Trustpilot under its privacy policy. Third-party websites and identity providers operate their own services.

5. Who receives information

We share the information needed for the selected service with hosting/CDN and infrastructure providers; transactional email providers; Apple, Google or Telegram for chosen sign-in; Apple for push; NOWPayments for cryptocurrency invoices and reconciliation in the Canadian app; and the selected product/telecom supplier for delivery. Verification providers receive the evidence required by an applicable verification flow. Support systems process the content of your requests. We may also disclose necessary records to professional advisers or authorities when legally required.

Providers acting on our instructions must protect the information and use it for the agreed service. Some providers, including identity providers, telecom operators and payment processors, may independently retain records under their own legal duties and privacy notices. Contact us for the providers relevant to your transaction.

6. International processing and safeguards

Gifty Code LLC is based in the UAE. Infrastructure and service providers may process information outside your country, including outside Canada, and it may be accessible to authorities under those countries’ laws. We remain responsible for personal information under our control and use contractual, access and technical safeguards appropriate to the processing. Contact us for information about cross-border providers and safeguards.

Connections to our API use HTTPS. Passwords are hashed; delivered codes and designated identity-verification payloads use application-level encryption. Access is restricted by role. Ordinary invoice and transaction fields are database records, not individually encrypted fields. No system can guarantee absolute security.

7. Retention and deletion schedule

We keep information for its stated purpose, then delete it or irreversibly de-identify it unless an identified legal obligation or unresolved claim requires specific records. The following schedule distinguishes operational targets from automatic expiry. A retained accounting record does not justify keeping an unrelated profile, message or document.

  • Account profile, sessions and linked identities: while the account is used; after a verified deletion request, our processing target is 30 calendar days. Unresolved transactions or services are reviewed separately. We remove information no longer needed when the request is completed and revoke linked Apple authorisation. A pending request does not mean the account has already been erased.
  • Tax and accounting evidence: necessary invoices, amounts, dates, transaction references and supporting evidence are retained for at least seven years after the end of the relevant UAE corporate-tax period where that obligation applies. A specific statutory extension, audit or legal hold may require longer. This term does not automatically apply to all account or identity data.
  • Support and security records: our ordinary targets are 12 months after a support case closes and 90 days for account-access/security records. Relevant evidence of an unresolved dispute, fraud investigation or legal obligation is separated for restricted retention with a review date. These are operating targets, not a representation that every legacy record has automatic expiry.
  • Identity-verification evidence: limited to the applicable verification/provider obligation. We review each retained category and its legal or contractual basis; where no continuing obligation exists, our target is deletion within 30 days after the verification purpose ends. We do not apply a blanket seven-year period to passports or verification payloads.
  • Push: device registrations inactive for 90 days are eligible for daily cleanup. Expired card-code/general delivery records are eligible for cleanup after seven days. eSIM reminder history can remain with the device registration to prevent duplicate reminders. Deleting the account removes its local push registrations.
  • Deletion receipt: a minimal request identifier, status and dates remain available to evidence processing; after completion the receipt has no account link. Our retention target is 12 months after completion, except a specifically documented dispute or restoration-suppression requirement.
  • Backups: routine database backup rotation is configured for 30 days locally and 14 days offsite; staging backups use seven days. Historical migration/deployment copies and documented legal holds are reviewed separately and may persist beyond routine rotation. They are restricted from normal use. Before restoring customer data, outstanding erasures must be reapplied. Contact us for the retention or exception affecting your request.

For an exception we identify the retained data, reason, applicable period or review date, and authorised access. We do not keep all personal information indefinitely “just in case”. Mandatory records are not reused for optional marketing.

8. Deleting an account and remaining funds

In supported iOS builds, use Account → Security → Delete account. The app saves a receipt and target date and allows status checks after sign-out. You can also email the privacy contact above. We may need proportionate verification of your identity; do not send an identity document unless requested through an appropriate channel.

Deletion is not merely logout or uninstalling the app. We review remaining balances, undelivered orders, active services, refunds and provider-held copies. We will explain required actions and any delay. A deletion request does not forfeit funds or remove statutory refund rights, and we do not make spending the balance a condition of exercising privacy rights.

Accounts with financial or provider history require a retention and settlement review. Once ordinary consumer transactions and services are settled, we erase the profile, sign-in access, support and verification copies under our control, while preserving only the required accounting and provider audit records with restricted access. The completion receipt identifies retained financial records and their retention date. Requests with remaining funds, pending transactions, active services or separate provider obligations remain under review; we explain what is still required. This review is not a requirement to spend remaining funds. Linked Apple accounts may require a fresh Apple confirmation so that we can revoke authorisation. Other providers may retain their independent records.

9. Your choices and rights

Depending on applicable law, you may request access, correction, deletion, information about disclosures and retention, restriction or objection to certain processing, portability, and withdrawal of consent for consent-based processing. Withdrawal does not undo lawful earlier processing. We aim to respond within 30 days, observe the applicable statutory deadlines and explain any permitted extension or refusal.

Canadian users may raise privacy concerns with us and, where applicable, the Office of the Privacy Commissioner of Canada or the competent provincial privacy regulator. These rights do not require closing your account.

10. Changes and contact

We date material changes to this notice and provide additional notice or obtain consent where required. Questions, access requests and complaints can be sent to [email protected], subject “Privacy”.