Privacy Policy

GiftCue - Effective: May 14, 2026 - Last updated: May 14, 2026

This Privacy Policy explains how GiftCue ("we," "us," "our") collects, uses, and protects information when you use our service at giftcue.app, getgiftcue.com, giftcue.ai, giftcue.org, and any related apps. By using GiftCue you agree to this policy.

GiftCue is an assumed business name of True Grit Toolkits LLC, an Oregon limited liability company (Oregon Registry #243310695), operating GiftCue under Oregon Assumed Business Name registration #257359597. Principal place of business: 1275 Monroe St, Eugene OR 97402.

1. The two kinds of people GiftCue serves

GiftCue exists to help one person (the Sender) give a gift to another person (the Recipient). The Sender provides information about the Recipient so we can build a personalized gift picker. This privacy policy treats both groups carefully, and treats the Recipient with extra care, because they didn't choose to share their information themselves.

2. What we collect

From the Sender (the person building a picker)

From the Recipient (the person opening the gift link)

3. How we use what we collect

We do not sell your data. We do not run third-party ad networks or analytics that fingerprint users. We do not share Recipient information with anyone other than the Sender who created their picker.

4. How long we keep things

5. Cookies

We use one cookie: giftcue_auth, an HMAC-signed timestamp used to keep you signed in. It's httpOnly, Secure, SameSite=Lax, and expires after 14 days. We don't use tracking cookies, third-party cookies, advertising cookies, or session-replay cookies. If we add privacy-respecting analytics (such as Plausible) we will update this policy first.

6. Third parties we use

ProviderWhat they doWhat they receive
CloudflareHosting, CDN, storage, AI image generationAll service data (encrypted in transit and at rest)
AnthropicAI option generation, help-chatRecipient profile info, help questions
Google Places (New)Real local business data for option hydrationRecipient city plus category preferences (no PII)
StripePayment processingPayment method, billing info
ResendEmail delivery (notifications, magic links, post-pick confirmation)Sender email plus message content

SMS delivery is not currently active. If we add SMS in the future it will be opt-in only, with documented TCPA-compliant consent.

7. Your rights

Regardless of where you live, you can:

To exercise any right, email privacy@giftcue.app. We respond within 30 days.

California residents (CCPA / CPRA)

California residents have the right to know what personal information we collect, request deletion, and opt out of "sale" or "sharing" of personal information. We don't sell personal information. We don't share it with third parties for cross-context behavioral advertising.

EU / UK residents (GDPR)

If you're in the EU or UK, our legal basis for processing is: (a) contract for service delivery (generating your picker), (b) legitimate interests for fraud prevention and product improvement, and (c) consent for optional features. GiftCue is currently a US service. EU/UK users access at their own discretion.

8. Recipient privacy specifically

If you are a Recipient who received a GiftCue link, your information was provided to us by the Sender who built your picker. We don't have your phone number, email, or any contact information beyond what the Sender wrote in the form (typically your first name and city).

If you want us to delete the entire session: email privacy@giftcue.app with the picker URL. We'll honor it within 7 days, which means the Sender will no longer see your pick.

9. Children

GiftCue is not intended for children under 13. We do not knowingly collect information about anyone under 13. If you believe we have, email us and we'll delete it.

10. Security

All traffic uses HTTPS / TLS. Authentication is HMAC-signed and httpOnly. Database access is encrypted at rest. We follow standard infrastructure security practices and use Cloudflare's enterprise-grade security platform. No system is 100% secure; we encourage you to use a strong, unique password and contact us immediately if you suspect an issue.

11. Changes to this policy

If we make material changes, we'll post the updated policy here and update the "Last updated" date. For users with an account, we'll also email you. Continued use after changes means you accept them.

12. Contact

For any privacy questions: privacy@giftcue.app

True Grit Toolkits LLC d/b/a GiftCue
1275 Monroe St, Eugene OR 97402, USA

This Privacy Policy reflects the operating reality of GiftCue at the date above. It will be reviewed by qualified counsel prior to scaled commercial launch.