Legal

Your privacy
matters.

We collect only what we need, we never sell your data, and we give you full control. Here's exactly how it works.

What we collect

Only what we need.

We collect the minimum data necessary to provide you with a great gifting experience.

Account Information

Name, email, and password when you sign up. Optional: profile photo, birthday, shipping address.

Wishlist Data

Items you add, lists you create, and preferences you set. This is the core of the service.

Usage Analytics

Anonymous usage patterns to improve the product. No individual tracking, no ad profiling.

How we use it

Transparent and simple.

Your data serves one purpose: making Gish work better for you.

Core Service

Your wishlist data powers the core features — sharing, smart routing, group buy, and notifications.

Notifications

We send you updates about your wishlists, purchases, and friends' activity. You control every notification.

Never Sold

We never sell your personal data to advertisers, data brokers, or anyone else. Period.

Your rights

You're in control.

GDPR, CCPA, and LGPD — your rights are the same no matter where you are.

Export Your Data

Download everything we have about you in a standard format, anytime.

Delete Your Account

Request full deletion. 30-day grace period during which you can cancel.

Control Sharing

Choose exactly what's public, what's shared with friends, and what's private.

Your data rights, mapped to the endpoint behind each one

Every right below is exposed in-app under Settings → Privacy → Your Data, and over the public API. No paperwork, no support ticket.

Right Law In-app API
Right of access (summary)GDPR Art 15 · LGPD Art 18 II · CCPAWhat we holdGET /v1/users/me/data-summary
RectificationGDPR Art 16 · LGPD Art 18 IIICorrect my dataPOST /v1/users/me/correct
Erasure (30-day grace)GDPR Art 17 · LGPD Art 18 VI · CCPADelete my accountPOST /v1/users/me/delete-request
Cancel pending deletion(grace-period mechanic)Cancel deletionPOST /v1/users/me/delete-cancel/<token>
Restrict processingGDPR Art 18 · LGPD Art 18 IVStop non-essential processingPOST /v1/users/me/restrict-processing
Data portabilityGDPR Art 20 · LGPD Art 18 VDownload my dataPOST /v1/users/me/export-request
"Do not sell / share" opt-outCCPA / CPRACookie banner + Privacy prefsPOST /v1/privacy/preferences

What we keep, and why: tax / anti-fraud law requires us to retain anonymized financial records (payments, contributions you received) for up to 7 years. We anonymize the name / email on those rows — we do not erase the rows themselves. Stripe is the data controller for payment-history details; request those directly at stripe.com/legal/privacy-center.

Cookies on landing pages are strictly-necessary by default. Analytics cookies are opt-in only. Use the "Reject all" button in the banner, or the analytics_opt_out preference, to refuse them globally.

GDPR Article 6

Lawful basis matrix.

Every category of personal data we process is tied to a specific lawful basis under Article 6 of the EU/UK GDPR.

Data categoryPurposeLawful basis (Art. 6)Retention
Account (email, password hash, handle)Provide the service6(1)(b) ContractAccount lifetime + 30d grace
Wishlist contentCore feature6(1)(b) ContractAccount lifetime
Shipping addressDelivery of gifts6(1)(b) ContractAccount lifetime
Payment metadata (last4, country)Fraud prevention, tax6(1)(c) Legal obligation7 years (tax law)
First-party analytics eventsCapacity, debugging, abuse6(1)(f) Legitimate interest13 months, then aggregated
Marketing email opt-inProduct updates6(1)(a) ConsentUntil withdrawn
Cookies (non-essential)Personalization, analytics6(1)(a) Consent (+ ePrivacy)Per cookie (see Cookie Policy)
Abuse / safety signalsTrust & safety6(1)(f) Legitimate interest24 months

A full GDPR Article 30 Record of Processing Activities is maintained by the operator and available to supervisory authorities on request. See operator records [VERIFY WITH FOUNDER — confirm public-facing link].

Regional rights

By jurisdiction.

Specific rights and contacts for users in the EU, UK, California, and Brazil.

EU (GDPR)

Rights of access, rectification, erasure, restriction, portability, objection, and to lodge a complaint with your national supervisory authority. DSAR: dsar-eu@gishme.com.

UK (UK GDPR + DPA 2018)

Same substantive rights as EU. Complaints: UK Information Commissioner's Office (ICO), ico.org.uk, +44 0303 123 1113. DSAR: dsar-uk@gishme.com.

California (CCPA / CPRA)

Right to know, delete, correct, and limit use of sensitive PI. Do Not Sell or Share My Personal Information. We do not sell personal information. DSAR: dsar-us@gishme.com.

Brazil (LGPD)

Article 18 rights: confirmation, access, correction, anonymization, portability, deletion, information about sharing, revocation of consent. Contact our DPO via dsar-eu@gishme.com (ANPD complaints: gov.br/anpd).

Data residency

EU/UK users' primary data is stored in AWS eu-west-1 (Dublin). US/RoW users in us-east-1 (N. Virginia). Cross-border transfers use the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum.

Data Protection Officer

DPO: [VERIFY WITH FOUNDER — DPO not yet appointed; solo-founder pre-launch]. EU representative under GDPR Art. 27: [VERIFY WITH FOUNDER — Art. 27 representative not yet retained]. Interim contact: dsar-eu@gishme.com.

DSAR addresses above are placeholder mailboxes pending DNS provisioning. [VERIFY WITH FOUNDER] before launch.

Version

Last updated.

This Privacy Policy is version 2.0, effective 10 June 2026. Prior version: v1.0 (May 2026, US-only). Material changes since v1.0: GDPR/UK GDPR/LGPD/CPRA sections, age-of-consent table, data residency, DPO contact, regional DSAR mailboxes.

Ready to get started?

Join us in making gifting more thoughtful and more personal.

First-party analytics

Gish operates its own first-party event collector to measure usage of the service (capacity planning, funnel debugging, abuse detection). These events are processing of service-provided data necessary to operate the service — they are not behavioral advertising tracking, and we never share them with third parties. We do not use Mixpanel, Amplitude, Segment, Google Analytics or any other 3rd-party analytics vendor. Events carry an opaque user id and device id only — no names, no email addresses, no free-text. Users who exercise their GDPR Article 18 right to restrict processing are excluded from all analytics at ingest. Full taxonomy: EVENT-SPEC.md.

ESC
to search Press ⌘K any time