Your privacy
matters.
We collect only what we need, we never sell your data, and we give you full control. Here's exactly how it works.
Only what we need.
We collect the minimum data necessary to provide you with a great gifting experience.
Account Information
Name, email, and password when you sign up. Optional: profile photo, birthday, shipping address.
Wishlist Data
Items you add, lists you create, and preferences you set. This is the core of the service.
Usage Analytics
Anonymous usage patterns to improve the product. No individual tracking, no ad profiling.
Transparent and simple.
Your data serves one purpose: making Gish work better for you.
Core Service
Your wishlist data powers the core features — sharing, smart routing, group buy, and notifications.
Notifications
We send you updates about your wishlists, purchases, and friends' activity. You control every notification.
Never Sold
We never sell your personal data to advertisers, data brokers, or anyone else. Period.
You're in control.
GDPR, CCPA, and LGPD — your rights are the same no matter where you are.
Export Your Data
Download everything we have about you in a standard format, anytime.
Delete Your Account
Request full deletion. 30-day grace period during which you can cancel.
Control Sharing
Choose exactly what's public, what's shared with friends, and what's private.
Your data rights, mapped to the endpoint behind each one
Every right below is exposed in-app under Settings → Privacy → Your Data, and over the public API. No paperwork, no support ticket.
| Right | Law | In-app | API |
|---|---|---|---|
| Right of access (summary) | GDPR Art 15 · LGPD Art 18 II · CCPA | What we hold | GET /v1/users/me/data-summary |
| Rectification | GDPR Art 16 · LGPD Art 18 III | Correct my data | POST /v1/users/me/correct |
| Erasure (30-day grace) | GDPR Art 17 · LGPD Art 18 VI · CCPA | Delete my account | POST /v1/users/me/delete-request |
| Cancel pending deletion | (grace-period mechanic) | Cancel deletion | POST /v1/users/me/delete-cancel/<token> |
| Restrict processing | GDPR Art 18 · LGPD Art 18 IV | Stop non-essential processing | POST /v1/users/me/restrict-processing |
| Data portability | GDPR Art 20 · LGPD Art 18 V | Download my data | POST /v1/users/me/export-request |
| "Do not sell / share" opt-out | CCPA / CPRA | Cookie banner + Privacy prefs | POST /v1/privacy/preferences |
What we keep, and why: tax / anti-fraud law requires us to retain anonymized financial records (payments, contributions you received) for up to 7 years. We anonymize the name / email on those rows — we do not erase the rows themselves. Stripe is the data controller for payment-history details; request those directly at stripe.com/legal/privacy-center.
Cookies on landing pages are strictly-necessary by default. Analytics cookies are opt-in only. Use the "Reject all" button in the banner, or the analytics_opt_out preference, to refuse them globally.
Lawful basis matrix.
Every category of personal data we process is tied to a specific lawful basis under Article 6 of the EU/UK GDPR.
| Data category | Purpose | Lawful basis (Art. 6) | Retention |
|---|---|---|---|
| Account (email, password hash, handle) | Provide the service | 6(1)(b) Contract | Account lifetime + 30d grace |
| Wishlist content | Core feature | 6(1)(b) Contract | Account lifetime |
| Shipping address | Delivery of gifts | 6(1)(b) Contract | Account lifetime |
| Payment metadata (last4, country) | Fraud prevention, tax | 6(1)(c) Legal obligation | 7 years (tax law) |
| First-party analytics events | Capacity, debugging, abuse | 6(1)(f) Legitimate interest | 13 months, then aggregated |
| Marketing email opt-in | Product updates | 6(1)(a) Consent | Until withdrawn |
| Cookies (non-essential) | Personalization, analytics | 6(1)(a) Consent (+ ePrivacy) | Per cookie (see Cookie Policy) |
| Abuse / safety signals | Trust & safety | 6(1)(f) Legitimate interest | 24 months |
A full GDPR Article 30 Record of Processing Activities is maintained by the operator and available to supervisory authorities on request. See operator records [VERIFY WITH FOUNDER — confirm public-facing link].
Age of consent, by region.
Different jurisdictions set different minimum ages for a child to consent to information-society services. Below this age, verifiable parental consent is required.
| Region | Minimum age | Statute |
|---|---|---|
| United States | 13 | COPPA, 15 U.S.C. §§6501–6506 |
| United Kingdom | 13 | UK GDPR / DPA 2018 s.9 |
| Ireland, Belgium, Denmark, Estonia, Finland, Latvia, Malta, Norway, Poland, Portugal, Sweden | 13 | GDPR Art. 8 (national derogation) |
| Spain, Bulgaria, Cyprus, Czechia, Greece, Italy | 14 | GDPR Art. 8 (national derogation) |
| Austria, France, Slovenia | 15 | GDPR Art. 8 (national derogation) |
| Germany, Hungary, Lithuania, Luxembourg, Netherlands, Romania, Slovakia, Croatia | 16 | GDPR Art. 8 (default) |
| Brazil | 12 (children) / 18 (adolescent rules) | LGPD Art. 14 |
| Australia | No statutory minimum; OAIC guidance ~15 | Privacy Act 1988 |
Gish geo-detects the registering user's country and applies the strictest applicable threshold. Users below the local threshold are blocked from registration pending verifiable parental consent.
By jurisdiction.
Specific rights and contacts for users in the EU, UK, California, and Brazil.
EU (GDPR)
Rights of access, rectification, erasure, restriction, portability, objection, and to lodge a complaint with your national supervisory authority. DSAR: dsar-eu@gishme.com.
UK (UK GDPR + DPA 2018)
Same substantive rights as EU. Complaints: UK Information Commissioner's Office (ICO), ico.org.uk, +44 0303 123 1113. DSAR: dsar-uk@gishme.com.
California (CCPA / CPRA)
Right to know, delete, correct, and limit use of sensitive PI. Do Not Sell or Share My Personal Information. We do not sell personal information. DSAR: dsar-us@gishme.com.
Brazil (LGPD)
Article 18 rights: confirmation, access, correction, anonymization, portability, deletion, information about sharing, revocation of consent. Contact our DPO via dsar-eu@gishme.com (ANPD complaints: gov.br/anpd).
Data residency
EU/UK users' primary data is stored in AWS eu-west-1 (Dublin). US/RoW users in us-east-1 (N. Virginia). Cross-border transfers use the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum.
Data Protection Officer
DPO: [VERIFY WITH FOUNDER — DPO not yet appointed; solo-founder pre-launch]. EU representative under GDPR Art. 27: [VERIFY WITH FOUNDER — Art. 27 representative not yet retained]. Interim contact: dsar-eu@gishme.com.
DSAR addresses above are placeholder mailboxes pending DNS provisioning. [VERIFY WITH FOUNDER] before launch.
Last updated.
This Privacy Policy is version 2.0, effective 10 June 2026. Prior version: v1.0 (May 2026, US-only). Material changes since v1.0: GDPR/UK GDPR/LGPD/CPRA sections, age-of-consent table, data residency, DPO contact, regional DSAR mailboxes.
First-party analytics
Gish operates its own first-party event collector to measure usage of
the service (capacity planning, funnel debugging, abuse detection).
These events are processing of service-provided data necessary
to operate the service — they are not behavioral advertising
tracking, and we never share them with third parties. We do not use
Mixpanel, Amplitude, Segment, Google Analytics or any other 3rd-party
analytics vendor. Events carry an opaque user id and device id only
— no names, no email addresses, no free-text. Users who exercise
their GDPR Article 18 right to restrict processing are excluded from all
analytics at ingest. Full taxonomy: EVENT-SPEC.md.