KiftMe
Create a Kift
PersonalBusinessPricingHelp
Log in
Privacy
IndividualsBusinessesPoint of sale
Legal information

Privacy policy

Last updated : July 2026

This policy explains what data KiftMe processes, why, and the rights you have. It is separate from the Terms of use, the Legal notice and the Cookie policy.

In short (the essentials in 2 minutes)

This notice concerns individuals who use KiftMe. If you are a merchant, see the Privacy Policy - Businesses (/privacy/business). The use of in-store payment terminals is described in the POS Notice (/privacy/pos).

KiftMe lets you give a Kift: an amount locked onto a specific experience (a service or a product) that your recipient uses at a business. To run this service:

  • We collect your account information (email or phone, first name, username, date of birth, password) and the information related to your Kifts.
  • Payments are handled by Stripe; KiftMe never stores your full card number.
  • To verify that a Kift has been used, you can scan a receipt: the image is analysed by an automated reading service (AI), and the validation decision is automated - you can contest it so a human reviews it (see §7).
  • We use no advertising trackers and no third-party audience analytics tools (see §13).
  • You have rights over your data (access, deletion, etc.) that you exercise from your account or by email (see §10).

Full details are below.

Contents

  1. Data controller and contact
  2. Definitions
  3. Who is concerned (categories of people)
  4. Data processed, purposes, legal bases and durations
  5. Recipients and processors
  6. Data transfers outside the European Union
  7. Automated decisions and profiling (GDPR Article 22)
  8. Artificial intelligence systems (AI Act)
  9. Sensitive data
  10. Your rights and how to exercise them
  11. Retention periods
  12. Security
  13. Cookies and trackers
  14. Minors
  15. Changes to this policy
  16. Complaint to the CNIL

1. Data controller and contact

RELOKE LTD, a company registered in England and Wales (company number 17037940), operating the service under the trading name “KiftMe”, is the controller of your personal data. The full details of the publisher (name, legal form, registered office, registration) as well as those of the host are set out in the Legal notice (separate document).

No data protection officer (DPO) has been appointed to date. A dedicated data protection contact handles your requests: for any question about this policy or to exercise your rights, write to this contact at the address shown at the bottom of this page.

2. Definitions

  • Personal data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on personal data (collection, recording, storage, consultation, transmission, deletion, etc.).
  • Controller: the entity that determines the purposes and means of processing (here, KiftMe).
  • Processor: a provider that processes data on behalf of KiftMe and under its instructions (for example Stripe for payments).
  • Kifter: the person who creates and funds a Kift.
  • Recipient: the person who receives the Kift and uses it.

3. Who is concerned (categories of people)

This policy applies to the following categories of people:

  • Kifter: the registered user who creates and pays for a Kift. Data: account information (email or phone, first name, username, date of birth, password in encrypted form), Kifts created and funded, payment data, devices and login sessions.
  • Unregistered recipient: the person who receives a Kift without yet having an account. Data: an email or phone number, used solely to deliver the Kift to them.
  • Registered recipient: the person who receives a Kift and claims it on an account. Data: in addition to the account, the details needed to pay out the funds due to them (payout account).
  • Onboarded business: a merchant with a KiftMe professional account. Data: identity and contact details of the business (trade name, legal name, contact email and phone). Any identity verification documents (KYC) that may be required are collected and kept by Stripe, not by KiftMe.
  • Non-onboarded business (free entry): a merchant entered freely by a Kifter, without a KiftMe account. Data: the business name and address entered by the Kifter; no personal data of a representative is collected.
  • Unregistered visitor: anyone who browses the service or uses the public help form without an account. Data: the name, email and message entered in the help form, as well as the IP address.

The detail of the data and its purposes is set out in §4.

4. Data processed, purposes, legal bases and durations

ProcessingPurposeLegal basisData usedSource
Account creation and managementLet you use KiftMePerformance of contract (art. 6.1.b)Email/phone, first name, username, date of birth, password (encrypted form), consentsYou (directly)
Creating and using a KiftProvide the Kift servicePerformance of contract (art. 6.1.b)Identity of the Kifter and recipient, amount, personal message, targeted service/businessYou (directly)
PaymentCollect the KiftPerformance of contract + legal obligation (PSD2/SCA)Stripe payment identifiers, last 4 digits / brand / card country, IP address, 3D Secure result, Stripe risk scoreYou + Stripe
RefundReturn unused funds to youPerformance of contract + accounting obligationPayment and Kift dataYou + Stripe
Payout to merchant / recipientPay out fundsPerformance of contractStripe Connect account identifier, amountsStripe
Receipt reading and validation (OCR)Verify that a Kift has been usedLegitimate interest (fraud prevention)Photo/PDF of the receipt, extracted data, file fingerprintsYou (directly)
Fraud and money laundering preventionSecure payments and accountsLegitimate interest + legal obligation (AML-CFT)Device signals, IP, usage frequency, approximate geolocation, risk score, receipt fingerprintsYou + derived + Stripe
Notifications (transactional)Inform you (receipts, codes, Kift statuses)Performance of contractEmail, phone, push notification token (encrypted)You (directly)
Marketing emailsSend you promotional communicationsConsent (art. 6.1.a) - opt-in checkbox, withdrawableEmailYou (consent at sign-up)
Support and help requestsHandle your requestsPerformance of contract / legitimate interestName, email, request contentYou (directly)
Security, logging and sessionsSecure accounts and detect abuseLegal obligation + legitimate interest (service security)IP, device/browser type, event logs, token fingerprintsYou + derived

Mandatory nature of the data (art. 13). The information requested at sign-up (email or phone, first name, username, date of birth, password) and acceptance of the Terms of use are necessary to create an account: without them, the account cannot be created. This privacy policy is information provided to you; it does not in itself constitute a basis for processing. The only processing based on your consent is sending marketing emails: it is optional and refusing it has no consequence on access to the service.

Data received from third parties or derived (art. 14). Some data is not collected directly from you: payment details (brand / last 4 digits / card country, risk score, 3D Secure result, Stripe account status) are sent to us by Stripe during payment and as your account evolves; certain risk signals are derived from your activity. The source of this data is indicated in the table above.

Approximate location data. We process an approximate location, inferred from your device at login and from the metadata of the receipt photo you scan. It is used to check the consistency of a use (for example a receipt scanned far from the expected business) and to prevent fraud. This is not precise, continuous tracking of your movements.

Usage counters. To apply the service limits and prevent abuse, we keep counters of the amounts and number of Kifts per period. These counters let us enforce the announced limits and detect abnormal usage.

5. Recipients and processors

Your data is never sold. It is shared only with the processors necessary to run the service, named below, and limited to what is useful to them:

  • Stripe - payments, merchant/recipient accounts (Connect), payouts, refunds, contactless in-store payment. Data shared: email, name, phone, amounts, internal identifiers; in return, Stripe sends us the card details (brand, last 4 digits, country), the 3D Secure result and a risk score. Identity verification (KYC) of recipients and business verification (KYB) of merchants, where required, is carried out and kept by Stripe; KiftMe neither collects nor stores these documents. KiftMe never stores your full card number.
  • OpenAI - automated reading and visual verification of receipts. Data shared: the full image or PDF of the receipt you scan.
  • Mistral - automated reading (text extraction) of receipts. Data shared: the image or PDF of the receipt.
  • Supabase (self-hosted software) - database, authentication and file storage. An open-source component that we host ourselves on our own AWS infrastructure (Europe, Ireland): no data is sent to the Supabase company.
  • Amazon Web Services (Amazon SES) - sending our emails (codes, receipts, notifications, invitations). Data shared: your email address and the message content. Configured sending region: Europe (Ireland, eu-west-1).
  • Cloudflare (Turnstile) - anti-bot verification at login. Data shared: a technical token and your IP address.
  • Redis (self-hosted software) - rate limiting, one-time codes and temporary sign-up drafts. An open-source component hosted on our own AWS infrastructure (Europe, Ireland): no data is sent to a third party.
  • Amazon Web Services (AWS) - application hosting infrastructure: runs and serves the application (servers, code execution, technical logs). In that capacity, this provider may process the data that passes through the application. Hosting is located in the European Union (Europe region - Ireland, eu-west-1).
  • Your browser/device push notification service - delivery of push notifications. This service is determined by your browser or system (Google, Mozilla or Apple). The content shared is deliberately minimal (technical notification identifier, event type, link) and contains no name, amount or personal content.
  • Catalogue search providers (Google Places, Google Books, Mapbox, Spotify, Last.fm, OMDb, Ticketmaster) - only when you search for an experience to give. Data shared: your search terms (and, for address autocomplete via Mapbox, the entered address). No identifying data from your account is shared with them.

We use no third-party audience analytics tool, nor any third-party emailing or SMS service beyond those listed above.

Your data may also be disclosed to administrative or judicial authorities where the law requires it.

6. Data transfers outside the European Union

Some processors handle data outside the European Union. For each one:

ProcessorCountry / regionData concernedSafeguard
OpenAIUnited StatesImage/PDF of your receiptStandard contractual clauses (art. 46)
StripeUnited StatesEmail, name, IP, card dataStandard contractual clauses (art. 46)
Cloudflare (Turnstile)Global network (United States)Token + IP addressStandard contractual clauses (art. 46)
Push service (e.g. Google FCM)United StatesMinimal payload, no personal dataStandard contractual clauses (art. 46)
Search providers - United States (Google, Mapbox, Spotify, OMDb, Ticketmaster, Google Books)United StatesSearch terms (and business address for Mapbox)Standard contractual clauses (art. 46)
Last.fmUnited KingdomSearch termsAdequacy decision (United Kingdom)
MistralEuropean UnionImage/PDF of your receiptNo transfer outside the EU

Stays within the European Union: the application is hosted on Amazon Web Services (AWS) in the Europe (Ireland, eu-west-1) region, and sending our emails via Amazon SES is configured in the Europe (Ireland) region.

Adequacy and safeguards. The United States does not benefit from a general adequacy decision of the European Commission: transfers to our US processors therefore rely on standard contractual clauses (art. 46 of the GDPR). The United Kingdom (Last.fm), by contrast, benefits from an adequacy decision of the European Commission, which recognises an equivalent level of protection.

The receipt images you scan may be sent to services located in the United States (OpenAI). You can request a copy of the safeguards applicable to these transfers at the contact address shown in §1.

7. Automated decisions and profiling (GDPR Article 22)

KiftMe uses fully automated processing that may affect you. In accordance with Article 22 of the GDPR, here is which, their logic and your safeguards.

7.1 Automatic validation of a receipt

When you scan a receipt to unlock the use of a Kift, the decision to validate or reject the receipt is made automatically.

  • Logic: a confidence score is computed from the consistency of the receipt with the expected service (business, amount, date), the quality of the reading, and fraud signals (already-used photo, AI-generated image, attempt to manipulate the system).
  • Consequence: a validated receipt triggers the payout; a rejected receipt does not. You can retry the scan up to three times.
  • Safeguards (GDPR art. 22(3)). If your receipt is rejected, you have the right to obtain human intervention, to express your point of view and to contest the decision. In practice, you can contest the rejection: your receipt is then sent to the person who gave you the Kift, who reviews it and decides whether to validate it; cases flagged as fraud are reviewed by an internal KiftMe team. This human intervention is real: the person sees the receipt and can overturn the automatic rejection. If they validate, the payout is unlocked.

7.2 Payment and fraud risk assessment

To protect the service against fraud and money laundering, some payments or limits are assessed automatically (notably from the Stripe risk score and usage signals). A high-risk payment may be declined, and a Kift’s limit may be adjusted automatically for a recent account or one showing risk signals.

  • Logic: payment risk score, account age, usage frequency, device and location signals.
  • Your safeguards: you can express your point of view and request human intervention by writing to us at the contact address (§1); we then review your situation.

These fraud-prevention processes are not based on sensitive data (Article 9).

8. Artificial intelligence systems (AI Act)

KiftMe uses AI systems for the following uses, and informs you of them:

  • Automated receipt reading (Mistral and OpenAI OCR and vision models): analysis of your receipt image to extract the business, amounts and date, and to check consistency with the service. An “AI analysis” mention is shown while your receipt is being processed.
  • Merchant-side catalogue assistant and structuring (OpenAI model): helps merchants structure their catalogue from text or a menu. An “AI-assisted” mention is shown on the onboarding assistant and the menu-scan feature.

The personal message you attach to a Kift is not analysed by AI.

Some of these AI models may be operated outside the European Union: the corresponding transfers and their safeguards are described in §6. These systems do not use sensitive data within the meaning of Article 9 of the GDPR.

You have a right to an explanation of the role of AI in decisions based on these systems where they significantly affect you (see §7 for contestation).

9. Sensitive data

KiftMe does not intentionally process sensitive data within the meaning of Article 9 of the GDPR (health, opinions, religion, etc.), and uses no biometric data.

However, two free-entry spaces may contain such data if you add it:

  • The receipts you scan may reveal the type of business visited (for example a pharmacy). We invite you to send only receipts necessary to validate your Kift.
  • The personal message attached to a Kift is a free field. A notice invites you to avoid entering sensitive information there, as this message is retained.

We ask you not to share sensitive data that is not necessary.

10. Your rights and how to exercise them

You have the following rights over your data. To exercise them, use your account settings where indicated, or write to the contact address in §1.

  • Right of access and portability: you can export your data from your account settings. The export is provided in a downloadable file and includes your profile, your Kifts, your payments (without card number) and the validation decisions. (The export does not include raw technical receipt-reading data or internal security logs.)
  • Right to erasure: you can request deletion of your account from the settings. This operation anonymises your account: your identifying information is erased from your active profile. To meet our accounting and legal obligations, two sets of data survive for 10 years in a restricted-access archived form, then are deleted: (a) the financial data of your payments (amounts, Kifts); (b) a snapshot of your identity data (email, phone, first name, date of birth) taken at the time of deletion. Deletion is blocked while you have Kifts in progress.
  • Right to rectification: to correct your data, contact us at the address in §1; we carry out the rectification. Some profile information can also be edited directly in your account settings.
  • Right to object: you can object at any time and without condition to marketing communications, via the unsubscribe link in our emails or your account notification preferences. You can also object, for reasons relating to your particular situation, to processing based on our legitimate interest (fraud prevention, receipt analysis, security) by writing to the address in §1; we then stop the processing unless there are compelling legitimate grounds or the defence of a legal claim.
  • Right to restriction of processing: send your request to the address in §1.
  • Right to withdraw your consent: where processing is based on your consent (marketing emails), you can withdraw it at any time, without affecting processing already carried out.
  • Post-mortem directives: in accordance with Article 85 of the French Data Protection Act, you may set directives on the fate of your data after your death, and appoint a person responsible for carrying them out.

Exercising your rights is free of charge. To protect your account, we may need to verify your identity before responding. We handle your requests within one month of receiving them; this period may be extended by two months for complex or numerous requests, in which case we inform you.

If you consider that your rights are not being respected, you may at any time lodge a complaint with the CNIL (see §16).

11. Retention periods

We retain your data for the following periods:

DataDuration
AccountAs long as your account is active; anonymised on deletion
Kift12 months (validity period)
Recipient claim of a Kift30 days
Photo of a scanned receipt5 years from the validation decision, then the image is deleted
Technical receipt fingerprints (anti-reuse)Kept to prevent fraudulent reuse of the same receipt
Support requests3 years
In-app notifications30 days
Your data export file7 days
Login sessions30 days
Known devices / security logs12 months
Accounting, payment, refund and payout data10 years (accounting and legal obligations)
Tax data6 years
Proof of consent5 years
Fraud-prevention data3 years
Marketing preferences3 years

12. Security

We implement the following technical measures, effectively present in the product:

  • Database partitioning and access control (row-level security policies, access restricted by user/role).
  • Passwords stored as an encrypted hash (never in plain text).
  • Encryption of strong-authentication secrets and push notification tokens (AES-256-GCM).
  • Pseudonymisation of trusted-device identifiers and receipt fingerprints.
  • Encryption of communications (HTTPS/TLS), with a security header forcing encrypted connections in production.
  • Strong payment authentication (3D Secure) delegated to Stripe.
  • Logging of sensitive actions and rate limiting against abuse.
  • Internal access to data strictly limited to authorised staff who need it.
  • Two-factor authentication (2FA) available to secure account access.

13. Cookies and trackers

KiftMe places no advertising trackers and no third-party audience analytics tools. The items placed on your device are strictly necessary for operation and exempt from consent:

PurposeTypeDurationConsent
Authentication and session (keep you logged in)CookieSession durationExempt
Language preferenceCookieAbout 1 yearExempt
Anti-bot security (Cloudflare Turnstile)CookieFor the duration of the checkExempt
Installable app functioningLocal storagePersistent while the app is installedExempt

None of these trackers is subject to consent: no banner (CMP) is therefore required to date. If an audience-measurement tool were to be activated, a consent banner would be put in place beforehand. Details are in the Cookie policy (separate document).

14. Minors

KiftMe is reserved for people aged at least 15, in line with the French digital consent threshold. The date of birth is requested at sign-up and access is refused below this age. If we learn that an account was created by a younger person, we delete it.

15. Changes to this policy

We may change this policy to reflect a change in the service or in regulation. The last-updated date appears at the top of the document. In the event of a substantial change, we inform you by an appropriate means (by email or in the app) before it takes effect.

16. Complaint to the CNIL

If you consider that the processing of your data does not comply, you can lodge a complaint with the French data protection authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 - www.cnil.fr.

GDPR contact : [email protected]

Back to home

KiftMe

Give what you love to the people you love.

Product

PersonalBusinessPricingCreate a Kift

Company

How it worksAboutContactHelp

Legal

Legal noticeTermsPrivacyCookiesRefunds & cancellationsContact

© 2026 KiftMe. All rights reserved.

·