Privacy policy
Last updated : July 2026
This policy explains what data KiftMe processes, why, and the rights you have. It is separate from the Terms of use, the Legal notice and the Cookie policy.
1. Data controller and contact
RELOKE LTD, a company registered in England and Wales (company number 17037940), operating the service under the trading name “KiftMe”, is the controller of your personal data. The full details of the publisher (name, legal form, registered office, registration) as well as those of the host are set out in the Legal notice (separate document).
No data protection officer (DPO) has been appointed to date. A dedicated data protection contact handles your requests: for any question about this policy or to exercise your rights, write to this contact at the address shown at the bottom of this page.
2. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data (collection, recording, storage, consultation, transmission, deletion, etc.).
- Controller: the entity that determines the purposes and means of processing (here, KiftMe).
- Processor: a provider that processes data on behalf of KiftMe and under its instructions (for example Stripe for payments).
- Kifter: the person who creates and funds a Kift.
- Recipient: the person who receives the Kift and uses it.
3. Who is concerned (categories of people)
This policy applies to the following categories of people:
- Kifter: the registered user who creates and pays for a Kift. Data: account information (email or phone, first name, username, date of birth, password in encrypted form), Kifts created and funded, payment data, devices and login sessions.
- Unregistered recipient: the person who receives a Kift without yet having an account. Data: an email or phone number, used solely to deliver the Kift to them.
- Registered recipient: the person who receives a Kift and claims it on an account. Data: in addition to the account, the details needed to pay out the funds due to them (payout account).
- Onboarded business: a merchant with a KiftMe professional account. Data: identity and contact details of the business (trade name, legal name, contact email and phone). Any identity verification documents (KYC) that may be required are collected and kept by Stripe, not by KiftMe.
- Non-onboarded business (free entry): a merchant entered freely by a Kifter, without a KiftMe account. Data: the business name and address entered by the Kifter; no personal data of a representative is collected.
- Unregistered visitor: anyone who browses the service or uses the public help form without an account. Data: the name, email and message entered in the help form, as well as the IP address.
The detail of the data and its purposes is set out in §4.
4. Data processed, purposes, legal bases and durations
| Processing | Purpose | Legal basis | Data used | Source |
|---|---|---|---|---|
| Account creation and management | Let you use KiftMe | Performance of contract (art. 6.1.b) | Email/phone, first name, username, date of birth, password (encrypted form), consents | You (directly) |
| Creating and using a Kift | Provide the Kift service | Performance of contract (art. 6.1.b) | Identity of the Kifter and recipient, amount, personal message, targeted service/business | You (directly) |
| Payment | Collect the Kift | Performance of contract + legal obligation (PSD2/SCA) | Stripe payment identifiers, last 4 digits / brand / card country, IP address, 3D Secure result, Stripe risk score | You + Stripe |
| Refund | Return unused funds to you | Performance of contract + accounting obligation | Payment and Kift data | You + Stripe |
| Payout to merchant / recipient | Pay out funds | Performance of contract | Stripe Connect account identifier, amounts | Stripe |
| Receipt reading and validation (OCR) | Verify that a Kift has been used | Legitimate interest (fraud prevention) | Photo/PDF of the receipt, extracted data, file fingerprints | You (directly) |
| Fraud and money laundering prevention | Secure payments and accounts | Legitimate interest + legal obligation (AML-CFT) | Device signals, IP, usage frequency, approximate geolocation, risk score, receipt fingerprints | You + derived + Stripe |
| Notifications (transactional) | Inform you (receipts, codes, Kift statuses) | Performance of contract | Email, phone, push notification token (encrypted) | You (directly) |
| Marketing emails | Send you promotional communications | Consent (art. 6.1.a) - opt-in checkbox, withdrawable | You (consent at sign-up) | |
| Support and help requests | Handle your requests | Performance of contract / legitimate interest | Name, email, request content | You (directly) |
| Security, logging and sessions | Secure accounts and detect abuse | Legal obligation + legitimate interest (service security) | IP, device/browser type, event logs, token fingerprints | You + derived |
Mandatory nature of the data (art. 13). The information requested at sign-up (email or phone, first name, username, date of birth, password) and acceptance of the Terms of use are necessary to create an account: without them, the account cannot be created. This privacy policy is information provided to you; it does not in itself constitute a basis for processing. The only processing based on your consent is sending marketing emails: it is optional and refusing it has no consequence on access to the service.
Data received from third parties or derived (art. 14). Some data is not collected directly from you: payment details (brand / last 4 digits / card country, risk score, 3D Secure result, Stripe account status) are sent to us by Stripe during payment and as your account evolves; certain risk signals are derived from your activity. The source of this data is indicated in the table above.
Approximate location data. We process an approximate location, inferred from your device at login and from the metadata of the receipt photo you scan. It is used to check the consistency of a use (for example a receipt scanned far from the expected business) and to prevent fraud. This is not precise, continuous tracking of your movements.
Usage counters. To apply the service limits and prevent abuse, we keep counters of the amounts and number of Kifts per period. These counters let us enforce the announced limits and detect abnormal usage.
5. Recipients and processors
Your data is never sold. It is shared only with the processors necessary to run the service, named below, and limited to what is useful to them:
- Stripe - payments, merchant/recipient accounts (Connect), payouts, refunds, contactless in-store payment. Data shared: email, name, phone, amounts, internal identifiers; in return, Stripe sends us the card details (brand, last 4 digits, country), the 3D Secure result and a risk score. Identity verification (KYC) of recipients and business verification (KYB) of merchants, where required, is carried out and kept by Stripe; KiftMe neither collects nor stores these documents. KiftMe never stores your full card number.
- OpenAI - automated reading and visual verification of receipts. Data shared: the full image or PDF of the receipt you scan.
- Mistral - automated reading (text extraction) of receipts. Data shared: the image or PDF of the receipt.
- Supabase (self-hosted software) - database, authentication and file storage. An open-source component that we host ourselves on our own AWS infrastructure (Europe, Ireland): no data is sent to the Supabase company.
- Amazon Web Services (Amazon SES) - sending our emails (codes, receipts, notifications, invitations). Data shared: your email address and the message content. Configured sending region: Europe (Ireland, eu-west-1).
- Cloudflare (Turnstile) - anti-bot verification at login. Data shared: a technical token and your IP address.
- Redis (self-hosted software) - rate limiting, one-time codes and temporary sign-up drafts. An open-source component hosted on our own AWS infrastructure (Europe, Ireland): no data is sent to a third party.
- Amazon Web Services (AWS) - application hosting infrastructure: runs and serves the application (servers, code execution, technical logs). In that capacity, this provider may process the data that passes through the application. Hosting is located in the European Union (Europe region - Ireland, eu-west-1).
- Your browser/device push notification service - delivery of push notifications. This service is determined by your browser or system (Google, Mozilla or Apple). The content shared is deliberately minimal (technical notification identifier, event type, link) and contains no name, amount or personal content.
- Catalogue search providers (Google Places, Google Books, Mapbox, Spotify, Last.fm, OMDb, Ticketmaster) - only when you search for an experience to give. Data shared: your search terms (and, for address autocomplete via Mapbox, the entered address). No identifying data from your account is shared with them.
We use no third-party audience analytics tool, nor any third-party emailing or SMS service beyond those listed above.
Your data may also be disclosed to administrative or judicial authorities where the law requires it.
6. Data transfers outside the European Union
Some processors handle data outside the European Union. For each one:
| Processor | Country / region | Data concerned | Safeguard |
|---|---|---|---|
| OpenAI | United States | Image/PDF of your receipt | Standard contractual clauses (art. 46) |
| Stripe | United States | Email, name, IP, card data | Standard contractual clauses (art. 46) |
| Cloudflare (Turnstile) | Global network (United States) | Token + IP address | Standard contractual clauses (art. 46) |
| Push service (e.g. Google FCM) | United States | Minimal payload, no personal data | Standard contractual clauses (art. 46) |
| Search providers - United States (Google, Mapbox, Spotify, OMDb, Ticketmaster, Google Books) | United States | Search terms (and business address for Mapbox) | Standard contractual clauses (art. 46) |
| Last.fm | United Kingdom | Search terms | Adequacy decision (United Kingdom) |
| Mistral | European Union | Image/PDF of your receipt | No transfer outside the EU |
Stays within the European Union: the application is hosted on Amazon Web Services (AWS) in the Europe (Ireland, eu-west-1) region, and sending our emails via Amazon SES is configured in the Europe (Ireland) region.
Adequacy and safeguards. The United States does not benefit from a general adequacy decision of the European Commission: transfers to our US processors therefore rely on standard contractual clauses (art. 46 of the GDPR). The United Kingdom (Last.fm), by contrast, benefits from an adequacy decision of the European Commission, which recognises an equivalent level of protection.
The receipt images you scan may be sent to services located in the United States (OpenAI). You can request a copy of the safeguards applicable to these transfers at the contact address shown in §1.
7. Automated decisions and profiling (GDPR Article 22)
KiftMe uses fully automated processing that may affect you. In accordance with Article 22 of the GDPR, here is which, their logic and your safeguards.
7.1 Automatic validation of a receipt
When you scan a receipt to unlock the use of a Kift, the decision to validate or reject the receipt is made automatically.
- Logic: a confidence score is computed from the consistency of the receipt with the expected service (business, amount, date), the quality of the reading, and fraud signals (already-used photo, AI-generated image, attempt to manipulate the system).
- Consequence: a validated receipt triggers the payout; a rejected receipt does not. You can retry the scan up to three times.
- Safeguards (GDPR art. 22(3)). If your receipt is rejected, you have the right to obtain human intervention, to express your point of view and to contest the decision. In practice, you can contest the rejection: your receipt is then sent to the person who gave you the Kift, who reviews it and decides whether to validate it; cases flagged as fraud are reviewed by an internal KiftMe team. This human intervention is real: the person sees the receipt and can overturn the automatic rejection. If they validate, the payout is unlocked.
7.2 Payment and fraud risk assessment
To protect the service against fraud and money laundering, some payments or limits are assessed automatically (notably from the Stripe risk score and usage signals). A high-risk payment may be declined, and a Kift’s limit may be adjusted automatically for a recent account or one showing risk signals.
- Logic: payment risk score, account age, usage frequency, device and location signals.
- Your safeguards: you can express your point of view and request human intervention by writing to us at the contact address (§1); we then review your situation.
These fraud-prevention processes are not based on sensitive data (Article 9).
8. Artificial intelligence systems (AI Act)
KiftMe uses AI systems for the following uses, and informs you of them:
- Automated receipt reading (Mistral and OpenAI OCR and vision models): analysis of your receipt image to extract the business, amounts and date, and to check consistency with the service. An “AI analysis” mention is shown while your receipt is being processed.
- Merchant-side catalogue assistant and structuring (OpenAI model): helps merchants structure their catalogue from text or a menu. An “AI-assisted” mention is shown on the onboarding assistant and the menu-scan feature.
The personal message you attach to a Kift is not analysed by AI.
Some of these AI models may be operated outside the European Union: the corresponding transfers and their safeguards are described in §6. These systems do not use sensitive data within the meaning of Article 9 of the GDPR.
You have a right to an explanation of the role of AI in decisions based on these systems where they significantly affect you (see §7 for contestation).
9. Sensitive data
KiftMe does not intentionally process sensitive data within the meaning of Article 9 of the GDPR (health, opinions, religion, etc.), and uses no biometric data.
However, two free-entry spaces may contain such data if you add it:
- The receipts you scan may reveal the type of business visited (for example a pharmacy). We invite you to send only receipts necessary to validate your Kift.
- The personal message attached to a Kift is a free field. A notice invites you to avoid entering sensitive information there, as this message is retained.
We ask you not to share sensitive data that is not necessary.
10. Your rights and how to exercise them
You have the following rights over your data. To exercise them, use your account settings where indicated, or write to the contact address in §1.
- Right of access and portability: you can export your data from your account settings. The export is provided in a downloadable file and includes your profile, your Kifts, your payments (without card number) and the validation decisions. (The export does not include raw technical receipt-reading data or internal security logs.)
- Right to erasure: you can request deletion of your account from the settings. This operation anonymises your account: your identifying information is erased from your active profile. To meet our accounting and legal obligations, two sets of data survive for 10 years in a restricted-access archived form, then are deleted: (a) the financial data of your payments (amounts, Kifts); (b) a snapshot of your identity data (email, phone, first name, date of birth) taken at the time of deletion. Deletion is blocked while you have Kifts in progress.
- Right to rectification: to correct your data, contact us at the address in §1; we carry out the rectification. Some profile information can also be edited directly in your account settings.
- Right to object: you can object at any time and without condition to marketing communications, via the unsubscribe link in our emails or your account notification preferences. You can also object, for reasons relating to your particular situation, to processing based on our legitimate interest (fraud prevention, receipt analysis, security) by writing to the address in §1; we then stop the processing unless there are compelling legitimate grounds or the defence of a legal claim.
- Right to restriction of processing: send your request to the address in §1.
- Right to withdraw your consent: where processing is based on your consent (marketing emails), you can withdraw it at any time, without affecting processing already carried out.
- Post-mortem directives: in accordance with Article 85 of the French Data Protection Act, you may set directives on the fate of your data after your death, and appoint a person responsible for carrying them out.
Exercising your rights is free of charge. To protect your account, we may need to verify your identity before responding. We handle your requests within one month of receiving them; this period may be extended by two months for complex or numerous requests, in which case we inform you.
If you consider that your rights are not being respected, you may at any time lodge a complaint with the CNIL (see §16).
11. Retention periods
We retain your data for the following periods:
| Data | Duration |
|---|---|
| Account | As long as your account is active; anonymised on deletion |
| Kift | 12 months (validity period) |
| Recipient claim of a Kift | 30 days |
| Photo of a scanned receipt | 5 years from the validation decision, then the image is deleted |
| Technical receipt fingerprints (anti-reuse) | Kept to prevent fraudulent reuse of the same receipt |
| Support requests | 3 years |
| In-app notifications | 30 days |
| Your data export file | 7 days |
| Login sessions | 30 days |
| Known devices / security logs | 12 months |
| Accounting, payment, refund and payout data | 10 years (accounting and legal obligations) |
| Tax data | 6 years |
| Proof of consent | 5 years |
| Fraud-prevention data | 3 years |
| Marketing preferences | 3 years |
12. Security
We implement the following technical measures, effectively present in the product:
- Database partitioning and access control (row-level security policies, access restricted by user/role).
- Passwords stored as an encrypted hash (never in plain text).
- Encryption of strong-authentication secrets and push notification tokens (AES-256-GCM).
- Pseudonymisation of trusted-device identifiers and receipt fingerprints.
- Encryption of communications (HTTPS/TLS), with a security header forcing encrypted connections in production.
- Strong payment authentication (3D Secure) delegated to Stripe.
- Logging of sensitive actions and rate limiting against abuse.
- Internal access to data strictly limited to authorised staff who need it.
- Two-factor authentication (2FA) available to secure account access.
13. Cookies and trackers
KiftMe places no advertising trackers and no third-party audience analytics tools. The items placed on your device are strictly necessary for operation and exempt from consent:
| Purpose | Type | Duration | Consent |
|---|---|---|---|
| Authentication and session (keep you logged in) | Cookie | Session duration | Exempt |
| Language preference | Cookie | About 1 year | Exempt |
| Anti-bot security (Cloudflare Turnstile) | Cookie | For the duration of the check | Exempt |
| Installable app functioning | Local storage | Persistent while the app is installed | Exempt |
None of these trackers is subject to consent: no banner (CMP) is therefore required to date. If an audience-measurement tool were to be activated, a consent banner would be put in place beforehand. Details are in the Cookie policy (separate document).
14. Minors
KiftMe is reserved for people aged at least 15, in line with the French digital consent threshold. The date of birth is requested at sign-up and access is refused below this age. If we learn that an account was created by a younger person, we delete it.
15. Changes to this policy
We may change this policy to reflect a change in the service or in regulation. The last-updated date appears at the top of the document. In the event of a substantial change, we inform you by an appropriate means (by email or in the app) before it takes effect.
16. Complaint to the CNIL
If you consider that the processing of your data does not comply, you can lodge a complaint with the French data protection authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 - www.cnil.fr.
GDPR contact : [email protected]