KiftMe
Create a Kift
PersonalBusinessPricingHelp
Log in
Privacy
IndividualsBusinessesPoint of sale
Legal information

Privacy Policy - Businesses

Last updated : June 2026

This notice explains what data KiftMe processes when you manage a professional account, why, on what basis and for how long. It is separate from the Terms of use, the Legal notice and the Cookie policy.

In short (the essentials in 2 minutes)

This notice concerns merchants. Your individual customers are covered by the Privacy Policy - Consumers (/privacy). The use of in-store payment terminals is covered by the POS Notice (/privacy/pos).

KiftMe provides you with a professional space to publish your catalogue, collect Kifts and receive the corresponding payouts. To run this service:

  • We process your professional account data (email, phone, first name, last name, password in encrypted form) and that of the members you invite.
  • Your business identity verification (KYB) and the payouts are operated by Stripe; KiftMe neither collects nor stores your KYB supporting documents.
  • A business’s activity is suspended automatically when an owed balance exceeds a limit; you can request human intervention and contest this decision (see §6).

Full details are below.

Contents

  1. Data controller and contact
  2. Who this notice is for
  3. Data processed, purposes, legal bases and durations
  4. Recipients and processors
  5. Data transfers outside the European Union
  6. Automated decisions and profiling (GDPR Article 22)
  7. Artificial intelligence systems (AI Act)
  8. Your rights and how to exercise them
  9. Retention periods
  10. Security
  11. Cookies and trackers (professional space)
  12. Changes to this notice
  13. Complaint to the CNIL

1. Data controller and contact

RELOKE LTD, a company registered in England and Wales (company number 17037940), operating the service under the trading name “KiftMe”, is the controller of the personal data described in this notice. The full details of the publisher (name, legal form, registered office, registration) as well as those of the host are set out in the Legal notice (separate document).

No data protection officer (DPO) has been appointed to date. A dedicated data protection contact handles your requests: for any question about this notice or to exercise your rights, write to this contact at the address shown at the bottom of this page.

2. Who this notice is for

This notice applies to the following natural persons, within the KiftMe professional space:

  • The professional account holder: the person who creates and administers the business account.
  • Invited team members: the people the holder invites to access the account, with a defined role.

Your individual customers (the people who give or receive a Kift) are covered by the Privacy Policy - Consumers (/privacy). The use of in-store payment terminals is covered by the POS Notice (/privacy/pos).

3. Data processed, purposes, legal bases and durations

The table below summarises, for each processing operation of the professional space, the purpose pursued, the legal basis, the data used and its source.

ProcessingPurposeLegal basisData usedSource
Professional account creation and managementGive you access to the professional spacePerformance of contract (art. 6.1.b)Email, phone, first name, last name, password (encrypted form), two-factor authentication factors (SMS / TOTP app), login IP addressYou (directly)
Business identity verification (KYB)Verify your business and activate payment and payout capabilitiesLegal obligation (AML-CFT) + performance of contractVerification status, capabilities and requirements returned by Stripe; supporting documents are provided to Stripe and kept by itStripe
Team invitationsAllow collaborators to access the accountPerformance of contract / legitimate interest (organising your team)Email address of the invited people, assigned role, invitation statusYou (directly)
Catalogue management and AI assistantHelp you structure and publish your cataloguePerformance of contractText, photo or menu you submit to the assistant; catalogue items producedYou (directly)
Payouts via Stripe ConnectPay out the funds due to youPerformance of contract + accounting obligationStripe Connect account identifier, amounts, payout statusesStripe
Audit and security logsSecure the account, trace sensitive actions and detect abuseLegal obligation + legitimate interest (service security)Login attempts and events, IP address, device/browser type, actions performedYou + derived
SupportHandle your assistance requestsPerformance of contract / legitimate interestName, email, request contentYou (directly)

Mandatory nature of the data (art. 13). The information requested to open and secure a professional account (email, phone, first name, last name, password) and acceptance of the Terms of use are necessary: without them, the account cannot be created. Business identity verification (KYB) is necessary to activate the collection and payout capabilities: without it, these capabilities remain unavailable. This notice is information provided to you; it does not in itself constitute a basis for processing.

Data received from Stripe (art. 14). Some data is not collected directly from you: during business identity verification and over the life of your account, Stripe sends us the verification status (KYB), the capabilities activated (for example collection and payouts) and the requirements remaining to keep your account active. The source of this data is Stripe, which acts as a payment provider and keeps the corresponding supporting documents.

4. Recipients and processors

Your data is never sold. It is shared only with the processors necessary to run the professional space, named below, and limited to what is useful to them:

  • Stripe - payments, business identity verification (KYB) and payouts (Stripe Connect). Data shared: email, name, phone, amounts, internal identifiers, and the identity verification items you provide. KYB verification is carried out and kept by Stripe; KiftMe neither collects nor stores these supporting documents.
  • Supabase - database, authentication and file storage. Processes all professional-space data.
  • Amazon Web Services (Amazon SES) - sending our emails and team invitations. Data shared: the email address and the message content. Configured sending region: Europe (Paris).
  • OpenAI - catalogue assistant (onboarding structuring and menu reading). Data shared: the text, photo or menu you submit to the assistant.
  • Application hosting infrastructure - runs and serves the application (servers, code execution, technical logs). In that capacity, this provider may process the data that passes through the application.

We use no third-party audience analytics tool, nor any third-party emailing or SMS service beyond those listed above.

Your data may also be disclosed to administrative or judicial authorities where the law requires it.

5. Data transfers outside the European Union

Some processors handle data outside the European Union. For each one:

ProcessorCountry / regionData concernedSafeguard
StripeUnited StatesEmail, name, phone, amounts, verification (KYB) dataStandard contractual clauses (art. 46)
OpenAIUnited StatesText, photo or menu submitted to the catalogue assistantStandard contractual clauses (art. 46)

Stays within the European Union: sending our emails and team invitations via Amazon SES is configured in the Europe (Paris) region.

Adequacy and safeguards. The United States does not benefit from a general adequacy decision of the European Commission: transfers to Stripe and OpenAI therefore rely on standard contractual clauses (art. 46 of the GDPR).

You can request a copy of the safeguards applicable to these transfers at the contact address shown in §1.

6. Automated decisions and profiling (GDPR Article 22)

KiftMe uses fully automated processing that may significantly affect your business’s activity. In accordance with Article 22 of the GDPR, here is which, their logic and your safeguards.

6.1 Automatic blocking of the business’s activity

When the balance your business owes to KiftMe exceeds a limit, the business’s activity is suspended automatically: the creation of new Kifts and collection are stopped until the situation is settled.

  • Logic: the decision is based on monitoring the owed balance and the funds held in reserve, together with risk signals related to account usage (for example an abnormal refund pattern). The precise thresholds are not published for security reasons.
  • Consequence: while suspended, your business can no longer create or collect Kifts. Kifts already issued and outstanding obligations are not erased. The suspension is lifted once the situation is settled.
  • Safeguards (GDPR art. 22(3)). You have the right to obtain human intervention, to express your point of view and to contest the decision. In practice, write to the contact address (§1): an internal KiftMe team reviews your situation, can take your explanations into account and lift the suspension.

6.2 Automatic account risk assessment

To protect the service against fraud and money laundering, the risk of a professional account is assessed automatically. This assessment may lead to requiring internal validation for certain sensitive operations, or to temporarily restricting the account.

  • Logic: account age and verification status, risk signals related to payments and refunds, consistency of usage. The precise parameters are not published for security reasons.
  • Your safeguards: you can express your point of view and request human intervention by writing to us at the contact address (§1); we then review your situation.

These fraud-prevention processes are not based on sensitive data (Article 9).

7. Artificial intelligence systems (AI Act)

KiftMe provides you with a catalogue assistant based on an artificial intelligence system, and informs you of it:

  • Onboarding assistant and catalogue structuring (OpenAI model): helps you structure your catalogue from text you enter.
  • Menu scan (OpenAI model): analyses the photo or menu you submit to extract the catalogue items.

An “AI-assisted” mention is shown on the onboarding assistant and the menu-scan feature. These systems may be operated outside the European Union: the corresponding transfers and their safeguards are described in §5. They do not use sensitive data within the meaning of Article 9 of the GDPR.

You have a right to an explanation of the role of AI in decisions based on these systems where they significantly affect you.

8. Your rights and how to exercise them

You have the following rights over your data. To exercise them, write to the contact address in §1.

  • Right of access: you can obtain confirmation that your data is processed and receive a copy of it.
  • Right to rectification: to correct your data, contact us at the address in §1; some profile information can also be edited directly in your account settings.
  • Right to erasure: you can request deletion of your data, subject to the retention periods imposed by our legal and accounting obligations (see §9).
  • Right to object: you can object, for reasons relating to your particular situation, to processing based on our legitimate interest (security, team organisation) by writing to the address in §1; we then stop the processing unless there are compelling legitimate grounds or the defence of a legal claim.
  • Right to withdraw your consent: where a processing operation relies on your consent (for example marketing communications), you can withdraw it at any time, without affecting the lawfulness of processing already carried out.
  • Right to restriction of processing: send your request to the address in §1.
  • Right to portability: for the data you provided to us and processed on the basis of the contract, you can request to receive it in a structured, machine-readable format.

The business identity verification (KYB) data is held and kept by Stripe. For rights relating to this data, your request may also need to be made to Stripe; we direct you accordingly where relevant.

Exercising your rights is free of charge. To protect the account, we may need to verify your identity before responding. We handle your requests within one month of receiving them; this period may be extended by two months for complex or numerous requests, in which case we inform you.

If you consider that your rights are not being respected, you may at any time lodge a complaint with the CNIL (see §13).

9. Retention periods

We retain your data for the following periods:

DataDuration
Professional accountAs long as the account is active
Accounting, payment and payout data10 years (accounting and legal obligations)
Tax data6 years
Business identity verification (KYB)Kept by Stripe under its own legal obligations
Authentication logs (logins)12 months
Security audit logs3 years
Proof of consent, where applicable5 years
Support requests3 years

10. Security

We implement technical and organisational measures suited to protecting professional-space data:

  • Access control and data partitioning between businesses and between roles.
  • Passwords stored as an encrypted hash (never in plain text).
  • Encryption of authentication secrets and communications (HTTPS/TLS).
  • Two-factor authentication (MFA) available, by SMS or authenticator app, to secure account access.
  • Logging of sensitive actions and logins, to trace and detect abuse.
  • Internal access to data strictly limited to authorised staff who need it.

11. Cookies and trackers (professional space)

The professional space places no advertising trackers and no third-party audience analytics tools. The items placed on your device are strictly necessary for operation and exempt from consent:

PurposeTypeDurationConsent
Dashboard authentication and session (keep you logged in)CookieSession durationExempt
Current business selection (remember the displayed business)CookieAbout 1 yearExempt
Anti-bot security at loginCookieFor the duration of the checkExempt

None of these trackers is subject to consent: no banner (CMP) is therefore required to date. Details are in the Cookie policy (separate document).

12. Changes to this notice

We may change this notice to reflect a change in the service or in regulation. The last-updated date appears at the top of the document. In the event of a substantial change, we inform you by an appropriate means (by email or in the app) before it takes effect.

13. Complaint to the CNIL

If you consider that the processing of your data does not comply, you can lodge a complaint with the French data protection authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 - www.cnil.fr.

GDPR contact : [email protected]

Back to home

KiftMe

Give what you love to the people you love.

Product

PersonalBusinessPricingCreate a Kift

Company

How it worksAboutContactHelp

Legal

Legal noticeTermsPrivacyCookiesRefunds & cancellationsContact

© 2026 KiftMe. All rights reserved.

·