← Giffit

🔒 Privacy Policy

This is a courtesy translation. The legally binding version is the Italian one; in case of any discrepancy, the Italian text prevails.

Version 1.6 — Last updated: 4 August 2026 — Effective from: 13 June 2026

Giffit ("the Service") is developed and operated by Michele Furgeri.
This Privacy Policy describes how we collect, use and protect your personal data under Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (Italian Privacy Code) as amended by Legislative Decree 101/2018.

In short: we only collect the data needed to let you use Giffit. We do not sell your data to third parties. The advanced personalization features based on your browsing are always optional and you can withdraw them at any time from the app settings.

1. Data Controller

Michele Furgeri
Email: info@giffit.me

No Data Protection Officer (DPO) has been appointed. For any question about your personal data, or to exercise your rights, you can write to the Controller at the email address above.

2. Data Collected

Data provided directly by the user

Data collected automatically

Data collected with explicit consent (optional)

Data received from sign-in providers (Google, Apple)

If you choose to sign in with Google or Apple, authentication takes place on the provider's systems: Giffit never sees the password of your Google or Apple account. We only receive:

This is the same data you would be asked for when registering, and it is used solely to create and identify your account: the legal basis is performance of a contract (Art. 6(1)(b) GDPR). We do not receive your contacts, calendar, photos, messages or any other content from your Google or Apple accounts, and we never post anything on your behalf.

Google and Apple process authentication data as independent controllers, under their own privacy notices (Google, Apple). You can revoke Giffit's access at any time from your Google or Apple account settings; to erase data already held by Giffit, use the account deletion described under "Your Rights".

3. Purposes and Legal Basis of Processing

Purpose Legal basis (GDPR) Data involved
Registration and account management Art. 6(1)(b) — Performance of a contract Email, password, profile
Provision of the Service (wishlists, events, connections, chat) Art. 6(1)(b) — Performance of a contract All profile data and content
Showing your sizes to the contacts you have authorised Art. 6(1)(b) — Performance of a contract Sizes and measurements (optional)
Profile-based AI gift suggestions Art. 6(1)(b) — Performance of a contract Interests, preferences, age, gender
Push notifications and transactional emails Art. 6(1)(b) — Performance of a contract Push token, email
Suggestion personalization via browsing data Art. 6(1)(a) — Consent (optional) URLs and descriptions of browsed products
Security, fraud and abuse prevention Art. 6(1)(f) — Legitimate interest Access logs, usage data
Service improvement (aggregated analytics) Art. 6(1)(f) — Legitimate interest Anonymous/aggregated data
Compliance with legal obligations Art. 6(1)(c) — Legal obligation Consent logs, data requested by authorities

Processing based on legitimate interest (Art. 6(1)(f)) is always balanced against the rights of the data subject. You may object to such processing at any time by contacting the Controller.

4. Automated Decision-Making and AI Profiling

The Service uses artificial intelligence systems to generate personalized gift suggestions based on your profile data (interests, negative preferences, gender, age) and — if you have given consent — the products you explore in the in-app browser. Requests are routed through OpenRouter, which forwards them to third-party AI models and may rely on its own compute providers (sub-processors). According to OpenRouter's policy, request content is not used to train models. The model used may change over time without altering the purposes of processing or the categories of data involved.

Such suggestions are purely indicative and produce no legal effects nor significantly affect you within the meaning of Art. 22 GDPR. No binding automated decision is made. You have the right to contest the results and request human review by writing to info@giffit.me.

5. Local Storage (AsyncStorage)

The app uses AsyncStorage (local storage on the device) to keep session preferences, authentication tokens, theme settings and consent logs. This data resides exclusively on your device and is not transmitted to third parties. It is automatically deleted upon logout or uninstallation of the app.

6. Service Providers (Sub-Processors)

Your data may be processed by the following providers, with whom we have entered into appropriate data processing agreements (DPAs) in accordance with Art. 28 GDPR:

Provider Location Purpose Transfer safeguard
Supabase Inc. USA Database, authentication, storage SCC (Art. 46(2)(c) GDPR)
OpenRouter, Inc. USA Routing of AI requests to third-party AI models; according to OpenRouter's policy, content is not used for training. May rely on its own compute providers (sub-processors) SCC (Art. 46(2)(c) GDPR)
Resend Inc. USA Transactional emails SCC (Art. 46(2)(c) GDPR)
Expo / 650 Industries Inc. USA App distribution, push notifications DPF + SCC
Render Services Inc. USA Backend hosting SCC (Art. 46(2)(c) GDPR)
Cloudflare Inc. USA Static website hosting (Cloudflare Pages), CDN and DDoS protection DPF + SCC
Functional Software, Inc. (Sentry) EU (Germany) Error monitoring and technical diagnostics for the stability of the Service (no IP address or personal request content) Data in the EU — no extra-EU transfer
PostHog, Inc. EU Aggregated, pseudonymized usage analytics to improve the Service (in-app analytics only with consent) Data in the EU — no extra-EU transfer

EU-U.S. Data Privacy Framework (DPF): adequacy framework approved by the European Commission with Decision 2023/1795 of 10 July 2023.
Standard Contractual Clauses (SCC): model approved by the European Commission with Decision 2021/914 of 4 June 2021.
For further information on the safeguards applied, contact the Controller.

7. Data Retention

Data category Retention period
Account and profile data Until account deletion, then erased within 30 days. If you do not open the app for 30 months the account is deleted automatically, after two email warnings at 12 and 24 months.
Incomplete sign-ups or Terms never accepted Automatic deletion: 30 days if sign-up was never completed, 60 days if the Terms were never accepted.
In-app browser navigation data Up to 12 months from collection (or until consent is withdrawn)
Consent logs (proof of T&C acceptance) 5 years from acceptance (legal documentation obligation)
Security and access logs 90 days
Chat messages Until account or conversation deletion

After account deletion, personal data is erased or anonymized within 30 days, except for consent logs retained for legal obligations.

8. Your Rights

Under Arts. 15–21 GDPR you have the following rights:

To exercise your rights, write to info@giffit.me stating your request. We will reply within 30 days of receipt (extendable by a further 60 days in complex cases, with notice of the reason).

9. Minimum Age

The Service is intended for users aged at least 16, in accordance with Art. 8 GDPR and Art. 2-quinquies of Legislative Decree 196/2003. We do not knowingly collect data from minors under 16. Should we become aware of having collected data from a minor without the consent of the holder of parental responsibility, we will delete it immediately.

10. Data Security

We adopt the following technical and organizational measures (Art. 32 GDPR):

In the event of a personal data breach likely to result in risks to your rights and freedoms, we will notify you without undue delay in accordance with Art. 34 GDPR. Notification to the Supervisory Authority (Art. 33 GDPR) will be made within 72 hours of becoming aware of the breach.

11. Complaints

You have the right to lodge a complaint with the Italian Data Protection Authority (Garante Privacy): www.garanteprivacy.it
Garante per la Protezione dei Dati Personali
Piazza Venezia, 11 — 00187 Rome, Italy
Tel: +39 06.69677.1

We nonetheless encourage you to contact us before filing a formal complaint, so that we can resolve the issue directly.

12. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy in the event of regulatory, technological or Service changes. Changes will be classified as:

The updated version is always available at giffit.me/en/privacy.html and in the app's Profile → Settings section.