In short
- We use only the data necessary to operate, protect, bill and improve gifty.
- The Merchant controls the data of its buyers and recipients; gifty processes it under its instructions.
- We do not sell or rent personal data; you may exercise your rights by writing to hola@crossup.ai.
1. Scope, controller and roles
This Policy describes how APPS 4 SELLERS CORP, with its address at 470 Ansin Blvd, Suite K, Hallandale Beach, FL 33009, United States ("gifty"), processes personal data in connection with the gifty platform, its sites (gifty.lat and app.gifty.lat) and its communications. It applies to merchants and their users, to buyers and recipients of gift cards, to visitors of the sites and to commercial contacts.
Gifty acts in two distinct roles. As controller, it decides how to process the data of the Merchant's account, the commercial relationship, billing, security, support and the sites. As processor, it processes the data of buyers and recipients that the Merchant uploads or has processed in the Service, following its instructions and the Data Processing Agreement (DPA): in that case the Merchant defines the purposes and the essential means, and this Policy is complemented by the Merchant's own privacy notice.
2. What data we process and where it comes from
Depending on your relationship with gifty, we may process the following categories of data:
- Identification and professional contact: name, email, phone, position, company, country and language.
- Account and store: username, role, permissions, identifiers of the store and of the Ecommerce Platform, configuration, catalog and templates.
- Commercial and billing data: plan, subscription, invoices, tax data and payment references (never the full card details).
- Gift card data: name and contact of the buyer and of the recipient (email or phone), gift message, delivery date and channel, associated order, amount, currency, status, balance and redemption movements.
- Technical and security data: IP address, device and browser identifiers, session, access logs and security events.
- Usage and performance data: interactions with the product, error and performance metrics, preferences and consents.
- Support and communications: messages, claims and their history.
The data comes from you, from the Merchant that operates the store, from the Ecommerce Platform and other enabled integrations, from our providers and from the use of the Service. Do not request or send sensitive data (health, religion, biometrics, etc.) in free-text fields such as the gift message: we neither need nor want to process it.
3. What we use the data for and on what legal basis
We process personal data for the following purposes, on the legal bases that the regulations of each jurisdiction require (performance of the agreement, legal obligation, proportionate legitimate interest or consent):
- Provide the Service: create and manage accounts, authenticate users, configure stores, issue, deliver and reconcile gift cards, and record redemptions (agreement).
- Bill and collect subscriptions, issue receipts and comply with accounting and tax obligations (agreement and legal obligation).
- Provide support and respond to inquiries and claims (agreement and legitimate interest).
- Protect the Service: prevent fraud and abuse, safeguard gift card codes, audit access and respond to incidents (legitimate interest and legal obligation).
- Communicate operational information: confirmations, delivery notices, balance, expirations, changes to the service and legal notices (agreement).
- Send our own commercial communications, always with the possibility of opting out and, where the law requires, only with prior consent (consent or legitimate interest, depending on the jurisdiction).
- Measure and improve the product with minimized and, when the data allows, aggregated or anonymized analytics (legitimate interest).
- Comply with the law and defend rights against claims or requirements of an authority (legal obligation and legitimate interest).
We do not use the data for purposes incompatible with those declared, and we do not sell or rent personal data to third parties.
4. Buyers and recipients of gift cards
When you buy or receive a gift card from a store that uses gifty, the commercial relationship is with that store (the Merchant), which is the controller of your data as a customer. Gifty processes your data on the Merchant's behalf to carry out the operation you requested: issue the gift card, deliver it to the recipient through the chosen channel, show balance and status, record redemptions, prevent fraud and provide support.
Receiving a gift card does not subscribe you to marketing from gifty or from the Merchant: any subsequent promotional communication requires the legal basis your country demands and always includes the possibility of opting out. If you want to exercise rights over data uploaded by the Merchant, you may contact the store or write to us: we will forward your request to the Merchant and assist it, as explained in Section 11.
5. Payment and billing data
Payments are processed through specialized providers (such as Mercado Pago or Stripe). The full card or payment method details are entered directly into those providers' forms and are never stored in gifty's systems; we keep only references (tokens), status, amount, currency, receipts and the tax data necessary to bill and comply with the law. Never send full card details by email, chat or support tickets.
7. Communications
Transactional communications (confirmations, gift card deliveries, balance or expiration notices, security alerts, billing notices and legal changes) are necessary for the Service and cannot be disabled while the relationship exists. Promotional communications are optional: every piece includes sender identification and an opt-out mechanism that is applied without delay and without affecting the operational notices.
8. With whom we share data
We share personal data only to the extent necessary and with the following categories of recipients:
- Infrastructure providers: hosting, database, storage and network (Vercel, Neon, Cloudflare).
- Task and job processing (Trigger.dev).
- Communications: transactional email and WhatsApp (Resend, Kapso).
- Payments and billing: Mercado Pago, Stripe, Tus Facturas.
- Observability and analytics: errors and usage metrics (Sentry, PostHog).
- The Merchant's Ecommerce Platform (for example, Tiendanube) and the integrations the Merchant enables, which may act as independent controllers.
- Professional advisors, auditors and authorities when the law requires it or to exercise or defend rights.
- An acquirer or successor in the framework of a merger, acquisition or corporate reorganization, with equivalent protections and notice when the law requires it.
All our providers process data under contracts that limit the use to the provision of the contracted service and require security measures. We do not sell or rent personal data.
9. International transfers
Our infrastructure is distributed and some providers process data outside your country, including the United States and, for the main database, the São Paulo region, Brazil. When we transfer personal data from Argentina, Brazil or another jurisdiction with international transfer requirements, we use a valid mechanism —adequacy decision, approved contractual clauses, binding corporate rules or another recognized tool— together with supplementary security measures. You may request information about the applicable mechanisms by writing to hola@crossup.ai.
10. How long we keep the data
We keep each category of data only for as long as necessary for its purpose:
- Account and store data: while the account is active and for a reasonable period thereafter to allow reactivation and the defense of rights.
- Gift card data: while the gift card has operational potential (validity, redemption, claims) and then according to the Merchant's instructions under the DPA.
- Billing and tax data: for the accounting and tax retention periods of each jurisdiction.
- Security and audit logs: for limited periods proportionate to their purpose.
- Backups: deleted by rotation in regular cycles; data deleted from the active system remains isolated in backups until the rotation is completed.
When the relationship with a Merchant ends, we return or delete the data processed on its behalf in accordance with the DPA. Irreversibly anonymized data ceases to be personal and may be kept for statistical purposes.
11. Your rights and how to exercise them
Depending on your jurisdiction, you have the right to request access, confirmation of processing, rectification, updating, portability, anonymization, blocking, deletion, objection, restriction of processing, withdrawal of consent and review of automated decisions. In Argentina you may also complain to the Argentine data protection authority (AAIP); in Brazil, to the Brazilian data protection authority (ANPD); in other jurisdictions, to the corresponding supervisory authority.
To exercise any right, write to hola@crossup.ai indicating your country, your relationship with gifty (merchant, buyer, recipient, visitor) and what you request. We will verify your identity in a manner proportionate to the risk and will respond within the legal deadlines of your jurisdiction. If the data was uploaded by a Merchant and gifty acts as processor, we will forward the request to the responsible Merchant and assist it in responding to you. Exercising your rights never results in discriminatory treatment.
12. How we protect information
We apply technical and organizational measures proportionate to the risk, which include:
- Encryption of data in transit and secure management of secrets and credentials.
- Data isolation per business (multi-tenant architecture with separation by merchant).
- Access restricted by need and with least privilege, with logging and review of access.
- Structured audit logs for sensitive operations.
- Regular backups, monitoring, vulnerability management and secure development practices.
- Security assessment of providers and data processing contracts with each one.
No transmission or storage is infallible; that is why we also maintain an incident response process, described in the following section.
13. Security incidents
If we detect a security incident that affects personal data, we will investigate it, mitigate its effects and notify without undue delay the affected merchants and, when the law requires, the authorities and the data subjects, reporting the nature of the incident, the categories and approximate volume of data involved, the likely consequences and the measures adopted. The notifications will be updated as the investigation progresses.
14. Minors
Gifty is a commercial service directed at adults and is not directed at minors. We do not deliberately collect data from minors. If a Merchant allows minors to buy in its store, it is its responsibility to comply with the applicable rules. If you believe we process a minor's data without the proper authorization, write to us at hola@crossup.ai and we will delete it in accordance with the law.
15. Automated decisions
We use automatic rules and systems to operate the Service —for example, to detect patterns of fraud or abuse—, but we do not make decisions based solely on automated processing that produce significant legal effects on people without human intervention. If that were to change, we will report the general logic involved, the anticipated consequences and the available rights, including the right to request human review.
16. Secret gifts and sender identity
When the buyer chooses the Secret gift option, the recipient sees a generic label instead of the sender's name. It is a presentation preference, not real anonymity: the Merchant and Gifty retain the buyer's real identity and the data necessary to carry out the delivery, prevent fraud, provide support, maintain audit records and comply with the law. The identity may additionally be revealed through purchase receipts, messages from the buyer, contact outside the platform or a legal requirement.
17. Changes and contact
We will publish each new version of this Policy with its effective date and will give notice of material changes through the Service or by email before they take effect. For privacy inquiries or the exercise of rights: hola@crossup.ai — APPS 4 SELLERS CORP, 470 Ansin Blvd, Suite K, Hallandale Beach, FL 33009, United States.