Skip to content
Create a card

Privacy Policy — GatherWishes.com

Effective date: 5 July 2026

This is a courtesy translation. The Polish version is the binding one.

1. Data controller

The controller of your personal data is:

JPDEV Sp. z o.o.
ul. Główna 85C/1, 55-080 Smolec
KRS 0001161911 · NIP 8961649757 · REGON 541182628
share capital: PLN 200,000
company website: https://jpdev.pl

Contact for all matters concerning personal data: privacy@gatherwishes.com (you may also write to the registered office address).

This policy applies to the gatherwishes.com service — a platform for group greeting cards with optional gift vouchers. You can read about cookies and browser storage in the separate Cookie Policy.

2. Who this policy applies to and where we obtain data from

2.1 Organizer / account holder / buyer

A person who creates an account, creates a card, or purchases a paid service (premium card, voucher, print). You provide the data yourself: e-mail address, password (stored exclusively as an irreversible hash), language, card data, and, for purchases — payment data and invoice details.

2.2 Signer (without an account)

A person who adds an entry to a card via a link — without registration. You provide the data yourself in the signing form: name/signature, the content of your wishes, optionally a photo or GIF, and optionally an e-mail address — solely so that the card's recipient can later send you a thank-you message.

2.3 Card recipient

The person for whom the card is intended. We received your data (name and e-mail address) from the card's organizer — the person who prepared it for you (Article 14 GDPR). We process it solely to deliver the card (and any voucher) to you, to enable you to send thank-you messages, and to inform the organizer that the card has reached you. We do not use your address for any other purposes, in particular marketing purposes.

2.4 Persons visible in content

Wishes and photos added by users may depict third parties. The person posting the content is responsible for the lawfulness of such publication (Terms of Service, § 10); reports of infringements: legal@gatherwishes.com.

2.5 Employees of a business customer (B2B subscription)

If the Service is used under a corporate B2B subscription, your employer (the business customer) may enter into the Service the data of the persons being recognized — e.g. an occasion calendar: first and last names, optionally work e-mail addresses, dates (birthdays, work anniversaries), and recognition history used for supporting features (including reminders about persons not recognized for a long time, and manager/steward budgets). Such persons are usually not users of the Service.

With respect to such data, your employer (the business customer) is the controller, and JPDEV acts as a processor (Article 28 GDPR) — we process it solely on the customer's documented instructions, for the purpose of providing the service to them. The legal basis and the rules for processing your data are set out in your employer's own notice/policy; direct requests for access, rectification, or erasure primarily to your employer as controller. On our side we use the same subprocessors as for the rest of the Service (section 4) and, if the customer enables the integration, notifications in Slack or Microsoft Teams.

> ⚖️ FOR LEGAL REVIEW: the formal data-processing agreement (DPA) between JPDEV and the business customer, and the exact controller/processor allocation, are a separate, open item (#203) requiring sign-off by a lawyer. Editorial annotation to be removed after review.

3. Purposes and legal bases of processing (Article 6 GDPR)

ProcessDataLegal basis
Organizer account (registration, sign-in, settings)e-mail, password hash, language, card historyArticle 6(1)(b) — contract for a service provided by electronic means
Creating and signing cardscard content, entries, photos, GIFs, signers' dataArticle 6(1)(b) — a service provided at your request (including free of charge)
Delivering the card to the recipientrecipient's name and e-mail (from the organizer)Article 6(1)(f) — legitimate interest of ours and of the organizer and signers: delivering the card to its addressee
"Card has been opened" information for the organizerthe fact and time of the recipient's first opening of the card, open counterArticle 6(1)(f) — informing the organizer that the card has arrived; the organizer's own preview is not counted; you have the right to object (section 8)
Thank-you loop (recipient → signer)signer's optional e-mailArticle 6(1)(b)/(f) — an e-mail provided voluntarily precisely for this purpose
Payments (premium card, vouchers, print)transaction data; card data is processed exclusively by StripeArticle 6(1)(b) — performance of the contract
Invoices, accounting, KSeFinvoice details (name/company name, address, NIP, e-mail)Article 6(1)(c) — legal obligation (tax and accounting regulations)
Auto-filling company details by NIPNIP passed to the GUS register (BIR)Article 6(1)(b)/(f) — facilitating correct issuance of the invoice
Gift voucherspurchase metadata; the voucher code is stored encrypted and made available exclusively to the recipient upon deliveryArticle 6(1)(b) — performance of the contract
Premium print and shippingorder and delivery data (InPost)Article 6(1)(b)
Content moderation, abuse preventionreported/verified content, technical dataArticle 6(1)(f) — security of the service and its users; obligations of a hosting provider (DSA)
Security (logs, event log, session protection)technical data, records of account activityArticle 6(1)(f) — network and information security
Complaints, correspondencedata from the submissionArticle 6(1)(b)/(c)/(f)
Newsletter and marketinge-mailwe currently do not send marketing communications; if we launch them — exclusively with your consent (Article 6(1)(a)), which you will be able to withdraw at any time

Providing data is voluntary, but necessary to use the given feature (e.g. without the recipient's e-mail we cannot deliver the card). We do not make decisions about you based solely on automated processing that would produce legal effects, and we do not profile you for marketing purposes.

4. Data recipients

We entrust or disclose data only to the extent necessary for the operation of the service:

EntityRolePurpose
Hetzner Online GmbH (Germany/Finland)processorhosting of the service and the database — exclusively within the EEA
e-mail provider (SMTP) / Cloudflareprocessorsending service e-mails (card delivery, notifications, password reset) and domain handling
Stripe (Stripe Payments Europe Ltd.)separate controllerpayment processing; we do not have access to your full card data (policy: stripe.com/privacy)
Multivouchervoucher supplieracquisition of the voucher of the selected offeror for the buyer
GUS (BIR register)separate controller (public register)retrieving company details based on the NIP provided for the invoice
KSeF (Ministry of Finance)separate controllertransmitting invoices in accordance with a legal obligation
KLIPYcontent provider (GIFs)GIF searches are performed via our server — KLIPY does not receive your IP address or device data, only the search phrase
Slack Technologies (Salesforce) / Microsoft (Teams)recipient / subprocessor — only when a B2B customer enables the integrationsending card notifications to the designated company channel (including the recipient's name, a "sign the card" prompt, delivery summary) via a webhook configured by the customer
AI service providers (planned)processorsif we launch AI-assisted moderation or content generation, we will update this policy before that happens; data will be minimized, and providers will be contractually obliged not to use it for training models

In addition, data may be disclosed to entities authorized under the law (e.g. courts, tax authorities) and — to the necessary extent — to the controller's legal and accounting advisers.

5. Transfers of data outside the EEA

The service is hosted on servers in the European Union (Hetzner). Some providers (Stripe, Cloudflare, and — where a B2B customer enables the integration — Slack/Microsoft) may process part of the data in the USA. The basis for such a transfer is the European Commission's adequacy decision on the EU–U.S. Data Privacy Framework (for certified entities), and, supplementarily, the standard contractual clauses (SCCs) approved by the European Commission together with additional safeguards. You can obtain a copy of the relevant safeguards by writing to privacy@gatherwishes.com.

6. Retention periods

DataPeriod
Organizer accountuntil the account is deleted (you can do this yourself in the settings)
Cards, entries, photosfor as long as the card is kept in the service; the organizer may delete the card at any time; deleting the account deletes or anonymizes the cards
Recipient's data (name, e-mail)until the card is delivered and the related notifications are handled, then together with the card
Voucher codesuntil delivery to the recipient and the expiry of the complaint period; we store the code exclusively in encrypted form
Invoices and accounting data5 years from the end of the tax year in which the tax obligation arose (accounting and tax regulations) — therefore, when an account with purchases is deleted, the data covered by this obligation is anonymized rather than erased
Security event logup to 24 months; upon account deletion, entries are stripped of identifying data
Technical server logsup to 90 days
Correspondence and complaintsuntil the limitation of any claims

7. Your rights

You have the right to: access your data and obtain a copy of it, rectification, erasure, restriction of processing, data portability (with respect to data processed on the basis of a contract), and objection to processing based on legitimate interest (section 8).

How to exercise them:

  • Account holders — self-service, instantly: in your account settings you can download a full export of your data (JSON) and delete your account. If you have paid purchases, the data covered by the accounting obligation will be anonymized (section 6), and everything else — including cards, entries, photos, vouchers, and orders — permanently deleted; we will also cancel any scheduled card deliveries.
  • Signers without an account: you can edit or delete your entry from the browser from which you added it (it stores your edit key); for all other matters, write to privacy@gatherwishes.com.
  • Recipients and all other persons: write to privacy@gatherwishes.com — we respond within one month at the latest; we may ask you to confirm your identity (e.g. a message from the e-mail address the request concerns).

Please note that the deletion of signers' entries also depends on the fate of the card on which they appear — the organizer may delete it in its entirety.

8. Right to object (Article 21 GDPR)

Against processing based on legitimate interest (Article 6(1)(f)) — in particular against recording the opening of a card and informing the organizer about it — you may object at any time on grounds relating to your particular situation: write to privacy@gatherwishes.com. Upon receiving your objection, we will cease the processing unless we demonstrate compelling legitimate grounds overriding your rights, or the data is necessary for the defence of claims.

9. Security

We apply, among other measures: encryption of transmission (TLS), sign-in sessions inaccessible to page scripts (httpOnly), CSRF protection, storage of passwords exclusively as hashes, encryption of voucher codes (AES-256-GCM), immediate session revocation after a password change, a security event log, backups within the EEA, and the principle of data minimization (e.g. drafts in the creator deliberately do not store e-mail addresses in the browser). Cards are accessible exclusively via unguessable links and are not publicly indexed.

10. Complaint to the supervisory authority

You have the right to lodge a complaint with the Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office) (ul. Stawki 2, 00-193 Warszawa, https://uodo.gov.pl) if you believe that the processing of your data violates the law. We would, however, appreciate it if you wrote to us first — we resolve most matters right away.

11. Changes to this policy

We will inform you of material changes in the service, and account holders also by e-mail, in advance. The current version with its effective date is always available in the service. If we launch new processing operations (e.g. AI features, a newsletter), we will update this policy before they start.

12. Contact

privacy@gatherwishes.com · JPDEV Sp. z o.o., ul. Główna 85C/1, 55-080 Smolec.
Related documents: Terms of Service, Cookie Policy, Refund Policy.