Privacy Policy
Last updated: 25 April 2026
1. Who we are
GiftKoin (a trading name of GiftKoin LTD, a company registered in England and Wales under company number 17080362, registered office 167–169 Great Portland Street, London, W1W 5PF) operates giftkoin.com, where you buy digital gift cards and pay in cryptocurrency. We are the data controller for the personal information described in this policy. You can reach us at [email protected].
2. Information we collect
Account information. Your email address. If you sign in with Google or Apple, the email and name they share with us — including Apple's "Hide My Email" relay address, which we treat as any other email.
Order information. What you bought, the email or account where we deliver the code, and the delivered code itself (encrypted).
Payment information. Details of your on-chain crypto payment: the network, token, transaction hash, sender wallet address, amount, and confirmation timestamp. We never see, ask for, or store bank card details — we don't accept them.
Verification information (only when triggered). For high-volume orders, we ask for a government-issued ID document and a short selfie/liveness check to confirm you are the person on the ID. We do not request this for normal purchases.
Technical information. IP address, approximate location derived from it, browser/device type, language, the pages you visit, and cookies as described in section 4.
3. How we use your information
To deliver your order. Process your purchase, confirm your crypto payment on-chain, generate or fetch the gift card code, and send it to you. Legal basis: performance of a contract.
To verify your identity when an order is flagged for review. Confirm that the person on the ID matches the person making the purchase. We only do this for high-volume orders or when our risk checks flag activity. Legal basis: legal obligation where applicable (anti–money-laundering rules), and our legitimate interest in preventing fraud.
To prevent fraud, abuse, and sanctions breaches. Screen wallet addresses and transactions against blockchain risk databases, block traffic from sanctioned jurisdictions, and apply velocity rules to detect unusual patterns. Legal basis: legal obligation, and legitimate interests in protecting our business and our users.
To run and secure the service. Operate giftkoin.com, prevent abuse of accounts and APIs, troubleshoot bugs, and keep audit trails. Legal basis: legitimate interests.
To respond to you. Reply to support requests over email, WhatsApp, and Telegram, and keep a record of the conversation. Legal basis: performance of a contract and legitimate interests.
To comply with legal requests and disputes. Respond to lawful requests from courts, tax authorities, and regulators, and defend or pursue legal claims. Legal basis: legal obligation, and legitimate interests where the basis is defending claims.
Risk decisions and human review. Our screening systems flag transactions or accounts for review. When a flag leads to a real consequence — for example, asking you for additional verification or returning your payment — a member of our team reviews the case before we act. You can ask us to explain a decision and request that a different person review it.
We do not sell your data, share it with advertisers, or use it for behavioural advertising.
4. Cookies
GiftKoin uses only strictly necessary cookies — to keep you signed in, remember your language and currency, and protect against attacks. We don't use advertising, marketing, or third-party tracking cookies. We don't run analytics that profile individual visitors.
5. Who we share information with
We don't sell your data. We share it only with the categories of recipients below, and only to the extent needed:
- Cloud and infrastructure providers that host the site, store data, send transactional emails, and run our backend. They process data on our instructions under contractual safeguards.
- Wallet and blockchain infrastructure partners that help us receive your crypto payment, monitor confirmations on-chain, and reconcile transactions. They see the same on-chain data anyone with a block explorer can see.
- Blockchain risk-analytics services that help us screen wallet addresses and transactions for fraud and sanctions risk. They receive the wallet address and transaction details to return a risk assessment.
- Identity verification systems we operate (when KYC is triggered) that process your ID document and selfie to confirm your identity. We control the verification logic; the underlying technology is supplied by cloud providers under contract.
- Sign-in providers, if you choose them. When you sign in with Google or Apple, those providers share your email and name with us. They do not see your activity on GiftKoin.
- Authorities and legal advisors when we receive a lawful request, when we need to defend or pursue a legal claim, or when we must report under anti–money-laundering rules.
We do not share your data with advertisers, data brokers, or third parties for their own marketing.
6. International transfers
GiftKoin is a UK company. Some of our service providers process data outside the UK, including in the European Economic Area and the United States. When that happens, we rely on UK-government-approved transfer mechanisms — UK adequacy decisions, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses — together with technical safeguards such as encryption.
You can ask us for a summary of the safeguards in place by emailing [email protected].
7. How long we keep data
- Account data (email, sign-in identifiers). While your account is open + 6 years after closure (HMRC accounting).
- Order and payment records. 6 years from the order date (HMRC accounting).
- KYC verification documents (ID, selfie). 5 years from the end of our relationship (Money Laundering Regulations 2017).
- Support correspondence. 2 years from last contact.
- Security and access logs (IP, device). 12 months.
When the period ends, we delete or anonymise the data, unless we're required to keep it longer for an active legal claim or regulatory request.
8. Your rights under UK GDPR
You have the following rights over your data. We respond to requests within one month:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — ask us to delete your data, subject to the retention obligations in section 7. We can't delete records we're legally required to keep, but we can restrict their use.
- Restriction — limit how we use your data while a question is being resolved.
- Portability — receive your data in a machine-readable format and send it elsewhere.
- Object — object to processing based on legitimate interests, including any future direct marketing.
- Withdraw consent — where we rely on consent, you can withdraw it at any time without affecting prior processing.
- Lodge a complaint — with the UK supervisory authority for data protection. We can provide their contact details on request.
To exercise any of these, email [email protected]. We may ask you to verify your identity before we act on a request.
9. Security
We use industry-standard measures to protect your data:
- All traffic between you and giftkoin.com is encrypted in transit (TLS).
- Sensitive data — gift card codes, KYC documents, authentication secrets — is encrypted at rest.
- Access to user data is limited to staff who need it for their role and is logged.
- We never store your bank card details. We don't accept bank cards.
- We never see or hold your wallet's private keys. You pay from a wallet you control.
- Passwords (where set) are stored as one-way hashes — even our team can't read them.
No system is 100% secure. If we ever experience a personal-data breach that risks your rights, we will notify the relevant supervisory authority within 72 hours where required, and notify you directly when the breach is likely to result in a high risk to you.
10. Crypto payments and on-chain transparency
Public blockchains are public. When you pay GiftKoin in cryptocurrency, the transaction is recorded on a public blockchain. The sender wallet address, recipient address, amount, token, network, and timestamp are visible to anyone using a block explorer. This is a property of the blockchain itself — not of GiftKoin — and we cannot remove or hide on-chain records.
What we read from the chain. We read your transaction details to confirm payment and reconcile your order. We may run wallet-address screening through blockchain risk-analytics services to prevent sanctions breaches and fraud. The wallet address you pay from is treated as personal data of yours under UK GDPR when we link it to your account.
What we don't do. We don't publish your wallet address ourselves, link your address to your name in any public way, or share it with anyone outside the recipient categories listed in section 5.
11. Children
GiftKoin is not for users under 18. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has given us their data, email [email protected] and we'll delete it.
12. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of the page reflects the most recent change. If we make material changes — for example, a new category of data, a new purpose, or a new recipient — we'll notify active users by email at least 14 days before the change takes effect, so you can review it.
Continuing to use GiftKoin after a change takes effect means you accept the updated policy. If you don't accept it, you can close your account and we'll handle your data per section 7.
13. Contact us
Data controller: GiftKoin LTD, a company registered in England and Wales.
Company number: 17080362
Registered office: 167–169 Great Portland Street, London, W1W 5PF
Email: [email protected]
For data-protection complaints, you can also contact the UK supervisory authority for data protection. We can share their current contact details on request.