PRIVACY
Privacy policy
Last updated: 8 October 2026
Greetings are personal. That’s why we only collect what your greeting or calendar needs, and explain here in plain words what happens to your data. This is a translation; the German version is authoritative.
Contents
- The essentials
- Controller
- Your rights
- Hosting and server logs
- Creating and sharing greetings
- Advent calendars
- When you open a greeting or calendar
- Emails
- Link preview, QR code and print cards
- Payment via Stripe
- Contact and withdrawal
- Cookies and storage on your device
- Analytics and advertising (only with consent)
- Fonts, third-party content, links
- Security
- Retention at a glance
- Other
The essentials
- No account, no password. What you create is reachable via private links. Anyone who knows a link can see the greeting or calendar – only share it with the right people.
- Only what’s needed. We store what you enter for your greeting or calendar and use it only for that. We don’t sell data and never show ads in greetings.
- Deleted automatically. Greetings 6 months after publishing (with Gift Moment 12 months from purchase), Advent calendars at the end of February after Advent – including all photos.
- Analytics and advertising only with your consent – and never on private pages such as a greeting or calendar. We currently don’t use any such services at all.
Controller
The controller responsible for data processing on giftquest.de is:
Mario Schulz – GiftQuestDibbersener Weg 5
21224 Rosengarten
Germany
Email: service@giftquest.de
We are not required to appoint a data protection officer. If you have any questions about data protection, simply write to us at service@giftquest.de.
Your rights
You have the right at any time to
- access the data we hold about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR) – send us the private link to your greeting or calendar and we will delete it including its photos,
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- withdraw your consent with effect for the future (Art. 7(3) GDPR), e.g. via the .
Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object to this processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims.
For all of this, just write to us at service@giftquest.de. As GiftQuest has no accounts, we identify your data by its private link (edit link) – please include it.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example where you live or with the authority responsible for us: the data protection authority of Lower Saxony (LfD Niedersachsen), Prinzenstraße 5, 30159 Hannover, Germany.
Hosting and server logs
GiftQuest is hosted by Railway Corporation, 548 Market St PMB 68956, San Francisco, CA 94104, USA. We use a data centre in the EU (Amsterdam, Netherlands). Railway processes the data as our processor (Art. 28 GDPR). As Railway is a US company, access from the USA cannot be ruled out; we have agreed EU standard contractual clauses with Railway for this (Art. 46(2)(c) GDPR).
Each request involves technically necessary connection data: IP address, date and time, requested address, status code, amount of data transferred, browser and operating system. It is stored in server logs for 7 to at most 30 days depending on the plan, and is used for operation, troubleshooting and defending against attacks.
To prevent abuse (e.g. mass submissions), we count requests per IP address – only in memory and for no longer than one hour.
The legal basis is our legitimate interest in secure, stable operation (Art. 6(1)(f) GDPR).
Creating and sharing greetings
Draft: While you design, everything stays on your device (in browser storage, see Cookies and storage). Only when you publish does the greeting go to our server.
When you publish, we store: the names of recipient and sender, your text, the chosen design, up to three photos, your signature (as stroke data), the scratch-off surprise including any voucher code and attachment (an image or PDF, such as a voucher you bought or a ticket), and an optional unlock time. We re-encode photos and image attachments and remove all metadata in the process – such as the location (GPS) and camera data. PDF attachments are stored unchanged; they can only be retrieved through the surprise of a paid greeting.
Purpose and legal basis: We provide the greeting via a private link – that is our service to you (Art. 6(1)(b) GDPR). Names and content you enter about other people (e.g. the recipient’s name or photos) are processed on the basis of the legitimate interest in delivering a personal greeting (Art. 6(1)(f) GDPR). Please only upload photos you are allowed to share.
My greetings: Your device remembers your edit links. On the “My greetings” page it asks us for the current status (recipient’s name, thank-yous). We don’t store anything additional when it does.
Retention: We automatically delete the greeting with all photos, events and thank-yous 6 months after publishing – for purchased greetings at the end of the term stated at purchase – or earlier at your request.
Advent calendars
For creators: We store the calendar’s settings (design, puzzle image, names of recipient and sender), the contents of the doors (messages, photos, vouchers including codes, links) and an optional email address. The legal basis is our contract with you (Art. 6(1)(b) GDPR).
For contributors: Anyone filling a door via the contribution link enters a name. A cookie then recognises you so that only you can edit your doors. Your name and content are visible to the calendar’s creator and – from the respective day – to the recipient. The legal basis is our legitimate interest and that of the creator in a shared calendar (Art. 6(1)(f) GDPR).
Retention: Calendars are deleted automatically with all content, photos and contributors at the end of February after Advent – or earlier at the creator’s request.
When you open a greeting or calendar
If someone sent you a greeting or calendar, we received your name and the content from the person who created it. When you open it, we only store that and when the greeting was opened and the surprise scratched off – for calendars, which doors were opened, which puzzle pieces placed and which vouchers redeemed. No IP address, no device, no location.
The sender sees this in their overview – so they know their greeting has arrived. If you say “Thank you”, we store your message and show it to the sender; on request we notify them by email.
The legal basis is the sender’s and our legitimate interest in delivering the greeting and enabling the experience (Art. 6(1)(f) GDPR). Everything is deleted together with the greeting or calendar.
Emails
Email addresses are always optional at GiftQuest. We only use them for the respective purpose – never for advertising or a newsletter:
- Your address: for your edit link and for notifications when someone says thank you or redeems a voucher.
- A recipient’s address: If you schedule delivery by email, we send the link once at the chosen time on your behalf. Please only enter addresses of people who are meant to receive the greeting.
The legal basis is our contract with you (Art. 6(1)(b) GDPR); for recipients’ addresses, our and your legitimate interest in delivery (Art. 6(1)(f) GDPR). The addresses are deleted together with the greeting or calendar.
We send our emails via IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, as our processor (Art. 28 GDPR).
Link preview, QR code and print cards
When you share a link, e.g. via WhatsApp, the messenger fetches a preview image from us. It shows the recipient’s first name and the sender, never text, photos or the surprise. The messenger’s own privacy policy applies to this request.
We generate QR codes and print cards (PDF) on request from the link and don’t store them.
Payment via Stripe
When you buy something from GiftQuest, you are redirected to the payment page of Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. There, Stripe processes your name, email address, billing address if applicable, payment details, and device and connection data for fraud prevention. We never see card numbers; we only receive the amount, time, payment method, confirmation of payment and the details needed for the receipt.
The legal bases are the contract (Art. 6(1)(b) GDPR) and legal obligations (Art. 6(1)(c) GDPR). Stripe itself is responsible for fraud prevention and its legal obligations. Stripe may transfer data to Stripe, Inc. in the USA, which is certified under the EU-US Data Privacy Framework. If you choose e.g. Apple Pay, Google Pay, PayPal or Klarna, their privacy policies also apply. More: stripe.com/privacy.
We keep receipts and accounting records for as long as commercial and tax law requires (usually 8 or 10 years, Section 147 AO, Section 257 HGB).
Contact and withdrawal
If you email us, we process your address and message to answer your request (Art. 6(1)(b) or (f) GDPR). We delete them once everything is settled, unless statutory retention periods apply.
If you use our “Withdraw from contract” function, we store your name, email address, the contract details, your message and the date and time of receipt, and send you an acknowledgement. This is required by law (Art. 6(1)(c) GDPR, Section 356a BGB). We keep the details for three years as evidence.
Analytics and advertising (only with consent)
We currently don’t use any analytics or advertising services. If that changes, we will ask for your consent beforehand and update this policy.
Fonts, third-party content, links
We serve fonts, images and films ourselves – no connection to Google Fonts or other font or content providers is made when you visit GiftQuest.
Greetings and calendars may contain links to other websites added by their creators. If you open such a link, that website’s privacy policy applies.
Security
All connections are encrypted via HTTPS. Private links are long random keys; we only store edit links as a checksum (hash). Private pages are blocked for search engines and don’t pass their address on to other websites.
Retention at a glance
| Data | Deleted |
|---|---|
| Greetings with photos, events, thank-yous, scheduled emails | 6 months after publishing (purchased greetings: at the end of the stated term) or on request |
| Advent calendars with all content and contributors | end of February after Advent or on request |
| Server logs | after 7 to 30 days |
| Request counting per IP address | after at most 1 hour |
| Withdrawal declarations, consent records | after 3 years |
| Receipts and accounting records | after 8 or 10 years (statutory) |
| Storage on your device | when you delete it |
Other
You are not obliged to give us any data – without names, text or photos, however, we can’t create a greeting. There is no automated decision-making including profiling (Art. 22 GDPR).
We update this policy when GiftQuest or the law changes. The version published here applies.