1 Introduction and Scope of the Policy
The website is owned and operated by CorporateGift.com Inc., which is committed to protecting the privacy of its corporate customers, gift recipients, and platform sellers.
The Policy may be amended from time to time, and in the event of a material change affecting Gifting Platform corporate accounts, advance notice will be sent. Continued use of the Services is deemed acceptance of the Policy and any amendments.
European Economic Area (EEA) Residents: With respect to users residing in the European Economic Area, this Policy is applied in a manner consistent with the General Data Protection Regulation (GDPR). Continued use of the Service does not constitute a sufficient legal basis for processing that requires explicit, separate consent, such as direct marketing, profiling for advertising purposes, or the use of non-essential cookies.
This Policy was last updated September 9, 2026.
2 Information Collected
Opening an account is voluntary and involves sharing information such as your name, address, phone number, email address, username, password, and employer, as well as details of registered gift recipients. Additional information is collected when sending an e-gift, placing an order, or browsing the website, including information collected automatically via cookies, location identifiers, or IP addresses. The company may also contact users for surveys, and customer service calls may be recorded for quality assurance purposes.
Data Categorization & Personal Data: The categories of information collected are organized according to the purpose of collection:
- Account Identification & Management: Name, username, password, contact details, employer name, phone number, day of birth, month of birth (optional).
- Delivery & Fulfillment: Recipient name, address, and gift details.
- Payment & Security: Payment credentials and security identifiers.
- Marketing & Analytics: Browsing history, IP address, location, and cookie identifiers.
Each of the categories above constitutes “personal data” as defined under applicable regulations. Recording phone calls for training and quality-assurance purposes is subject to prior notice to the caller or obtaining their consent, in accordance with applicable local law.
3 Use of Information and Legal Bases for Processing
Information is used to provide the requested Services. With external suppliers, only information essential to completing an order is shared (uploaded artwork, gift-message text, recipient address), and never email addresses, payment details, or passwords. With technology providers, navigation information is shared to improve and personalize the Service, including for targeted advertising purposes. Information may also be disclosed pursuant to a legal requirement, to enforce the Policy, or in the event of a merger or sale of the company. The company relies on legitimate interests to improve the Service, ensure security, and prevent fraud.
Legal Bases under Article 6 (GDPR): Every processing activity is mapped to an explicit legal basis:
- Performance of a Contract: Fulfilling orders, managing accounts, and facilitating platform services.
- Legitimate Interest: Improving services, maintaining security, and preventing fraud. Where processing relies on legitimate interest, a balancing test is conducted between the company's interests and the data subject's fundamental rights.
- Consent: Sharing information with technology providers for targeted advertising is strictly conditional on the user's explicit, separate consent, which may be withdrawn at any time as easily as it was given.
- Legal Obligation: Disclosing information pursuant to statutory or court requirements.
4 Access to Information and Data Subject Rights
Users may choose to stop receiving marketing materials, review and update or correct their information, or deactivate their account by contacting the company or through the Communication Preferences page.
Expanded Rights: Under applicable regulation, users possess the following rights:
- Right of Access & Copy: To inspect and obtain a copy of held personal data.
- Right to Rectification: To correct inaccurate or incomplete data.
- Right to Erasure: The right to be forgotten.
- Right to Restriction & Objection: To restrict processing or object to processing, including for marketing and profiling.
- Right to Data Portability: To receive personal data in a structured, machine-readable format.
- Automated Decision-Making: The right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
Requests will be responded to generally no later than 30 days from receipt. Users also have the right to lodge a complaint with the relevant supervisory authority in their country of residence.
5 Data Security
The company is ISO 27001:2022 and PCI-DSS (self attestation) compliant, and employs technical, administrative, and physical measures to protect information against unauthorized access or use, including encryption during the payment process. However, the company cannot guarantee absolute security. Users are responsible for maintaining the confidentiality of their account details, and the company is not responsible for the privacy practices of third-party sellers operating on the Marketplace.
Data Breach Notification Procedure: In the event of a data security incident likely to result in a risk to the rights and freedoms of data subjects, the company will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Affected users will be notified without undue delay where the incident is likely to result in a high risk to their rights.
6 Data Retention Period
Information is retained based on explicit criteria rather than indefinite timelines:
- Business Relationship: The duration of the active business relationship between the parties.
- Legal Obligations: Legal requirements applicable in the company's country of incorporation and operational jurisdictions (including accounting and tax regulations).
- Risk Management: Legitimate needs for legal risk management.
Information is retained for as long as necessary to provide the Services described in the Policy and the User Agreement, while the account remains active, or as needed to provide requested services. Suppliers may also be required to retain and use information in accordance with their own policies and obligations. At the end of the relevant period, information will be deleted or anonymized unless a legal obligation requires continued retention.
7 Governing Law and International Data Transfers
The company and its servers are located in the United States and are subject to applicable US federal and state law. The company processes the personal information of California residents and residents of the European Economic Area, and is subject to the CCPA and GDPR.
International Data Transfer Mechanisms: Reliance on implied consent given merely by contacting the company as a basis for international data transfers is removed, as it does not meet the requirements for explicit and informed consent. Furthermore, the Privacy Shield framework is no longer relied upon following its invalidation in Schrems II (2020). International transfers to the United States are conducted under valid transfer mechanisms, such as Standard Contractual Clauses (SCCs) approved by the European Commission, alongside supplementary safeguards. Users may request details or a copy of the applicable transfer mechanism upon request.
8 EU Representative and Data Protection Officer (DPO)
As the company is established outside the European Union but processes the personal data of EU residents, an EU Representative has been appointed pursuant to Article 27 of the GDPR. The representative can be contacted regarding matters relating to personal data processing.
- EU Representative Contact: eurep@corporategift.com
- Data Protection Officer (DPO) Contact: dpo@corporategift.com
9 Automated Processing and Artificial Intelligence
The company may use automated tools and artificial-intelligence-based technologies to analyze user behavior, personalize offers and content, detect fraud, and secure the Services.
Such processing includes statistical analysis and limited profiling of usage patterns, but does not include automated decision-making that produces legal or similarly significant effects on the user without human involvement. Where automated processing may significantly affect a user, the user is guaranteed the right to receive an explanation of the underlying logic, request human review, and express their point of view.
10 Contact
Users may contact the company with questions regarding the Policy, or to request removal or updates to their information, by email, telephone, or letter to the company's address in Tenafly, New Jersey.
- Dedicated Data Protection Email: privacy@corporategift.com
- EU Representative / DPO Contact: privacy@corporategift.com
- Postal Address: CorporateGift.com Inc., 4 Washington St., Tenafly, New Jersey 07670, USA
11 California Privacy Rights (CCPA/CPRA)
If you are a resident of California, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights regarding your personal information:
- Categories of Information Collected: In the past 12 months, we have collected Identifiers (name, email, address, IP address), Commercial Information (order history), Network Activity (browsing data), and Geolocation Data.
- Right to Know & Access: You have the right to request the specific pieces and categories of personal information we have collected about you, as well as the sources and business purposes for collecting it.
- Right to Delete & Correct: You may request the deletion of your personal information or the correction of inaccurate data, subject to legal exceptions.
- Right to Opt-Out of Sale or Sharing: We do not sell your personal data for monetary compensation. However, sharing data via third-party cookies for targeted advertising may be considered “sharing” under CPRA. You may opt out at any time by clicking the “Do Not Sell or Share My Personal Information” link in our footer or by enabling a browser Global Privacy Control (GPC) signal.
- Non-Discrimination: We will not discriminate against you for exercising any of your California privacy rights.
To exercise these rights, submit a request via privacy@corporategift.com or through your account settings.