Summary: We collect only what we need to fulfill your order and deliver your gift box. We never sell your personal data. Your recipient's details are used solely for delivery purposes.
01
Information We Collect
When you use Open When to create and send a personalized gift box, we collect the following categories of information:
- Order Information: box type, selected contents, number of cards, and card messages you write.
- Sender Details: your name and any contact information you provide during checkout.
- Recipient Details: the recipient's name, delivery address, city, and country.
- Photos: any image you voluntarily upload for printing inside the box.
- Payment Information: processed securely through our payment provider — we do not store your card details.
- Usage Data: browser type, IP address, pages visited, and device type, collected automatically for analytics.
02
How We Use Your Information
The information we collect is used exclusively to provide and improve our service. Specifically, we use it to:
- Process, assemble, and deliver your gift box order.
- Print and include your photos and card messages inside the box.
- Send you order confirmation and shipping updates.
- Respond to your customer service inquiries.
- Prevent fraud and maintain the security of our platform.
- Improve our website experience based on aggregated usage patterns.
We will never use your personal data for advertising purposes without your explicit consent.
03
Information Sharing
We do not sell, rent, or trade your personal information to third parties. We share your data only in the following limited circumstances:
- Delivery Partners: courier and logistics companies receive the recipient's name and address solely to complete delivery.
- Payment Processors: your payment data is handled by our certified payment gateway under their own privacy terms.
- Legal Compliance: we may disclose information if required to do so by law or in response to a lawful government request.
All third-party partners we work with are bound by data processing agreements and are prohibited from using your information for any purpose other than fulfilling their contracted service.
04
Data Retention
We retain your order information for as long as necessary to fulfill your order, resolve disputes, and comply with our legal obligations. Typically, this means:
- Order records are kept for 3 years from the date of purchase for accounting and legal purposes.
- Uploaded photos are deleted from our servers within 30 days after your order is fulfilled.
- Card message content is deleted within 60 days after fulfillment.
- Analytics data is retained in anonymized form indefinitely.
You may request early deletion of your data at any time by contacting us (see Section 10).
05
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of Access: request a copy of the personal data we hold about you.
- Right to Rectification: ask us to correct inaccurate or incomplete information.
- Right to Erasure: request that we delete your personal data, subject to legal retention obligations.
- Right to Restrict Processing: ask us to limit how we use your data in certain circumstances.
- Right to Data Portability: receive your data in a structured, machine-readable format.
- Right to Object: object to processing based on legitimate interests.
To exercise any of these rights, please contact us using the details in Section 10. We will respond within 30 days.
06
Cookies
Our website uses cookies and similar tracking technologies to enhance your browsing experience and understand how visitors interact with our site.
- Essential Cookies: required for the website to function correctly (e.g. session management, cart state).
- Analytics Cookies: help us understand traffic patterns and improve our service. These are anonymized.
- Preference Cookies: remember your choices to personalize your experience.
You can control or disable cookies through your browser settings at any time. Note that disabling essential cookies may affect website functionality.
07
Security
We take the security of your personal data seriously. We implement industry-standard technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction.
These measures include SSL/TLS encryption for data in transit, access controls limiting who within our team can view order data, and regular security reviews of our systems. However, no method of transmission over the internet is 100% secure, and we encourage you to take precautions with any personal information you share online.
08
Children's Privacy
Our service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with their personal information, please contact us immediately and we will take steps to delete that information promptly.
09
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this page.
We encourage you to review this policy periodically. Your continued use of our service after any changes constitutes your acceptance of the updated policy.
10
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please reach out to us: