Privacy Policy
This is the permanent copy of version 2026-09-13. It will not be edited.
The current version is always at /giftcardgenerator/privacy.
1. Our role
Gift Card Generator is a Shopify app provided by Software Etc. Limited, a company registered in England and Wales under company number 17455166 ("we", "us").
You are the data controller. The app operates on your Shopify store, at your instruction. You decide what gift cards to create, when, and what to do with the codes afterwards.
We are a data processor. We process information only to carry out the instructions you give through the app. We do not use it for our own purposes, and we do not decide what happens to it.
Where required, this relationship is governed by a data processing agreement between us.
Contact us at privacy@software-etc.co.uk with any question about this policy.
2. What the app does
You install Gift Card Generator on your Shopify store. It creates gift cards in your store in bulk, and produces an encrypted file containing the resulting codes for you to download.
3. What we process on your behalf
Store information. Your Shopify store domain and an access token allowing the app to act on your store at your instruction. Held while the app is installed.
Batch records. For each batch: the date, code format, denominations and quantities, currency, any expiry date, the status of each card, and the last four characters of each code. Held while the app is installed.
Gift card codes. The full codes generated for a batch, held encrypted. Deleted seven days after the batch is created, or immediately when you instruct us to. After deletion they cannot be recovered by us or by you.
Export files. The encrypted file you download, retained so you can download it again within the permitted number of downloads. Deleted on the same seven-day schedule.
Code fingerprints. A one-way cryptographic value derived from every code the app has generated. It cannot be reversed to produce a code, and contains no information about your store.
These are retained after the codes themselves are deleted, and serve as a record that a code was issued — so the app can guarantee it never issues the same code twice, including codes it no longer holds. Because a duplicate code would be a financial defect rather than an inconvenience, this record has to outlive the code.
Activity records. A log of actions taken in the app: batches created, files exported and downloaded, codes deleted, batches deactivated, and passcodes issued or revoked. Each entry records which member of your staff took the action, taken from your Shopify session.
Gift cards carry monetary value, so their creation is recorded and attributable. This is the app's audit trail, held on your behalf.
Access credentials. Where a passcode has been issued, it is stored hashed, with the name of the organisation it was issued to.
4. What we do not process
We do not request or receive access to your customers, orders, products, inventory, or payment information. The app requests permission to read and write gift cards, and nothing else.
Gift cards created by the app have no recipient attached, so no card is associated with a customer. The app sends no email to your customers and holds no customer contact details.
We do not request or receive the store owner's name, email address, phone number or physical address. Shopify grants apps access to this by default; this app never reads it.
We do not sell personal data, share it for advertising, use it for our own purposes, or use it to train any system.
5. How long we keep it
| What | Retention |
|---|---|
| Gift card codes | 7 days from batch creation, or immediately on your instruction |
| Export files | 7 days from batch creation, or immediately on your instruction |
| Store information and sessions | Deleted when you uninstall the app |
| Batch records | Deleted when your store data is erased |
| Code fingerprints | Retained indefinitely — one-way, not reversible to a code, contains nothing about your store |
| Activity records | Life of your account |
6. Security
Gift card codes are encrypted at rest. Export files are encrypted with AES-256 and protected by a password shown to you once and never stored by us — so it cannot be retrieved or resent, by us or by anyone else.
Codes are decrypted only to produce an export file at your request, and every decryption is recorded in the activity log.
Downloads are limited to three per batch and require you to be signed in to your Shopify admin.
No system is perfectly secure. Because gift card codes carry monetary value, we limit how long we hold them rather than relying on protection alone.
7. Sub-processors
We use the following sub-processors to deliver the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway | Hosting and database | Netherlands (EEA) |
| Sentry | Error monitoring | Frankfurt, Germany (EEA) |
Shopify is the platform the app operates on, and its handling of your store's data is governed by Shopify's own terms and privacy policy rather than this one.
Error reports sent to Sentry are automatically filtered to remove gift card codes, export passwords and access credentials before transmission.
We will inform you before adding or replacing a sub-processor.
8. Where your data is held
All data is held within the European Economic Area — hosting and database in Amsterdam, the Netherlands, and error monitoring in Frankfurt, Germany. We do not transfer personal data outside the EEA.
9. Rights of individuals
Because you are the controller, requests from individuals about their personal data should be made to you, not to us.
If we receive such a request directly, we will refer it to you rather than responding to it ourselves.
We will assist you in responding to requests, and in meeting your own obligations relating to the security of the data we process and to reporting any personal data breach. If we become aware of a breach affecting data we process for you, we will notify you without undue delay.
10. When you uninstall
Stored gift card codes and export files for your store are deleted immediately on uninstallation.
If Shopify sends us a request to erase your store's data, we delete all data relating to your store.
Code fingerprints are retained, for the reason set out in section 3. They contain no information about your store and cannot be reversed to produce a code.
11. Changes to this policy
We will update this page if our practices change, and revise the date above. Where a change materially affects how we handle data we process for you, we will make reasonable efforts to notify you in the app.
12. Contact
Software Etc. Limited — privacy@software-etc.co.uk
Registered office: 111 Winchester House, Bond Way, Bracknell, Berkshire, RG12 1LD, United Kingdom. Further details at company information.