Privacy Policy
Last updated: July 14, 2026
GiftKit is a gift-card and store-credit app for OpoShop merchants, published by Found. This policy explains what data GiftKit handles, why, and how we protect it. GiftKit is installed and used by merchants inside their OpoShop store admin; we act as a service provider to the merchant for the data that flows through their store.
Who this covers
- Merchants — store owners who install GiftKit to sell gift cards and issue store credit.
- Customers / gift recipients — people who buy, receive, or redeem a gift card or store credit at a merchant's store.
What we collect and store
- Store connection. When a merchant installs GiftKit, we store the store's ID, subdomain, and an OpoShop access token so GiftKit can act on the store's behalf (create discounts to apply gift-card value at checkout, read orders, send branded emails). We never share these tokens.
- Gift cards & store credit. Gift-card codes, balances, currency, status, and a transaction ledger; per-customer store-credit balances and their ledger. Balances are stored to the cent.
- Recipient & customer details for delivery. When a gift card is sent or store credit is issued, we store the recipient/customer email and optional name, sender name, and gift message so the card can be delivered and redeemed. This comes from the merchant's action or from an order the buyer placed on the store.
- Order references. The OpoShop order ID a gift card was purchased from, or an order/return a credit relates to — used to deliver and reconcile value.
- Merchant settings & branding. Business name, logo, accent color, denominations, expiry policy, and email copy the merchant configures.
What we do NOT collect
- We do not collect or store payment-card numbers, bank details, or passwords. Payments are processed by OpoShop and its payment providers, not by GiftKit.
- Our product analytics contain no personal information — events are keyed to a non-identifying store ID only, never to a customer's name or email.
- We do not sell personal data, and we do not use it for advertising.
How we use data
- To provide the service: issue, deliver, redeem, and reconcile gift cards and store credit for the merchant's store.
- To send transactional emails (gift-card delivery, balance) through OpoShop's email service, on the merchant's behalf, branded as their store.
- To secure the service: prevent double-redemption, over-redemption, and cross-store access; rate-limit public balance lookups.
- To improve the product using non-personal, aggregate usage analytics.
Sharing & processors
We share data only with the service providers needed to run GiftKit, and only for that purpose:
- OpoShop — the platform GiftKit runs on; the source of store, order, and email delivery.
- Cloud hosting & database — to run the app and store gift-card/credit records securely.
- Product analytics — non-personal usage data only.
We do not sell or rent personal data to anyone.
Security
Data is transmitted over HTTPS. Store access tokens and records are access-controlled and scoped so a store can only ever see its own data. Gift-card codes are unguessable, and the public balance-check page is rate-limited and returns a generic response for codes that don't exist — it never reveals whether a code is real.
Data retention
We keep gift-card and store-credit records for as long as the merchant has GiftKit installed, so outstanding balances remain redeemable — outstanding gift-card value is a liability the merchant owes their customers. When a merchant uninstalls GiftKit, we stop processing new activity for that store; on request we will delete a store's data, subject to any legal or financial-record obligations.
Your choices & rights
- Merchants can edit branding and settings in the app, and can uninstall GiftKit at any time from their OpoShop admin.
- Customers should contact the store they purchased from for requests about their gift card, store credit, or personal data — the merchant is the controller of that data.
- You may request access to or deletion of your data by emailing us (below); we'll coordinate with the relevant store where needed.
Children
GiftKit is a tool for merchants and their customers and is not directed to children under 13.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected here with a new "last updated" date.
Contact
Questions about this policy or your data? Email brandon@tryfound.io. GiftKit is published by Found and runs on the OpoShop platform.