PRIVACY NOTICE
What GiftDrop knows about you, and what it does not.
The short version. If you only use GiftDrop to check a gift card balance, we collect nothing at all unless you agree to app analytics when the app asks, and your card details never reach us. On Android, the Google component that reads a card in the camera reports on its own performance to Google; that is described in Part A and we cannot see it. If you donate, you create an account, and Part B below lists exactly what that involves. If you write to us through the contact form, we receive what you typed and nothing else, and we do not store it on this website.
Who we are
GiftDrop is operated by Global Outsource Solutions Pty Ltd, ABN 76 147 725 040, a commercial business registered in Australia. We are not a charity, and we are not a deductible gift recipient. Donations go to registered charities that you choose, and we retain a disclosed service fee. There is no GiftDrop Foundation.
Privacy questions, access requests, corrections and complaints go to donations@giftdrop.app, or through our contact form. Either reaches the same mailbox, and you do not have to use a particular one, a particular form of words, or explain why you are asking.
Small businesses are generally outside the Australian Privacy Act 1988, and GiftDrop is a small business. We hold ourselves to the Australian Privacy Principles anyway, and we handle your information as though the Act applied to us. We have not lodged the formal choice under section 6EA that would make the Act apply to us as a matter of law, so the Office of the Australian Information Commissioner may not be able to take a complaint about us. Write to us first. If we cannot put something right, we will tell you so plainly rather than send you to a regulator who may not be able to help.
What this notice covers
The GiftDrop app for iPhone, the GiftDrop app for Android, and the GiftDrop website. Part A is the app on its own, and says which phone it means wherever the two differ. Part B applies once you sign in to donate, which you do on the website. Neither app has a sign-in or a donation of its own.
Part A — checking a gift card balance
Your card details stay on your device. We cannot see them and they are never sent to us.
Most of this part is the same on both phones. Where the iPhone app and the Android app genuinely differ — where your card is held, what unlocks it, and what reads the card in the camera — each is described separately below, because a single sentence covering both would be false for one of them.
- Card credentials — the card number, expiry, security code and PIN you scan or type.
On iPhone: held in the iOS Keychain in a device-only item that needs Face ID, Touch ID or your passcode each time it is read. Device-only Keychain items are excluded from iCloud Keychain and from device backups.
On Android: held in the phone's own hardware-backed key store. Each card gets its own key, held by the phone's secure hardware, and that key protects the details — they are never stored in a form the app can read on its own. Reading them back requires unlocking GiftDrop with your fingerprint, face or screen lock. Some Android phones have an extra-secure chip for this and some do not; GiftDrop uses it where it exists and falls back to the phone's standard secure hardware where it does not. Either way the key never leaves that hardware. Your cards are excluded from every Android backup — the cloud backup Google offers and the phone-to-phone transfer you use when you get a new handset — so if you uninstall GiftDrop, or move to a new phone, your saved cards do not come with you and you would scan them again. That is the cost of them never being anywhere but this phone. - Card details for display and for your donation history — a nickname, the provider, the card network, the last four digits, the most recent balance and when it was checked, the links the provider publishes, when you added the card, and, if you have donated a card's balance, the amount, the charity you chose and the receipt reference. These are kept in a local database excluded from backups. They are not sent to us as part of checking a balance; what we hold when you donate is Part B.
- Provider website data — cookies and site data created by a provider when you check a balance — are kept in a separate browser GiftDrop keeps for that provider. Inside that browser the provider's own site and the services it uses can set and read cookies as they would in your ordinary browser. You can clear it: on iPhone in Settings, and on Android in Settings › Card providers › Start fresh with providers, which clears cookies and stored site data for every provider.
- Diagnostics — a short, masked log of app stages, kept on the phone. Card numbers, security codes and PINs are masked before anything is written to it, and scanned text is never written to it. An expiry date is not masked, because the masking works on runs of three or more digits and an expiry written
12/26is two and two — so if a provider's own error message quotes your expiry back, the log can keep that. It leaves the phone only if you copy it and send it to us yourself.
On Android there is also a Detailed logging switch, off unless you turn it on. With it on, a balance check additionally records what the provider's own page reported to the browser, the addresses it contacted, and your phone's model, browser version and display settings. The same masking applies.
Reading a card with the camera
On iPhone: the camera reads the text on a card entirely on the device using Apple's Vision framework. No image or video is saved or uploaded. Face ID and Touch ID are used through Apple's Local Authentication framework; GiftDrop never sees your biometric data.
On Android: when you scan a card, the camera image is read entirely on your phone. GiftDrop uses Google's ML Kit text and barcode recognition, which is built into the app and works without a network connection: no photograph is taken, no image is saved, and neither the image nor the text read from it is sent to GiftDrop or to anyone else. The fingerprint, face or screen-lock check is performed by the phone itself, which tells GiftDrop only yes or no; GiftDrop never sees your biometric data. Adding a new fingerprint to your phone does not delete your saved cards.
The recognition library reports on itself to Google, and that is not covered by the analytics choice below. On Android, Google's ML Kit sends Google its own technical information about how it ran: your device manufacturer, model, Android version and build, which machine-learning hardware your phone offers, GiftDrop's package name and version, the version of the recognition feature, how long recognition took, the image's format and resolution, the size of the input and output, the type of event, any error codes, and an identifier for this installation of the app. It sends this on its own schedule, which can be while you are not using GiftDrop. It does not report the card, the image, or the text that was recognised. This is part of the Google component itself rather than something GiftDrop chooses to collect, we cannot see it, and it is not governed by the analytics choice described below. Google states that it does not pass this information to third parties. Described from Google's own ML Kit data-disclosure page, read on 19 September 2026.
When you check a balance, GiftDrop opens the provider's own official website inside the app and enters your card details into that site's form. The provider receives those details exactly as if you had typed them yourself, and its site may set cookies, run bot protection and collect analytics under its own privacy policy. On Android you can instead choose Take control, and type the details into the provider's form yourself; GiftDrop then enters nothing, but it is still reading the page so that it can save the balance when the provider shows it. GiftDrop opens only the verified site for the provider you chose. On iPhone it also cancels any navigation away from that site.
Deleting a card removes its credentials from secure storage and its details from the local database. It does not clear that provider's browser data, which you clear separately as described above. Deleting the app removes everything described above from your phone.
Measuring the app
This section is about analytics you are asked to agree to. It applies wherever GiftDrop asks you — today that is the iPhone app. If an app of ours does not ask you, it is not collecting this. The Google reporting described above is a separate thing, and no choice here affects it.
If you agree when the app first asks, GiftDrop collects anonymous information about how you use it — which screens you open, which actions you take, and whether they succeed — using Firebase Analytics, a product of Google LLC. It never includes card numbers, expiry dates, CVVs, PINs, balances, your name, your email, or which gift cards you hold. Google LLC stores and processes this information outside Australia, mainly in the United States, and we keep it for 14 months from your last use of the app. You can say no when asked, and you can turn it off at any time in Settings › Privacy › App analytics. Nothing about the app changes if you do.
Part B — donating
Donating needs an account, and an account means we hold information about you.
What we collect. The email address and profile details your sign-in provider reports (Google, Apple or Microsoft); sign-in and transaction dates and times; your IP address and a country-level or approximate location derived from it; your browser or device description; the amount you donate, the charity you choose, the status of the donation and whether you asked to stay anonymous; Stripe transaction references; your card brand and last four digits; security alerts; a record of administrative actions taken on your account; and, while you are signed in, a record of which of your own pages you opened — your account, your donation list, a receipt, the invite page — and whether you used a referral link. We use that last one to understand how the site is used. It is ours and is not sent to anyone else, and unlike the rest of this list it is kept after an account is deleted.
What we never receive. Your full card number and security code. Stripe's own payment fields handle those, and they do not pass through GiftDrop.
Why. To authenticate you, to process and reconcile donations, to issue transaction records, to prevent fraud and card misuse, to investigate disputes and chargebacks, to meet legal and financial obligations, and to keep an auditable record of privileged administrative activity. Without this information we cannot safely process a payment.
Impact, product and marketing messages are off unless you turn them on in My GiftDrop, and you can turn them off again at any time without affecting receipts or security messages.
Invitation links. If you use or share one we record a random first-party identifier, aggregate visit and share counts, and whether a donation followed. We never upload address books and never tell the person who shared a link who acted on it.
What the charity you choose is told
We tell the charity that a donation was made, what it was for, and how much it receives. If you asked to stay anonymous we do not give them your name or your email address. If you did not, we may.
Staying anonymous to a charity does not make the payment anonymous to GiftDrop, to Stripe, to your bank, to regulators, or to law enforcement acting lawfully. It is a choice about what the charity sees.
Our service fee is shown to you before you donate, on the same screen as the amount. We are paid out of your donation, and the charity receives the rest.
Cookies this website sets
Opening the donate page loads Stripe's payment fields, and Stripe sets its own cookies at that point — including one that identifies your device for up to a year and that it uses to detect fraud. That happens whether or not you sign in or donate. We also set a short-lived cookie to protect the forms, one that keeps you signed in once you do sign in, and, if you arrived through a referral link, one that remembers the referral for 30 days. None of them is advertising, and none is sold. This section applies however you reach the site, including before you have signed in.
Measuring the website
This website uses Google Analytics to count visits and see which pages people read. It sets cookies in your browser and tells Google your approximate location, worked out from your IP address, along with your device, browser, the pages you opened and the site or search that sent you here.
What we deliberately do not send. Addresses on this site can contain a receipt number, a donation reference or a referral code, and the address you land on after a card security check carries a payment reference from Stripe. All of those are stripped out before anything is reported, so they never reach Google. Pages in the staff console are not reported at all.
We use this to understand traffic, nothing else. Google’s advertising features and Google Signals are switched off, we do not run ads, and we do not sell or share this information. Google processes it under its own terms and outside Australia.
If you would rather not be counted, block cookies for this site in your browser, use private browsing, install Google’s Analytics opt-out add-on, or use any tracker blocker. Nothing about donating changes if you do, and we do not detect or treat you differently for it.
Contacting us
You can write to us without an account, and without donating. The contact form at giftdrop.app/contact asks for your name, your email address and your message, and sends them to our mailbox. Nothing you send through the form is stored on this website or in our database — there is no support ticket, no queue and no record here. What exists afterwards is the email in our mailbox, which we keep for as long as we need it to answer you and to show what was agreed, and no longer.
Please do not send card numbers, security codes or PINs. We never need them, an email is not a secure channel, and we will ask you to send a replacement message if you do.
Both of our public forms — the contact form and the account deletion form — are protected by Cloudflare Turnstile, which checks that a person rather than a script is submitting them. It starts that check when you open the form rather than when you send it, so Cloudflare receives your IP address and information about your browser as soon as the page loads, under its own terms, and may process it outside Australia. It does not read your message. If you would rather not use the form, write to the address on the contact page from your own mail program instead — it reaches the same mailbox, and nothing about our answer changes.
Where your information goes
Google, Apple, Microsoft, Stripe, Cloudflare and Twilio SendGrid handle information under their own terms and may process it outside Australia. Apple may give us a private relay address if you choose Hide My Email. Cloudflare checks that whoever submits one of our public forms is a person rather than a script. SendGrid delivers the email we send: your receipt, a refund confirmation, anything you send us through the contact form, and an account-deletion request you make through giftdrop.app/delete-account. Our servers are hosted on DigitalOcean infrastructure. Sensitive security records are encrypted before they are stored, IP addresses are matched using a keyed fingerprint rather than the address itself, and access is restricted and audited.
Stripe keeps its own record of every payment. We cannot delete it, and neither can you through us.
Deleting your account
Use giftdrop.app/delete-account, which asks only for the address on the account. You do not need to sign in, and you do not need the app or a password. If you are already signed in on the website you can instead open My GiftDrop › Settings and choose Request account closure, and you can always write to donations@giftdrop.app. All three reach the same place: we verify that you control the address and then erase the account — your name, your email address, your profile picture and every stored sign-in identity are removed, so no provider can reach the account again; every session on every device is signed out; if you signed in with Apple we ask Apple to revoke the authorisation; and the email address held in our security records is cleared. It cannot be undone. Neither app has a sign-in, so neither has a deletion control of its own; an account made with an earlier version of the iPhone app is deleted in the same way.
Be aware of one limit. A person handles it, so it is not immediate, and we have not set ourselves a deadline we could promise you here; until it is done, your name and your email address stay on the record.
What we keep, and why. The record of each donation, the charity it went to and its receipt number. Fundraising and tax law require us to keep the transaction; they do not require us to keep you. These records no longer carry your name or your address.
We want to be straight about the limit of that. GiftDrop can still tell which closed account a donation belonged to. We have removed the details that identify you to anyone reading the record, but we have not made the record untraceable, and we will not claim otherwise.
What we cannot undo. Receipts already emailed to you are in your own mailbox and cannot be recalled. A refund that settles after you delete is recorded against the transaction, and we do not email you about it. Stripe keeps its own copy of the payment.
If you sign in again afterwards you get a new account with no history. Your saved cards, their balances and their details are never touched by this: they live only on your phone, and Part A applies to them.
An account we have restricted cannot sign in, so it cannot use Settings. Use the deletion page, or write to the address above.
How long we keep things
Detailed security records are kept for 90 days unless they are needed for an active fraud, dispute, legal or security investigation. Payment, charity, tax and fundraising records are kept for the periods Australian law requires, which is longer, and they survive the deletion of an account. Invitation link attribution lasts about 30 days.
The encrypted network fingerprint of a deleted account is kept for the 90-day security window. We keep it because clearing it on request would let somebody sever the link between accounts they control.
Children
GiftDrop is not directed at children under 13 and we do not knowingly collect their information. Part A sends us nothing about anybody.
Your choices, and complaints
You can ask us what we hold about you, ask us to correct it, ask us to delete your account, or complain, at donations@giftdrop.app or through our contact form. If you are not satisfied with our answer, the Office of the Australian Information Commissioner at oaic.gov.au is the regulator for privacy in Australia — though, as “Who we are” above explains, it may not be able to take a complaint about us until we have lodged the section 6EA choice.
Changes
If we change how we handle information we will update this page and its version below, describe the change in the App Store and Google Play release notes, and ask you to read it again before your next donation.
Notice version: 2026-09-donor-v8 · Updated 25 September 2026
Return to GiftDrop