Skip to content
PresentForMe

Privacy Policy

How we handle your personal data.

Last updated: July 2026

Contents

1. Data controller

The data controller for personal data is Bussolari Alessio, based at Via del Prete 123, 47841 Cattolica (RN), Italy.

For any request related to the protection of personal data, you can contact us at info@presentfor.me.

2. Personal data collected

We collect different categories of personal data necessary for the operation of the platform.

Account data
  • Name
  • Email address
  • Date of birth (optional)
  • Username
  • Profile picture
  • Preferred language
Authentication data
  • Password hash (bcrypt)
  • Session tokens
  • API tokens
  • IP address and browser user agent
Shipping addresses
  • Recipient name, street, city, postal code, country
Preferences and settings
  • Notification preferences for each type of activity
Device data
  • Token used to deliver push notifications, and device platform
Social data
  • Friendships and friend requests
  • Invitations sent and received
Gift and wishlist data
  • Gift names, descriptions, prices, URLs, and categories
  • Reservations
  • Notes and comments for gift givers

3. Automatically collected tracking data

In addition to data you provide directly, we automatically collect:
  • Session data: access logs, session duration, pages visited
  • Commercial clicks: clicks on links to partner sites for affiliate tracking
  • Administrative logs: administrator actions for security and audit purposes

4. Purposes and legal basis

We process your personal data in accordance with Art. 6(1) of the GDPR, based on the following legal grounds:

Performance of contract (Art. 6(1)(b))
  • Account creation and management
  • Provision of the wishlist, sharing, and gift reservation services
  • Sending service-related notifications (reservations, invitations)
  • Handling support requests
Consent (Art. 6(1)(a))
  • Analytical cookies
  • Push notifications on your device
  • Sending promotional communications
Legitimate interest (Art. 6(1)(f))
  • Platform improvement through aggregate analysis
  • Fraud and abuse prevention
  • Service security
Legal obligation (Art. 6(1)(c))
  • Data retention required by tax and accounting regulations
  • Responding to requests from competent authorities

5. Cookies

For detailed information about the cookies used by the platform, their purposes, and how to manage them, please refer to our Cookie Policy available on the dedicated page of the site.

6. Third-party services

We use no web analytics and no profiling tools — no Google Analytics, no advertising pixels. Error and performance monitoring runs on CloseYourIt, a tool of ours hosted on our own infrastructure, so that data never reaches an outside provider.

To operate the platform we do rely on a small number of providers, which as such process your data.
  • Hetzner (Germany) — the servers and databases the platform runs on. This is where your data lives.
  • Resend (United States) — sending service emails such as address confirmation, password reset and event invitations. It receives your name and email address.
  • Amazon Web Services (S3 storage, European region in Frankfurt) — the images you upload, that is avatars and gift photos.
  • Firecrawl (United States) — reads the product page when you paste a link, so we can suggest a title, a price and a photo. It receives the page address, not your data.
  • Google Gemini — does two things. It completes the reading of a product page when it comes back partial, working on the text we already downloaded; and it screens every gift you save or edit, to stop what does not belong on a gift list. In this second case it receives the gift text — name, description, link and where to find it — which in the hand-filled form is text you wrote. It does not receive your name, your email or any other profile data.
  • Google Places — searches for an event location as you type it. It receives what you type in the field and nothing else — the call is made by our server, not by your phone, so Google sees neither your network address nor who you are. You can always write the location by hand without using the search.
  • Firebase Cloud Messaging (Google) — delivers push notifications to your phone, if you turned them on. It receives the device identifier and the text of the notification.
  • Affiliate programs (e.g., Amazon) — when a gift is saved we add an affiliate tag to the product link. Click tracking happens on the seller's site when you go there, not on ours.
Each provider is required to process data exclusively for the stated purposes and in compliance with applicable regulations.

7. International data transfers

The platform is hosted in Germany and the images you upload sit in the European AWS region (Frankfurt).

Some providers are however based in the United States — Resend, Firecrawl and Google (Gemini, Places and Firebase Cloud Messaging). Data transfers to the US are carried out on the basis of:
  • EU-US Data Privacy Framework for certified providers
  • Standard Contractual Clauses (SCCs) approved by the European Commission
In any case, we adopt supplementary measures to ensure an adequate level of protection for your personal data.

8. Data retention period

We retain your data for the time strictly necessary for the purposes for which they were collected:
  • Account data: until account deletion, plus 30 days for permanent removal
  • Session data and logs: 30 days
  • Technical monitoring data (errors and performance): 24 months
  • Support requests: 12 months after closure
  • Affiliate data: according to partner program terms
  • Backups: 90 days, then automatically deleted
At the end of the retention period, data is deleted or irreversibly anonymized.

9. Data subject rights

Under Articles 15-22 of the GDPR, you have the right to:
  • Access (Art. 15): obtain confirmation of processing and a copy of your data
  • Rectification (Art. 16): correct inaccurate or incomplete data
  • Erasure (Art. 17): request deletion of your data ("right to be forgotten")
  • Restriction (Art. 18): restrict processing in certain circumstances
  • Portability (Art. 20): receive your data in a structured, machine-readable format
  • Objection (Art. 21): object to processing based on legitimate interest
  • Withdrawal of consent (Art. 7): withdraw consent at any time
To exercise your rights, write to info@presentfor.me. We will respond within 30 days.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) at www.garanteprivacy.it if you believe that the processing of your data violates the GDPR.

10. Children's data

PresentForMe is intended for users aged 14 years or older, the threshold Italy set under Article 8 GDPR. The date of birth is asked for when you finish setting up your account, and a date below that age is rejected. We do not knowingly collect personal data from children under 14. If a parent or guardian discovers that a minor has provided personal data without consent, they can contact us at info@presentfor.me to request its deletion.

11. Data security

We adopt technical and organizational measures to protect your personal data:
  • Password encryption: passwords are protected with bcrypt (irreversible hashing)
  • HTTPS: all communications are encrypted with TLS
  • CSRF protection: anti-forgery tokens on every request
  • Rate limiting: API request throttling to prevent abuse
  • Revocable tokens: sessions, API tokens, and sharing links can be revoked at any time

12. Changes to the privacy policy

We reserve the right to update this policy to reflect changes in our practices or for regulatory compliance. In case of substantial changes, we will inform you via:
  • Notice on the platform
  • Email to the address associated with your account
We encourage you to periodically review this page to stay informed.

13. Contact

For any question, request, or report related to the protection of your personal data:

Email: info@presentfor.me
Website: www.presentfor.me