Privacy

Privacy Policy

Last updated: May 2026

Your privacy matters to us. This policy explains what data we collect, why we collect it, and how we protect it — in plain language.

1. Who We Are

GiftBangers is an AI music generation platform. For the purposes of the General Data Protection Regulation (GDPR) and applicable EU data protection law, GiftBangers acts as the data controller.

For any privacy-related enquiries, please contact our Data Protection contact at: privacy@giftbangers.com

2. What We Collect

We collect the following categories of personal data:

  • Account data: Your email address, collected and managed via Firebase Authentication (Google LLC). We do not store passwords — Firebase handles authentication securely.
  • Payment data: Payments are processed by Stripe, Inc. GiftBangers never sees or stores your full card number, CVV, or bank account details. We only receive a payment confirmation token and transaction metadata.
  • Story content: The personal details you provide in the song wizard (recipient name, occasion, memories, relationship) to personalize your song. This content may include personal data about third parties — please ensure you have their consent or a legitimate interest in sharing this information.
  • Usage analytics: Aggregated, anonymized page-view data collected by Vercel Analytics. No cookies are used and no personal identifiers are tracked.

3. Why We Collect It

We use your data for the following purposes:

  • To create your personalized song — your story content is passed to AI models to generate lyrics and music. This is the core service you purchase.
  • To process payment — we send transaction details to Stripe to complete your purchase and prevent fraud.
  • To deliver your order — we use your email address to send you the finished song, video, and any updates about your order.
  • To improve the Service — anonymized analytics help us understand which features are most valuable and where users encounter friction.

Our legal bases for processing are: contract performance (delivering the service you paid for), legitimate interests (analytics and fraud prevention), and consent where required by law.

4. Data Retention

We retain your account data and project data for up to 12 months after your last purchase. After this period, data is automatically deleted from our active systems.

If you would like your data deleted before this period, you can request deletion at any time by emailing privacy@giftbangers.com. We will process your request within 30 days.

Note: Some data may be retained for longer periods where required by law (for example, payment records for tax compliance purposes, typically 7 years).

5. Third-Party Services

We share data with the following trusted third-party service providers, each of whom processes data only as necessary to provide their respective services:

  • Stripe — payment processing (Privacy Policy)
  • Firebase / Google LLC — authentication and file storage (Privacy Policy)
  • Supabase — database (project metadata and order records)
  • OpenAI— AI content generation (lyrics and music). Story content is sent to OpenAI's API under our data processing agreement; OpenAI does not use API data to train its models.
  • Resend — transactional email delivery of your song
  • Vercel — hosting and infrastructure. Vercel Analytics collects anonymized traffic data with no cookies.

All providers are contractually bound to protect your data in accordance with GDPR requirements. Where providers are located outside the EEA, appropriate safeguards (such as Standard Contractual Clauses) are in place.

6. Your Rights (GDPR)

If you are located in the European Economic Area, you have the following rights regarding your personal data:

  • Right of access — you may request a copy of the personal data we hold about you.
  • Right to rectification — you may ask us to correct inaccurate or incomplete data.
  • Right to erasure — you may request that we delete your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Right to data portability — you may request your data in a structured, machine-readable format.
  • Right to object — you may object to processing based on legitimate interests at any time.
  • Right to lodge a complaint — you have the right to lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact us at privacy@giftbangers.com. We will respond within 30 days.

7. Cookies

GiftBangers does not use tracking cookies or advertising cookies. The only session data we store is a secure authentication token in your browser to keep you logged in (this is a strictly necessary cookie and does not require consent under EU law).

Vercel Analytics — our analytics tool — is cookie-free and uses no fingerprinting or cross-site tracking techniques.

8. Children

GiftBangers is not intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us at privacy@giftbangers.com and we will delete that information promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. For material changes — such as new categories of data collected or new sharing arrangements — we will notify you by email at least 14 days before the changes take effect.

We encourage you to review this page periodically. Your continued use of the Service after any changes constitutes acceptance of the updated policy.