Privacy Policy
Last updated 30 August 2026
This policy explains what OnyxGift (“we”) collects when you use OnyxGift, why, and what you can do about it. We keep the amount of personal data we hold deliberately small.
What we never hold: your wallet’s private keys or seed phrase, and any card or bank details. Payment happens at our payment provider — we only receive confirmation that an order was paid.
1. What we collect
You give us
- Email address — to create your account, deliver codes, and answer support.
- Your answer about marketing email — whether you agreed, when, where you answered, the wording you were shown, and the IP address you answered from. We keep this so we can show that a message we sent you was one you asked for.
- Password — handled by our identity provider; we never see or store it.
- Optional profile details — name, date of birth, gender, if you choose to fill them in.
- Support correspondence — whatever you send us in an email.
- A refund wallet address — only if you request a refund.
Created by using the Service
- Order records — what you bought, when, the amount, and the delivery status.
- Payment confirmations — transaction reference and status from the payment provider.
- Technical data — IP address, device and browser type, and error logs, used for security and to keep the site working.
2. Why we use it, and on what basis
- To perform our contract with you — taking and delivering orders, support, refunds.
- To meet legal obligations — tax and accounting records, sanctions and anti-money-laundering screening.
- For our legitimate interests — preventing fraud and abuse, securing accounts, and improving the Service. We balance these against your rights.
- With your consent — only where we ask for it, and you can withdraw it at any time.
We do not sell your personal data, and we do not build advertising profiles about you. If you allow analytics, we do measure whether a visit came from one of our Google ads and whether it led to an order — that is counting our own advertising, not profiling you.
Marketing email
We only send offers to people who asked for them. The box on the sign-up form starts unticked, it is never a condition of buying, and leaving it alone is not a refusal — it simply means we have not asked you, and we will not write anything down.
You can turn it on or off at any time from your profile, or from the unsubscribe link at the bottom of any offer we send. That link works without signing in.
Order confirmations, gift-card codes and security emails are separate and are never affected. Those are part of what you bought, and unsubscribing from offers does not stop them.
Each time you change this answer we record what you chose, when, which of the three places you changed it from, the exact wording you were shown, and the IP address of the request. We keep it because a preference that has been overwritten cannot answer the question that actually gets asked — whether a message we sent last March was one you had agreed to at the time.
3. Who we share it with
Only the processors we need to run the Service:
- Identity provider (Google Firebase Authentication) — sign-in, email verification, password reset.
- Crypto payment provider — to take payment and confirm it.
- Gift-card suppliers and issuing brands — to source and issue your code.
- Hosting and email providers — to serve the site, send transactional email, and send offers to people who asked for them.
- Google (Tag Manager and Analytics) — to see which pages and products people use, and to measure whether our own ads lead to orders. If you have not agreed to cookies, it runs in a restricted mode: no cookies, and nothing that identifies you or your device. Never active on the 2-step verification page.
- Microsoft Clarity — with your consent only, to understand how the browsing pages are used: heatmaps and anonymised session replays with all text masked. It never runs on your account, checkout-confirmation or order pages, so it can never see a gift-card code, and it does not run at all unless you agree to cookies.
- Authorities — where we are legally required to disclose.
Some of these operate outside your country. Where data is transferred internationally we rely on the appropriate safeguards, such as standard contractual clauses.
4. Storage on your device
We use your browser’s local storage for things the site needs to function: your sign-in session, your theme, and your answer about analytics. These are always present — without them the site cannot keep you signed in. Clearing your browser storage signs you out.
Analytics cookies are separate, and we do not set them unless you agree. If you agree, Google Analytics sets its own cookies and can record that your visit came from one of our ads.
If you decline or simply ignore the question, we still count the visit — but with no cookie and no identifier attached, so it cannot be tied to you, your device, or anything you do later. Google estimates the totals from those anonymous signals. That is how we can respect a refusal completely and still know whether our advertising works, without making the choice feel like it costs you something.
Turning it off stops any further measurement. It cannot recall data already sent, and the container stays loaded until you reload the page — so a reload is the cleanest way to make the change take effect immediately.
5. How long we keep it
- Account data — while your account exists. When you ask us to close it, we anonymise the personal details on it by hand; we do not yet run this on a schedule, so an account left unused is not cleared automatically.
- Order and payment records — retained for as long as tax, accounting and anti-money-laundering law requires (commonly 5–7 years), even after account closure.
- Support emails — up to 2 years.
- Your marketing answers — the full history, for as long as your account exists and for a period after it closes. It is the only evidence that a message we sent was one you had agreed to, so deleting it would remove the proof that protects you.
- Technical logs — up to 12 months.
6. Your rights
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. You can also complain to your local data protection authority.
Email [email protected]. We may need to verify your identity first. We aim to reply within one month, and we will tell you if a request will take longer than that.
Being straight with you about how this works today: there is no button for it, and no automated process behind the address. A person handles each request by hand. That is slower than a self-service export, and it is the honest description of what we can actually do — we would rather say so than publish a promise the shop cannot keep.
Two limits apply whatever we do. We cannot delete records we are legally required to keep — order and payment history in particular, for the periods named above — and closing your account does not undo orders already delivered. Where a record has to stay, we remove the personal details attached to it rather than the record itself.
7. Security
The site is served over HTTPS, sessions are short-lived, and access to order data is restricted. No system is perfectly secure, so please use a strong, unique password and keep your email account protected — anyone with access to your inbox can reach your codes.
8. Children
The Service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.
9. Changes
We may update this policy. The “last updated” date above reflects the current version. If a change materially affects how we use your data, we will tell you before it takes effect.
10. Contact
See also our Terms of Service and Refund Policy.