Effective: July 19, 2025

Privacy Policy

We take this stuff seriously

1. Introduction

This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our gift registry application ("Service"). We are committed to protecting your privacy and ensuring transparency about our data practices.

2. Information We Collect

2.1 Information You Provide

  • Account Information: E-mail address, password, and any (optional) profile details you provide us
  • Registry Information: Gift lists, preferences, addresses (optional), and special occasion details (optional)
  • Communication Data: Messages, support requests, and feedback
  • Payment Information: Processed through Stripe (HANEWA does not store credit card details)

2.2 Information Automatically Collected

  • Usage Data: How you interact with our Service, features used, and time spent
  • Device Information: IP address, browser type, operating system, and device identifiers
  • Log Data: Server logs, error reports, and performance metrics
  • Cookies and Tracking: Information from cookies and technologies that enable HANEWA to function

2.3 Information from Third Parties

  • Stripe: Transaction data and payment processing information
  • Affiliate Partners: Product information and purchase confirmations
  • Social Media: If you connect social media accounts (with your permission)

3. How We Use Your Information

3.1 Service Provision

  • Create and manage your gift registry accounts
  • Process and fulfill gift purchases
  • Provide customer support and respond to inquiries
  • Send service-related communications and updates

3.2 Service Improvement

  • Analyze usage patterns to improve our Service
  • Develop new features and functionality
  • Conduct research and analytics
  • Ensure security and prevent fraud

3.3 Marketing and Communications

  • Send newsletters and promotional materials (with your consent)
  • Provide personalized product recommendations (with your consent)
  • Notify you about affiliate offers and deals (with your consent)
  • Conduct surveys and gather feedback (with your consent)

3.4 Legal and Business Operations

  • Comply with legal obligations and regulations
  • Protect our rights and enforce our Terms of Service
  • Resolve disputes and investigate violations
  • Support business transfers or acquisitions

4. Information Sharing and Disclosure

4.1 Service Providers

We share information with trusted third parties who help us operate our Service:

  • Fly.io: Cloud hosting and infrastructure services
  • PocketBase: Database and backend services
  • Stripe: Payment processing and transaction management
  • Affiliate Partners: For commission tracking and product recommendations (HANEWA does not directly provide your personal information to affiliates, but affiliates may track this as part of their service offering)

4.2 Registry Sharing

  • Registry information is shared with people you invite to view your registry
  • Gift purchasers may see registry details necessary to complete purchases
  • You control the visibility and sharing settings of your registry

4.3 Legal Requirements

We may disclose information when required by law or to:

  • Comply with legal processes, court orders, or government requests
  • Protect our rights, property, or safety
  • Prevent fraud or other illegal activities
  • Enforce our Terms of Service

4.4 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

5. Data Security

5.1 Security Measures

  • Data encryption in transit and at rest
  • Regular security audits and vulnerability assessments
  • Access controls and authentication requirements
  • Employee training on data protection practices

5.2 Data Hosting

  • Data is hosted on Fly.io infrastructure with industry-standard security
  • PocketBase backend implements security best practices
  • Automated backups and self-healing disaster recovery procedures

5.3 Payment Security

  • Payment processing handled entirely by Stripe
  • We do not store or have access to your payment card information
  • Stripe maintains PCI DSS compliance for payment security

6. Your Rights and Choices

6.1 Account Management

  • Access and update your account information
  • Modify registry settings and privacy preferences
  • Delete your account and associated data

6.2 Communication Preferences

  • Opt out of marketing e-mails and newsletters
  • Manage notification settings
  • Control how we contact you about Service updates

6.3 Data Rights (Where Applicable)

Depending on your location, you may have additional rights including:

  • Right to access your personal data
  • Right to correct inaccurate information
  • Right to delete your data
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

7. Cookies and Tracking Technologies

7.1 Types of Cookies

  • Essential Cookies: Required for basic Service functionality
  • Analytics Cookies: Help us understand how you use our Service
  • Marketing Cookies: Support personalized recommendations and advertising
  • Preference Cookies: Remember your settings and preferences

7.2 Managing Cookies

  • You can control cookies through your browser settings
  • Disabling certain cookies may limit Service functionality
  • We respect "Do Not Track" signals where technically feasible

8. Data Retention

8.1 Retention Periods

  • Account data: Retained while your account is active
  • Registry data: Retained as long as registries are active
  • Transaction data: Retained for legal and tax requirements
  • Log data: Typically retained for 90 days

8.2 Deletion

  • You can request deletion of your data at any time
  • Some data may be retained for legal or legitimate business purposes
  • Anonymized data may be retained for analytics and research

9. International Data Transfers

  • Our Service may transfer data internationally for processing
  • We ensure adequate protection through appropriate safeguards
  • Data may be processed in countries with different privacy laws
  • We comply with applicable data transfer regulations

10. Children's Privacy

  • Our Service is not directed to children under 13
  • We do not knowingly collect personal information from children under 13
  • If we discover we have collected such information, we will delete it promptly
  • Parents can contact us to request deletion of their child's information

11. Third-Party Services

11.1 Stripe Integration

  • Payment processing governed by Stripe's privacy policy
  • We share necessary transaction information with Stripe
  • Stripe may have different data practices than we do

11.2 Affiliate Partners

  • Product recommendations may link to affiliate partner websites
  • These partners have their own privacy policies
  • We may earn commissions from purchases through affiliate links

11.3 External Links

  • Our Service may contain links to third-party websites
  • We are not responsible for the privacy practices of other sites
  • We encourage you to review third-party privacy policies

12. California Privacy Rights

California residents have specific rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt out of sale of personal information
  • Right to non-discrimination for exercising privacy rights

We do not sell personal information to third parties.

13. Changes to This Privacy Policy

  • We may update this Privacy Policy from time to time
  • We will notify you of material changes via e-mail or Service notification
  • Continued use after changes constitutes acceptance of the updated policy
  • Previous versions will be archived and available upon request

14. Contact Us

For questions about this Privacy Policy or to exercise your privacy rights, contact us at:

E-mail: support@hanewa.com

Address: Greyworks LLC. 1123 Broadway. New York, NY 10010

Phone: (917) 472-9967

For California Residents:

You may also contact us using the above information to exercise your CCPA rights.

For EU Residents:

If you are in the European Union, you may contact our Data Protection Officer or your local data protection authority.