Giftstation Privacy Notice

September 2024

This privacy notice (“Privacy Notice”) explains how we process your personal data (“Personal Data”) while you use our services, including when you browse our website (“Website”), perform a transaction with us (“Services”) , whether as a customer, a visitor and/or a user of our Website, or however you might otherwise interact with us (collectively, “you”, “your” or “users”). In this Privacy Notice, we also describe whether your Personal Data is shared with other parties and the mechanisms we have in place to protect your data.

We encourage you to regularly review this Privacy Notice and check the Website for any updates. Updates to this Privacy Notice will be published on our Website, and by continuing to deal with us, you agree to this Privacy Notice and any future modifications.

Where local law requires additional details to be included in this Privacy Notice, such information has been included in the Regional Privacy Notices section below.

Content Regional Notices

What Personal Data is collected and why?

Legitimate interest

How long do we keep Personal Data?

Do we disclose Personal Data?

Data Security

Marketing and Advertising

Description of Personal Data Rights

Privacy Complaints

Our companies by service

Notice to European (EEA) residents

Notice to New Zealand residents

Notice to Australian residents

Frequently asked questions (FAQs)

How can I contact the company regarding my Data?
To make any request or consultation, you may contact us by email to [email protected].

Who are we?
We are Epay, a part of Euronet Worldwide group of companies.

What type of Personal Data is collected?
We collect only the Personal Data necessary to provide you with the Service and to comply with applicable law.

Why do We collect Personal Data?
We collect Personal Data for specific contractual and legal purposes. With your consent, we also collect data for additional purposes.

How long do we keep Personal Data?
We keep Personal Data only for as long as necessary or as required by applicable law.

With whom we share Personal Data?
We share Personal Data with other Euronet Group companies, legal authorities, and partners where necessary to meet regulatory requirements or contractual commitments.

Where do we store Personal Data?
We store Personal Data in secure locations with strict security measures in place. If we need to transfer Personal Data to other locations, we take all necessary measures to comply with legal obligations and ensure a proper level of security.

What are your Personal Data rights?
Depending on where you live, you may have rights in relation to your Personal Data under applicable law. A description of common Personal Data rights is set out in section 15 below.

Who are we

To know more about our companies, you click here and find all necessary information.

1. What Personal Data is collected and why?

The categories, sources, and reason for collecting Personal Data are listed below. Where the collection of Personal Data is based on your consent, you may withdraw your consent at any time. We do not “sell” or “share” Personal Data, as those terms are defined under applicable laws. We retain Personal Data for as long as reasonably necessary to provide the Services and meet our legal obligations.

If you have questions or concerns regarding the processing of your Personal Data, you may contact us any time at [email protected]

We collect Personal Data from the following sources:

  • Directly from you through direct interactions and forms.
  • Internet websites, through passive collection of information about Your interactions, including page clicks, time spent, or other automatically collected meta-data.
  • Advertising networks, social media services.
  • Internet service providers; Operating systems and platforms.
2.1. Types of Personal Data

a) Identifiers or Identification Data

The Personal Data we collect from you may include name, email, telephone and/or fax numbers, residential and/or business address and other contact data (“Contact details”), title, date of birth, gender, images, videos, or signature.

Where necessary, Identification data is only used for the described purposes.

Purpose for Processing Legal Basis
To perform/supply the Services. Contractual obligation
To provide customer service and record customers’ instructions, we will monitor and record (via automated means or transcripts) our telephone calls, emails, and chat conversations with you. We will use transcripts of these calls to confirm the instructions provided to us. Contractual obligation
Legitimate interest
To provide advertising and marketing. Consent
To measure and evaluate your behavior using automated processing to provide you with a more personalized Service. Consent
Your participation in events or giveaways: You may wish to take part in events organized by us or in a specific giveaway. Consent

To meet our legal obligations related to record keeping we keep correspondence including e-mails, faxes, and any kind of electronic communication, together with any records of the customer’s account.

We also keep customer service letters and other communications between us and any Euronet Group company as well as our partners and suppliers. 

Legal Obligation

b) Behavioral and Technical Information

IP address, internet, or other similar network, browsing, or search activity, behavioral information (to understand the way you behave while using our products and services), browser type and version, time zone setting, screen resolution settings, browser plug-in types and versions, operating system, and platform.

Our Cookie Policy is available here

Purpose for Processing Legal Basis
To perform analytics to measure the use of our website and Services, including number of visits, average time spent on the Website, pages viewed, page interaction data (such as scrolling, clicks, and mouse-hovers), etc., and to improve the content we offer to you. Consent
To undertake activities to verify or maintain the quality of the Service, and to improve, upgrade, or enhance the Service, including to administer the Website and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes. Consent
Legitimate Interest
To help ensure the safety and security of our Website Legitimate Interest
To provide advertising and marketing, including measuring the impact of our emails. Consent

c) Non-Identifiable Data

Whenever possible, we use data where you cannot be directly identified (such as anonymous demographic and usage data) rather than Personal Data (“non-identifiable data”). This nonidentifiable data may be used to improve our internal processes or delivery of services, without further notice to you.

We may use aggregate data for a variety of purposes, including to analyze, evaluate and improve our Services.

2.2 Accuracy of Personal Data

We are committed to keeping your Personal Data accurate and up to date. We take reasonable steps to ensure the accuracy of your Personal Data by ensuring that the latest Personal Data we have received is accurately recorded and when considered necessary, we run periodic checks and request that you update your Personal Data. From time to time, we may send you an email asking you to confirm and/or update your Personal Data. This communication is based on our legitimate interest and legal obligation to maintain accurate and up to date information.

If you notice that your Personal Data is not accurate, you may request a correction or update your information by sending an email to [email protected].

2. Legitimate Interest

When we use your Personal Data to pursue our legitimate interests, we will make every effort to match our interests with yours so that your Personal Data will only be used as permitted by relevant law, or when it will not adversely affect your rights. Upon request, customers may request information on any processing based on legitimate interest.

3. How long do we keep Personal Data?

Personal Data is kept for as long as it is necessary to provide the Services requested and to comply with applicable legal, accounting, or reporting obligations. The retention period is determined based on the applicable requirements and obligations, which may include:

  • Legal and Regulatory Requirements: Your Personal Data is kept as long as necessary to comply with all our legal obligations including without limitation, commercial, tax and anti-money laundering laws and regulations. While we store your Personal Data only for the purposes of complying with legal obligations, your Personal Data will be restricted such that it cannot be used for any other purposes. While restricted, only when necessary, will your Personal Data be accessed. Whenever we receive a request for deletion, we will also maintain your Personal Data further to our legal obligations.
  • Customer Service and Contractual relationship (administration of customer relationship, complaint handling, etc.): We will keep your Personal Data if you remain our customer. Once we consider our contractual relationship to be over, we will proceed to restrict your data to make it available only to comply with legal obligations as expressed above.
  • Marketing: We will process your Personal Data for marketing purposes if you haven’t asked us to opt out or until we become aware that you are no longer interested or that your data is not accurate.

4. Do We disclose Personal Data?

Epay´s disclosure of Personal Data for business purposes or to meet legal obligations are outlined below:

a. Euronet Group

Types of Personal Data Purpose Legal Basis

Identification Data

Behavioral and technical Data

We disclose your Personal Data with Euronet and Euronet Group affiliates for our affiliates’ everyday business purposes and compliance with group obligations.

As a result of a sale, acquisition, merger, or reorganization involving Euronet, a company within the Euronet Group, or any of their respective assets, we may transfer customer Personal Data to a third party. In doing so, we will take reasonable steps to ensure that their information is adequately protected.

Your Personal Data is also disclosed to be able to provide you with customer service, regardless of when you require our help. To provide access to our 24/7

Legal obligation Contractual obligation
Identification Data customer service, we must share your Personal Data with the Group affiliates.  

b. Third-Party Service Providers 

Types of Personal Data  Purpose Legal Basis
Identification Data To data analytics and ID verification providers to perform compliance verification (e-KYC) and fraud prevention services.

Legal Obligation

Consent

Contact Details

To our agents and correspondents to provide the Services.

Legitimate interest
Legal obligation Consent

Contact details.

Behavioral and technical Data

To advertisers or advertising networks and social media companies to place personalize placed advertisements in digital services and to adapt to consumer preferences. Consent

c. Legal and Regulatory Authorities

Types of Personal Data  Purpose Legal Basis
Identification Data  We may need to disclose your Personal Data if requested by a legal authority. We may share your Personal Data with legal authorities to enforce or apply our Terms and Conditions or any other agreement or understanding we may have with you. Legal obligation
Contractual obligation

d. Professional Partners

Types of Personal Data  Purpose Legal Basis
Identification Data  We will share your Personal Data with advisers, lawyers, consultants, auditors, or accountants in order to comply with our legal obligations and to provide our Services and our contractual obligations and best practices. Legitimate interest

5. Data Security

We are committed to protecting your Personal Data and have put in place the highest standard of data protection by adopting industry-standard measures to protect your privacy, preventing any loss, abuse, and alteration of the information you have entrusted us. At Epay, we will always strive to ensure your Personal Data is well protected, in accordance with international best practices. We maintain this commitment to data security by implementing appropriate physical, electronic, and managerial measures to safeguard and secure your personal information.

To safeguard our systems from illegal access we use secure, cutting-edge physical and organizational security measures which are continuously enhanced to ensure the highest level of security in accordance with international best practices and cost efficiency. All Personal Data is kept in a secure location protected by firewalls and other sophisticated security mechanisms with limited administrative access.

Personnel who have access to your Personal Data as well as the processing activities surrounding your Personal Data are contractually bound to keep your data private and adhere to the Privacy Policy we have implemented in our organization.

6. Marketing and Advertising

Third-party advertisers provide advertisements that are displayed on our website, or elsewhere in our services. Third-party advertisers don’t have access to any of the information our customers have given us directly. Typically, advertisers rely on cookies or some other web mechanism to assess which advertisements may be interesting to you. We do not place “Targeting Cookies” or enable “Targeting” and “Location” on your system without your consent.

If you have provided your consent by accepting Targeting Cookies on the Website, we may use third parties to do so (remarketing and Similar Audience features). You can opt-out of advertising by modifying your cookies settings here.

Third parties are not bound by our Privacy Notice. To understand the privacy policy of their notices, you should visit the third-party website. You can find all the third parties that may use Cookies for targeting in our Cookie Policy.

We may contact you from time to time (by email, SMS text, letter, or phone as necessary and according to your specific instructions) and when you have provided us with your consent to provide targeted marketing about our Services and/or our products.

6.1. Why would you receive electronic communications?

You will receive marketing communications if you have authorized us to process your Personal Data for those purposes.

6.2. How can you opt-out?

You will be able to withdraw your consent at any time by using one of the following mechanisms:

Use the opt-out link you will receive in any of our communications.

By sending an email at [email protected]

If you have any additional questions regarding the usage of your Personal Data for marketing purposes and/or wish to start receiving marketing communications, you can also send an email to [email protected].

7. Description of Personal Data Rights

Depending on where you live, your Personal Data Rights under applicable law may include:

  1. Right to Access: the right to request access to a copy of your Personal Data.
  2. Right to Correct Inaccuracies: the right to request correction of inaccuracies in your Personal Data.
  3. Right to Deletion: the right to request deletion of your Personal Data where certain conditions apply.
  4. Opt-Out Rights:
    1. The right to opt-out of the processing of Personal Data for the purposes of targeted advertising.
    2. The right to opt-out of the processing of Sensitive Personal Data.
    3. The right to opt out of the processing of personal data for profiling in furtherance of decisions that produce legal or similarly significant effects concerning the Data Subject.
  5. The right to limit sensitive personal data use and disclosures to specifically permitted purposes.
  6. Right to Restrict Processing: the right to restrict processing where certain conditions apply.

We will respond to your request as soon as possible and within the timeframe stated in the applicable law.

For applicable rights please refer to the Regional Privacy Notice section below.

To exercise any of your rights, you must send an email to [email protected]. To help protect your privacy and maintain security we will take necessary steps to verify your identity and may ask you to provide other details before granting you access to your Personal Data or initiating a modification of any Personal Data. When required, if we don’t have a copy of your ID or any legal valid document that proves your identity, we will not be able to answer your request.

Be aware that some rights may not be enforceable due to business necessities or legal obligations while providing you with the Service. Your rights may be limited to comply with other legal obligations such as anti-money laundering, contractual and compliance obligations. Notwithstanding that you will always be responded to when exercising any of the rights stated above and/or any additional right you may have depending on your jurisdiction. If your rights can’t be enforced, you will always receive a proper explanation.

8. Privacy Complaints

If you have a complaint regarding our processing of your Personal Data, you may contact us at [email protected].

Depending on the applicable privacy law, you may have the right to make a complaint to a Data Protection Authority or other regulatory body if you believe we have failed to comply with our obligations under this Privacy Notice or the applicable law:

9. Regional Privacy Notices

9.1. Notice to European (EEA) residents.

In accordance with the General data protection Regulation (GDPR) and in addition to the rights state in section 15 above, all resident of the Economic European Area (EEA) may exercise the following rights:

  • Right to Access
  • Right to Correct Inaccuracies
  • Right to Deletion
  • Right to Restrict Processing

To exercise any of the rights listed above, you shall comply with the obligations set in section 15 of this Privacy Notice.

From the day we receive your request, we will respond to you within a maximum time of 30 days, unless an extension is requested.

9.2. Notice to New Zealand residents

To all resident in New Zealand, the rights you may exercise regarding the processing of your Personal Data are the following:

  • Right to Access
  • Right to Correct Inaccuracies
  • Right to Deletion
  • Right to Restrict Processing

To exercise any of the rights listed above, you shall comply with the obligations set in section 15 of this Privacy Notice.

From the day we receive your request, we will respond to you in a maximum time of 20 days.

9.3. Notice to Australian residents.

To all residents in Australia, the rights you may exercise regarding the processing of your Personal Data are the following:

  • Right to Access
  • Right to Correct Inaccuracies
  • Right to Deletion
  • Right to Restrict Processing

You may also ask us to explain our data policies and practices according to the applicable law.

From the day we receive your request, we will respond to you within a maximum time of 30 days.

10. Our companies by service

TABLE TBC

You can always submit a request to our Data Protection Officer by sending an email to the following address: [email protected].