Privacy Policy
How we handle personal information — for the businesses that sell vouchers with us, for the people who buy and receive them, and for anyone visiting the site.
1. Who we are
eVoucher.gift is operated by Sumo Monkey Development Ltd, registered in England and Wales, of 9 West Street, Congleton CW12 1JN, United Kingdom. For privacy questions, subject access requests or anything else in this policy, write to [email protected] or to that address.
Our supervisory authority is the Information Commissioner's Office (ICO), the UK's data protection regulator. If you are unhappy with how we have handled your information you can complain to the ICO at ico.org.uk — though we would rather you told us first, so we can fix it.
2. The two roles we play
eVoucher.gift is a platform: independent businesses use it to sell their own gift vouchers. That means we handle personal data in two different capacities, and which one applies changes who is answerable for it.
- As controller. For merchant account holders and their staff, for people who enquire about the product, and for visitors to eVoucher.gift itself, we decide why and how the data is used. This policy is our privacy notice to you.
- As processor. For the customer data inside a merchant's account — buyers, recipients, orders, vouchers and redemptions — the merchant is the controller and we act on their instructions. Their own privacy notice governs what they do with it. We handle it only to run the shop, deliver the vouchers and keep the records the merchant needs. The processing terms are in the annex.
If you bought a voucher and want your data deleted or corrected, ask the business you bought it from. If you ask us, we will pass the request on and help them action it.
3. Information about merchants
When a business registers and uses the Platform, we hold:
- Account details — name, email address, password (stored only as a salted hash), two-factor authentication settings and recovery codes, and the users you invite into your account with their roles.
- Business details — trading name, shop address and slug, contact details, country, logo and brand assets, billing address and VAT number.
- Billing records — plan, subscription payments, invoices, transaction fees, and the card brand and last four digits of a card used to pay us (nothing more of the card).
- Payment-connection data — your Stripe connected account identifier and the onboarding and capability status Stripe reports back to us. Identity documents you give Stripe go to Stripe, not to us.
- Usage and technical data — sign-in times, IP address, browser and device information, pages and actions in the app, and application logs and error diagnostics.
- Correspondence — support emails and anything else you send us.
4. Information about buyers and recipients
When someone buys a voucher from a merchant's shop, we process the following on that merchant's behalf:
- Buyer details — name, email address, and the order: what was bought, the amount, the currency, the time, and Stripe's payment reference.
- Recipient details — the recipient's name and email address, the gift message written to them, and any delivery date chosen.
- Voucher records — the voucher code, its value and remaining balance, expiry date, and the record of redemptions, including when and by which merchant user it was redeemed.
- Delivery records — that a voucher email or receipt was sent, and any failure reported back to us (for example a bounced address), so the merchant can put a wrong address right.
- Technical data — IP address and browser information captured in server logs when a shop page or voucher wallet page is loaded, used for security and fraud prevention.
We do not use buyer or recipient data for our own marketing, we do not build profiles across merchants, and we do not sell or rent it to anyone.
5. Information about website visitors
If you just browse eVoucher.gift, we process the technical data described under cookies — pages viewed, referrer, approximate location derived from IP address, device and browser type — through our own server logs and Google Analytics. If you type your website address into the shop-preview tool on the home page, we process that address and the public content of the pages we fetch from it (see AI-assisted features).
6. Why we use it, and our legal basis
| What we do | Legal basis (UK GDPR) |
|---|---|
| Create and run merchant accounts; provide the designer, storefront and voucher tools | Performance of our contract with the merchant |
| Take subscription payments, charge transaction fees, issue invoices | Contract; legal obligation (tax and accounting records) |
| Process voucher orders, issue and deliver vouchers, record redemptions | On the merchant's instructions as their processor — the merchant's own basis, normally contract with the buyer |
| Send transactional emails (voucher delivery, receipts, expiry reminders, service notices) | Contract; legitimate interests in keeping people informed about something they bought |
| Keep the Platform secure; prevent, detect and investigate fraud and abuse; enforce our terms | Legitimate interests in protecting the Platform, merchants and buyers; legal obligation |
| Support, troubleshooting and correspondence | Contract; legitimate interests in running a supported service |
| Analytics, product improvement and aggregate statistics | Legitimate interests in understanding and improving the service; consent where cookies require it |
| Marketing emails to merchants and prospects about our own product | Consent, or legitimate interests where we are contacting an existing customer about a similar service — you can opt out at any time |
| Complying with legal requests, disputes, chargebacks and regulatory duties | Legal obligation; legitimate interests in establishing or defending legal claims |
Where we rely on legitimate interests, we have considered the impact on you and are satisfied the processing is not overridden by your rights. You can ask us for our assessment.
7. Payments — what we never see
Card payments for voucher sales are taken by Stripe directly on the merchant's own connected account, and payments to us for subscriptions are also taken by Stripe. A small number of older merchant shops take payment through PayPal instead.
Full card numbers, CVC codes and bank credentials are entered on the payment provider's pages and are never received or stored by us. What comes back to us is the outcome: a payment identifier, the amount, the status and, for cards saved to pay us, the brand and last four digits. Stripe and PayPal are independent controllers of the payment data they hold, under their own privacy policies (stripe.com/gb/privacy, paypal.com privacy statement).
8. AI-assisted features
Two parts of the Platform use Google's Gemini models, through Google's generative language API:
- Shop preview. If you enter a website address, we fetch that site's public pages and send extracted text, colours and imagery to the model to compose a suggested shop design.
- Voucher designer. Prompts, brand colours and images you supply may be sent to the model to generate or adapt design artwork.
We send only what the feature needs. Do not paste customer personal data or confidential information into design prompts — it is not needed and we ask you not to. Output is a suggestion: check it before you publish or send it. Google processes this content under its API terms as our sub-processor and, for paid API use, does not use it to train its general models.
9. Emails we send
Voucher emails, receipts, expiry reminders and account notices are sent through Twilio SendGrid. Voucher and receipt emails are sent on the merchant's behalf and show the merchant's branding; the merchant chooses when they go out. Service emails about your own account (security alerts, billing, changes to these policies) are not marketing and cannot be opted out of while you hold an account. Marketing emails from us always carry an unsubscribe link.
11. Where your information is held
The Platform's database and file storage are hosted in the United Kingdom. Some of our providers process data outside the UK, including in the United States. Where they do, the transfer is protected by an adequacy decision, or by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with additional safeguards where needed. You can ask us for details of the safeguards that apply to a particular provider.
12. How long we keep it
- Merchant accounts — while the account is open. After closure we keep the data available for export for 30 days, then delete or anonymise it, except as below.
- Orders, invoices and payment records — six years after the end of the relevant financial year, because tax law requires it.
- Vouchers and redemption records — while the voucher can still be redeemed, and then as part of the merchant's order records above. A merchant may instruct us to delete individual customer records sooner where no legal or accounting reason to keep them applies.
- Server and security logs — typically 30 to 90 days, longer where a specific security or fraud investigation requires it.
- Analytics data — for the retention period set on our Google Analytics property (14 months by default).
- Support correspondence — up to two years after the matter is closed.
- Backups — deleted data can persist in encrypted backups until they age out of their normal cycle, and is restored only in a disaster-recovery scenario.
13. Security
All traffic to the Platform is encrypted in transit with TLS. Data is stored on managed, access-controlled infrastructure with encryption at rest. Passwords are stored only as salted hashes, never in a readable form. Two-factor authentication is available to every account and required for platform administrators. Access to production data is limited to the people who need it, and merchant data is separated by account and filtered on every query.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the ICO within 72 hours and tell affected people where the law requires it. Where we act as a merchant's processor, we will notify that merchant without undue delay so they can meet their own obligations.
14. Your rights
Under UK data protection law you have the right to: be told how your data is used; get a copy of it; have inaccurate data corrected; have data erased in some circumstances; restrict or object to processing, including objecting to processing based on legitimate interests and to direct marketing at any time; receive data you gave us in a portable format; and withdraw consent where we relied on it, without affecting what was done beforehand. You are not subject to any decision with legal or similarly significant effects made solely by automated means.
To exercise a right, email [email protected]. We will respond within one month and may ask for information to confirm your identity. There is no charge unless a request is manifestly unfounded or excessive.
If your data is held inside a merchant's shop — because you bought or received a voucher — the merchant is the controller and the request is properly made to them. Tell us anyway if you cannot reach them: we will forward it and support them in dealing with it.
16. Children
The Platform is intended for adults. We do not knowingly collect data from children under 13, and merchant accounts may only be held by people aged 18 or over. If you believe a child's data has reached us, tell us and we will delete it.
17. Changes to this policy
We update this policy as the Platform and the law change. The version in force is always published here with its date. For changes that materially affect merchants — new sub-processors, new purposes — we will give notice by email or in the app before they take effect.
Annex — processing on behalf of merchants
This annex is the data processing agreement required by Article 28 of the UK GDPR between the merchant (controller) and Sumo Monkey Development Ltd (processor). It forms part of our Terms of Service and applies whenever we process personal data on a merchant's behalf.
- Subject matter and duration. Provision of the eVoucher.gift platform, for as long as the merchant's account is open, plus the retention periods in section 12.
- Nature and purpose. Hosting, storing, organising, transmitting, rendering and deleting data so the merchant can sell, issue, deliver, redeem and account for gift vouchers.
- Types of personal data. Names, email addresses, gift messages, order and payment references, voucher codes, balances and redemption records, delivery outcomes, and technical data such as IP addresses in server logs.
- Categories of data subject. The merchant's buyers, voucher recipients, and the merchant's own staff users.
- Our obligations. We process personal data only on the merchant's documented instructions (which include the instructions inherent in using the Platform's features) unless the law requires otherwise, in which case we will tell the merchant unless prohibited. We ensure people authorised to process it are bound by confidentiality; take the technical and organisational measures described in section 13; assist the merchant, at their cost where the assistance is substantial, with data subject requests, breach notification, impact assessments and consultations with the ICO; and make available the information needed to demonstrate compliance, allowing audits by the merchant or an auditor they mandate, on reasonable notice, no more than once a year unless a breach or regulator requires more.
- Sub-processors. The merchant gives general authorisation for the sub-processors listed in section 10. We impose equivalent obligations on each of them and remain responsible for their performance. We will give notice before adding or replacing a sub-processor; a merchant who reasonably objects on data protection grounds may terminate their account without penalty for the unused portion of any prepaid period.
- Transfers. Transfers outside the UK are made on the safeguards described in section 11.
- Breach. We notify the merchant without undue delay after becoming aware of a personal data breach affecting their data, with the information they need to meet their own obligations.
- Deletion and return. On termination, the merchant can export their data. After the 30-day export window we delete or anonymise the personal data, except copies we must keep by law or that remain in backups until those age out.