Privacy Policy
How we handle your personal data.
Last updated: July 2026
1. Data controller
The data controller for personal data is Bussolari Alessio, based at Via del Prete 123, 47841 Cattolica (RN), Italy.
For any request related to the protection of personal data, you can contact us at info@presentfor.me.
For any request related to the protection of personal data, you can contact us at info@presentfor.me.
2. Personal data collected
We collect different categories of personal data necessary for the operation of the platform.
Account data
Account data
- Name
- Email address
- Date of birth (optional)
- Username
- Profile picture
- Preferred language
- Password hash (bcrypt)
- Session tokens
- API tokens
- IP address and browser user agent
- Recipient name, street, city, postal code, country
- Notification preferences for each type of activity
- Token used to deliver push notifications, and device platform
- Friendships and friend requests
- Invitations sent and received
- Gift names, descriptions, prices, URLs, and categories
- Reservations
- Notes and comments for gift givers
3. Automatically collected tracking data
In addition to data you provide directly, we automatically collect:
- Session data: access logs, session duration, pages visited
- Commercial clicks: clicks on links to partner sites for affiliate tracking
- Administrative logs: administrator actions for security and audit purposes
4. Purposes and legal basis
We process your personal data in accordance with Art. 6(1) of the GDPR, based on the following legal grounds:
Performance of contract (Art. 6(1)(b))
Performance of contract (Art. 6(1)(b))
- Account creation and management
- Provision of the wishlist, sharing, and gift reservation services
- Sending service-related notifications (reservations, invitations)
- Handling support requests
- Analytical cookies
- Push notifications on your device
- Sending promotional communications
- Platform improvement through aggregate analysis
- Fraud and abuse prevention
- Service security
- Data retention required by tax and accounting regulations
- Responding to requests from competent authorities
5. Cookies
For detailed information about the cookies used by the platform, their purposes, and how to manage them, please refer to our Cookie Policy available on the dedicated page of the site.
6. Third-party services
To operate the platform, we use the following third-party services that may process your data:
- Google Analytics (Google LLC) — Web traffic analysis, activated only with cookie consent
- Sentry (Functional Software Inc.) — Application error and performance monitoring
- Resend (Resend Inc.) — Sending transactional emails (notifications, confirmations, password resets)
- Amazon Web Services S3 (Amazon Inc.) — Storage of files and images uploaded by users
- Affiliate partners (e.g., Amazon) — Click tracking on product links for the affiliate program
7. International data transfers
Some of our service providers (Google, Amazon, Sentry, Resend) are based in the United States. Data transfers to the US are carried out on the basis of:
- EU-US Data Privacy Framework for certified providers
- Standard Contractual Clauses (SCCs) approved by the European Commission
8. Data retention period
We retain your data for the time strictly necessary for the purposes for which they were collected:
- Account data: until account deletion, plus 30 days for permanent removal
- Session data and logs: 30 days
- Analytics data: 24 months
- Support requests: 12 months after closure
- Affiliate data: according to partner program terms
- Backups: 90 days, then automatically deleted
9. Data subject rights
Under Articles 15-22 of the GDPR, you have the right to:
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) at www.garanteprivacy.it if you believe that the processing of your data violates the GDPR.
- Access (Art. 15): obtain confirmation of processing and a copy of your data
- Rectification (Art. 16): correct inaccurate or incomplete data
- Erasure (Art. 17): request deletion of your data ("right to be forgotten")
- Restriction (Art. 18): restrict processing in certain circumstances
- Portability (Art. 20): receive your data in a structured, machine-readable format
- Objection (Art. 21): object to processing based on legitimate interest
- Withdrawal of consent (Art. 7): withdraw consent at any time
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) at www.garanteprivacy.it if you believe that the processing of your data violates the GDPR.
10. Children's data
PresentForMe is intended for users aged 16 years or older. We do not knowingly collect personal data from children under 16. If a parent or guardian discovers that a minor has provided personal data without consent, they can contact us at info@presentfor.me to request its deletion.
11. Data security
We adopt technical and organizational measures to protect your personal data:
- Password encryption: passwords are protected with bcrypt (irreversible hashing)
- HTTPS: all communications are encrypted with TLS
- CSRF protection: anti-forgery tokens on every request
- Rate limiting: API request throttling to prevent abuse
- Revocable tokens: sessions, API tokens, and sharing links can be revoked at any time
12. Changes to the privacy policy
We reserve the right to update this policy to reflect changes in our practices or for regulatory compliance. In case of substantial changes, we will inform you via:
- Notice on the platform
- Email to the address associated with your account
13. Contact
For any question, request, or report related to the protection of your personal data:
Email: info@presentfor.me
Website: www.presentfor.me
Email: info@presentfor.me
Website: www.presentfor.me