← Back to Home

Cookie Policy

Effective Date: April 1, 2026  ·  Last Updated: June 2, 2026  ·  Jurisdiction: Ontario, Canada

We value your privacy. This Cookie Policy explains what cookies and similar local storage technologies are used on the SYNC-Gift web platform and mobile app, why we use them, and how you can control your preferences at any time. It should be read alongside our Privacy Policy.

Table of Contents

  1. What Are Cookies and Similar Technologies?
  2. Who Sets Cookies?
  3. Categories of Cookies We Use
  4. Cookies in Use — Full Reference Table
  5. Local Storage and Session Storage
  6. Server-Side Logging and Cookies
  7. Mobile App — No Browser Cookies
  8. How to Manage Your Preferences
  9. Global Privacy Control (GPC)
  10. Do Not Track (DNT)
  11. Third-Party Cookie Policies
  12. Cookie Consent for Minors
  13. Changes to This Policy
  14. Contact Us

1. What Are Cookies and Similar Technologies?

Cookies are small text files placed on your device (computer, tablet, or phone) when you visit a website. They allow the site to recognise your device, remember your settings, and provide a consistent experience across sessions.

Similar technologies include:

Throughout this policy, "cookies" refers collectively to all of the above technologies where the context applies.

2. Who Sets Cookies?

First-party cookies and storage are set directly by SYNC-Gift Inc. (sync-gift.com) to operate the platform, maintain your logged-in state, and remember your preferences.

Third-party cookies are set by service providers we use:

✓ No advertising or retargeting cookies

SYNC-Gift does not use Google Analytics, Facebook Pixel, or any third-party advertising network cookies. We do not share cookie data with data brokers or ad exchanges.

3. Categories of Cookies We Use

3.1 Strictly Necessary Cookies

These are essential for the platform to function. They are set in response to actions you take — logging in, processing a payment, or recording your consent choice. These cannot be disabled without breaking core functionality.

Legal basis (GDPR): Legitimate interests / contract performance. No consent required — these are operationally essential.

Legal basis (PIPEDA): Collected for purposes a reasonable person would consider appropriate to the service.

3.2 Preference / Functional Cookies

These remember choices you make to personalise your experience — currency selection, display theme, and regional settings. Disabling them does not prevent access to the platform but may reset your preferences on each visit.

Legal basis: Consent (GDPR Art. 6(1)(a)). You may withdraw consent at any time via Consent Preferences.

3.3 Analytics / Performance Cookies

SYNC-Gift uses internal, first-party analytics only — aggregated server-side request logs generated by our application server. We do not use Google Analytics, Mixpanel, Hotjar, or any third-party analytics platform that tracks individual users across sites.

Our server logs capture: URL path (not query string — tokens and sensitive params are automatically stripped), HTTP method, response status code, and response time. These logs are retained for 12 months and are used solely for performance monitoring, error diagnosis, and capacity planning. They do not identify individual users.

Legal basis: Legitimate interests (GDPR Art. 6(1)(f)) — platform stability and security. These are server-side logs and not browser cookies.

3.4 Marketing / Targeting Cookies

SYNC-Gift does not currently deploy any marketing or targeting cookies. We do not run retargeting campaigns, cross-site behavioural advertising, or sell advertising inventory. No advertising network cookies are set on our platform.

If this changes in the future, we will update this policy with at least 14 days' advance notice, and explicit opt-in consent will be collected before any marketing cookies are activated.

4. Cookies in Use — Full Reference Table

This table reflects all known cookies and storage keys as of the Last Updated date. The Termly consent scanner audits this list continuously and will update it if new cookies are introduced. No marketing or analytics third-party cookies are present.

5. Local Storage and Session Storage

Our web platform is a single-page application (SPA). In addition to browser cookies, it uses the browser's localStorage API to store:

What is NOT stored in localStorage or cookies: your PIN, any biometric data, raw payment card details, wallet transaction history, or gift messages. These are held server-side only and transmitted over HTTPS.

You can clear localStorage at any time via your browser's developer tools (Application → Local Storage → sync-gift.com → Clear). This will log you out.

6. Server-Side Logging and Cookies

Our application server generates structured request logs using industry-standard logging. These logs are used strictly for security monitoring, error diagnosis, and platform health — not for building user profiles or advertising.

Our logging configuration automatically:

Server logs do not contain raw email addresses, phone numbers, gift claim tokens, QR codes, wallet balances, or payment details. Server logs are retained for 12 months and then deleted automatically.

7. Mobile App — No Browser Cookies

The SYNC-Gift mobile application (iOS and Android, built with React Native / Expo) does not use browser cookies. It uses two platform-native storage mechanisms:

Mobile storage is governed by your device's operating system privacy controls. You can clear all app data by uninstalling the SYNC-Gift app. Biometric authentication data (Face ID / Touch ID) is handled entirely by the OS-level biometric framework and is never transmitted to or stored by SYNC-Gift.

8. How to Manage Your Preferences

8.1 Termly Consent Manager (Recommended)

The easiest way to review and update your cookie choices is to click "Consent Preferences" in the footer of any page on our website. The Termly panel allows you to enable or disable each category individually (except Strictly Necessary). Your choices are saved and respected on all future visits for up to one year.

8.2 Browser Settings

You can also manage cookies directly in your browser. Note that blocking Strictly Necessary cookies (session, Stripe, Termly consent) will prevent you from logging in or completing payments.

8.3 Clearing localStorage

To clear SYNC-Gift's localStorage (which will log you out):

8.4 Stripe Cookie Opt-Out

Stripe's fraud-prevention cookies are set during payment flows and are operationally necessary for secure transaction processing. If you do not wish Stripe to set these cookies, you will not be able to use card payment features. You can review Stripe's cookie usage at stripe.com/privacy.

9. Global Privacy Control (GPC)

SYNC-Gift honours the Global Privacy Control (GPC) signal for users in California and other jurisdictions where GPC is recognised as an opt-out of sale/sharing of personal data. When your browser sends a GPC signal to our platform, we treat it as a request to:

Note: because SYNC-Gift does not engage in advertising or sell personal data, GPC signals have no practical effect beyond disabling functional cookies. Your session authentication (localStorage sync-session) is required for login and is not affected by GPC as it is operationally necessary.

GPC-compatible browsers include Brave, DuckDuckGo, Firefox (with privacy extensions), and others that implement the GPC specification at globalprivacycontrol.org.

10. Do Not Track (DNT)

Some browsers transmit a "Do Not Track" (DNT) HTTP header. Because there is no universally accepted standard defining how websites should respond to DNT, and because SYNC-Gift already does not engage in cross-site tracking or advertising, we do not alter our data practices specifically in response to DNT signals. You can use the Consent Preferences tool (Section 8.1) or browser settings (Section 8.2) to control non-essential cookies at any time regardless of DNT.

11. Third-Party Cookie Policies

Where third-party cookies are used on our platform, those parties operate under their own privacy policies and cookie notices. We are not responsible for their content or practices.

SYNC-Gift does not use Google Analytics, Facebook, TikTok, Twitter/X, LinkedIn, or any other advertising or analytics network cookies. If you see cookies from those providers in your browser on our site, please report them to privacy@sync-gift.com so we can investigate.

12. Cookie Consent for Minors

Our Services are intended for users aged 18 and over. We do not knowingly collect data from or set tracking cookies for anyone under 18. If you are under 18, please do not use the SYNC-Gift web platform. If you believe a minor has accessed the platform, please contact privacy@sync-gift.com.

13. Changes to This Cookie Policy

We may update this Cookie Policy from time to time to reflect changes in technology, regulation, or our services. The "Last Updated" date at the top of this page reflects the most recent revision. We will notify you of material changes — including the introduction of any new cookie categories or new third-party providers — by:

We will not introduce marketing or advertising cookies without presenting you with a fresh explicit opt-in consent request.

14. Contact Us

If you have questions about this Cookie Policy, want to exercise your privacy rights, or believe cookies are being used inconsistently with this policy:

We aim to respond to all cookie-related enquiries within 2 business days.