← Back to KlausPicks

Privacy Policy

Effective 5 May 2026  ·  Last updated 5 May 2026

1. Data Controller

The data controller responsible for the personal data processed through klauspicks.com is:

ROȘATĂ PATRICIU PERSOANĂ FIZICĂ AUTORIZATĂ

CUI (Tax ID): 47322797

VAT ID: RO49762921

Registration: F40/6397/2022

Address: Bd. Bucureștii Noi 136, et. Parter, ap. 5, Sector 1, București, Romania

Privacy contact: privacy@klauspicks.com

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have under the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data We Collect

We collect different categories of personal data depending on how you interact with the platform:

A. Account Registration

  • Email address
  • Display name (optional — may be your first name or a chosen handle)
  • Password (stored as a secure hash — we never have access to your plaintext password)
  • Account creation date and last sign-in timestamp

B. Secret Santa Events

  • Event name, date, budget, and settings configured by the organiser
  • Participant names and email addresses (provided by the event organiser — see Section 4 for the lawful basis)
  • Secret gift assignment pairs (stored encrypted in our database)
  • Email delivery status and interaction logs (sent, opened, bounced) via our email provider

C. Wishlists

  • Wishlist name, occasion type, event date (if set)
  • Item names, URLs, notes, priority, and price (entered by the wishlist owner)
  • Claim records — when a guest claims an item, we store the claim status and an anonymous browser-generated identifier (not linked to a real identity unless the claimant is logged in)
  • Wishlist view counts and timestamps (aggregate analytics)

D. Usage & Analytics Data

  • IP address (processed by Google Analytics — not stored in our own database beyond server access logs, which are retained for 30 days)
  • Browser type, device type, operating system
  • Pages visited, referral source, session duration
  • Clicks on affiliate product links (via our own click-tracking endpoint)

E. Support & Contact Communications

  • Any data you voluntarily provide when contacting us (name, email, message content)

F. Guest Visitors (No Account)

  • A randomly-assigned reindeer name stored in your browser's local storage (e.g., "Dasher") — used only to display your anonymous identity to other viewers of the same wishlist in real time. This data never leaves your device unless you are actively viewing a shared wishlist.

3. How We Use Your Data

  • Providing the Service — creating and managing your account, running Secret Santa draws, sending reveal emails, displaying wishlists.
  • Transactional emails — sending Secret Santa reveal notifications, event invitations, and any transactional messages you explicitly trigger.
  • Analytics and improvement — understanding how the platform is used so we can fix bugs and improve the experience (via Google Analytics / Google Tag Manager).
  • Affiliate tracking — recording clicks on affiliate product links to attribute commissions. No personal data is sent to affiliate networks; only anonymous click identifiers and product identifiers are used.
  • Security and fraud prevention — detecting abuse of the platform, preventing spam, and protecting users.
  • Newsletter / marketing — only if you have explicitly opted in (see Section 11).
  • Legal compliance — meeting obligations under Romanian and EU law.

We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.

5. Third-Party Processors & Services

We use the following third-party services. Each is bound by a Data Processing Agreement (DPA) and appropriate transfer safeguards where applicable:

Supabase

Purpose: Database, authentication, real-time presence, file storage

Location: EU (AWS eu-central-1, Zurich, Switzerland)

All primary user data is stored within the EU/EEA. Supabase DPA is in place.

Resend

Purpose: Transactional email delivery (Secret Santa reveals, invitations, notifications)

Location: United States

Data transfer covered by Standard Contractual Clauses (SCCs). Resend only processes email addresses and message content strictly for delivery.

Google Analytics 4 / Google Tag Manager

Purpose: Web analytics, traffic analysis, user behaviour measurement

Location: United States

Activated only with user cookie consent. IP anonymisation enabled. Data transfer covered by SCCs and Google's EU-US Data Privacy Framework certification.

Google Search Console / Bing Webmaster Tools

Purpose: Search engine indexing and performance monitoring (no personal user data sent)

Location: United States / Global

No personal data of platform users is shared with these tools.

Buy Me a Coffee

Purpose: Optional voluntary donation processing

Location: United States

An independent third-party platform. Only users who click the donation button interact with Buy Me a Coffee. Their privacy policy governs any data they collect.

6. Data Retention

We retain personal data only as long as necessary for the stated purpose:

User account dataUntil account deletion request, then 30 days for recovery, then permanently deleted
Event data (organiser + participants)3 years from date of last activity on the event, then permanently deleted
Wishlist dataUntil the user deletes the wishlist, or 2 years after the last update if the account is inactive, then permanently deleted
Email delivery logs6 months, then deleted
Analytics data (Google Analytics)26 months (Google Analytics 4 default retention), aggregated only
Server access logs (IP addresses)30 days, then automatically purged
Cookie consent logs3 years (to demonstrate compliance)
Affiliate click records13 months (standard affiliate attribution window), anonymised thereafter
Support correspondence3 years from last contact, or as required by law

You may request early deletion of your personal data at any time (see Section 8). Note that certain data may be retained beyond the above periods if required by a legal obligation (e.g., Romanian accounting law requires retaining financial records for 10 years).

7. International Data Transfers

Your primary data is stored in the European Union (Supabase / AWS eu-central-1, Zurich, Switzerland). Switzerland is recognised by the European Commission as providing an adequate level of data protection.

Some of our processors (Resend, Google) are based in the United States. We ensure appropriate safeguards are in place for any transfers of personal data to these processors, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Implementing Decision (EU) 2021/914).
  • Where applicable, reliance on the EU-US Data Privacy Framework for certified US organisations.

You may request a copy of the relevant transfer safeguards by contacting us at privacy@klauspicks.com.

8. Your Rights Under GDPR

If you are located in the EU/EEA, you have the following rights under the General Data Protection Regulation:

Right of Access (Art. 15)

Request a copy of the personal data we hold about you.

Right to Rectification (Art. 16)

Request correction of inaccurate or incomplete personal data.

Right to Erasure (Art. 17)

Request deletion of your personal data ('right to be forgotten'), subject to legal retention obligations.

Right to Restriction (Art. 18)

Request that we restrict processing of your data in certain circumstances.

Right to Data Portability (Art. 20)

Receive your personal data in a structured, machine-readable format and, where technically feasible, have it transferred to another controller.

Right to Object (Art. 21)

Object to processing based on legitimate interests, including profiling. You may also object to direct marketing at any time.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at privacy@klauspicks.com. We will respond within 30 days. Identity verification may be required before we process the request.

You also have the right to lodge a complaint with the competent supervisory authority. In Romania, this is:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)

Bd. G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 București, Romania

Website: dataprotection.ro

Phone: +40.318.059.211

9. Children's Privacy

The Service is not directed to children under 13 years of age (or 16 for EU residents), and we do not knowingly collect personal data from children below these thresholds without verifiable parental consent.

If you are a parent or guardian and believe your child has provided personal data to us without appropriate consent, please contact us at privacy@klauspicks.com and we will delete that information as soon as practicable.

Note that children may appear as participants in family Secret Santa events organised by an adult. In such cases, the adult organiser is responsible for ensuring that sharing the child's name and email (if applicable) is appropriate and compliant with parental responsibility obligations.

10. Cookies

We use cookies and similar technologies on our website. For full details, please read our Cookies Policy.

In summary, we use:

  • Essential cookies — required for authentication and security (Supabase session tokens). These cannot be disabled.
  • Analytics cookies — Google Analytics 4 cookies (_ga, _gid, etc.) activated only with your explicit consent via our cookie banner.
  • Functional local storage — a randomly-assigned anonymous reindeer name stored in your browser's local storage for the wishlist viewer presence feature.

You can manage your cookie preferences at any time via the cookie settings button in the footer, or through your browser settings.

11. Newsletter & Marketing Communications

We may send marketing communications (newsletter, product updates, gift inspiration content) to users who have explicitly opted in.

Our newsletter subscription process uses a double opt-in mechanism: you submit your email address, receive a confirmation email, and must click a confirmation link before you are added to our mailing list. This ensures your consent is unambiguous.

Key newsletter commitments:

  • You may unsubscribe at any time by clicking the unsubscribe link in any email or by contacting privacy@klauspicks.com. Unsubscribe requests are processed within 3 business days.
  • Newsletter emails are sent via Resend (and may in future be sent via Mailchimp or a similar marketing platform — we will update this policy if we switch providers).
  • We do not sell or share your email address with any third party for their own marketing purposes.
  • Newsletter subscription is entirely independent of your use of the Secret Santa or wishlist features. Declining to subscribe does not affect any functionality.

Newsletter recipients may include users worldwide. We apply the same GDPR-compliant consent and opt-out standards to all subscribers regardless of their location.

12. Changes to This Policy

We may update this Privacy Policy periodically. When we do, we will update the "Last updated" date at the top of this page. For material changes that affect your rights, we will make reasonable efforts to notify registered users via email.

Your continued use of the Service after any changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.

13. Contact & Complaints

For any privacy-related questions, requests, or complaints, please contact our privacy point of contact:

Privacy Contact — KlausPicks

Email: privacy@klauspicks.com

Postal: ROȘATĂ PATRICIU PFA, Bd. Bucureștii Noi 136, et. Parter, ap. 5, Sector 1, București, Romania

Response time: within 30 calendar days.

If you are not satisfied with our response, you have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP) — see Section 8 above.

✉️ SEND A LETTER TO KLAUS

Have a feature request or just want to spread some cheer? Our inbox is always open.

Drop Us A Line