01Who we are
Ribbonwise is a free gift-planning and product-discovery service at ribbonwise.app, operated by Patrick Godfrey. This policy explains the information we handle when you browse, sign in, create a gift list, answer an invitation, or contact us.
For privacy questions or requests, email patrickgodfrey@godfreyenterprise.com. This policy covers Ribbonwise, not the independent websites you visit through product links.
02Information we collect
- Account information: your email address, account identifier, sign-in information, and basic profile information supplied by your sign-in provider, such as your name and profile picture. Ribbonwise currently displays your name or email; a profile picture may be stored by the authentication provider even though Ribbonwise does not display it.
- Gift-list information: recipient name, optional email or phone number, relationship, occasion, budget, constraints, interview answers, generated summaries, recommendations, and related creation/completion information.
- Support reports: the description you submit, optional reply email, category, error code and reference, sanitized page identifier, basic browser/device type, status, and investigation notes. Reporting does not require sign-in. We do not automatically attach screenshots, gift answers, authentication tokens, or full private invitation links. Report descriptions can contain personal information you voluntarily include; keep sensitive details out.
- Product activity: when you use a product button, we record an event identifier, product, placement, affiliate flag, and timestamp. These click records do not include your account identity, email, IP address, or private gift-list URL. Technical logs are separate and may be processed as described below.
- Technical information: hosting, authentication, and security providers may process IP addresses, browser/device information, request details, cookies, timestamps, and error/security logs to deliver and protect the service.
Some recipient information comes from the organizer rather than the recipient. Only provide someone else’s details when you have a legitimate reason and permission where required. Use a first name or nickname when possible. Do not submit passwords, payment-card details, government identifiers, medical records, or other highly sensitive information. Describe practical gift preferences without unnecessary personal detail.
03Visitor map and first-party analytics
We measure page views, approximate network location, basic device/browser type, campaign tags, and gift-planning actions to understand how Ribbonwise is used. A private administrator dashboard shows aggregates such as top pages, campaign performance, and returning-browser estimates. We use random browser and session identifiers and store only hashes on the server. After verified sign-in, minimal activity events may carry an account hash. Authorized administrators can connect that hash to a separate account directory containing the verified name, email, and provider account timestamps to review sign-ins, saved gift-list counts, product views, retailer and affiliate clicks, and reliably recorded session sources. Anonymous events are not reassigned to an account. Account activity reports omit gift answers, recipient names, contact details, private list URLs, and authentication tokens. This information is used for operating Ribbonwise, not advertising targeting. A returning visitor means the same browser identifier was seen in an earlier session; it does not identify a person.
Invitation pages are recorded only as /invite, without the private access token. We omit query strings, fragments, private identifiers, and answer text. External referrers are reduced to a hostname; campaign reporting uses only standard UTM fields. Administration and analytics pages are excluded.
Hosting metadata provides approximate locations. When configured, MaxMind also receives your network address to estimate a network location if hosting coordinates are unavailable. Ribbonwise does not store raw IP addresses in visitor-map records or location diagnostics. Coordinates are rounded to one decimal place and are not a precise device or street location; VPNs and network routing can affect the estimate. Broad-area estimates are labeled separately from city-level estimates. Lookup diagnostics store only a general result, source, and estimate precision—not your network address. Browser geolocation permissions are not requested.
The browser identifier expires after 90 days. Visitor and event records are retained for up to 90 days, with expired records removed as new activity arrives. This first-party analytics honors Do Not Track and Global Privacy Control. It is separate from Google advertising. See MaxMind’s privacy policy.
Loading this browser’s analytics preference…
This controls new visitor analytics and Google sign-up conversion events on this browser. It does not delete existing records, block necessary sign-in cookies, or replace Google’s separate advertising choices.
04Google sign-in
Google sign-in is handled through Supabase. We request basic identity permissions: openid, email, and profile. These identify your account and allow us to associate your lists with you, display your name or email, and maintain a secure session. We do not request access to Gmail messages, Drive files, Calendar events, contacts, or payment information.
Supabase stores authentication records and provider profile information and handles sign-in tokens. Ribbonwise uses server-managed session cookies. Google identity information is not used to target advertising, sold to advertisers or data brokers, or sent to the gift-generation AI as account-profile input.
We handle Google account data in accordance with the Google API Services User Data Policy, including its Limited Use requirements where applicable.
You can remove Ribbonwise’s access through your Google account’s third-party connections. Removing that connection does not automatically delete information already stored by Ribbonwise or Supabase; contact us to request deletion. Email-code sign-in is handled through Supabase and our email-delivery provider, which process your email address and verification messages to authenticate you.
05How we use information
We use information to authenticate you, save and display your lists, run gift interviews, generate personalized suggestions, measure product-link activity, respond to support and privacy requests, troubleshoot problems, prevent abuse, and meet applicable legal obligations.
We do not sell personal information or use Google account data for advertising. Where applicable privacy law requires a legal basis, the relevant basis depends on the activity: providing a service you request, legitimate interests in operating and securing it, consent when required, or compliance with law. Consent can be withdrawn where it is the basis for processing; doing so may make the related feature unavailable.
06AI and your gift interview
Ribbonwise uses OpenAI’s API for answer feedback, follow-up questions, gift summaries, and product recommendations. Depending on the step, we send interview questions and answers, recipient name, occasion, budget, and organizer constraints. This may include answers marked for recommendation-only use in older lists. Those labels limit intended display, not AI processing.
Product recommendations may use OpenAI’s web-search tool. Search queries can be derived from your gift preferences and processed by OpenAI and its search infrastructure. Avoid including sensitive or identifying details that are not needed to choose a gift. AI processing is not a confidential professional relationship.
Our interview implementation stores some OpenAI responses to continue the conversation. Final recommendation requests disable response storage, but that does not eliminate all provider logging or retention. OpenAI’s standard documentation describes stored response state lasting at least 30 days and separate abuse-monitoring retention, with exceptions and account-specific controls. This is not a zero-retention service. See OpenAI’s API data controls for its current practices.
You do not need a ChatGPT account to use ordinary Ribbonwise sign-in. If you do not want interview information sent to the AI provider, do not start or submit a gift interview; you can still read the public homepage and these policies. There is currently no separate user-selectable AI opt-out mode. An optional legacy-list import uses the hosting platform’s verified ChatGPT identity solely to confirm ownership and transfer your old lists to your Ribbonwise account.
09Storage, retention, and security
Error incidents store codes, timestamps, sanitized operation/page identifiers, fallback status, and a small allowlist of provider status/code/request identifiers—not raw exception text, prompts, answers, cookies, or secrets. Support reports and incident records are restricted to authorized administrators. A transient hourly hash derived from the request’s network address limits report abuse; it is not attached to support reports, and expired counters are removed as new reports arrive. Hosting providers may separately process the underlying address.
When support-email notifications are configured, Resend processes the support recipient and a short notification containing the code, reference, category, and sanitized page. Report descriptions and reply addresses stay in the private dashboard and are not included in those notification emails. A provider accepting an email does not guarantee delivery to an inbox. See Resend’s privacy policy.
Gift lists and answers are stored in our hosted database; authentication records are stored separately by Supabase. Lists currently have no automatic expiration and remain until deleted or removed in response to a verified request. Product click records and aggregate performance reports are kept separately from private gift lists for product reporting and reconciliation; they currently have no automatic expiration. We retain support and operational information only as needed for the relevant support, security, or legal purpose. Provider logs and backups have their own retention cycles; we cannot promise every copy disappears immediately.
Deleting a gift list removes its active list and answer records. It does not by itself delete your Supabase account, previously processed AI responses, provider logs, backups, or copies kept by another person. Ask us for account deletion or broader assistance.
We use HTTPS, server-verified sign-in, restricted organizer access, and production HttpOnly session cookies. These measures reduce risk but cannot guarantee absolute security. Keep invitation links and sign-in codes private, sign out on shared devices, and report suspected access problems to us.
Providers may process information in the United States and other countries where they operate. Those countries may have different privacy protections. Where applicable law requires transfer safeguards, the relevant provider arrangements and safeguards must apply; we do not promise that all information stays in one country.
10Your choices and privacy requests
You can choose what to share, refine interview answers, sign out, and use the organizer dashboard’s delete action to remove a list you own. In Account settings, you can edit your Ribbonwise display name and request an email-address change; email changes require verification. These changes do not change your Google profile or the ownership of your saved gift lists. An invited recipient can contact us to request access, correction, or deletion of information about them, even without an account.
Email patrickgodfrey@godfreyenterprise.com to request account or personal-information access, correction, deletion, or a copy. Depending on your location and applicable law, you may also have rights to portability, restrict or object to processing, withdraw consent, appeal a decision, or complain to a privacy regulator. We will assess and respond under the law that applies to your request. We may need to verify your identity and relationship to a list; do not email passwords, tokens, or sign-in codes.
Account deletion and complete data export are currently handled by contacting us, not an automated button. Legal/security obligations can require retaining limited information. Copies already received by organizers or external providers are subject to their own obligations and controls.
11Age, updates, and contact
Ribbonwise’s initial service is intended for adults aged 18 or older and is not directed to children. Do not create accounts or submit personal information about children through gift interviews. If you believe a child has supplied personal information, contact us so we can investigate and take appropriate action. A stated age restriction is not a guarantee of age verification.
We will update the date at the top when this policy changes. Material changes will be brought to users’ attention through an appropriate site notice or other communication, with consent requested where required. New Google-data uses will not begin without the required disclosure and authorization.
Privacy contact: Patrick Godfrey, Ribbonwise — patrickgodfrey@godfreyenterprise.com.
