Skip to content

Privacy Policy

This Privacy Policy explains how Little Promises (“Little Promises”, “we”, “us”), operated by Little Promises, handles information when you create, send, open, or redeem a coupon book.

Who we are, and who this applies to

The data controller is Little Promises, established in Sweden. For any privacy question or request, contact us at hello@littlepromises.shop.

Little Promises is available worldwide, and this policy applies to everyone who uses it. The baseline we apply to all users is the European standard: we collect only what the service needs, we tell you what we do with it, and we honour requests to see, correct, export, or delete your information wherever you live. Some regions grant additional specific rights, and those are set out under Your rights.

If someone made a book for you

A coupon book contains a recipient’s first name, and sometimes a personal note, written by the sender rather than by the recipient. If a book was made for you and you would like it corrected or deleted, email hello@littlepromises.shop — you do not need the sender’s permission, and you do not need an account with us. Quote the secret code if you have it, as that is how we locate a book.

Information we collect

Information you give us

  • Gift content — the recipient and sender names, the occasion, your written note, the promises you add, the selected language, theme, cover choices, and whether a promise has been redeemed or kept.
  • Cover images — if you upload a premium cover image, we store the image file so it can be shown to the recipient.
  • Payment information — when you buy a premium gift, your card details are entered directly with our payment processor, Stripe. We never see or store your full card number. We retain a Stripe identifier, the payment status for the gift, and the email address you give Stripe at checkout, which we use to send your receipt and the link back to your gift.
  • Your email address, if you ask us to save your book — the share screen offers to email you your gift’s code, its share link and your private edit link, because otherwise those live only in the browser you built the book in. We store the address so we can send that email and honour any later request about it. If you additionally tick the optional box on that screen, we keep the address to send you occasional product updates, and we record the date you agreed. That box is never pre-ticked, the email is sent whether or not you tick it, and you can unsubscribe from any update we send.
  • Delivery details, if you order a printed book — to post you a physical hardback we need somewhere to post it. Stripe collects your name, postal address, phone number and email address at checkout and passes them to us, and we store them against your order. The phone number is there because couriers ask for one when a delivery fails; we do not call you.
    We pass these details to Lulu, the print-on-demand company that prints, binds and posts the book — they cannot send you a parcel without them. The book itself, including your recipient’s name and the promises you wrote, is also sent to them as a print file, because that is what gets printed.
  • Support messages — if you contact us, we process the information you send so we can respond.

Information we collect automatically

  • Technical and security data — IP address, request metadata, and rate-limit counters used to operate the service, prevent abuse, and troubleshoot errors.
  • Local storage — we store small items in your browser (a private creator token for gifts you create, your in-progress draft, your sent and received coupon-book lists, and your cookie-notice choice) so you can manage and re-open gifts. This stays on your device. See Cookies & local storage.
  • Analytics data — we use Vercel Web Analytics for aggregated page view statistics, such as page URL, referrer, approximate location, device type, browser, and operating system. We do not use analytics for advertising or cross-site tracking. A gift’s secret code travels in the page address, so we remove it before the page view is recorded — gift codes, private edit tokens and checkout session identifiers are never sent to analytics.

How we use your information

  • To create, deliver, and let recipients open and redeem coupon books.
  • To process premium payments and provide proof of purchase.
  • To keep the service secure and prevent fraud and abuse.
  • To respond to your support requests.
  • To understand basic usage and improve the service.
  • To meet legal, tax, accounting, and dispute-resolution obligations.

Legal bases

Where the EU GDPR, UK GDPR, or Swiss FADP applies, we rely on: performance of a contract to provide the gift service and process purchases; legitimate interests to secure, debug, and improve the service; legal obligations for records we must keep; and consent where we ask for it.

Two of those deserve a note. The recipient’s name and any note about them are provided by the sender, not by the recipient — we process them on the legitimate interest of delivering a gift that someone chose to send, and the recipient can ask us to change or remove them at any time. Analytics also runs on legitimate interests, and you can turn it off from the notice at the bottom of the page or by clearing the lp-cookie-consent item in your browser storage.

Consent is what we rely on for product-update emails, and only those. Emailing you your own book is not consent-based — you asked us to send it, so it is part of providing the service. Withdrawing consent to updates is one click in any update we send, and it does not stop us answering a support message or sending a receipt for something you bought.

Who we share information with

We do not sell your information. We share it only with the providers that run the service:

We may also disclose information where required by law.

Where your information is stored, and international transfers

Gift content and accounts live in our database in the European Union (Ireland). Our other providers operate globally and may process data outside your country, including in the United States — payment data with Stripe, application hosting and analytics with Vercel, receipt emails with Resend, and, if you order a printed book, your delivery details with Lulu, who are based in the United States and print through a network of facilities worldwide. Which facility prints your book depends on where it is going, so a book posted within Europe is normally printed in Europe.

Because the service is available worldwide, information you give us may be transferred across borders. Where the law requires a safeguard for that transfer, we rely on the appropriate one: the European Commission’s Standard Contractual Clauses for transfers out of the EEA, the UK International Data Transfer Addendum for the UK, and the equivalent recognised mechanism for Switzerland and other jurisdictions with transfer rules.

How long we keep it

We keep gift content for as long as needed to provide the coupon book, handle support, prevent abuse, and comply with law, unless you ask us to delete it sooner and we are able to do so. Some data is deleted automatically on a schedule:

  • Abandoned premium gifts — a premium book whose payment was never completed is deleted after 30 days of inactivity, along with its promises.
  • Payment event records — the details we receive from Stripe about a payment (which can include your name and email) are erased after 90 days. We keep only the event identifier, so a repeated notification from Stripe cannot charge or publish a gift twice.
  • Email addresses you gave us to save a book — kept until you ask us to remove yours, or until you unsubscribe, whichever is first. Unsubscribing stops the product updates immediately. We then keep a single record that this address has asked not to be emailed, and nothing else about it: that record is what makes the request stick if the address ever reaches us again, and deleting it would quietly re-open you to a future mailing. Ask us and we will remove that too. We do not keep an address on the basis of a book that has itself been deleted.
  • Delivery details for a printed book — the name, address and phone number on an order are erased six months after the book is despatched or the order is cancelled. We keep the order record itself — what was bought, for how much, and when — because bookkeeping law requires it, but it holds nothing that identifies where you live. Orders still in progress are not touched: an address is what a reprint or a refused delivery needs.
  • Rate-limit counters — cleared hourly.

Browser local-storage items stay on your device until you clear them or the app replaces them. Payment, tax, accounting, and dispute records may be kept longer where law or payment-network rules require.

Your rights

Wherever you live, you can ask us to access, correct, delete, or export your information, and to object to or restrict processing. Email hello@littlepromises.shop. We answer within one month — the GDPR deadline, which we apply to every request rather than only to European ones. We will not charge you for it, and we will not treat you differently for asking.

You do not need an account to make a request. If you are asking about a specific coupon book, quote its secret code — that is how we locate one.

Additional rights in specific regions

  • EEA, UK, Switzerland — the rights above are statutory, and you may withdraw consent at any time where we relied on it. You may complain to a supervisory authority: ours is the Swedish Authority for Privacy Protection (IMY, imy.se), and you may instead complain to the authority where you live or work.
  • California and other US states — you may request the categories and specific pieces of personal information we hold, request deletion or correction, and opt out of “sale” or “sharing”. We do neither, and we do not use personal information for cross-context behavioural advertising or profiling with legal effects.
  • Brazil (LGPD) — you may additionally ask about the public and private entities we share data with, and about the consequences of refusing consent.
  • Canada, Australia, and elsewhere — you may access and correct your information and complain to your national privacy regulator.

Cookies & local storage

Little Promises does not use advertising cookies or cross-site tracking cookies. We use functional browser storage to remember your draft, your creator token, your coupon-book library, and your cookie-notice choice. Vercel Web Analytics does not use third-party cookies. If we add advertising or cross-site tracking technologies, we will update this policy and ask for consent where required.

What we never do

We do not sell personal information, share it for cross-context behavioural advertising, use it to build advertising profiles, or run third-party tracking on this site. There is no advertising network in Little Promises and we have no plans to add one. If that ever changes, we will update this policy and ask for consent where the law requires it.

Children

Little Promises is not directed to children under 16, and we do not knowingly collect their information. Where a lower age of digital consent applies (13 in some countries, including the United States and parts of the EEA), we apply that local age instead. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, take reasonable steps to let you know.

Contact

Questions about this policy or your information? Email hello@littlepromises.shop.