Privacy Policy
Last updated: 2026-08-30
At [Missing: Entity Name], privacy is a structural premise of the service, not an afterthought. We build our systems to protect the financial privacy of the giver and the locational privacy of the couple receiving the gift.
- Nothing ships without your explicit approval.You review and approve each delivery before it goes to the florist.
- We never see or store your card number.Your billing goes directly through secure, documented payment providers.
- Your couple's address is masked.Privacy is paramount. We don't display their full address in your dashboard or send it via SMS.
- Old data is systematically erased.Raw addresses and message texts are purged 30 days after a confirmed delivery.
- The deadline is their real candle-lighting time.We don't guess. We use the real weekly sunset time for their zip code.
- Your couple never sees a price.The recipient experience is purely about receiving flowers, free of any financial details.
What we collect
To facilitate the recurring delivery of flowers, we collect and store only the data necessary to operate the program:
- From the giver: Account details, verified contact methods, and program configuration limits.
- From the couple: Contact details (name, email, and E.164 formatted phone number), delivery addresses, access instructions, flower restrictions, and optional short card notes.
- System data: SMS message logs, delivery event histories, and strict audit records detailing who performed what action in the system.
What we deliberately do not store
We enforce strict financial boundaries. We do not see, process, or store raw card numbers, CVC codes, bank details, or raw payment tokens. We retain only an opaque billing reference provided by our secure payment partners, alongside permitted non-sensitive display metadata (such as the last four digits of a card) so you can identify your chosen payment method.
Address privacy and handling
The physical address of the couple is treated with the highest degree of care. Full delivery addresses are masked by default in the giver's dashboard. Furthermore, full addresses are never included in SMS messages to anyone, including the giver.
Routine data deletion
We do not retain raw personal data indefinitely. Raw delivery addresses and raw SMS message texts are permanently deleted 30 days after a confirmed delivery. We retain only redacted historical records to maintain a coherent audit trail without compromising long-term privacy.
SMS consent and opt-out
We require explicit consent to send SMS delivery reminders to the couple. Consent is recorded at the time of onboarding. A recipient may immediately revoke this consent and opt out of all future messages at any time by replying STOP to any message.
Third parties
Operating a physical fulfillment network requires coordinating with specialized partners. We share data only where technically required:
- Florist One: Our fulfillment partner. They receive the delivery address and printed card text necessary to fulfill the order.
- Hebcal: We query their data source to determine accurate candle-lighting and holiday times for a given location.
- Telnyx: Our telecommunications provider, used to securely route and deliver SMS messages.
- Transactional Email: Our email provider, used for account verification and critical system notices.
Role-based access
Our infrastructure enforces strict boundaries between participants. Givers are restricted to viewing and managing only their own programs. Recipient managers are restricted to their assigned program's delivery preferences and never have access to payment details, pricing, budget limits, or approval policies.
Data requests and contact
If you have questions regarding our data practices or wish to submit a data access or deletion request, please direct your inquiry to:
[Missing: Entity Name]
[Missing: Data Request Address]
Email: [Missing: Email]