Privacy Policy

This Privacy Policy explains how Little Promises (“Little Promises”, “we”, “us”), operated by The Primate Collective, handles information when you create, send, open, or redeem a coupon book.

Who we are, and who this applies to

The data controller is The Primate Collective, established in Sweden. For any privacy question or request, contact us at hello@theprimatecollective.com.

Little Promises is available worldwide, and this policy applies to everyone who uses it. The baseline we apply to all users is the European standard: we collect only what the service needs, we tell you what we do with it, and we honour requests to see, correct, export, or delete your information wherever you live. Some regions grant additional specific rights, and those are set out under Your rights.

If someone made a book for you

A coupon book contains a recipient’s first name, and sometimes a personal note, written by the sender rather than by the recipient. If a book was made for you and you would like it corrected or deleted, email hello@theprimatecollective.com — you do not need the sender’s permission, and you do not need an account with us. Quote the secret code if you have it, as that is how we locate a book.

Information we collect

Information you give us

  • Gift content — the recipient and sender names, the occasion, your written note, the promises you add, the selected language, theme, cover choices, and whether a promise has been redeemed or kept.
  • Cover images — if you upload a premium cover image, we store the image file so it can be shown to the recipient.
  • Payment information — when you buy a premium gift, your card details are entered directly with our payment processor, Stripe. We never see or store your full card number. We retain a Stripe identifier, the payment status for the gift, and the email address you give Stripe at checkout, which we use to send your receipt and the link back to your gift.
  • Support messages — if you contact us, we process the information you send so we can respond.

Information we collect automatically

  • Technical and security data — IP address, request metadata, and rate-limit counters used to operate the service, prevent abuse, and troubleshoot errors.
  • Local storage — we store small items in your browser (a private creator token for gifts you create, your in-progress draft, your sent and received coupon-book lists, and your cookie-notice choice) so you can manage and re-open gifts. This stays on your device. See Cookies & local storage.
  • Analytics data — we use Vercel Web Analytics for aggregated page view statistics, such as page URL, referrer, approximate location, device type, browser, and operating system. We do not use analytics for advertising or cross-site tracking. A gift’s secret code travels in the page address, so we remove it before the page view is recorded — codes and checkout session identifiers are never sent to analytics.

How we use your information

  • To create, deliver, and let recipients open and redeem coupon books.
  • To process premium payments and provide proof of purchase.
  • To keep the service secure and prevent fraud and abuse.
  • To respond to your support requests.
  • To understand basic usage and improve the service.
  • To meet legal, tax, accounting, and dispute-resolution obligations.

Legal bases

Where the EU GDPR, UK GDPR, or Swiss FADP applies, we rely on: performance of a contract to provide the gift service and process purchases; legitimate interests to secure, debug, and improve the service; legal obligations for records we must keep; and consent where we ask for it.

Two of those deserve a note. The recipient’s name and any note about them are provided by the sender, not by the recipient — we process them on the legitimate interest of delivering a gift that someone chose to send, and the recipient can ask us to change or remove them at any time. Analytics also runs on legitimate interests, and you can turn it off from the notice at the bottom of the page or by clearing the lp-cookie-consent item in your browser storage.

Who we share information with

We do not sell your information. We share it only with the providers that run the service:

We may also disclose information where required by law.

Where your information is stored, and international transfers

Gift content and accounts live in our database in the European Union (Ireland). Our other providers operate globally and may process data outside your country, including in the United States — payment data with Stripe, application hosting and analytics with Vercel, and receipt emails with Resend.

Because the service is available worldwide, information you give us may be transferred across borders. Where the law requires a safeguard for that transfer, we rely on the appropriate one: the European Commission’s Standard Contractual Clauses for transfers out of the EEA, the UK International Data Transfer Addendum for the UK, and the equivalent recognised mechanism for Switzerland and other jurisdictions with transfer rules.

How long we keep it

We keep gift content for as long as needed to provide the coupon book, handle support, prevent abuse, and comply with law, unless you ask us to delete it sooner and we are able to do so. Some data is deleted automatically on a schedule:

  • Abandoned premium gifts — a premium book whose payment was never completed is deleted after 30 days of inactivity, along with its promises.
  • Payment event records — the details we receive from Stripe about a payment (which can include your name and email) are erased after 90 days. We keep only the event identifier, so a repeated notification from Stripe cannot charge or publish a gift twice.
  • Rate-limit counters — cleared hourly.

Browser local-storage items stay on your device until you clear them or the app replaces them. Payment, tax, accounting, and dispute records may be kept longer where law or payment-network rules require.

Your rights

Wherever you live, you can ask us to access, correct, delete, or export your information, and to object to or restrict processing. Email hello@theprimatecollective.com. We answer within one month — the GDPR deadline, which we apply to every request rather than only to European ones. We will not charge you for it, and we will not treat you differently for asking.

You do not need an account to make a request. If you are asking about a specific coupon book, quote its secret code — that is how we locate one.

Additional rights in specific regions

  • EEA, UK, Switzerland — the rights above are statutory, and you may withdraw consent at any time where we relied on it. You may complain to a supervisory authority: ours is the Swedish Authority for Privacy Protection (IMY, imy.se), and you may instead complain to the authority where you live or work.
  • California and other US states — you may request the categories and specific pieces of personal information we hold, request deletion or correction, and opt out of “sale” or “sharing”. We do neither, and we do not use personal information for cross-context behavioural advertising or profiling with legal effects.
  • Brazil (LGPD) — you may additionally ask about the public and private entities we share data with, and about the consequences of refusing consent.
  • Canada, Australia, and elsewhere — you may access and correct your information and complain to your national privacy regulator.

Cookies & local storage

Little Promises does not use advertising cookies or cross-site tracking cookies. We use functional browser storage to remember your draft, your creator token, your coupon-book library, and your cookie-notice choice. Vercel Web Analytics does not use third-party cookies. If we add advertising or cross-site tracking technologies, we will update this policy and ask for consent where required.

What we never do

We do not sell personal information, share it for cross-context behavioural advertising, use it to build advertising profiles, or run third-party tracking on this site. There is no advertising network in Little Promises and we have no plans to add one. If that ever changes, we will update this policy and ask for consent where the law requires it.

Children

Little Promises is not directed to children under 16, and we do not knowingly collect their information. Where a lower age of digital consent applies (13 in some countries, including the United States and parts of the EEA), we apply that local age instead. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, take reasonable steps to let you know.

Contact

Questions about this policy or your information? Email hello@theprimatecollective.com.