🔒 Google Play Store Compliant Policy

Privacy Policy

Welcome to Bloomistry — the modern modular gifting ecosystem for Customers, Vendors, and Business Partners. We are committed to safeguarding your personal data, gifting preferences, address books, and transaction records.

Application: Bloomistry Gifting Platform Effective Date: August 28, 2026 Version: 1.0.0

1. Information We Collect

Bloomistry collects personal details required to personalize gift recommendations, manage recipient address books, process e-commerce orders, and coordinate custom gift requests:

A. Account Credentials & Personal Identity

  • Identity Data: Full Name (`firstName`, `lastName`), unique Username, Email Address, and Phone Number (`phoneNumber`, E.164 formatted `phoneE164`).
  • Demographic Details: Date of Birth (`DOB`), Gender, Pronouns, Country, and City.
  • Profile Media: Profile avatar pictures (`profileImage`) and cover photos (`coverImage`) uploaded via AWS S3 / Cloudflare object storage.

B. Gifting Persona Preferences & Taste Profiles

To provide accurate gift matches, Bloomistry collects multi-select persona tags you choose on your profile:

  • Persona Tags: `kindOfPerson`, `colorTaste`, `favoriteEdibles`, `interests`, `entertainment`, and `dislikes`.

C. Social Connections, Occasions & Address Book

  • Saved Delivery Addresses: Recipient full names, shipping street addresses, city, postal codes, and delivery instructions.
  • Friends & Connections: Connected Bloomistry friends (`Friendship`), address book entries (`Connection`), and custom date reminders (`Occasion`, `Reminder`).
  • Wish Box & Surprise Plans: Saved wishlist items (`WishBoxItem`), surprise gift requests (`SurprisePlan`), and custom gift options (`CustomGift`).

D. Orders & Payment Information

  • Purchase Details: Order items, vendor shop selections, delivery status, and custom message notes.
  • Payment Receipts & Credentials: Payment proof uploads (bank receipts) or gateway tokens. Bloomistry uses PCI-DSS compliant payment processors; raw credit card numbers or PINs are never stored on our servers.

E. Device Identification & Push Notifications

  • Device Tokens: Firebase Cloud Messaging tokens (`fcmToken`) and platform identifiers (`ios`, `android`, `web`) used to deliver push alerts for occasion reminders and order updates.

2. How We Process Your Data

We process your data strictly to fulfill e-commerce gifting operations and enhance your app experience:

  • Gift Order Fulfillment: Dispatching products from verified shops (`Shop`) to recipient addresses.
  • Occasion Reminders: Dispatching push notifications and email alerts for upcoming birthdays, anniversaries, and scheduled reminders.
  • Personalized Gift Matching: Utilizing persona taste tags (`colorTaste`, `favoriteEdibles`, `interests`) to curate tailored recommendations.
  • Customer & Vendor Support: Operating live support chat (`ChatMessage`), processing custom gift requests, and verifying payment receipts.
  • Security & Authentication: Verifying accounts via OTP email codes, enforcing rate limits, and preventing fraudulent transactions.

3. Contact Sync & Profile QR Codes

Bloomistry provides social gifting features to connect with friends:

  • Contact Visibility Controls: You can toggle whether other customers can find your profile via phone number (`discoverableByPhone`) or email (`discoverableByEmail`).
  • Profile QR Codes: Each customer is issued a unique profile QR code (`qrCode`) for easy in-person friend adding. You can rotate or revoke your QR code at any time.

4. Data Sharing & Third-Party Disclosure

Zero Data Sales Guarantee: Bloomistry NEVER sells, rents, or monetizes your personal information or address book entries to third-party data brokers or advertisers.

We share minimal necessary data only with trusted service partners:

  • Vendors & Logistics Carriers: Recipient names, shipping addresses, and contact numbers required for order delivery.
  • Cloud & Media Storage: Cloudflare R2 / AWS S3 infrastructure for storing profile images and payment receipt images.
  • Push & Email Infrastructure: Google Firebase Cloud Messaging (FCM) for mobile push alerts and SMTP email services for order receipts and OTPs.
  • Legal Requirements: Information disclosed only when required by valid court subpoenas or statutory financial regulations.

5. Data Security & Encryption

Your security is paramount. Bloomistry implements enterprise-grade technical safeguards:

  • Encryption in Transit: TLS 1.3 / HTTPS encryption for all mobile app API traffic.
  • Password Hashing: Accounts are secured using high-strength Argon2 cryptographic password hashing.
  • Token Security: JWT access tokens with short lifetimes and revocable refresh tokens (`RefreshToken`).

6. Data Retention & Account Deletion

We retain your personal data only while your account remains active.

Account Deletion Rights: You may permanently delete your Bloomistry account at any time via the mobile app settings or our online web portal at /delete-account.

When account deletion is executed:

  • Your profile, credentials, persona tags, wishlists, address books, FCM push tokens, and social connections are permanently soft-deleted and deactivated.
  • Exit feedback is recorded in `AccountDeletionFeedback` for quality control.
  • Order financial transaction receipts are retained strictly as required by statutory accounting laws.

7. Your Privacy Rights & Choices

  • Access & Modify: Update your profile, persona tags, and addresses anytime in the app.
  • Discovery Toggles: Enable or disable phone/email discoverability in your privacy settings.
  • Notification Controls: Turn off push notifications for reminders or announcements in device settings.
  • Permanent Deletion: Request full account and data removal online or in-app.

Contact Bloomistry Privacy Team

If you have any questions, concerns, or privacy requests, please reach out to our team:

Email: [email protected]