Privacy Policy
Welcome to Bloomistry — the modern modular gifting ecosystem for Customers, Vendors, and Business Partners. We are committed to safeguarding your personal data, gifting preferences, address books, and transaction records.
1. Information We Collect
Bloomistry collects personal details required to personalize gift recommendations, manage recipient address books, process e-commerce orders, and coordinate custom gift requests:
A. Account Credentials & Personal Identity
- Identity Data: Full Name (`firstName`, `lastName`), unique Username, Email Address, and Phone Number (`phoneNumber`, E.164 formatted `phoneE164`).
- Demographic Details: Date of Birth (`DOB`), Gender, Pronouns, Country, and City.
- Profile Media: Profile avatar pictures (`profileImage`) and cover photos (`coverImage`) uploaded via AWS S3 / Cloudflare object storage.
B. Gifting Persona Preferences & Taste Profiles
To provide accurate gift matches, Bloomistry collects multi-select persona tags you choose on your profile:
- Persona Tags: `kindOfPerson`, `colorTaste`, `favoriteEdibles`, `interests`, `entertainment`, and `dislikes`.
C. Social Connections, Occasions & Address Book
- Saved Delivery Addresses: Recipient full names, shipping street addresses, city, postal codes, and delivery instructions.
- Friends & Connections: Connected Bloomistry friends (`Friendship`), address book entries (`Connection`), and custom date reminders (`Occasion`, `Reminder`).
- Wish Box & Surprise Plans: Saved wishlist items (`WishBoxItem`), surprise gift requests (`SurprisePlan`), and custom gift options (`CustomGift`).
D. Orders & Payment Information
- Purchase Details: Order items, vendor shop selections, delivery status, and custom message notes.
- Payment Receipts & Credentials: Payment proof uploads (bank receipts) or gateway tokens. Bloomistry uses PCI-DSS compliant payment processors; raw credit card numbers or PINs are never stored on our servers.
E. Device Identification & Push Notifications
- Device Tokens: Firebase Cloud Messaging tokens (`fcmToken`) and platform identifiers (`ios`, `android`, `web`) used to deliver push alerts for occasion reminders and order updates.
2. How We Process Your Data
We process your data strictly to fulfill e-commerce gifting operations and enhance your app experience:
- Gift Order Fulfillment: Dispatching products from verified shops (`Shop`) to recipient addresses.
- Occasion Reminders: Dispatching push notifications and email alerts for upcoming birthdays, anniversaries, and scheduled reminders.
- Personalized Gift Matching: Utilizing persona taste tags (`colorTaste`, `favoriteEdibles`, `interests`) to curate tailored recommendations.
- Customer & Vendor Support: Operating live support chat (`ChatMessage`), processing custom gift requests, and verifying payment receipts.
- Security & Authentication: Verifying accounts via OTP email codes, enforcing rate limits, and preventing fraudulent transactions.
3. Contact Sync & Profile QR Codes
Bloomistry provides social gifting features to connect with friends:
- Contact Visibility Controls: You can toggle whether other customers can find your profile via phone number (`discoverableByPhone`) or email (`discoverableByEmail`).
- Profile QR Codes: Each customer is issued a unique profile QR code (`qrCode`) for easy in-person friend adding. You can rotate or revoke your QR code at any time.
4. Data Sharing & Third-Party Disclosure
Zero Data Sales Guarantee: Bloomistry NEVER sells, rents, or monetizes your personal information or address book entries to third-party data brokers or advertisers.
We share minimal necessary data only with trusted service partners:
- Vendors & Logistics Carriers: Recipient names, shipping addresses, and contact numbers required for order delivery.
- Cloud & Media Storage: Cloudflare R2 / AWS S3 infrastructure for storing profile images and payment receipt images.
- Push & Email Infrastructure: Google Firebase Cloud Messaging (FCM) for mobile push alerts and SMTP email services for order receipts and OTPs.
- Legal Requirements: Information disclosed only when required by valid court subpoenas or statutory financial regulations.
5. Data Security & Encryption
Your security is paramount. Bloomistry implements enterprise-grade technical safeguards:
- Encryption in Transit: TLS 1.3 / HTTPS encryption for all mobile app API traffic.
- Password Hashing: Accounts are secured using high-strength Argon2 cryptographic password hashing.
- Token Security: JWT access tokens with short lifetimes and revocable refresh tokens (`RefreshToken`).
6. Data Retention & Account Deletion
We retain your personal data only while your account remains active.
Account Deletion Rights: You may permanently delete your Bloomistry account at any time via the mobile app settings or our online web portal at /delete-account.
When account deletion is executed:
- Your profile, credentials, persona tags, wishlists, address books, FCM push tokens, and social connections are permanently soft-deleted and deactivated.
- Exit feedback is recorded in `AccountDeletionFeedback` for quality control.
- Order financial transaction receipts are retained strictly as required by statutory accounting laws.
7. Your Privacy Rights & Choices
- Access & Modify: Update your profile, persona tags, and addresses anytime in the app.
- Discovery Toggles: Enable or disable phone/email discoverability in your privacy settings.
- Notification Controls: Turn off push notifications for reminders or announcements in device settings.
- Permanent Deletion: Request full account and data removal online or in-app.
Contact Bloomistry Privacy Team
If you have any questions, concerns, or privacy requests, please reach out to our team:
Email: [email protected]
Email Privacy Support