1. Overview & Core Philosophy
GiftCardToCash ("we", "our", or "the Platform") operates a decentralized and peer-to-peer (P2P) trading network facilitating the exchange of digital gift cards, fiat currencies, utility recharges, and freelance services for cryptocurrencies (USDT, Bitcoin). We adhere to strict data minimization: we only collect the minimum telemetry and identity details necessary to prevent fraud, arbitrate disputes, and secure financial custody.
2. Information We Collect
Email address, chosen display name, avatar, preferred currency, and cryptographic password hash (stored using salted bcrypt).
When submitting verification for higher tier trading, users provide government ID images or passport scans. These are stored in private encrypted object storage and accessed solely by authorized compliance officers.
Chat transcripts, card redemption proofs, receipt screenshots, and transaction references exchanged within encrypted trade rooms. These are preserved for automated escrow verification and dispute arbitration.
IP address, approximate country/geographic location, browser user-agent, session timestamps, and device fingerprints used exclusively for fraud detection, multi-accounting prevention, and rate-limiting.
3. How We Use Your Information
- Escrow Settlement & Trade Execution: Locking, releasing, and crediting digital assets between verified counterparties.
- Dispute Arbitration: Assisting human moderators in reviewing evidence if a party raises a trade conflict or payment dispute.
- Security & Anti-Fraud Algorithms: Monitoring unauthorized access attempts, bot traffic, Sybil attacks, and chargeback patterns.
- Multi-Channel Notifications: Delivering real-time trade alerts via Web Push, Telegram bots, WhatsApp notifications, or Email.
4. Blockchain Ledger & Public Addresses
Cryptocurrency transactions (USDT on TRC20/BEP20 and Bitcoin on Mainnet/Lightning) are processed on public decentralized ledgers. Deposit transaction hashes (TxHash) and destination payout addresses are published to the blockchain as an inherent function of distributed ledger technology and cannot be altered or deleted.
5. Security Safeguards & Encryption
All HTTP traffic is secured via modern TLS 1.3 encryption. We support hardware/app-based Two-Factor Authentication (TOTP Google Authenticator) and mandatory release security challenges. Database backups are encrypted at rest with AES-256 standards.
6. Cookies & Client Storage
We utilize essential HTTP-only session cookies and local storage tokens for user authentication, language preferences, and audio chimes. We do not sell user data to advertising brokers or track visitors across third-party websites.
7. Privacy Inquiries & Data Rights
Users can export their profile data or request account termination at any time by contacting our 24/7 support desk or opening a support ticket in the Support Center.