📋 Plain English summary before the legal version:
- We don't sell your personal data. Ever. To anyone.
- We don't require you to create an account or log in.
- Gift searches you enter are processed by AI but not stored on our servers.
- We use basic anonymous analytics to understand how the site is used.
- Clicking "Shop on Amazon" takes you to Amazon, which has its own privacy policy.
- We earn a small affiliate commission when you buy through our links — at no cost to you.
- You can email us any time to ask questions about your privacy.
- Who we are
- Information we collect
- How we use your information
- AI data processing
- Cookies and tracking
- Third-party services
- Affiliate links and Amazon
- Data sharing and selling
- Data security
- Your rights and choices
- Children's privacy
- California privacy rights (CCPA)
- International visitors (GDPR)
- Changes to this policy
- Contact us
1. Who We Are
DesireBuy ("we," "us," or "our") operates the website located at desirebuy.com (the "Site"). We are an independent gift discovery platform that uses artificial intelligence to help people find personalized gift ideas. Our primary monetization model is affiliate commissions earned when visitors purchase products through links on our Site.
We are not a retailer — we do not sell products directly, hold inventory, or process payments. We are a content and technology platform that connects people with products on third-party retailers, primarily Amazon.
For privacy-related inquiries, you can contact us at: hello@DesireBuy.com
2. Information We Collect
We collect two types of information: information you provide directly, and information collected automatically when you use our Site.
2.1 Information You Provide Directly
| Data type | When collected | How used |
|---|---|---|
| Gift search inputs (recipient, occasion, budget, personality, notes) | When you use the AI gift finder | Sent to our AI provider to generate gift recommendations. Not stored on our servers after the session ends. |
| Name and email address | When you submit the contact form | To respond to your inquiry. Not used for marketing without your consent. |
| Quiz answers | When you take the Gift Personality Quiz | Processed locally in your browser to generate your result. Not sent to our servers. |
| Message content | When you contact us | To respond to your question or feedback. |
2.2 Information Collected Automatically
When you visit our Site, we automatically collect certain technical information through standard web technologies. This may include:
- Log data: Your IP address, browser type and version, operating system, referring URL, pages visited, time and date of your visit, and time spent on pages.
- Device information: Device type (desktop, mobile, tablet), screen resolution, and device identifiers.
- Usage data: Which pages you visit, which links you click, and how you navigate the Site.
- Geographic data: General location based on IP address (country and region level only — never precise location).
We do not collect: your full name without you providing it, your precise location, payment information, social security numbers, government IDs, health information, or any sensitive personal data.
3. How We Use Your Information
We use the information we collect for the following purposes:
Your search inputs are sent to our AI provider (Anthropic) to generate 10 personalized gift recommendations. This is the core function of our Site.
Anonymous, aggregated usage data helps us understand which pages are most useful, how visitors navigate the Site, and where we can improve the experience.
When you contact us through our contact form, we use your name and email to respond to your message. We do not add you to any mailing list without explicit consent.
Log data and IP addresses may be used to detect and prevent abusive behavior, spam, or attacks on our infrastructure.
We may process your data when required to do so by applicable law, court order, or regulatory authority.
We use aggregated, anonymized data to understand trends, measure content performance, and make decisions about what gift guides and collections to create.
We will never use your information to:
- Send you unsolicited marketing emails without your consent
- Build advertising profiles or retarget you with ads
- Sell or rent your personal data to third parties
- Make automated decisions that have legal or significant effects on you
4. AI Data Processing
Our core feature — the AI gift finder — uses Anthropic's Claude API to generate personalized gift recommendations based on the inputs you provide (recipient type, occasion, budget, personality, and any optional notes you add).
4.1 What we send to Anthropic
When you click "Find perfect gifts," we send your search inputs to Anthropic's servers. This data is used solely to generate your gift recommendations and is not associated with your name, email address, or any other identifying information.
4.2 What Anthropic does with the data
Anthropic processes your inputs to generate AI responses. Their handling of this data is governed by Anthropic's Privacy Policy. We encourage you to review it. As of the date of this policy, Anthropic states that they do not use API data to train their models by default.
4.3 What we store
We do not store your gift search inputs on our servers. Once the AI response is returned to your browser, the data is not retained by DesireBuy. Each search is treated as a fresh, independent request.
⚠️ Important: Do not enter sensitive personal information (such as health conditions, financial details, or identifying information about third parties) into the gift finder. The tool is designed for describing personalities and gift preferences only.
5. Cookies and Tracking Technologies
Cookies are small text files that a website stores on your device. We use cookies and similar technologies in limited ways:
5.1 Types of cookies we use
| Cookie type | Purpose | Duration | Can you opt out? |
|---|---|---|---|
| Essential | Required for basic site functionality. Without these, parts of the Site may not work. | Session | No — required for the site to function |
| Analytics | Help us understand how visitors use the Site (page views, popular content, traffic sources). Data is aggregated and anonymous. | Up to 2 years | Yes — see Section 5.3 |
| Amazon affiliate | When you click an Amazon link, Amazon may set cookies to track the referral and attribute any commission to DesireBuy. | 24 hours (cookie window) | Manage through Amazon's settings |
5.2 Analytics tools
We may use Google Analytics or similar tools to collect anonymous usage data. These tools use cookies to track visits across sessions. The data collected is aggregated — we cannot identify you individually from analytics data. We have configured these tools to anonymize IP addresses where possible.
5.3 How to manage cookies
You can control cookies through your browser settings. Most browsers allow you to:
- View and delete existing cookies
- Block third-party cookies
- Block cookies from specific sites
- Block all cookies (though this may break some site features)
- Delete all cookies when you close your browser
Note: Disabling cookies does not affect your ability to use the AI gift finder. The recommendations feature works without cookies.
6. Third-Party Services
Our Site integrates with several third-party services. Each has its own privacy policy and data practices:
| Service | Purpose | Data shared | Their privacy policy |
|---|---|---|---|
| Anthropic (Claude API) | Powers the AI gift finder | Your gift search inputs (not linked to your identity) | anthropic.com/privacy |
| Cloudflare | API security proxy and CDN | Request metadata (IP, headers) for security | cloudflare.com/privacypolicy |
| Netlify | Website hosting | Standard server logs (IP, browser type) | netlify.com/privacy |
| Amazon Associates | Affiliate program | Click data when you follow our links to Amazon | Amazon privacy notice |
| Google Analytics | Anonymous site analytics (if enabled) | Anonymized usage data, device type, country | policies.google.com/privacy |
| Google Fonts | Typography (fonts loaded from Google servers) | IP address (to serve font files) | policies.google.com/privacy |
We do not control how these third parties use the data they collect when you interact with their services or follow our links to their platforms. We encourage you to review their privacy policies.
7. Affiliate Links and Amazon
DesireBuy.com is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon.com.
7.1 How it works
When you click a "Shop on Amazon" button on our Site, you are directed to Amazon.com with a tracking tag (tag=desirebuy-20) appended to the URL. If you make a qualifying purchase within 24 hours of clicking our link, DesireBuy earns a small commission (typically 1–10% depending on the product category) at no additional cost to you.
7.2 What Amazon collects
When you arrive at Amazon through our links, Amazon may place cookies on your device and collect data in accordance with their own Privacy Notice. Amazon's data collection practices are entirely separate from DesireBuy's and are governed by Amazon's policies, not ours.
7.3 Our recommendations are not influenced by commissions
Our gift recommendations are generated by AI based solely on your search inputs. We do not — and cannot — instruct the AI to recommend higher-commission products. Our interest is in recommending gifts you'll actually want to buy, because that's the only way we earn.
For full transparency about our affiliate relationships, including all programs we participate in, please read our complete Affiliate Disclosure.
8. Data Sharing and Selling
We do not sell, rent, trade, or otherwise transfer your personal information to third parties for their marketing purposes. Period.
We may share information in the following limited circumstances:
8.1 Service providers
We share data with third-party service providers who help us operate the Site (such as Anthropic for AI processing, Netlify for hosting, and Cloudflare for security). These providers are only given access to the data necessary to perform their services and are contractually prohibited from using it for other purposes.
8.2 Legal requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency). We will notify you of such requests where legally permitted to do so.
8.3 Business transfers
If DesireBuy is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via a prominent notice on our Site before your information becomes subject to a different privacy policy.
8.4 Protection of rights
We may share information when we believe disclosure is appropriate to protect the rights, property, or safety of DesireBuy, our users, or others — for example, to prevent fraud or investigate security incidents.
9. Data Security
We take reasonable technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These include:
- HTTPS encryption: All data transmitted between your browser and our Site is encrypted using TLS (HTTPS).
- API key security: Our Anthropic API key is stored as an encrypted environment variable in Cloudflare Workers — it is never exposed in your browser or in our HTML files.
- No unnecessary data retention: We don't store your gift search inputs after they've been processed.
- Limited access: Access to any data we do collect is restricted to those who need it to operate the Site.
However, no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.
⚠️ If you believe your interaction with us has been compromised or you suspect a security incident, please contact us immediately at hello@DesireBuy.com.
10. Your Rights and Choices
Depending on where you live, you may have certain rights regarding your personal information:
| Right | What it means | How to exercise it |
|---|---|---|
| Access | Request a copy of the personal data we hold about you | Email us at hello@DesireBuy.com |
| Correction | Ask us to correct inaccurate personal data | Email us at hello@DesireBuy.com |
| Deletion | Request that we delete your personal data | Email us at hello@DesireBuy.com |
| Objection | Object to how we process your data | Email us at hello@DesireBuy.com |
| Portability | Receive your data in a portable format | Email us at hello@DesireBuy.com |
| Opt-out of analytics | Disable tracking cookies | Adjust your browser cookie settings |
Because we collect very little personal data and do not require account creation, most of these rights may have limited practical application for typical visitors. We will respond to all verifiable requests within 30 days.
11. Children's Privacy
DesireBuy.com is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at hello@DesireBuy.com and we will take steps to delete such information.
If we learn that we have inadvertently collected personal information from a child under 13, we will delete that information as quickly as reasonably possible.
Visitors between the ages of 13 and 18 should review this policy with a parent or guardian before using the Site.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
12.1 Right to Know
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business purpose for collecting it, and the categories of third parties with whom we share it.
12.2 Right to Delete
You have the right to request deletion of personal information we have collected from you, subject to certain exceptions (such as where the data is needed to complete a transaction, detect security incidents, or comply with a legal obligation).
12.3 Right to Opt-Out of Sale
We do not sell personal information. However, if this ever changes, California residents would have the right to opt out by clicking a "Do Not Sell My Personal Information" link, which we would add to our Site.
12.4 Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. We will not deny you goods or services, charge you different prices, provide a different level of service, or suggest that you will receive a different level of service as a result of exercising your rights.
12.5 Categories of personal information collected
In the past 12 months, we have collected the following categories of personal information (as defined by the CCPA):
- Identifiers: IP addresses, browser identifiers (collected automatically via server logs)
- Internet or other electronic network activity: Pages visited, links clicked, time on site
- Geolocation data: Country/region level only, derived from IP address
- Communications: Name and email if you contact us via our contact form
We have not collected: biometric data, financial information, health information, or sensitive personal information as defined by CPRA.
To exercise your California rights, contact us at hello@DesireBuy.com with "California Privacy Request" in the subject line.
13. International Visitors (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent local laws.
13.1 Legal basis for processing
| Processing activity | Legal basis |
|---|---|
| Sending gift search inputs to Anthropic to generate recommendations | Legitimate interests (providing the core service you requested) |
| Server logs and analytics | Legitimate interests (operating and improving the Site securely) |
| Responding to contact form submissions | Contract (responding to your request) / Legitimate interests |
| Legal compliance | Legal obligation |
13.2 Data transfers
Your data may be transferred to and processed in the United States, where our service providers (Anthropic, Cloudflare, Netlify) are based. The US may not have data protection laws equivalent to those in the EEA. We rely on standard contractual clauses and our providers' compliance certifications where applicable.
13.3 Your GDPR rights
In addition to the rights listed in Section 10, EEA residents have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data in accordance with applicable law.
13.4 Data retention
We retain personal data only as long as necessary for the purposes outlined in this policy:
- Gift search inputs: Not retained after the session ends
- Server logs: Typically 30–90 days
- Contact form submissions: Until your inquiry is resolved, then deleted within 12 months
- Analytics data: Up to 26 months in aggregated, anonymous form
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Update the "Last updated" date at the top of this page
- Post the revised policy on this page
- For material changes that significantly affect how we use your data, we will provide a more prominent notice (such as a banner on the homepage)
We encourage you to review this policy periodically. Your continued use of the Site after we post changes constitutes your acceptance of the updated policy.
If you disagree with any changes to this policy, you should discontinue use of the Site and may contact us to request deletion of any data we hold about you.
15. Contact Us About Privacy
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: hello@DesireBuy.com
- Subject line for privacy requests: "Privacy Request — [your specific request]"
- Response time: We aim to respond to all privacy-related inquiries within 5 business days, and no later than 30 days as required by applicable law.
For California residents submitting CCPA requests or EU/UK residents submitting GDPR requests, please include your state or country of residence in your email so we can ensure compliance with applicable law.
Have a privacy question?
We're a small team and we take your privacy seriously. Reach out — we respond to everything.
Contact us →