GiftLink - Influencer Gifting for Shopify
Last updated: 12 August 2026
GiftLink is a Shopify app by Timmgard GmbH for automated influencer gifting: merchants create gift links through which influencers and creators select and redeem product gifts; the App turns each redemption into an order with an order value of EUR 0.00 in the merchant’s shop. This privacy policy informs about the processing of personal data when using the App and is structured in line with Art. 13 GDPR. The Terms of Service governing the use of the App are available at https://tg-ai.de/en/apps/gift-link/terms-of-service.
Provider and data controller within the meaning of Art. 4(7) GDPR for the operation of the GiftLink app (the “App”) as a software service is:
Timmgard GmbH
Kurhausstraße 78a
53773 Hennef
Germany
Commercial Register: HRB 17527 (Amtsgericht Siegburg)
VAT ID: DE359202464
Authorised Representative: S. Timm
Email: [email protected]
Contact form: https://tg-ai.de/en/kontakt - response guaranteed within 24 hours
For the processing of data arising from individual gift redemptions, Timmgard GmbH acts as processor under Art. 28 GDPR - see Section 2.
GiftLink processes personal data in two distinct roles:
• As controller under Art. 4(7) GDPR for installation, operation, and billing of the App vis-à-vis the merchant (e.g. Shopify shop domain, admin contact data, support chat).
• As processor under Art. 28 GDPR for the data of the influencers and creators who redeem a gift link. The controller for that data is the merchant. Timmgard GmbH processes such data exclusively on the merchant’s documented instructions under the data processing agreement (DPA). The full DPA is available at https://tg-ai.de/en/dpa/gift-link.
Important: The data subjects in GiftLink are primarily not the shop’s end customers but the influencers/creators redeeming a gift. End-customer orders are processed only in the form of order numbers and amounts (discount code attribution, see Section 7) - without buyers’ names, email addresses, or postal addresses.
The consent checkbox in the gift form links to the respective merchant’s privacy policy (configured by the merchant in the app settings). This policy additionally describes the processing performed by Timmgard GmbH as the App’s provider; it does not replace the merchant’s own privacy policy.
GiftLink processes personal data for the following purposes:
• Redemption of gift links via the public form and creation of the corresponding order with an order value of EUR 0.00 in the merchant’s shop, so the gift runs through the merchant’s regular fulfilment process.
• Optional approval queue: redemptions can require the merchant’s manual approval before the order is created.
• Sending transactional emails: delivery of the gift link to the influencer, approval/rejection notifications, an optional Shopify order confirmation, and notifications to the merchant.
• The merchant’s creator CRM: per-creator notes and manually maintained links to published content with manually entered reach figures.
• Discount code attribution: matching shop orders in which a creator’s personal follower discount code was redeemed.
• Abuse prevention via rate limiting and a honeypot field.
• Fulfilment of the Shopify compliance webhooks CUSTOMERS_DATA_REQUEST, CUSTOMERS_REDACT, and SHOP_REDACT, and evidence of their timely handling.
• Optional support chat between merchant and provider inside the Shopify admin (only where enabled server-side).
Where Timmgard GmbH acts as processor for the merchant, determining the legal basis is the merchant’s responsibility as controller. Typically, the following apply:
• Art. 6(1)(b) GDPR - handling the gift redemption and creating the corresponding order as part of the cooperation agreed between merchant and creator.
• Art. 6(1)(a) GDPR - the separate UGC/repost consent (where the merchant has enabled it for a link) and voluntary details such as optional social media profiles. Any consent given can be withdrawn at any time with effect for the future (Art. 7(3) GDPR); the consent wording is provided by the merchant.
• Art. 6(1)(f) GDPR - legitimate interest in abuse prevention (rate limiting with ephemeral IP processing, honeypot), in the creator CRM and in discount code attribution as commercial documentation, and in the traceability of operations.
• Art. 6(1)(c) GDPR in conjunction with Art. 12(3) GDPR - logging of data subject requests received via Shopify to demonstrate timely handling.
When a gift link is redeemed via the public form, the following data of the influencer/creator is processed:
• First and last name (mandatory)
• Email address (mandatory)
• Social media profiles (Instagram, TikTok, YouTube): disabled, optional, or required depending on the link’s configuration; “required” means at least one profile, never all three
• Selected products (variant, title, quantity, unit price) and the merchandise value of the gift (merchandiseValue) - independent of the EUR 0.00 order value, e.g. for the merchant’s commercial documentation
• Personal follower discount code (derived from the name or entered as a requested code; only where the merchant has enabled the feature)
• Consent timestamps: privacy consent (always), acceptance of the merchant’s terms and the UGC/repost consent (each only where required by the merchant for the link)
• Form language and an internal creator key (creatorKey; derived from the email address, alternatively the social handle or the name; used in URLs only as a SHA-256 hash)
Phone numbers are not collected; the form has no phone field.
Shipping address (data minimisation): The shipping address is, as a rule, not stored in the GiftLink database. It flows directly into the created Shopify order and therefore resides exclusively in the merchant’s Shopify system. The only exception: if the approval queue is active for a link, the address is held temporarily in the pendingShipping field while the redemption has PENDING status - and is nulled on every decision (approval as well as rejection, including the automatic rejection after 30 days and a GDPR erasure request). For the one-time display of the confirmation page, the address is additionally held briefly (at most 5 minutes, retrievable once) in memory, never in the database.
IP address: The full IP address is processed only ephemerally in memory for rate limiting (abuse prevention, Art. 6(1)(f) GDPR) and is not stored in the database; the data model has no IP field. In rate-limit keys, the email address is used exclusively as a SHA-256 hash.
For the merchant’s creator CRM, the following is processed per creator (linked via the creatorKey):
• CreatorNote: a free-text note by the merchant (maximum 2,000 characters).
• CreatorContent: URLs of publicly accessible content (e.g. social media posts) entered manually by the merchant, together with manually maintained reach figures.
The reach figures are maintained exclusively by the merchant by hand. GiftLink performs no scraping and calls no platform APIs (Instagram, TikTok, YouTube); the App merely renders links to the public profiles. Both data sets are fully deleted upon an erasure request via both redaction paths (see Section 13).
When a shop end customer places an order using a creator’s personal follower discount code, GiftLink stores an attribution record (AttributedOrder) with the following fields: order number and order ID, order amount, currency, order timestamp, discount code, and creatorKey.
Deliberately no end-customer data: the buyer’s name, email address, or postal address is not stored, although the Shopify webhook contains this data - only the business figures listed above are kept. The link to the creator exists solely via the name-derived discount code; attribution records are therefore fully deleted by both redaction paths. If an order is cancelled (orders/cancelled), the corresponding record is removed again.
For installation, operation, and billing of the App vis-à-vis the merchant, the following is processed:
• Shopify session data of admin users: Shopify user ID, first and last name, email address, language, and role flags.
• Shop master data: shop domain, shop name, merchant email, app settings (including the branding details configured by the merchant and the URL of the merchant’s own privacy policy), onboarding status, billing and usage counters (number of gift orders per billing period), and installation/uninstallation timestamps.
• The merchant’s support chat messages (see Sections 10 and 13), where the support chat is enabled.
The same applies in the admin area: IP addresses are processed only ephemerally in memory for rate limiting and are not stored.
Every data subject request received via the Shopify compliance webhooks (CUSTOMERS_DATA_REQUEST, CUSTOMERS_REDACT, SHOP_REDACT) is logged internally in a GdprRequest table with timestamp, request type, and completion status. The purpose is to demonstrate compliance with the 30-day deadline under Art. 12(3) GDPR. These logs are deliberately not cascade-deleted with the shop account (proof of processing); they contain no additional personal data beyond what is already held in the affected tables.
In addition, the App maintains a webhook deduplication table (ProcessedWebhook: webhook ID, topic, shop domain, timestamp; no further personal content), whose entries are automatically pruned after 30 days. Legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 12(3) GDPR.
GiftLink uses the following sub-processors, each engaged under a data processing agreement per Art. 28 GDPR:
• Shopify Inc. (151 O'Connor Street, Ottawa, Ontario K2P 2L8, Canada) - role: shop platform; creation of the EUR 0.00 orders and the discount codes via the Shopify Admin API, sender/recipient of the webhooks, host of the embedded admin session. Location: Canada (headquarters), US-based infrastructure. Safeguarded by the adequacy decision for Canada (Decision 2002/2/EC) and the EU-U.S. Data Privacy Framework for US components, failing that EU Standard Contractual Clauses 2021/914 (within the Shopify DPA).
• Render Services Inc. (525 Brannan St, Suite 300, San Francisco, CA 94107, USA) - role: hosting of the application and the PostgreSQL database. Primary server location: Frankfurt, Germany (region eu-central). DPF-certified since 6 January 2025; subsidiarily SCCs 2021/914.
• Resend Inc. (2261 Market Street, San Francisco, CA 94114, USA) - role: dispatch of the transactional emails (gift link delivery, approval/rejection notifications, merchant notifications, optional order confirmation). Sending infrastructure in the EU (Ireland, AWS eu-west-1); account metadata and sent-logs reside in US infrastructure. DPF-certified since March 2025; subsidiarily SCCs 2021/914.
• Slack Technologies Limited (a Salesforce company; Salesforce Tower, 60 R801, North Dock, Dublin, Ireland) - role: delivery channel of the optional support chat between merchant and provider; only where the support chat is used. Only the chat content entered by the merchant together with the shop domain is transmitted, plus internal operational notices (e.g. shop name, booked plan) - no influencer/creator data, no address or order data. Contracting party in Ireland (EU); the Slack/Salesforce processing infrastructure is located in the USA. DPF-certified (Salesforce/Slack since July 2023); subsidiarily SCCs 2021/914.
Beyond this, no personal data is shared with third parties. In particular, no data is processed or transferred for advertising or profiling purposes. GiftLink connects no shipping carriers; gifts are shipped through the merchant’s regular fulfilment process.
The public gift form sets no cookies and uses no local storage or session storage. The page loads no framework JavaScript and no third-party resources; only product and logo images are loaded from the Shopify CDN. Access is authorised solely via the gift link token; the page is served with noindex and restrictive security headers (including X-Frame-Options: DENY and Cache-Control: no-store).
The Shopify admin-embedded merchant dashboard uses only technically necessary session cookies of the Shopify platform; these are set by Shopify, not by GiftLink. The support chat panel remembers the dismissal of a teaser notice in a session storage entry without personal reference and retrieves new messages via periodic API polling. No analytics, marketing, or third-party tracking is performed.
The App infrastructure and the database operate exclusively within the EU (Frankfurt, Germany). Transfers to third countries (notably the USA) occur only with the sub-processors listed in Section 10 and are safeguarded by:
• EU-U.S. Data Privacy Framework (Render, Resend, and Salesforce/Slack as well as the US infrastructure components of Shopify are certified).
• EU Standard Contractual Clauses under Implementing Decision (EU) 2021/914 as a subsidiary safeguard.
• The adequacy decision of the European Commission for Canada (Shopify headquarters).
• Supplementary technical and organisational measures (transport encryption, access restrictions).
The following retention and deletion rules apply:
• Redemption records: stored for the duration of the App installation; an automatic deletion period is currently not implemented, as the records serve the merchant’s commercial documentation (e.g. merchandise value of the gift). Personal references are anonymised upon an erasure request (see below).
• Open approval requests (PENDING status): automatically rejected after 30 days; the transiently stored shipping address (pendingShipping) is deleted in the process. The address is also nulled on every manual decision (approval or rejection).
• Creator CRM (notes, content links) and attribution records: for the duration of the App installation; fully deleted upon an erasure request via both redaction paths.
• Personal follower discount codes: valid for 90 days (rolling from creation).
• Webhook deduplication entries (ProcessedWebhook): automatically pruned after 30 days.
• Support chat histories: for the duration of the App installation; deleted with the shop account (SHOP_REDACT).
• Rate-limit data (full IP address, hashed email): ephemeral in memory, process-local, never stored in the database.
• GdprRequest log: retained beyond the deletion of the shop account as proof of processing (Art. 5(2) GDPR); it contains no additional personal data.
Deletion upon uninstallation: Upon uninstallation, the Shopify access sessions are deleted first; the remaining data persists briefly so that a quick reinstallation retains the configuration. The complete deletion of all shop and creator data (including redemptions, creator CRM, attribution, and support chat) takes place immediately upon receipt of the SHOP_REDACT compliance webhook, which Shopify sends approximately 48 hours after uninstallation, via cascade delete in a single transaction.
Erasure request for individual creators (CUSTOMERS_REDACT): Immediately upon receipt of the webhook, the creator’s redemption records are anonymised (the name is replaced with “REDACTED”; email address, social handles, any transient shipping address, post URL, and discount code are removed; the creatorKey is emptied) and creator notes, content links, and attribution records are fully deleted. Business figures without personal reference (order reference, merchandise value, campaign) are retained. For creators without an email address known to Shopify, the App provides the merchant with a dedicated erasure path in the creator CRM that performs the same anonymisation.
GiftLink implements appropriate technical and organisational measures under Art. 32 GDPR:
• TLS encryption for all data transmissions
• Gift link tokens are held in the database only as a SHA-256 hash (lookup) and as an AES-256-GCM-encrypted value for re-display; the key is derived via HKDF and never stored
• HMAC verification of all incoming webhooks (Shopify; Slack additionally with replay protection)
• Rate limiting on multiple levels (ephemeral, in memory; email addresses there only as SHA-256 hashes)
• Honeypot field against automated form submissions and request size limits
• Cross-shop isolation via shopId scoping on all database queries
• Restrictive security headers and cache prohibitions on the public form; noindex
• PII-free logging: email addresses are masked in logs, query strings and gift tokens are stripped from server logs, errors are logged without raw data
• Encrypted database backups at the hosting provider
• Access to personal data restricted to authorised personnel only
GiftLink does not carry out any automated individual decisions within the meaning of Art. 22 GDPR and performs no profiling and no fraud scoring. Where the approval queue is enabled, the decision to approve or reject a redemption is made manually by the merchant. The only automated rule is a deadline rule: approval requests the merchant has not decided on within 30 days are rejected automatically, and the transiently stored shipping address is deleted (data minimisation); the creator is informed by email.
GiftLink is directed at businesses (merchants) and the influencers/creators they select. The App does not knowingly collect data from minors and is not directed at children under 16 within the meaning of Art. 8 GDPR. Selecting the invited creators and any age verification are the merchant’s responsibility.
Influencers/creators have the following rights vis-à-vis the merchant as controller:
• Right of access (Art. 15 GDPR)
• Right to rectification (Art. 16 GDPR)
• Right to erasure (Art. 17 GDPR)
• Right to restriction of processing (Art. 18 GDPR)
• Right to data portability (Art. 20 GDPR)
• Right to object (Art. 21 GDPR)
• Right to withdraw consent (Art. 7(3) GDPR) - particularly relevant here for the UGC/repost consent
Requests can be made via the merchant (primary route) or directly to the processor at [email protected]. Erasure requests arriving through Shopify (CUSTOMERS_REDACT) are handled automatically (see Section 13); access requests (CUSTOMERS_DATA_REQUEST) are logged, and the merchant answers them based on the data available in the App. Responses are provided within the deadline set by Art. 12(3) GDPR (generally 30 days).
Data subjects have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for Timmgard GmbH is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestr. 2-4
40213 Düsseldorf
Germany
Timmgard GmbH is not required to appoint a data protection officer under Section 38(1) of the German Federal Data Protection Act (BDSG) because it has fewer than 250 staff and no core activity involving large-scale regular monitoring or the processing of special categories of data. Privacy requests are handled centrally at [email protected] and answered within the statutory deadlines (Art. 12(3) GDPR, generally no longer than 30 days).
This privacy policy may be updated when processing changes or legal requirements so require. The current version is always available at this URL. Version date: 12 August 2026.