Skip to content

Draft. This text is awaiting legal review and the operator's details.

Privacy policy

Last changed: September 26, 2026

A gift starts from a personal story, so we handle data carefully. This policy explains what personal data we process when you use Daymaker, why, who we share it with, and the rights you have under the General Data Protection Regulation (GDPR).

1. Controller

Data controller: ReachMe media s. r. o.

Registered office: Námestie Osloboditeľov 3784/3B, 040 01 Košice - mestská časť Juh

Company ID (IČO): 55615643

Registered in: Obchodnom registri Mestského súdu Košice, oddiel Sro, vložka č. 57269/V

Email: hello@daymaker.gift

The controller operates the Daymaker service at daymaker.gift and decides for what purposes and by what means your personal data is processed.

2. What data we process

We process only the data we need to make and deliver your gift and to run the service securely:

Account data: your email address, your chosen language and your name, if you give it to us.

Your story: the recipient's name or nickname, your relationship to them, the occasion and its date, their traits, memories, places, inside jokes and other details you write, as well as the mood, style and language you choose for the gift.

Photos: for gifts that need them, the photos you upload. They may show your face and the faces of other people.

Consents: a record of what you agreed to, in which wording, when, from which IP address and from which browser.

The gift page: the signature, dedication and page settings. We store the PIN only as an irreversible fingerprint (hash), never in readable form.

Order and payment: what you ordered, the price, any discount, the status of the payment and of any refund, and billing details (name, address and, where applicable, VAT number) if the payment page asks for them. Card details are handled by Stripe and never reach us.

Communication: the messages you exchange with us, for example about a complaint or a request concerning your personal data.

Technical data: IP address, browser details and access logs we need to run the service securely and to prevent abuse, for example to limit the number of attempts at entering a PIN.

Order statistics: at steps such as opening checkout or paying, we record in our database which gift and which step was involved. They contain nothing from your story.

Website usage data, only with your consent in the cookie bar: which pages you visited, which gifts you looked at and bought and for how much, your device and browser type, your approximate location from your IP address and identifiers from the cookies of the analytics and marketing tools (section 6). They contain nothing from your story, no photos and no links to gift pages.

We do not collect data about the recipient and other people in your story and photos from them, but from you. So only write what you are free to share about them.

If you are the recipient opening a gift page, we process only the technical data needed to show and protect it (for example your IP address when you enter a PIN) and a cookie that remembers a correctly entered PIN.

4. Payment processing

Payments are processed by Stripe. Stripe processes your payment data as an independent controller under its own privacy terms and the applicable card security standards. We receive only confirmation of payment and basic order details, not your full card number. We do not store your full card details on our servers.

5. Email delivery

We use Resend to send email. Through it we send sign-in codes, order confirmations and messages about a failed payment, a refund and a finished gift. Your email address and the content of these messages are shared with this provider only to deliver them.

We do not currently send newsletters or other marketing emails, so we use no service for them either.

6. Cookies and browser storage

We group cookies into three categories:

Necessary: needed for the service to work, and therefore always on. These are only our own cookies:

dm_locale: remembers your chosen language (1 year);

dm_guest: links a gift in progress to your browser until you sign in (60 days);

logto_…: keeps you signed in (14 days);

dm_return_to: takes you back to where you were after signing in (15 minutes);

dm_gift_…: remembers that you entered the correct PIN on a gift page (30 days);

dm_consent (in browser storage): remembers your choice in the cookie bar (1 year, after which we ask again).

Analytics, only with your consent: Google Analytics 4 by Google Ireland Limited. It shows us which pages are read and where visitors leave. Cookies _ga and _ga_… (2 years). We keep data in Google Analytics for 14 months.

Marketing, only with your consent: the Meta pixel by Meta Platforms Ireland Limited. It measures which Facebook or Instagram ad brought a visitor to us and whether they bought a gift. Cookies _fbp and _fbc (3 months). Meta may also set its own cookies on its own domain under its policies.

Both tools load through Google Tag Manager, and only after you consent in the cookie bar. Until you do, none of them loads, not even Tag Manager itself. The page addresses sent to the tools are stripped of order and project numbers, and nothing is measured on gift pages. You can change or withdraw your consent at any time through the Cookie settings link in the page footer; we then delete the cookies of the withdrawn category from our domain.

Order statistics (section 2) are recorded directly on our server, without cookies and without third-party services.

Our sign-in service at auth.daymaker.gift uses its own necessary cookies while you sign in. Cloudflare, through which the service is delivered, may set technical cookies to protect the site, for example when checking that you are not a robot. The Stripe payment page uses its own cookies under that company's policy.

We also save a gift in progress in your browser's local storage so nothing gets lost. It reaches our server only when you upload photos or save the gift. It stays in your browser until you delete it in the browser's settings.

7. Who we share data with

We do not sell your personal data. We share it only with the processors and partners who help us run the service, and with each only what it needs for its part of the work:

Hetzner Online GmbH: server, database and file storage, including photos and finished gifts (in the European Union);

Cloudflare: content delivery and protecting the site from attacks and abuse;

Google (Google Ireland Limited): measuring visits through Google Analytics and Google Tag Manager, only with your consent;

Meta (Meta Platforms Ireland Limited): measuring advertising through the Meta pixel, only with your consent. For collecting and passing on the pixel data we are joint controllers with Meta; Meta then processes it as an independent controller under its own policy;

Stripe: payment processing (as an independent controller, see section 4);

Resend: sending email, including sign-in codes;

Anthropic: writes the text of gifts (song lyrics, stories and dedications) and the briefs for images and video; it receives data from your story, not your photos;

Higgsfield: makes images and videos; it receives a text brief and, for gifts made from photos, your photos, and only with your consent;

Suno: a music tool in which a member of our team makes the music from the song lyrics and the chosen style; it receives the lyrics, which may contain names and details from your story.

Authorised members of our team also take part in making and checking gifts. They have access to data only as far as their work requires.

We conclude data processing agreements with our processors, as the GDPR requires. We may also disclose data to public authorities where the law requires us to.

8. Transfers outside the EU

Some of these providers are based in, or process data in, countries outside the European Economic Area (EEA), mainly the USA. Such transfers take place only on the basis of appropriate safeguards: an adequacy decision of the European Commission (for example for companies that participate in the EU-US Data Privacy Framework) or standard contractual clauses approved by the European Commission.

You can ask us for more information about these safeguards at hello@daymaker.gift.

9. How long we keep data

We keep personal data only as long as needed for the purpose it was collected for:

A gift in progress you saved without signing in: we delete it, together with its photos, 90 days after it was last changed, unless you sign in by then.

Original uploaded photos: we delete them at the latest 12 months after the project was last changed. This does not affect the finished gift.

Your account, stories and finished gifts: while you have an account, or until you ask us to delete them.

Orders, invoices and related accounting records: 10 years, as accounting law requires.

Records of consents: for as long as we may need to prove that we obtained the consent.

Attempt counters with IP addresses, used to prevent abuse: 1 day.

Data processed on the basis of consent is kept until you withdraw it or the purpose ends. Once the relevant period is over, we securely delete or anonymise the data; it may remain in database backups for a short time until they are overwritten.

10. Your rights

Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict its processing, to data portability, and to object to processing based on our legitimate interest. Where processing is based on your consent, you can withdraw it at any time; this does not affect the lawfulness of processing before the withdrawal.

To exercise any of your rights, email hello@daymaker.gift. We reply without undue delay, and at the latest within one month.

You also have the right to lodge a complaint with the supervisory authority, the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Hraničná 12, 820 07 Bratislava 27, www.dataprotection.gov.sk.

11. Data security

We use appropriate technical and organisational measures to protect personal data: encrypted connections, private file storage that can only be reached through short-lived links, and access to data only for people who need it for their work. No method of transmission over the internet and no method of electronic storage is completely secure, however, so we cannot guarantee absolute security.

12. Children

Only people over 18 may place orders. Only upload photos of children with the consent of their parent or guardian.

13. Changes to this policy

We may update this policy. The current version is always available on this page, with the date of the last change shown above.

14. Contact

For any question or request about your personal data, email hello@daymaker.gift.