Privacy Policy
Last updated June 2026
The short version
Nifty is a place to keep gift wishlists and share them with people you choose. We collect only what we need to run the service, we never sell your data, and you control what other people can see. This policy also covers our “Save to Wishlist” browser extension — see the dedicated section below.
What we collect
- Account info: your email address, and optionally a display name, username, avatar, and birthday.
- Content you create: wishlists and items, comments and reactions, your “All About Me” gift profile, gift exchanges, and any shipping address you add.
- Technical data: cookies needed to keep you signed in, plus basic device and log information used for security and reliability.
How we use it
To provide and improve the service, to send the notifications and emails you’ve opted into (you can turn these off any time in your settings), and to keep accounts secure. We do not use your data for advertising and we do not sell it.
Who can see your information
Your wishlists are visible only to the people you share them with — friends, circles, or anyone holding a share link you create. There are no public profiles and no storefront. To keep gifts a surprise, list owners never see who claimed or bought an item.
We use trusted service providers to operate Nifty: Supabase (database, authentication, file storage), Vercel (hosting), and Resend (transactional email). They process data on our behalf under their own security commitments.
How we store & protect your data
Data is transmitted over encrypted HTTPS connections and stored encrypted at rest by our infrastructure providers. We keep your account and content for as long as your account is active; when you delete an item or your account, the associated content is removed. We do not sell your data or share it with advertisers or data brokers.
Your choices
- Edit or remove your profile details at any time.
- Control which emails you receive, and set your email-address visibility, in settings.
- Export a copy of your data from your account.
- Delete your account, which removes your lists and content.
- Depending on where you live, you may have rights to access, correct, delete, or port your data (for example under the GDPR in the EEA/UK or the CCPA in California). Email us to make a request.
The “Save to Wishlist” browser extension
Our “Save to Wishlist” browser extension adds a toolbar button (and a keyboard shortcut) that saves the product page you’re viewing to one of your Nifty wishlists. It works only with your own Nifty account, and it runs only when you invoke it — it does not run in the background, monitor your browsing, or act on pages you haven’t asked it to. The “Children,” “Changes,” and “Contact” sections at the end of this policy also apply to the extension.
Extension — what it collects
The extension accesses the following, and only at the moment you click its toolbar button or press its keyboard shortcut on a page:
- The current tab’s address and title— to record what you’re saving and fetch its details. (Web history / user activity for the single page you act on, never your browsing history as a whole.)
- Product details read from that page— title, image, price, currency, and a short description, extracted from the page’s own visible content and structured data by a script the extension runs on that one page. (Website content.)
- Your Nifty sign-in session— requests to Nifty include your existing Nifty session cookie so the extension can act as you on your own account. It never sees, stores, or transmits your password. (Authentication information.)
- Anything you type into the save form — for example a note, or an edited title or price — before you press Save.
- One setting — the Nifty app address the extension talks to, saved with the browser’s
storageAPI. No personal data, page content, or browsing history is ever stored inside the extension.
The extension does not collect your location, contacts, financial or payment details, health data, or personal communications, and it contains no third-party analytics, advertising, or tracking code.
Extension — how it’s used
The page address and the details read from it are used for a single purpose: to preview the item and save it to the wishlist you choose. Your session cookie is used only to authenticate you to your own Nifty account, and the saved app-address setting only tells the extension which Nifty server to contact. None of it is used for advertising, profiling, or any purpose unrelated to saving items to your wishlist.
Extension — how it’s stored & secured
- In the extension: the only thing stored is the app-address setting, kept by the browser’s
storageAPI (which may sync it across your own signed-in browser profiles). No saved items, page content, or browsing history are stored in the extension. - On Nifty’s servers: items you save are stored in your Nifty account in our database and kept until you delete the item or your account.
- In transit and at rest: all communication between the extension and Nifty happens over an encrypted HTTPS connection, and data stored in the Nifty database is encrypted at rest.
Extension — who it’s shared with
The information above is sent only to your own Nifty backend (app.nifty.gift). To operate that service, Nifty relies on infrastructure providers that process the data on our behalf under their own security commitments — Supabase (database, authentication, file storage) and Vercel (hosting). We do not sell, rent, or share your data with advertisers, data brokers, analytics companies, or any other third party.
Extension — permissions & Limited Use
activeTab— temporary access to the current tab, granted only when you invoke the extension, to read that page’s address and title and run the product reader on it.scripting— to run the product reader on the page you’re saving so it can pull the title, image, and price.storage— to remember the single app-address setting.- Host access — to send the item you save to your Nifty backend.
Save to Wishlist’s collection and use of information from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not sell or transfer your data to third parties such as advertising platforms, data brokers, or information resellers; we do not use or transfer it for any purpose unrelated to saving items to your wishlist; and we do not use or transfer it to determine creditworthiness, for lending, or for personalized or interest-based advertising.
Children & managed accounts
A parent or guardian can create and manage an account on behalf of a child. The managing adult controls that account’s sign-in and content. Nifty is not directed at children under 13 acting on their own, and we do not knowingly collect personal information from children under 13.
Changes & contact
We’ll post any material changes to this page and update the date above. Questions about privacy, or a data request? Email privacy@nifty.gift.
