Privacy policy
Version in force from 1 August 2026. This privacy policy describes how Swigift processes personal data in accordance with the Federal Act on Data Protection (revFADP) and, for individuals located in the EU, the GDPR.
1. Data controller
Swigift Varin, Chemin de la Fenatte 12, 2824 Vicques (Val Terbi) – UID: CHE-309.525.138 (full contact details in the legal notice) – is responsible for processing the data collected via the swigift.ch website. Contact: see the Contact page.
2. Collected data
During an order: name, email address, telephone number, voucher content (message, optional photo), recipient's contact details where applicable, and delivery data. During a partnership request: business identity, contact details, IBAN (encrypted at rest), transmitted media, as well as the date, partially anonymised IP address and version of the terms and conditions upon acceptance. When using the contact form: name, email and message.
3. Purposes
Execution of orders (generation and sending of vouchers, transactional emails), management of partnerships (validation, payouts), response to contact requests, compliance with legal obligations (accounting, proof), and – with your consent – audience measurement and advertising.
4. Payment (Stripe)
Payments are processed by Stripe Payments Europe Ltd. Swigift does not store any card numbers. Stripe processes your payment data as a processor; see Stripe's privacy policy.
5. Cookies and similar technologies
The site uses strictly necessary cookies (shopping basket, checkout session) which do not require consent, as well as local storage in your browser for preferences (favourites, display). Audience measurement and advertising cookies (e.g. Google Analytics, Meta) may be used only if you accept them via the consent banner; you can change your choice at any time by clearing your browser's site data.
6. Data disclosure
The data required to redeem a voucher (code, service, amount) is sent to the issuing partner. No data is sold to third parties. Technical service providers (web hosting, email, payment) may process data on behalf of Swigift, under contracts that comply with the nLPD/GDPR.
7. Conservation
Order data is kept for the time necessary to perform the contract and then for the statutory retention periods (10 years for accounting records, Art. 958f CO). The PDF vouchers are automatically purged after their retention period.
8. Safety
TLS encryption in transit, IBANs encrypted at rest (AES-256), sensitive files stored out of public access and served via time-limited signed links.
9. Your rights
You have the right to access, rectify, erase, object to the processing of, and receive a copy of your data (Art. 25 et seq. of the new Data Protection Act; Art. 15 et seq. of the GDPR where applicable). You may exercise these rights via the Contact page. You may also refer the matter to the Federal Data Protection and Information Commissioner (FDPIC).
10. Modifications
This policy may be adapted, in particular when new measurement or advertising tools are added. The version published on this page shall prevail.
