Keepsake

Privacy

How we handle what you give us, written to be read. The short version is in section 2, and it is the whole truth of it.

Privacy Policy
GRADUAL AXE LABS S.R.L. · Version 1.0 · Effective from the date of first publication of this page

1Who we are

Keepsake is operated by GRADUAL AXE LABS S.R.L., a company registered in Romania.

Registered nameGRADUAL AXE LABS S.R.L.
Registered officeStrada Brașov 25L, bloc B4, scara A, et. 7, ap. 35, cam. 1, sector 6, București 061444, Romania
Trade register numberJ2026051680004
Tax identification (CUI)55488910
Email[email protected]
Privacy contact[email protected]

We are the data controller for the personal data described in this policy. Our lead supervisory authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).

2The short version

In one paragraphYou choose a photograph and a few words. Your phone turns them into the image for an Apple Wallet pass, and your original photograph never leaves it. We sign the finished pass, email it to you, and keep no copy. We keep your email address and a record of what you bought, because accounting law requires us to. We do not sell anything to anyone, we do not advertise, we do not track you across the internet, we do not analyse what is in your photograph, and there is no account to delete because there was never an account.

Everything below is the same statement in the detail the law requires. If any part of it is unclear, that is a failure on our side, write to [email protected] and we will explain it in plain words.

3What we collect, and why

In one sentenceAlmost all of it is the thing you are buying; the rest is your email address and what accounting law requires us to keep.
WhatWhyLegal basisKept for
The finished pass image, made on your phone from your photograph (the original never reaches us)To sign and deliver your keepsake. Nothing else.Performance of a contract, Art. 6(1)(b)Only while it is signed and sent; for a gift, until it is opened (§5)
The name, engraving and words on the backThey are printed on the pass, and appear in the emails we send you.Art. 6(1)(b)Same as the pass; the email text is also kept by our email provider for 45 days (§6)
If you add a button: the song link, and the phone number for a Call buttonThey go into the pass, so the buttons under it work. Nothing else.Art. 6(1)(b)Only inside the pass, like the words on it: not kept for a keepsake you keep for yourself; for a gift, inside the stored pass until it is opened, at most 90 days from sending (§5)
Your email addressTo send you your keepsake and your receipt. With no accounts, this is the only way you ever get it.Art. 6(1)(b); and legal obligation for the receipt, Art. 6(1)(c)10 years (accounting law)
Order record, what you bought, when, how muchRomanian accounting law requires it.Legal obligation, Art. 6(1)(c)10 years
Your country, from your connectionTo show the right price and currency, and to decline payment where we cannot sell.Legitimate interests, Art. 6(1)(f)Not stored: it is read on each visit. If our EU sales pass the €10,000 threshold, VAT rules will require us to keep evidence of your country, and this row will say so.
For a gift: the recipient’s name and email, and your name as the sender and your note, if you add themTo deliver the gift, tell you when it was opened, and remind you once if it wasn’t.Art. 6(1)(b)The email address is used once and not kept once the gift email has gone; for a gift scheduled for a later date, held sealed until that morning. The names and note are kept with the gift record, so its link can show who it is from, and deleted 90 days after sending, opened or not.
Basic technical logs, IP address, browser, timestampsKeeping the service running and stopping fraudulent payments.Legitimate interests, Art. 6(1)(f)30 days

We do not collect: your name (unless you write it on a keepsake or sign a gift with it), your address, your phone number (unless you put one on a Call button, above), your date of birth, or your card details. Card details go directly to our payment provider and never reach us.

Showing you the song’s name. When you paste a song link, we ask that music service (Spotify, YouTube or SoundCloud) for the song’s title and cover, so you can check it’s the right one. Only the link is sent, and nothing is kept.

We do not do: advertising, profiling, automated decision-making with legal effects, selling or sharing personal data, or training any machine-learning model on anything you give us.

One small exception, and only for buyers: the emails we send you about your order can end with a short invitation to make another keepsake or send one as a gift. That is direct marketing of our own similar products to our own customers, which the law allows without asking first, as long as you can refuse at any moment (ePrivacy Directive art. 13(2); Romanian Law 506/2004 art. 12(2)). Tap “Turn off” on the checkout screen, or use “Turn off these suggestions” in any email, and it stops for good. We keep only a coded fingerprint of your address to remember that choice. We never add this to emails sent to someone receiving a gift, or to anything about a keepsake made in memory of someone.

4Your photograph

In one sentenceIt never leaves your phone. Your phone crops it and builds the pass image, and only that finished image reaches us.

A photograph is different from the rest of the information here, so it gets its own section.

What we do with it

Your own browser resizes and crops it to the dimensions Apple Wallet requires. The original stays on your phone and is never uploaded; only the finished pass image is sent to us, to be signed and delivered. The crop is the one you chose; we do not adjust it for you.

What we do not do with it
Photographs of other people

When you upload a photograph of somebody else, you are asking us to process their personal data on your instruction. Our terms require you to confirm you have the right to do so. If you are in a photograph someone else has used and you want it dealt with, write to [email protected], although we never hold the original, and once a keepsake is delivered there is nothing left with us to act on. An unopened gift is the exception, and we can take it down (Terms §9).

Photographs of people who have died

Under EU data protection law, information about a person who has died is not personal data (GDPR Recital 27), and Romania has not made separate rules for it. Some countries, including Spain, France, Italy, Denmark and Portugal, give family members specific rights over a deceased person’s data. We apply the same deletion rules whether the person in the photograph is living or not, so in almost every case there is nothing held that anyone could ask us to remove. If you are next of kin and want to make a request anyway, we will treat it exactly as we treat any other request in section 9.

5How long we keep things

In one sentenceWe never receive your photograph; the order record has to stay for ten years; everything in between is measured in days.
ItemRetentionWhy that long
Your original photographNever uploadedIt stays on your phone. We never receive it.
The finished pass, when you buy it for yourselfNot retainedIt is attached to your receipt email. Your inbox holds the only copies, which is why that email matters.
The finished pass, and the preview image shown on the claim page, when you send it as a giftUntil opened, at most 90 days from sendingThe recipient has not received it yet. The preview image is removed the moment the gift is opened, and the pass within 48 hours; unopened, deleted at 90 days. A gift scheduled for a later date is made at purchase, while your photo is still on your phone, and held sealed until its morning; its 90 days start when it is sent.
Your draft, while you are making it7 days, on your own deviceHeld in your browser so a dropped connection does not lose your work. Never sent to us. Kept for 7 days after purchase so a free remake can start from what you made, then cleared.
An email we could not deliverUp to 30 daysIf an email bounces or is refused, we keep that one message, pass included, so we can send it again, then delete it.
The text of the emails we send45 days, at our email providerPostmark keeps each message’s text (not its attachments) for 45 days for delivery and abuse checks. It cannot be switched off.
Email address and order record10 yearsRomanian accounting law. We cannot delete this on request, and neither can anyone else.
Your “no suggestions” choice, if you make itFor goodSo the choice holds for every later email. Only a coded fingerprint of your address is kept, never the address itself.
Technical logs30 daysLong enough to investigate a fault or a fraudulent payment.

Deleted means deleted. Files are removed from live storage immediately and from backups within 30 days as those backups rotate.

6Who else is involved

In one sentenceFive companies help us run this, each does one job, and none of them may use your data for anything of their own.
WhoWhat they doWhere
Stripe Payments Europe, Ltd.Takes the payment. Holds your card details; we never see them.Ireland
Postmark (ActiveCampaign, LLC)Sends your receipt with the keepsake attached, and gift emails; keeps the text of each email for 45 days.United States
Cloudflare, Inc.Runs the website and builds the pass file.United States (global edge network)
ZohoRuns our hello@ mailbox, where your emails to us arrive.European Union (Zoho’s EU data centres)
Apple Inc.Apple Wallet itself, once the pass is on your phone. Governed by Apple’s privacy policy, not ours.United States

Each is bound by a written data processing agreement under Article 28 GDPR. We do not sell, rent, share or trade personal data with anybody, and we have no advertising, analytics or marketing partners of any kind.

We would disclose data if a court or a competent authority lawfully required it. We would tell you if we were permitted to.

7Cookies and storage

In one sentenceThere is no cookie banner because there is nothing to consent to.

Keepsake uses no advertising cookies, no analytics cookies and no third-party tracking of any kind. There is nothing that follows you to another website and nothing that builds a profile of you.

One thing is stored on your device, strictly necessary to provide the service you asked for, and therefore exempt from the consent requirement under the ePrivacy Directive:

We set no cookies at all. The payment page is Stripe’s own, and any cookies there are set by Stripe under its privacy policy. You can clear what we store at any time through your browser; it loses your unfinished work, and nothing else happens.

8Where your data goes

In one sentenceOur systems run on a global network; where a provider is outside the EEA, the transfer is covered by the safeguards the law requires.

Our systems run on Cloudflare’s global network, including the small amount of gift data we hold, so data may be processed wherever Cloudflare operates. Where a provider named in section 6 processes data outside the EEA, that transfer relies on one of:

For customers in Australia, this section is our disclosure under Australian Privacy Principle 8. You can ask us for a copy of the safeguards in place at [email protected].

9Your rights

In one sentenceWrite to [email protected]; we answer within 30 days; there is no charge and no form to fill in.

If you are in the EU or EEA, you have the right to: access a copy of what we hold; correct anything wrong; erase data where we have no overriding reason to keep it; restrict or object to processing based on legitimate interests; receive your data in a portable format; and complain to a supervisory authority.

What you should expect in practice

Because we hold so little, most requests are quick and slightly anticlimactic. If you ask what we have about you, the honest answer for most people is: an email address and one order record. We never had the photograph.

The one thing we cannot delete is the order record, for ten years, because Romanian accounting law requires it and a request cannot override a legal obligation. Everything else, we can and will.

How to ask

Email [email protected] from the address you used to buy, or tell us the reference number from your receipt. We reply within 30 days, and if a request is genuinely complex we will tell you before that deadline rather than after it.

If we get it wrong

You can complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or to the authority in your own country. You do not have to come to us first, though we would rather you did.

10Country-specific rights

United States
For California, and the nineteen other states with a privacy lawWe do not sell your personal information and we do not share it for cross-context behavioural advertising. We never have. There is nothing to opt out of, but the rights below are yours regardless.

If you live in California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia or Washington, you have the right to know what we collect, to get a copy, to correct it, to delete it, and not to be discriminated against for asking. Section 3 is our notice at collection; section 9 is how to exercise any of it.

Universal opt-out signals. We honour Global Privacy Control and equivalent browser signals. Since we do not sell or share data, the signal has nothing to act on, but it is respected rather than ignored.

Biometric information. We do not collect, capture, store, transmit or use biometric identifiers or biometric information, including scans of facial geometry. This is a deliberate design choice, not an omission, and it is stated here so it can be relied upon in Illinois, Texas and Washington.

Sensitive personal information. We do not collect it, and we do not use or disclose personal information for purposes to which a right to limit would apply.

Canada

We rely on your meaningful consent, given by choosing to make a keepsake after reading this policy. Under PIPEDA you may access and correct your information and complain to the Office of the Privacy Commissioner. If you are in Quebec, you additionally have the right to data portability and the right to be informed of automated decision-making, of which we do none. Our privacy contact under Law 25 is [email protected].

Australia and New Zealand

We handle personal information in accordance with the Australian Privacy Principles and the New Zealand Privacy Act 2020. Section 8 is our APP 8 disclosure about overseas recipients. You may complain to the OAIC or to the New Zealand Privacy Commissioner.

11Children

In one sentenceKeepsake is not for children, and we do not knowingly take their data.

Keepsake is intended for people aged 16 or over. We do not knowingly collect personal data from anyone younger, and we do not direct the service at children. If you believe a child has used Keepsake, write to [email protected] and we will delete what we hold.

For the United States: Keepsake is not directed to children under 13, and we do not knowingly collect personal information from them (COPPA).

Photographs of children are a different matter. A grandparent making a keepsake of a grandchild is exactly who this is for. What matters is that the person buying it is an adult and has the right to use the photograph, which our terms require you to confirm.

12Changes to this policy

If we change anything that affects you, we will update the version and date at the top and, where the change is significant, email everyone who has bought in the previous twelve months. We will not make a change that applies retroactively to data we have already deleted, because there would be nothing to apply it to.

GRADUAL AXE LABS S.R.L. · Strada Brașov 25L, bloc B4, scara A, et. 7, ap. 35, cam. 1, sector 6, București 061444, Romania · [email protected]
Keepsake is an independent service, not affiliated with, endorsed by or sponsored by Apple Inc. Apple Wallet, Apple Pay and iPhone are trademarks of Apple Inc.