This policy explains how GreetingHQ handles personal information. We collect only the information reasonably needed to provide group cards, manage accounts and payments, protect the service and improve how it works.
1. Who we are
GreetingHQ is operated by Dowsett Rogers Pty Ltd in Melbourne, Australia. References to “GreetingHQ”, “we”, “us” and “our” mean the service and its operator.
If you have a privacy question, request or complaint, use our contact page.
2. Information we collect
The information we collect depends on how you use GreetingHQ and may include:
- Account and organisation information: your name, email address, username, authentication details, organisation name, role, profile settings, notification choices and security preferences.
- Card and contributor information: card titles, recipient names, contributor names and addresses, invitation status, delivery settings, messages, signatures, photos, videos, GIFs and other card content.
- Design information: uploaded card covers, design metadata, visibility choices, AI prompts, reference images, generated concepts and revision activity.
- Billing information: products purchased, currency, amount, promotion code, transaction status, card-credit balance and invoice records. Our payment provider handles complete payment-card details; GreetingHQ does not store them.
- Communications: messages and attachments you send through support or other service communications.
- Technical and usage information: IP address, approximate location, browser and device details, referring page, session activity, feature use, timestamps, diagnostic information and security events.
Please do not include sensitive information in a card or support request unless it is necessary and you understand who may see it.
3. How we collect information
We collect information directly from you when you register, configure an account, create or sign a card, upload content, use an AI tool, make a purchase or contact us.
We may receive information about you from another user, for example when a card organiser enters your name or sends you a contributor invitation. If you provide information about someone else, you must have a reasonable basis to do so and should tell them how the information will be used.
If you sign in with Google or Microsoft, we receive the account information that provider makes available with your permission, such as your name, address and provider account identifier. We also collect some technical and usage information automatically through cookies, logs and similar technologies.
4. How we use information
We use personal information to:
- create and manage accounts, organisations, cards, designs and contributors;
- display card content to organisers, intended contributors and recipients;
- send invitations, delivery messages, account notices, invoices and support responses;
- process payments, promotions, refunds and card-credit balances;
- generate AI card-design concepts and enforce concept, revision and abuse limits;
- select an appropriate pricing currency and remember preferences;
- secure GreetingHQ, prevent fraud and spam, rate-limit activity, investigate misuse and enforce our Terms of use;
- measure performance, diagnose faults and improve features and usability; and
- comply with legal obligations and resolve disputes.
Service messages needed to operate your account or deliver a card may still be sent when optional notifications are disabled. Where we send optional marketing, you can opt out using the control in the message or your account settings.
5. When we share information
We do not sell personal information. We disclose it only where reasonably needed for the purposes above, including:
- With card participants: organisers, contributors and recipients may see names and card content according to the card flow. Anyone with a valid signing link may be able to access the contribution experience.
- Within an organisation: authorised organisation members and administrators may access organisation cards, designs, users, billing information and activity according to their role. A user’s private designs remain visible to that user unless they choose a broader visibility.
- With service providers: hosting, storage, content-delivery, email-delivery, authentication, payment, analytics, security, support and AI-generation providers process information for us under appropriate arrangements. Only prompts and reference images intentionally submitted to an AI design tool are sent for that generation request.
- For public designs: a design deliberately submitted for public use may appear in GreetingHQ’s catalogue after approval. It may be promoted on GreetingHQ social channels only where that promotional option has been selected and approved.
- For legal and safety reasons: we may disclose information where required by law or reasonably necessary to protect people, rights, property or the security of the service.
- Business changes: information may be transferred as part of a merger, financing, restructure or sale, subject to confidentiality and applicable privacy law.
6. Overseas processing
Some providers that help us operate GreetingHQ process or store information outside Australia, including in the United States and other countries where they or their infrastructure operate. Privacy protections in those places may differ from Australian law. We take reasonable steps to select reputable providers, limit the information shared and require it to be handled for the intended purpose.
7. Cookies and analytics
GreetingHQ uses cookies and similar technologies for essential functions such as sign-in, security, session continuity and saved preferences. We may also use analytics to understand aggregate traffic and feature use, diagnose problems and improve the service.
You can control cookies through your browser. Blocking essential cookies may prevent sign-in or other parts of GreetingHQ from working correctly. Third-party sign-in, payment and embedded services may set their own cookies under their privacy policies.
8. Security and retention
We use technical and organisational safeguards designed to protect personal information, including access controls, encryption in transit, authentication controls, logging, restricted administrative access and service monitoring. No online service can guarantee absolute security.
We retain information for as long as reasonably needed to provide GreetingHQ, keep cards available as requested, maintain billing and transaction records, prevent fraud, resolve disputes and meet legal obligations. Retention periods vary by information type. When information is no longer required, we take reasonable steps to delete or de-identify it, subject to secure backups and lawful retention requirements.
9. Your choices and rights
You can update much of your account and organisation information from GreetingHQ’s settings. You may also request access to or correction of personal information we hold, ask us to delete information where applicable, or raise an objection or concern through our contact page. We may need to verify your identity before acting on a request.
You can manage optional notifications in your account. Card organisers can remove pending invitees, and users can delete eligible content or accounts using the controls provided. Some records may remain where retention is required for billing, fraud prevention, disputes or law.
10. Children and third-party links
GreetingHQ is not directed to children under 16. A person under 18 should use the service only with a parent or guardian’s permission and supervision. If you believe a child has provided information without appropriate permission, use our contact page.
GreetingHQ may link to or integrate with third-party services. Their handling of personal information is governed by their own policies, which we encourage you to review.
11. Questions, complaints and changes
For access, correction, deletion or privacy complaints, use our contact page. Please give enough detail for us to understand the issue. We will acknowledge and investigate privacy complaints and respond within a reasonable time.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
We may update this policy when our practices, service or legal obligations change. We will publish the revised policy here and update the date above. Where a change is material, we will take reasonable steps to notify affected users.