Privacy Policy
Last updated: 29 June 2026
greeting.bg respects your privacy. This Policy explains what personal data we collect when you use the site and order a personalized greeting, how we use it, who we share it with, and what rights you have under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Bulgarian Personal Data Protection Act.
This English text is a convenience translation. The Bulgarian version at greeting.bg/privacy is the legally binding one; in case of any discrepancy, the Bulgarian text prevails.
1. Data controller
For questions about the protection of your personal data, write to privacy@greeting.bg. For general enquiries: contact@greeting.bg.
Given the nature and scale of our activity, we are not required to appoint a data protection officer. For anything concerning your personal data, please use the addresses above.
2. What personal data we process
When you order a greeting through the site, we process the following data:
- Contact details: name and email address (required); phone number (optional).
- Order details:type of greeting, chosen style, occasion, the recipient’s name (“who for”), the sender (“from whom”, optional) and the free text describing the occasion.
- Payment data: when you pay, your information (including payment details) is processed directly by Stripe. We never receive or store card numbers.
- Technical data: IP address and related technical signals (e.g. user agent), used to protect against abuse and automated requests.
- Usage data (analytics):with your consent — data from Google Analytics 4 about how you use the site (pages viewed, actions taken, device type, approximate location). Until consent is given, we process only limited, non-identifying technical signals without cookies, for aggregated statistics. See the “Cookies” section below.
The description of the occasion and the recipient details may contain personal data about other people (e.g. names or details of private memories). Please provide only information you are entitled to share, and do not enter sensitive data (e.g. about health, ethnic origin, religious or political views) — none of it is needed to make your greeting.
3. Purposes and legal bases for processing
We process your personal data for the following purposes, on the following legal bases under Art. 6(1) GDPR:
- Fulfilling your order and delivering the finished greeting — performance of a contract or steps taken before entering into one (point (b)).
- Communicating with you about your order, including clarifying details and sending the finished greeting — performance of a contract (point (b)).
- Payment and invoicing through Stripe — performance of a contract (point (b)) and compliance with accounting and tax obligations (point (c)).
- Security — protecting the site from abuse, fraud and automated requests (Cloudflare Turnstile, per-IP rate limiting) — our legitimate interest in keeping the service secure (point (f)).
- Compliance with legal obligations — accounting, tax, and official requests from competent authorities (point (c)).
- Traffic analysis through Google Analytics 4 — for cookies and identifiers, on the basis of your consent (point (a)). Until consent is given, GA runs in a mode without cookies or identifiers (Consent Mode), and we process only limited technical data for aggregated, non-identifying statistics — on the basis of our legitimate interest in measuring traffic (point (f)). You can withdraw your consent or object at any time.
- Third-party data in your description — we process it in order to fulfil your order (legitimate interest, point (f)), and it is your responsibility to have a basis for providing it.
We do not send marketing messages and do not use your data for marketing without your explicit consent.
4. Recipients and processors
To provide the service, we share personal data with carefully selected providers, who process it on our behalf or as independent controllers:
- Resend (Resend, Inc.) — sending email; your order is forwarded to our team by email.
- Cloudflare (Cloudflare, Inc.) — the Turnstile bot-protection service, which processes your IP address and technical signals.
- Stripe (Stripe Payments Europe, Limited and affiliated companies) — payment processing and invoicing.
- Vercel (Vercel Inc.) — hosting and serving the site.
- Google (Google Ireland Limited) — Google Analytics 4 for traffic analysis. With your consent it sets analytics cookies; without consent it processes only limited technical data with no identifiers.
- Competent public authorities — only where required by law.
We do not sell personal data and do not provide it to third parties for their own marketing purposes.
5. Transfers outside the EEA
Some of the providers listed above (Resend, Cloudflare, Stripe, Vercel, Google) may process data outside the European Economic Area, including in the United States. In those cases the transfer is protected by appropriate safeguards within the meaning of Art. 46 GDPR — certification under the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses adopted by the European Commission.
6. Retention periods
We keep your personal data only for as long as is necessary for the purposes it was collected for:
- enquiries that do not lead to an order, and the correspondence about them — up to 12 months;
- data relating to completed orders — for the duration of fulfilment and a reasonable period afterwards, in view of possible complaints and claims;
- accounting documents (e.g. invoices) — for the periods laid down in the Bulgarian Accountancy Act and tax legislation;
- technical security records (e.g. IP addresses) — for the short period needed for security purposes.
Once the relevant period expires, the data is deleted or anonymized.
7. Your rights
Under the GDPR you have the following rights in relation to your personal data:
- the right of access to your data;
- the right to rectification of inaccurate data;
- the right to erasure (the “right to be forgotten”);
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing based on legitimate interest;
- the right to withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise these rights, write to us at privacy@greeting.bg. We will respond within one month, which may be extended where necessary in accordance with the GDPR. Exercising your rights is free of charge, except in the cases provided for by law.
8. Right to lodge a complaint with a supervisory authority
If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the supervisory authority:
Commission for Personal Data Protection (CPDP), Bulgaria
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Phone: +359 2 915 3555
Email: kzld@cpdp.bg
Website: www.cpdp.bg
Before that, you are welcome to contact us at privacy@greeting.bg — we will be glad to help.
9. Data security
We apply appropriate technical and organizational measures to protect your personal data — including an encrypted connection (HTTPS), restricted access to the data, and working with trusted providers. No method of transmission or storage is completely secure, however, so we cannot guarantee absolute security.
11. Children's personal data
The service is intended for adults who are able to enter into contracts. We do not knowingly collect personal data from children. If we find that we have collected such data without the necessary consent, we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. The current version is always available on this page, with the date of the last update shown at the top.
Questions about this Policy or about how we handle your personal data: privacy@greeting.bg.