Belovity Privacy Policy
Last Updated: September 6, 2026
Table of Contents
- Who We Are and What This Covers
- Information You Give Us
- Information From Google and Facebook Sign-In
- Information Collected Automatically
- Information About People Who Do Not Have Accounts
- Information About Others You Add
- How We Use Information
- Notice at Collection
- How Information Is Shared
- Who Can See Your Content
- Cookies and Similar Technologies
- AI Features
- How We Protect Information
- How Long We Keep Information
- Your Choices and Rights
- US State Privacy Rights
- Canadian Privacy Rights
- International Data Transfers
- Data Breach Notification
- Third-Party Links and Services
- Anti-Phishing Note
- Changes to This Policy
- Contact Us
1. Who We Are and What This Covers
Belovity is operated by Belovity LLC ("Belovity," "we," "us," "our"). This Privacy Policy explains what personal information the Belovity web application and progressive web app (the "Service") collects and how we use it. It also covers our website at belovity.com (the "Site"), where we collect much less; the bullets below marked "on the Site" say what applies there. The Service is offered in the United States (including California) and Canada (including Quebec). It is not directed to, or offered in, the European Economic Area or the United Kingdom.
2. Information You Give Us
- Account data: your first and last name, a derived full name, username, email address, timezone, and the country, region/state/province, and city you enter. We do not collect a phone number, date of birth, gender, or government ID.
- Billing data (only if you subscribe): a Stripe customer identifier, your card's brand (for example, Visa), the last four digits of the card, your subscription's status, price, and renewal or end dates. We never receive or store your full card number, expiry date, or security code — those are entered on Stripe's own pages. Your name and email address are shared with Stripe so it can identify the customer and send receipts. If you enter a billing address at checkout, Stripe holds it; we do not.
- Password: we do not store a password you choose. The Service uses passwordless sign-in, so there is no password login form.
- Location: your city, region, and country are self-declared by you in Settings. We do not derive your location from your IP address.
- Family Page details: name, public URL slug, description, avatar, and cover image.
- Gift List data: Gift List names; Gift List items (name, user-entered price, color, size, SKU, free-text notes, quantity, "most wanted" flag, retailer domain, and product URL); and, where you provide one, a shipping address and recipient name. Gift Lists are sometimes called registries; this policy uses the two terms interchangeably. The notes field is free text, so please avoid putting sensitive information about anyone in it.
- Purchases and gift messages: quantity, the gift-giver names you enter, and free-text gift messages.
- Support requests: the message you write, the subject you select, and any files you attach (up to four).
- Contact-form messages (on the Site): the name, email address, and message you submit through the contact form at belovity.com/contact. It is delivered to us by email; no account is needed and none is created.
- Communications you send us: we keep any communication you send us — support requests, emails, DMCA and removal notices, privacy and billing requests, and any attachments — along with our replies and the email address or account it came from, so that we have a record of the exchange.
3. Information From Google and Facebook Sign-In
If you sign in with Google, we receive your email address, Google user ID, given name, family name, full name, and avatar image URL. If you sign in with Facebook, we receive your email address, Facebook user ID, name, and avatar image URL. In both cases we download and re-host your provider avatar image in our own storage. We do not keep any Google or Facebook access or refresh tokens, so we cannot act on your Google or Facebook account after you sign in.
4. Information Collected Automatically
We want to be candid about what happens automatically.
- Page-view logging: every view of a Family Page or Gift List, including views by signed-out visitors, is logged with the visitor's IP address, browser User-Agent string, a device fingerprint computed from the IP and User-Agent, the signed-in user ID (if any), and the item viewed. This logging happens on every Family Page regardless of its plan. The paid analytics feature controls only whether a family can see these statistics; it does not control whether they are collected.
- Product analytics and session replay: we use PostHog for analytics. It automatically records page views and interactions such as clicks and form inputs, and session replay is on, which means your interactions with pages may be recorded and later replayed by us to debug problems and improve the product.
- Viewer analytics visible to families: on a Family Page with our paid plan, Owners and Admins can see a "People Breakdown" showing each signed-in viewer's avatar, username, and visit counts. If you view a family's page while signed in, that family may be able to see that you did.
- Guest identifier: before you sign in, we assign an anonymous analytics identifier and later link it to your account when you sign in.
- Timezone: we read and store your browser's timezone on page load.
- Email open and click tracking: we record when our emails are opened and when links in them are clicked.
- Audit trail: we keep an audit log of changes to records, which includes prior and new values, IP address, and User-Agent.
- On the Site: we run the same analytics product in cookieless mode, which stores no identifier on your device and no persistent profile. Session replay is not enabled on the Site. Page-view logging, the guest identifier, viewer analytics, and the audit trail described above are Service features and do not run on the Site.
5. Information About People Who Do Not Have Accounts
Belovity may hold information about people who never created an account: email addresses used to invite Admins; the names and messages of gift-givers; and email addresses on notification records. If you are one of these people and want your information removed, contact alex@belovity.com.
6. Information About Others You Add
Your Gift Lists and gift records may name or describe other people — for example, a gift recipient.
Belovity is a general-audience service for adults. Accounts are for people 18 and older. Content is created and added by adult account holders, who confirm they have the authority and permission needed to share information about anyone they name or describe. Belovity is not directed to people under 18.
We do not show advertising to anyone, and we do not build advertising profiles of anyone. We do not use facial recognition or any biometric processing.
If you are named or described in someone's Content and want us to remove that information, even if a family member added it, contact alex@belovity.com. We will review and respond to removal requests.
7. How We Use Information
| Purpose | Information used |
|---|---|
| Provide and operate the Service | Account data, Content, Gift List data, social sign-in data |
| Deliver notifications you have not turned off | Account data, email, push subscription |
| Show families who viewed their content | Page-view and fingerprint data, account data |
| Debug, secure, and improve the Service | Analytics, session replay, audit logs, page-view logs |
| Prevent abuse and secure sign-in | reCAPTCHA signals, IP, User-Agent |
| Respond to support and legal requests | Support requests, account data |
| Take payment and manage subscriptions | Name, email, billing data, subscription status |
| Optional gift-list item name shortening | The product name you type (see AI Features) |
8. Notice at Collection
This table is our California "notice at collection." We collect the following categories, and we do not sell or "share" (for cross-context behavioral advertising) any of them.
| Category (CCPA) | Examples | Source | Business purpose | Recipients | Sensitive? |
|---|---|---|---|---|---|
| Identifiers | Name, username, email, user ID, IP address, device fingerprint | You; automatic; Google/Facebook | Operate Service, notifications, security | Analytics, email, storage, sign-in providers | Account credentials, if any, treated as sensitive |
| Customer records | Postal shipping address, recipient name | You | Enable gifting | Family Page Admins/Followers (if displayed) | Yes (address) |
| Commercial / financial information | Subscription plan and status; card brand and last four digits; Stripe customer ID | You, via Stripe | Take payment, manage subscriptions | Stripe | No (no full card number held) |
| Internet activity | Page views, clicks, session replay, referrer | Automatic | Debugging, product improvement | PostHog | No |
| Geolocation | Self-declared city/region/country | You | Localization, display | Analytics | No (not precise; not IP-derived) |
| Visual information | Avatars and cover images | You; Google/Facebook | Display to your audience | Storage/CDN | No |
| Sensitive PI | Account credentials | You | Operate the Service | Storage | Yes |
We retain each category as described in How Long We Keep Information.
9. How Information Is Shared
We use service providers to run the Service. Each is bound by a contract that limits its use of personal information to providing services to us.
- PostHog Inc. (United States): product analytics, including your analytics identifier, email address, IP address (server-side), household and role data, and event details. Session replay is on.
- Amazon Web Services (United States): stores uploaded media (S3), delivers content and analytics traffic (CloudFront, Route 53), and runs the endpoint that receives contact-form messages from the Site (Lambda).
- Resend: delivers our email and returns delivery, open, click, bounce, and complaint events.
- Google (Sign in with Google; reCAPTCHA): identity and anti-abuse. reCAPTCHA also loads on the Site’s contact form.
- Meta Platforms (Sign in with Facebook): identity.
- Stripe, Inc. (United States): processes subscription payments. Stripe receives your name, email address, the card details you enter on its pages, and a tag identifying which Family Page the subscription belongs to. Stripe acts as an independent controller of payment data for its own legal, fraud-prevention, and accounting purposes; see Stripe's privacy policy at https://stripe.com/privacy. Stripe's checkout and billing-portal pages are Stripe's own and may set their own cookies.
- Anthropic: processes the product name you type into the optional gift-list item-name shortener (see AI Features).
- Browser push services (Google, Apple, Mozilla): deliver web push notifications.
- Slack (Salesforce): receives support requests internally, including your name, email, message, and links to any attachments.
- Public script CDNs (jsDelivr; cdn.tailwindcss.com): receive your IP address and User-Agent to load certain scripts; they set no cookies.
We may also disclose information to comply with law, enforce our Terms, or protect rights and safety, and in connection with a merger, acquisition, or sale of assets. We do not use advertising, ad-tech, marketing-automation, or data-broker services. We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising.
10. Who Can See Your Content
- Private by default: unless you change the setting, your Family Page is private. Only its Owners, Admins, and Followers can view the page and its gift lists. This applies to every Family Page without any action by you and does not depend on a feature tier or paid plan. You can opt in to making the page viewable by anyone with the link. Even on a public page, shipping addresses are not shown to unauthenticated visitors.
- Search engines: search visibility starts ON for every new Family Page, and turning it off requires our paid plan. On a Family Page with the paid plan that has chosen to hide, the page is served with a
noindex, nofollowinstruction to search engines. On a free Family Page we do not send that instruction, and there is no way to turn search visibility off. Honoring anoindexinstruction is in any case at each search engine's discretion. - Belovity's own family search: signed-in Belovity users can search for families. A family appears in those results if the searcher already belongs to it, if the family's search visibility is on, or if the Family Page does not have the paid hide-from-search capability. This means a free Family Page is listed in this search even when the page itself is private. The search matches on the family name and on an Owner's or Admin's name, username, or last name, and a result shows the family name, avatar, and the usernames of its Owners and Admins. Appearing in a search result does not grant access: opening the page is still subject to the rules above, so a private page remains unviewable to someone who finds it this way. What such a person learns is that your family exists, its name and avatar, and the usernames of its Owners and Admins.
- Followers see only what an Admin permits. On a Family Page with our paid plan, an Admin controls which gift lists each Follower can see, list by list; each gift list also has a "visible to new followers" setting deciding whether people who join later get access automatically, and turning it on when you create a list grants access to the Followers you already have. On a free Family Page these per-Follower controls are not available and every Follower sees every gift list that is turned on. In both cases, a Follower never sees a gift list that is turned off or that has no published items.
- If a Family Page's paid plan or free trial lapses, Followers and public visitors lose access to all of its gift lists until its Owner subscribes or moves the page to the free plan.
- Owners and Admins see everything on the Family Page, including all gift lists (even ones that are turned off or empty) and purchase records — and, on the paid plan, the per-viewer analytics described above. Only the Owner can see or manage billing.
- On a public Family Page, every gift list that is turned on and has at least one published item is visible to anyone with the link, and per-Follower gift-list permissions no longer apply.
- The share link admits anyone who opens it as a Follower, without review, and does not expire until regenerated.
- Shipping addresses are shown to a Family Page's Admins and Followers only when display is turned on.
- When someone leaves: removing a Follower or unfollowing revokes access immediately, but that person's prior purchases remain, attributed to them.
11. Cookies and Similar Technologies
We use a small set of cookies and similar storage. We do not use advertising cookies. For the complete list and your controls, see our Cookie Policy (https://belovity.com/cookies).
12. AI Features
The only AI feature is optional product-name shortening for gift-list items. It is part of our paid plan and is available only on Family Pages that have it. When used, the product name you type (up to 255 characters) is sent to our AI provider (Anthropic) to produce a shorter name; the input and output are logged by us and recorded in analytics. Nothing else about the item — and nothing about you — is sent. We do not use your Content to train AI models. We do not use automated decision-making that produces legal or similarly significant effects about you.
13. How We Protect Information
We protect information using measures that include: encryption of data in transit (TLS); encryption at rest for uploaded media in our object storage; private media storage served only through short-lived links that expire in about five minutes; direct-from-device uploads to storage; passwordless sign-in, which removes password-reuse risk; Google reCAPTCHA for bot and abuse protection on sign-in and invitation pages; an audit trail; full session invalidation when you sign out; and, for the browser extension, short-lived access tokens (15 minutes) with single-use refresh credentials that are replaced on every use, so that replaying an old one automatically disconnects that extension. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.
14. How Long We Keep Information
We keep information for as long as your account is active and for as long afterward as necessary to operate the Service, comply with law, resolve disputes, and enforce our agreements. In practice:
- Account and Content: kept while your account is active; removed on account deletion, subject to the exceptions below.
- Browser extension connections: each connection expires within 30 days whether or not it is used, ends immediately when you disconnect it on the Browser extension connections page, and is deleted when your account is deleted. We store only a hash of each token, never the token itself, along with the browser label, the last time it was used, and the IP address it was issued to.
- Web push subscriptions: deleted when your account is deleted. They are removed along with the account, so no push endpoint for you remains on our servers.
- Subscription and billing records: kept while the subscription exists. Deleting your account or a Family Page cancels its subscription immediately and removes our local subscription records, including the stored card brand and last four digits. Stripe keeps its own record of the customer, payments, and invoices to meet its legal, tax, fraud-prevention, and accounting obligations; that retention is governed by Stripe's privacy policy and is not something we can delete on your behalf.
- Archived Gift List items and gift-purchase records: retained as part of the receiving family's records, but the link between a purchase record and your account is removed when you delete your account. The gift-giver name and message you typed remain on the record for that family; the record is no longer associated with your Belovity account.
- Page-view logs (with IP, User-Agent, and device fingerprint), audit logs, AI prompt logs, mail delivery logs, and in-app notification records: retained for security, integrity, and operational reasons, and these persist after account deletion.
- Communications you send us: support requests, emails, and other correspondence, together with our replies, are kept for as long as needed to answer you and to keep a record of the exchange, and they may persist after account deletion where we need them to resolve disputes, meet a legal obligation, or defend a claim.
- Backups and caches: copies may persist for a limited period after deletion. You acknowledge that certain security, audit, and operational logs, and gift-purchase and support records, survive account deletion. We are candid that automated deletion of these logs is not yet in place; we will define concrete retention periods as we build deletion routines.
15. Your Choices and Rights
- Notification preferences: in the in-app preference center you can set email and web push notifications by category. In-app notifications are always delivered and cannot be turned off, and certain transactional messages (such as gift-purchase confirmations and sign-in links) are always sent.
- Turning off push: turning off the in-app push toggles stops new push notifications; to fully stop push, also revoke the notification permission in your browser settings. Turning off the toggles does not delete the stored push subscription record; deleting your account does delete it.
- Editing your profile: you can edit your first name, last name, username, country, region, city, and avatar in Settings. Your email address cannot be changed in the app; to change it, contact alex@belovity.com.
- Family Page visibility: if you are an Owner or Admin, your Family Page settings control who can view the page (followers only, or anyone with the link). Whether the page is visible to search is a separate control that is only available on our paid plan; on the free plan the page remains visible to search and to Belovity's family search. Per-Follower gift-list access is likewise a paid-plan control, managed on the Followers page.
- Billing: if you are a Family Page's Owner, you can view your plan, change your payment method, see invoices, and cancel from the Billing page, which opens Stripe's billing portal. Cancelling stops future renewals; deleting your account or the Family Page cancels immediately.
- Deleting your account: you can delete your account yourself from Settings; see https://belovity.com/terms#deleting-your-account.
- Access, correction, deletion, and portability: to request a copy of your information, corrections, deletion, or a portable export, email alex@belovity.com. We do not have a self-serve data-download feature today, so we fulfill these requests manually.
16. US State Privacy Rights
Depending on your state, you may have rights under laws including the California Consumer Privacy Act as amended (CCPA/CPRA) and comprehensive privacy laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island.
Your rights generally include the right to know/access, correct, delete, and obtain a portable copy of your personal information, and to opt out of sale, targeted advertising, and certain profiling. We do not sell personal information, do not "share" it for cross-context behavioral advertising, and do not use it for targeted advertising or profiling with legal or similarly significant effects, so there is nothing to opt out of in those categories.
California specifics: you have the right to know the categories and specific pieces of personal information we collect, the right to delete, the right to correct, and the right to non-discrimination for exercising your rights. We collect the categories listed in the Notice at Collection, including sensitive personal information (account credentials). We use sensitive personal information only to provide the Service and do not use it to infer characteristics.
Maryland: Maryland's Online Data Privacy Act (effective October 1, 2025; enforced by the Maryland Attorney General beginning April 1, 2026) bans the sale of sensitive personal data under any circumstances, requires that collection be limited to what is strictly necessary, and prohibits selling the personal data of, or using it for targeted advertising to, consumers we know or should know are under 18. We do not sell sensitive data, do not sell any personal data, and do not run targeted advertising, consistent with these requirements.
How to exercise: email alex@belovity.com. We will verify your request using information associated with your account and respond within 45 days, extendable by another 45 days when reasonably necessary. You may use an authorized agent, who must provide proof of authorization. If we deny a request, you may appeal by replying to our decision; if you remain unsatisfied, you may contact your state attorney general.
Universal opt-out / Global Privacy Control (GPC): several states require businesses to honor browser opt-out signals such as GPC for sale and targeted advertising. Because we do not sell or share personal information or run targeted advertising, there is no sale or targeted-advertising activity for a GPC signal to stop. We do not currently operate a mechanism that detects GPC signals.
17. Canadian Privacy Rights
For users in Canada, we handle personal information in accordance with PIPEDA and, for Quebec residents, Quebec's Law 25.
- Consent: we rely on your consent to collect and use personal information. By adding information about another person, you confirm you have the authority and consent needed to do so.
- Access and correction: you may request access to, or correction of, your personal information at alex@belovity.com.
- Complaints: you may complain to us and to the Office of the Privacy Commissioner of Canada, or, in Quebec, the Commission d'accès à l'information.
- Quebec Law 25 – person in charge: the person responsible for the protection of personal information at Belovity can be reached at alex@belovity.com, 8735 Dunwoody Place, Suite R, Atlanta, GA 30350, USA.
- Portability and de-indexing: you may request a portable copy of the computerized personal information you provided, and you may request that we stop disseminating, or de-index, personal information where the law requires. Family Pages are private by default, so page content is not exposed unless an Owner or Admin opts in to public visibility. Search visibility, however, starts on, and on the free plan a Family Page cannot turn it off — so if you want your family de-indexed and removed from Belovity's family search and cannot do it from your settings, contact us at alex@belovity.com and we will action it for you at no charge.
- Confidentiality incidents: if a confidentiality incident poses a risk of serious injury, we will notify the appropriate regulator and affected individuals, and keep a record, as required.
18. International Data Transfers
All Belovity infrastructure and data, including our application server, database, cache, and media storage, are located in the United States. If you use Belovity from Canada, your personal information is processed and stored in the United States and is subject to US law, and US authorities may be able to access it under US legal process. By using the Service, you understand your information will be handled in the United States.
19. Data Breach Notification
If we become aware of a breach of security safeguards affecting your personal information that creates a real risk of significant harm, we will notify affected individuals and the appropriate regulators without unreasonable delay, consistent with PIPEDA, Quebec Law 25, Georgia's breach-notification statute (O.C.G.A. § 10-1-910 et seq.), and other applicable law. Notice will describe, to the extent known, what happened, the information involved, and steps you can take.
20. Third-Party Links and Services
The Service links out to third-party retailer websites and works with a separately distributed browser extension. We are not responsible for the privacy practices of retailers or other third parties. Their terms and privacy policies govern your interactions with them.
The Belovity browser extension. The extension reads product details (such as the title, price, image, color, size, and page address) from the retailer page you are viewing, on your own device. Nothing is sent to us until you choose to add an item; when you do, those details and the item you filled in are sent to our API over HTTPS and saved to the gift list you selected. The extension cannot read your Belovity session: it works only after you connect it from the Browser extension connections page in your account, which issues it a short-lived token of its own, and it stops working as soon as you disconnect it there. We do not receive your browsing history, and the extension does not send us pages you visit but do not add. If your family has the AI name-shortening feature and you press "Shorten it" in the extension, the product name — and nothing else — is sent to our AI provider to suggest a shorter version (see AI Features).
21. Anti-Phishing Note
We will never send you unsolicited email or call you to request your personal information. A genuine Belovity sign-in link is only ever sent in response to a sign-in you just requested. If you receive a sign-in link you did not request, do not click it, and contact alex@belovity.com.
22. Changes to This Policy
We may update this Privacy Policy. We will post the updated version with a new "Last Updated" date and, for material changes, provide reasonable notice.
23. Contact Us
Belovity LLC
General and privacy requests: alex@belovity.com
Privacy requests (access, correction, deletion, portability; Quebec Law 25 person in charge): alex@belovity.com
Mailing address: 8735 Dunwoody Place, Suite R, Atlanta, GA 30350, USA