Privacy Policy
This Privacy Policy explains how Canadian Gift Card Network, operating GiftCardsForCash.ca (“GiftCardsForCash.ca”, “GCFC”, “we”, “us”, or “our”), collects, uses, discloses, stores, and protects personal information when you use our website, submit a gift card, complete seller verification, communicate with us, or receive a payout (collectively, the “Service”).
- We collect information needed to process a gift-card submission, verify the seller and card, prevent fraud, complete a sale where applicable, and issue an Interac e-Transfer payout.
- Seller identity verification is performed using Didit, a third-party identity-verification provider.
- We may use automated and AI-assisted tools to review gift-card details, images, balance evidence, card format, and fraud or inconsistency signals.
- We do not sell your personal information.
- For a Higher Payout transaction, gift-card redemption information may be provided to a purchaser when necessary to complete the card sale. Seller identity-verification documents and biometric/liveness information are not part of ordinary buyer fulfillment.
- Questions, access requests, correction requests, and privacy complaints can be sent to our Privacy Officer at [email protected].
Contents
- Scope and applicable privacy laws
- Information we collect
- Identity verification and Didit
- Automated and AI-assisted verification
- How we use information
- Fast Cash and Higher Payout flows
- How we disclose information
- Cross-border processing
- Retention and deletion
- Security
- Cookies, analytics, and attribution
- Email and SMS communications
- Your privacy rights
- Age requirement
- Changes to this Policy
- Privacy Officer and contact
1) Scope and applicable privacy laws
Canadian Gift Card Network is based in British Columbia. We handle personal information in accordance with applicable Canadian private-sector privacy laws, including British Columbia’s Personal Information Protection Act (“PIPA”) and, where applicable, the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”) and other applicable privacy requirements.
These laws may apply differently depending on where a transaction occurs, where information is processed, and whether information crosses provincial or national borders.
2) Information we collect
A. Seller and contact information
- first and last name;
- email address;
- phone number;
- Interac e-Transfer payout email address;
- communications with support and related correspondence.
B. Gift-card and submission information
- gift-card brand and card type (for example, digital or physical);
- submitted balance and balance-verification information;
- gift-card number, redemption code, PIN, or other card identifiers where required for processing;
- screenshots, images, receipts, balance-check pages, or other proof submitted to establish the current balance and ownership;
- submission reference number, submission-group information, route information, timestamps, and transaction status;
- additional-card information when you submit an eligible multi-card Fast Cash submission.
C. Identity-verification information
Identity verification is required as part of the seller-verification process. Depending on the verification steps used, identity information may include:
- government-issued identity-document images and information read from those documents;
- name, date of birth, document number, document expiry, and other document data;
- selfies, facial images, video or liveness captures;
- face-match, liveness, authenticity, risk, quality, or verification results;
- verification-session identifiers and verification status;
- device, IP, or fraud-prevention signals when enabled in the verification workflow.
Some identity-verification processes can involve sensitive biometric information. Where required by law, express or otherwise appropriate consent is requested before that information is collected or processed.
D. Technical, device, and usage information
- IP address, browser type, device type, operating system, pages viewed, timestamps, and basic diagnostics;
- referring page, landing page, and website interaction information;
- cookie identifiers and analytics information, subject to applicable consent requirements;
- UTM parameters, advertising click identifiers, and similar attribution information where permitted.
E. Transaction and payout records
- estimated and verified payout amounts;
- Fast Cash, Enhanced Fast Cash, or Higher Payout route information;
- approval, verification, sale, payment, or completion status;
- payout records, reconciliation information, and transaction-related audit logs.
3) Identity verification and Didit
We use Didit to provide identity-verification and fraud-prevention services. Canadian Gift Card Network determines why identity verification is required for the GCFC seller flow, while Didit processes verification information on our behalf in accordance with its applicable terms, privacy notices, and our configuration.
Didit may process identity documents, selfies, face images, liveness captures, extracted identity data, verification scores, device or fraud signals, and verification results depending on the workflow used. Didit’s verification privacy materials are available at didit.me/terms.
As of the effective date of this Policy, Didit states that verification data is processed in the European Union by default, including on infrastructure in Ireland, unless a different data-residency arrangement applies. Didit also provides configurable retention and deletion controls.
Didit may offer provider-level settings relating to service improvement and model development. GCFC does not independently use seller identity-document images, selfie/liveness media, or biometric verification data to train GCFC AI models. Any processing performed by Didit for its own service improvement is governed by Didit’s applicable terms, privacy notices, and account-level settings. Questions about a particular verification may be directed to our Privacy Officer.
Completing an identity-verification session does not by itself approve a gift-card submission. GCFC also verifies the submitted gift-card details, current balance, and other required checks before a submission can move to Approved.
4) Automated and AI-assisted verification
We use automated and AI-assisted tools to help process submissions efficiently and reduce fraud. These tools may be used to:
- identify or normalize a gift-card brand;
- check whether submitted card details match expected card formats;
- review images and balance evidence;
- compare submitted details against other information in the transaction;
- detect inconsistencies, duplicate information, unsupported cards, or potential fraud signals;
- assign internal confidence, review, or verification signals;
- request additional proof or corrected card details where the available evidence is not sufficient;
- help route the submission through the appropriate verification process.
Automated signals do not guarantee approval or payout. A submission may be held for additional evidence or manual review. If you believe a verification result is incorrect, contact us and include your GCFC reference number so we can review the issue where appropriate.
5) How we use your information
We may use personal information and submission information to:
- create and maintain your GCFC submission and reference number;
- calculate or display an estimated cashout amount and available cashout route;
- verify seller identity and lawful ownership or control of the submitted gift card;
- verify card brand, format, identifiers, current balance, proof, and related submission details;
- detect, investigate, and prevent fraud, misuse, duplicate submissions, unauthorized activity, or security incidents;
- request additional proof, corrected details, or renewed verification where needed;
- determine whether the required verification gates have passed;
- administer Fast Cash, Enhanced Fast Cash, and Higher Payout submissions;
- make an approved Higher Payout card available for sale for the applicable sale window;
- complete card fulfillment following a valid sale;
- send Interac e-Transfer payouts and reconcile completed payments;
- provide status updates such as Submitted, Further Verification, Approved, and payment or completion-related updates;
- respond to customer-service requests and disputes;
- maintain security, accounting, audit, fraud-prevention, legal, and compliance records;
- improve the reliability, security, and user experience of the Service;
- comply with applicable legal, regulatory, tax, anti-fraud, anti-money-laundering, law-enforcement, or record-keeping obligations where they apply.
6) How information is used in the current cashout routes
Fast Cash and Enhanced Fast Cash
Eligible Fast Cash submissions are verified before approval and payout. Eligible sellers may submit more than one qualifying Fast Cash card together under the Enhanced Fast Cash route, subject to the current eligibility rules. We use the submitted seller, card, proof, identity, and payout information to verify and process the submission and, after approval, move it toward Interac e-Transfer payout.
Higher Payout
Higher Payout submissions are also subject to seller, gift-card, and balance verification. Once approved, a qualifying card may be made available for sale for up to the applicable sale window, currently up to 72 hours. Approval does not mean the card has sold, and payment is sent only after a completed sale and any required final verification.
To complete a Higher Payout sale, we may disclose the gift-card redemption information reasonably necessary for the purchaser to receive and use the purchased card. We do not disclose the seller’s Didit identity-document images, selfie/liveness media, or biometric verification data to the purchaser as part of ordinary card fulfillment.
7) How we disclose information
We may disclose information in the following limited circumstances:
- Identity-verification provider: Didit, for seller identity verification, liveness, fraud-prevention, and related verification services.
- Cloud and workflow providers: service providers that help us host the website, store business records, automate workflows, manage CRM/contact records, process files, or deliver operational communications.
- Payment and banking providers: banks, Interac-related services, payment/reconciliation providers, or other financial-service providers used to send or reconcile payouts.
- Gift-card purchasers / fulfillment: where necessary to complete a valid Higher Payout sale, the redemption information needed to fulfill the purchased card may be provided to the purchaser or fulfillment process.
- Professional advisers: accountants, legal advisers, insurers, auditors, or other professional advisers where reasonably necessary.
- Legal, regulatory, and safety purposes: where required or permitted by law, legal process, regulatory requirement, fraud investigation, dispute process, or to protect our rights, users, systems, or others.
- Business transaction: in connection with a merger, financing, acquisition, reorganization, or sale of all or part of the business, subject to appropriate safeguards and applicable law.
We do not sell personal information. The transfer of gift-card redemption information necessary to complete a gift-card sale is part of the GCFC transaction and is not a sale of the seller’s identity information.
8) Cross-border processing and service providers
Some service providers may process or store information outside British Columbia or outside Canada. Information processed in another jurisdiction may be subject to that jurisdiction’s laws and may be accessible to courts, law-enforcement, regulators, or other authorities in accordance with applicable law.
We remain responsible for personal information under our control and use contractual, technical, administrative, and other safeguards appropriate to the sensitivity of the information and the service provided.
9) Retention and deletion
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including verification, fraud prevention, transaction completion, dispute handling, security, accounting, audit, legal, and compliance needs.
Identity-verification data
Our standard retention period for raw identity-verification session data is up to 24 months after the verification attempt, unless a shorter period is appropriate or a longer period is reasonably required for an unresolved fraud investigation, dispute, legal hold, regulatory requirement, or other lawful purpose.
This may include identity-document images, selfie/liveness media, extracted identity information, and related verification-session data held by our identity-verification provider. Verification outcomes, session identifiers, fraud-prevention indicators, and the fact that identity verification was completed may be retained separately where needed to protect the Service, prevent duplicate or fraudulent activity, or document the transaction.
Gift-card, submission, and transaction records
Submission records, payout records, sale records, reconciliation records, invoices, accounting records, and other business records may be retained for at least six years from the end of the tax year to which they relate where required for Canadian tax, accounting, audit, or legal purposes. Gift-card credentials and proof materials are retained only for as long as reasonably necessary to verify, fulfill, support, investigate, or resolve the applicable transaction and related fraud or dispute risk.
Deletion and de-identification
When information is no longer reasonably required, we take steps to delete, destroy, de-identify, or otherwise dispose of it as appropriate. Deletion may be delayed where information remains subject to backups, legal holds, unresolved disputes, fraud-prevention requirements, accounting obligations, or other lawful retention requirements.
Identity-verification data processed by Didit is also subject to the retention configuration applied to our Didit application and Didit’s applicable terms. Our intended configuration is to align that provider retention with the 24-month standard described above.
10) Security
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, collection, use, disclosure, copying, modification, loss, or disposal. Safeguards may include access controls, restricted permissions, encrypted connections, audit logging, vendor controls, and security monitoring.
Didit states that its verification data is encrypted in transit and at rest and that access to verification information is role-based. No system is completely secure, and we cannot guarantee absolute security.
If we become aware of a privacy or security incident involving personal information, we will assess and respond to it and provide notifications to affected individuals or regulators where required by applicable law.
11) Cookies, analytics, and attribution
We may use cookies, browser storage, and similar technologies for website functionality, security, session continuity, fraud prevention, analytics, and attribution.
Where required, analytics or marketing technologies are used based on the consent choices available on the site. Attribution information may include UTM parameters, landing-page information, and advertising click identifiers. You can also control cookies through your browser settings, although disabling some storage may affect site functionality.
12) Email and SMS communications
We may send operational or transactional communications relating to your submission, verification, requests for additional information, sale status, payout, security, or customer support.
Promotional or marketing email or SMS messages are handled separately and, where required, are sent only with the consent required by Canada’s Anti-Spam Legislation (“CASL”). Marketing messages will include the identification and unsubscribe information required by applicable law. Withdrawing marketing consent does not prevent us from sending service-related messages that are necessary to administer an active submission or transaction.
13) Your privacy rights and choices
Subject to applicable law, you may have the right to:
- request access to personal information we hold about you;
- request correction of inaccurate or incomplete personal information;
- withdraw consent to certain collection, use, or disclosure, subject to legal, contractual, fraud-prevention, and operational limitations;
- ask questions about our privacy practices, service providers, cross-border processing, or identity-verification practices;
- request deletion of information where applicable, subject to lawful retention requirements;
- challenge our compliance with applicable privacy requirements;
- ask us to review a verification outcome where you believe information or an automated signal is incorrect.
A withdrawal of consent may mean that we cannot complete identity verification, gift-card verification, a Higher Payout sale, or payout.
To exercise a privacy right or make a complaint, contact our Privacy Officer using the information below. We may need to verify your identity before giving access to personal information or making certain changes.
External privacy regulators
If you are not satisfied with our response, you may also have the right to contact the Office of the Information and Privacy Commissioner for British Columbia or, where federal jurisdiction applies, the Office of the Privacy Commissioner of Canada.
14) Age requirement
The Service is not intended for individuals under the age of majority in their province or territory. Do not submit a gift card or identity-verification information if you are not legally eligible to use the Service.
15) Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to our Service, verification providers, privacy practices, legal requirements, or business operations. The current version will be posted on GiftCardsForCash.ca with an updated effective or revision date.
Where required by law, we will provide additional notice or obtain consent before using personal information for a materially new purpose.
16) Privacy Officer and contact
Canadian Gift Card Network
Operating: GiftCardsForCash.ca
Privacy contact: Privacy Officer
Location: British Columbia, Canada
Email: [email protected]
When contacting us about a GCFC submission, include your GCFC reference number if available. Do not email full gift-card codes, PINs, identity-document images, or other sensitive verification material unless we specifically instruct you to use an approved secure method.