Public policy · USA

Privacy Policy

Effective date: July 19, 2026 · Service: Warmly · Contact: privacy@bewarmly.com

1. Scope and our role

This policy describes Warmly's United States service, including its website, applications, personal and professional workspaces, Company workspaces, group pools, Cloud messages, and Human Operations fulfillment. A Company workspace may provide employee information and control how that workspace uses it; in those cases, employees may also need to contact their employer about employer-controlled records.

2. Information we collect

  • Account and workspace information: name, email, timezone, authentication and session identifiers, preferences, workspace type, membership, role, plan, and billing status.
  • Owner phone verification information: the account owner's United States mobile phone number, its verification status and timestamps, bounded attempt counters, and provider identifiers. Twilio Verify generates and checks the one-time code; Warmly does not generate, store, or log the code.
  • People, relationships, and dates: names, relationship labels, phone numbers or email addresses, birthdays, anniversaries, custom dates, notes, social links, and people updates you choose to add or import.
  • Company and employees data: employee identifiers, work contact details, departments, roles, status, relevant celebration dates, policy choices, approvals, budgets, and audit records supplied by a workspace administrator or integration.
  • Recipient and contributor information: recipient profiles, delivery addresses, gift wishes, pool invitations, contributor names or contact details, contribution messages, and anonymous-display choices.
  • Consent, message, and delivery information: channel-specific consent or revocation evidence, suppression status, drafts and edits, send mode, scheduled time, provider identifiers, segment counts, delivery state, and feedback.
  • Gift, order, and payment information: selected gifts, frozen quotes, pool allocations, order status, delivery instructions, Stripe customer, Checkout, payment, charge, and refund identifiers. Payment-card details are collected by the payment processor rather than stored as full card numbers by Warmly.
  • Manual Operations evidence: sourcing notes, organizer-approved substitutions, receipts, invoices, assembly and quality checks, shipment and tracking records, delivery proof, exception notes, and restricted gift-card fulfillment evidence.
  • Device, security, and usage information: device and browser details, IP-derived security information, push tokens, request and audit records, diagnostics, and interactions needed to protect and operate the service.

3. Where information comes from

We receive information from account holders, workspace administrators, employees, recipients, contributors, connected Company systems, devices, and service providers acting on a transaction or delivery. Address-book import sends only people you select for import; device permission and selection remain under the user's control.

4. How we use information

  • create accounts and workspaces; remember people, dates, rules, and preferences;
  • verify that an account owner possesses the mobile phone they provide, protect welcome-credit eligibility, prevent duplicate promotional grants, and secure phone-dependent service actions;
  • prepare and deliver approved greetings through Cloud delivery, or support a premium user-operated device send;
  • record consent, honor revocation, suppress messages, and investigate delivery exceptions;
  • quote, collect, allocate, source, assemble, ship, refund, and reconcile one-time gifts and order-scoped pools;
  • administer subscriptions, Company policies, approvals, budgets, integrations, and audit history;
  • secure, troubleshoot, support, improve, and comply with legal obligations.

5. Owner-phone verification and messaging choices

Mobile numbers and SMS opt-in data are not sold or shared with third parties for marketing or promotional purposes. Service providers may process these details only to deliver and support the messaging service. Message frequency varies with the selected occasions and service activity. Message and data rates may apply. Reply STOP to unsubscribe or HELP for support.

Warmly uses Twilio Verify to send an account owner a one-time verification message and confirm possession of the phone. Verification and other transactional service SMS are separate from optional marketing consent. Verifying a phone does not enroll the owner in marketing, does not establish a recipient's consent, and does not authorize unrelated messages.

Changing the owner phone invalidates the prior verified state and requires the replacement number to be verified. A verified phone may be used to enforce the one-time welcome-credit rules described in the Terms, including eligibility once per user and once per verified phone.

6. AI, Cloud delivery, and Human Operations

When a user requests a draft, gift suggestion, group-card text, or wishlist question, relevant prompt details are sent to the configured AI provider. Users must review generated content. Cloud messaging providers process phone numbers, message content, and delivery metadata to send approved messages. Human Operations staff and authorized contractors may review the minimum order, recipient, consent, and evidence information needed to source, assemble, ship, support, and reconcile fulfillment.

7. Service providers and disclosures

Verified product integrations include Stripe for one-time Account top-ups and refunds, Twilio for owner-phone verification and Cloud SMS, Resend for transactional email, Expo services for mobile push delivery, Google or Apple for authentication when chosen, and Anthropic or an OpenAI-compatible provider for configured AI requests. Warmly, rather than a Stripe recurring subscription, administers subscription renewals from the internal Account balance. Infrastructure, database, file-storage, retailers, shipping carriers, support, security, and professional advisers may process information as needed for their services. We may also disclose information to comply with law, protect people or the service, or complete a business transaction subject to appropriate safeguards.

8. Sale, analytics, and advertising choices

With Advertising consent, configured Meta Pixel measures visits to our public product landing pages and completed registrations on account entry, workspace home, or initial onboarding pages. Meta receives standard browser and advertising-cookie information and the page URL, which can include a workspace identifier on its home or initial onboarding page. We do not include names, email addresses, phone numbers, birthdays, contact records, or greeting content in the events. Automatic event collection, advanced matching, and Conversions API are not enabled by this integration. Meta Pixel does not load on contact, order, payment, administrative, or token and capability pages. Rejecting Advertising keeps this integration off; changing that choice stops subsequent measurement.

We do not sell personal information. Before consent, configured Google measurement loads only on five eligible public ad landing pages: the home, Personal, Professional, Business, and Group Gifts pages. It uses analytics and advertising storage denied, redacts ad-click identifiers, and may send cookieless measurement signals before you make a choice. It does not load before consent on other pages, and it never loads on token or capability pages or on administrative and Human Operations pages. Warmly does not send customer identifiers or business conversion events in the pre-consent state.

Analytics and Advertising are separate choices. Analytics permits optional product-journey events, while Advertising permits conversion measurement and associated advertising storage and identifiers. On other eligible non-sensitive pages and ordinary signed-in app routes, Google measurement requires a matching stored choice; signed-in configuration disables automatic page views and uses a generic app location rather than workspace, person, pool, order, or transaction paths. Optional analytics events and Google Ads conversion events remain off unless you make the relevant choice. Enhanced conversions and customer-data matching are not enabled, and Warmly does not send email addresses, phone numbers, or other customer data with these conversion events. You can reject both, choose either one, or change your choices later without disabling core service functions.

9. Privacy requests and California notice

Where applicable, privacy law may provide rights to know or access, correct, delete, obtain a portable copy, opt out of sale or sharing, limit certain uses of sensitive information, and receive equal service for exercising a right. California law applies only when its coverage requirements are met. Whether or not a particular statute requires it, Warmly will voluntarily receive access, correction, deletion, and copy requests at privacy@bewarmly.com and respond after reasonable identity and authority verification. Legal, security, fraud-prevention, accounting, dispute, and transaction-record exceptions may require retention or limit a response.

10. Retention and security

We retain information for as long as reasonably needed to provide the service, maintain consent and suppression records, complete and reconcile transactions, meet legal or accounting duties, resolve disputes, and protect the service. Account ledger and billing records remain immutable where needed to preserve financial history, even when other account information can be deleted. Retention varies by record and context. We use administrative, technical, and physical safeguards designed for the nature of the information, but no system can guarantee absolute security.

11. Children and changes

Warmly is not directed to children under 16, and we do not knowingly create accounts for them. We may update this policy as the service or law changes. The effective date above identifies the current public draft, and material changes will be communicated by a reasonable method.