Privacy Policy
How Little Box of Goodies collects, uses, shares, retains, and protects care-package, account, and purchase data.
Last updated: 2026-08-26
Who is responsible for your data
Little Box of Goodies is operated under that name by an independent individual developer. The operator is responsible for the personal information processed to provide this service. We provide online-only customer service and have no public office or retail location.
For privacy questions or verified data requests, email support@littleboxofgoodies.com.
The short version
Little Box of Goodies lets you create a digital care package without an account. Packages are not published in a directory or intentionally submitted for search indexing. Each package is reached through a long, unlisted link.
That link is private by obscurity, not by encryption. Anyone who receives it can view the package and can forward it. Do not put passwords, financial details, government identifiers, medical records, or other highly sensitive information in a package.
We do not sell package content or personal information, and we do not use private package content to train generative-AI models.
Information we process
Depending on how you use the service, we process:
- Package content: recipient and sender display names, package messages, notes, captions, coupons, location descriptions, photos, drawings, voice recordings, and third-party links.
- Account information: name, email address, authentication identifiers, profile details, and account-security records.
- Purchase information: payment provider, checkout or transaction identifiers, purchase status, amount, currency, product, receipt email, refund status, and voucher use. We do not receive or store a full card number.
- Support information: messages, attachments, package links, and other details you choose to include in a support or rights request.
- Technical information: IP address, browser and device type, request time, error logs, rate-limit records, and fraud or security signals.
- Browser storage: language, theme, an anonymous package draft, and—only for older purchases—a private wallet capability stored in the browser.
Why we use information
We use information to:
- Create, store, deliver, and preserve packages.
- Create accounts, authenticate users, and protect account access.
- Process purchases, issue vouchers, provide receipts, and handle refunds or disputes.
- Answer support, privacy, safety, and intellectual-property requests.
- Prevent fraud, abuse, malware, unlawful content, and unauthorized access.
- Debug errors, maintain reliability, and understand aggregate service performance.
- Comply with tax, accounting, payment-network, sanctions, and other legal obligations.
Where privacy law requires a legal basis, we rely as applicable on performing the service or purchase contract, your consent, compliance with law, and our legitimate interests in security, support, fraud prevention, and reliable operation. You may withdraw consent where consent is the applicable basis, without affecting earlier lawful processing.
Accounts, packages, and sharing
No account is required to create or open a package. Once created, package content cannot be edited through the service. Anyone with the long, unlisted private link can open the package, so the link should be shared only with trusted people. A signed-in person with an available voucher may preserve an eligible package if they have its private link, even if they did not create it. Preserving a package does not transfer ownership or grant editing or deletion rights.
Packages created while signed in are associated with that account so the creator can find the sharing link and preservation status later. Packages created while signed out remain unassociated and cannot currently be claimed.
Account-based voucher purchases and preserved-package records are associated with the signed-in purchasing account. Older purchases may use a private wallet link. A wallet link is a bearer secret; anyone who obtains it may be able to use the associated unused vouchers. New account-based purchases do not rely on a wallet link.
Retention
- A new unpreserved package is viewable for 7 days, followed by a 7-day hidden recovery period. Earlier packages may retain a longer deadline that was assigned when they were created. At the end of the applicable recovery period, we permanently delete the package's personal content, including service-hosted photos and voice recordings.
- A minimal non-content tombstone remains so the old link returns a stable deleted state and delayed payment events cannot restore deleted content.
- A preserved package remains for the operating life of the service unless it is removed for a legal, safety, rights, technical, refund, or discontinuation reason.
- Account information is kept while the account is active and for a reasonable period needed to handle deletion, fraud, security, and legal obligations.
- Purchase, refund, and accounting records may be kept for up to seven years where required for tax, payment, dispute, or legal compliance.
- Closed support requests are normally kept for up to two years unless a longer period is needed for an active legal, safety, or dispute matter.
- Routine security and diagnostic logs are normally kept for no more than 90 days unless they are needed to investigate abuse, fraud, or a technical incident.
- Temporary copies may remain in caches or backups for a limited period after primary deletion and are removed through normal rotation.
Service providers and disclosures
We use service providers only as needed to operate the service. Depending on configuration, they may include:
- Cloudflare for hosting, database, object storage, content delivery, email, and Turnstile abuse prevention.
- Stripe or Creem for hosted checkout and payment processing.
- Authentication or OAuth providers chosen by the user at sign-in.
- Email and customer-support providers configured by the operator.
- Analytics providers configured by the operator to measure aggregate service use.
These providers process information under their own terms and privacy notices. We may also disclose information when required by law, to protect users or the service, to investigate fraud or rights violations, or as part of a business transfer subject to appropriate safeguards. We do not facilitate payments to package creators or disclose package content to advertisers.
Providers may process information in countries other than yours. Where required, we rely on contractual safeguards or another lawful transfer mechanism.
Cookies, local storage, and analytics
Essential cookies and browser storage support authentication, security, language, theme, and unsent package drafts. Turnstile may process device and request signals to distinguish people from automated abuse.
If analytics or customer-service tools are enabled, they may set cookies or similar identifiers. Where applicable law requires consent for a non-essential tool, we will request it before activating that tool. You can also limit cookies through your browser, although blocking essential storage may prevent sign-in or other features from working.
Your choices and rights
Only upload content you have the right and consent to share. Consider whether every identifiable person shown or heard would be comfortable with anyone holding the link seeing the content.
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection; to withdraw consent; and to complain to your local data-protection authority. To make a request, email support@littleboxofgoodies.com from the account or purchase email when possible. We may request limited information to verify identity and protect private package links.
Some records cannot be deleted immediately when retention is required for payment, tax, fraud-prevention, safety, or legal reasons. We will explain any applicable limitation when responding.
Children
The service is not directed to children under 13. Do not create an account or submit a package if you are under 13. Do not include a child's personal information without permission from their parent or legal guardian where that permission is required.
Security and availability
We use HTTPS in production, hosted payment checkout, access controls, hashed capability tokens, rate limits, and other reasonable safeguards. No online service can guarantee absolute security or permanent availability.
If a package or older wallet link has been shared with the wrong person, stop sharing it and contact support. Link rotation is not currently available.
Changes to this policy
We may update this policy as the service changes. The date shown above identifies the latest version. We will provide reasonable notice if a material change significantly alters how we use existing personal information.
Contact
For privacy questions, verified data requests, or package removal, email support@littleboxofgoodies.com. Include the relevant package link when necessary, but do not send a full card number or unrelated sensitive information.