Privacy at Lammigo
Privacy Policy
This policy explains what information Lammigo handles when you create, personalize, pay for, share, or open a digital card. Lammigo is operated by Gvantsa Kakhniashvili, a sole proprietor registered in Georgia. We collect only what is needed to provide and protect the service, and we do not sell personal information.
Last updated:
Who we are and when this policy applies
Lammigo provides account-free digital greeting cards under the Lammigo brand. This policy applies to the Lammigo website, card creation tools, checkout flow, and card pages. It does not replace the privacy terms of a third-party service you choose to use, such as Paddle or WhatsApp.
Information we collect
The information we handle depends on how you use Lammigo. You may provide recipient and sender names, a written message, an organizer email address (optional for a free individual card, required for a group card and for any purchase), an optional recipient email for group-card delivery, card design choices, language, occasion, and timing details. Group-card contributors may provide a display name, a message, an optional photo or GIF, and a sticker. Custom cards no longer take a photo; one already added to an older custom card is kept and removed with that card. Anyone may also leave an email address to be told when a new product launches.
When a purchase is made, we receive payment confirmation and transaction identifiers from Paddle. We do not receive or store your full payment-card number. Our hosting and security infrastructure may also process basic technical information such as IP address, browser or device type, request time, and error information.
To run and protect the service, to understand which pages lead people to make a card, and to measure how well our advertising and marketing work, we keep a shortened form of your IP address (with its last part removed) together with the date, the country, the pages you opened and how long they were open on your screen (time in a background tab is not counted), the kind of device (phone, tablet or computer), its system and browser and the app the link was opened in (read from your browser, without keeping its full identification string), where the visit came from (the referring site’s domain, a campaign name, or the fact of a Google Ads click - never the full address you came from), and, if a card is made from that network, which card it was (its public link, never its private management link). We omit the card link for visitors from the European Economic Area, the United Kingdom and Switzerland, and when the country is unknown. This record is visible only to the operator of Lammigo, is not used to target advertising at anyone, is not sold or shared, and is deleted after 30 days.
To limit abuse, our own request counter also keeps your full IP address for up to 48 hours. If you report a card you may add your email, and an organizer who appeals a decision writes an explanation; both are kept until the report or appeal is resolved and for six months after.
How we use information
We use information only for legitimate service and business purposes, including to:
- understand how the site is used and measure, in aggregate, how well our advertising and marketing work - never to target ads at an individual;
- create, personalize, display, share, and deliver cards;
- process and confirm purchases, prevent fraud, and handle support or refund requests;
- send essential service messages, deliver a group card by email when an organizer requests it, and send a launch notice you asked for;
- protect Lammigo, enforce these policies, diagnose errors, and improve reliability;
- meet tax, accounting, legal, and regulatory obligations.
Shared card links and user content
A card is unlisted, but it is not access-controlled: anyone who receives its link may be able to view the names and messages shown on it and may forward that link. We ask search engines not to index card pages, but that is not a substitute for access control. Do not add confidential, highly sensitive, or private information to a card.
A card management link is a credential. Keep it private and contact us promptly if you believe it has been exposed.
Payments and service providers
Paddle processes purchases as the Merchant of Record. Information entered in Paddle Checkout is handled under Paddle’s own privacy terms. Lammigo receives the transaction data needed to activate a purchase, keep accounting records, and provide support.
We may use carefully selected providers for hosting, databases, email delivery, file storage, error monitoring, and security. They may process information only to provide their services to us and under appropriate contractual or legal safeguards. Because these providers may operate internationally, information may be processed outside your country.
Photos attached to group messages are also sent to our automated content-safety provider when available. Flagged photos are held for the Lammigo operator to review before appearing on the card; the organizer cannot approve them. If the check is unavailable, photos may pass without automated review.
A voice message recorded on a group card is sent to our automated content-safety provider to be turned into text, and that text is checked the same way as a written message; a voice that fails the check is not saved, and the writer can record it again. The text is used only for that check - it is not shown on the card and we do not keep it. The recording itself is stored with the card, like its photos, and is deleted with it.
When our automated content-safety service is configured and available, the text of a card or message is sent to it before saving to check for hate speech, threats and sexual content. The provider may keep the text briefly for its own abuse monitoring and does not use it to train its models; no one at Lammigo reads it as part of that check, and the result is only whether the wording may be sent. A message held back for review may be machine-translated by a similar service so that the person reviewing it can read it. If the automated check is unavailable, the report and moderation tools remain the backstop for abuse.
Cookies and tracking
Lammigo does not sell personal information for targeted advertising. Technology that is strictly necessary to load, secure, and operate the service may be used.
We measure page visits with Vercel Web Analytics, which sets no cookies and receives page addresses with card names and management links removed.
We use the Google Ads tag on our pages to measure whether a visit that arrived from one of our ads ended in a purchase, and to show our ads again to people who have already visited. It may set or read Google cookies and advertising identifiers in your browser. Card addresses are shortened before they are sent, so a management link, a recipient name, and anything written on a card never reach Google. For visitors in the European Economic Area, the United Kingdom and Switzerland the tag runs without advertising cookies. You can turn off personalized Google advertising at myadcenter.google.com.
A third-party checkout or destination you open, including Paddle or WhatsApp, may use its own cookies and is governed by its own policy.
How long we keep information
We retain information only while it is reasonably needed for the purposes described here. A free individual card stays available while the service runs, and what was written on it is cleared three months after it was created - or, if its payment was refunded, three months after the refund. A paid card - an unlocked individual card or a paid group card - is kept without that time limit, which is part of what the payment buys; its organizer can delete it at any time from the management page. Photos on a paid group card are kept with the card for as long as the card is kept; the organizer can download them as a ZIP at any time. An unpaid group card does not follow that three-month clock: one that nobody has touched for 40 days, and whose closing date (if it has one) passed more than a month ago, is deleted - after a refund, never sooner than three months after it; its organizer is warned by email two weeks before, and again as the date approaches. Any card is also removed on a valid deletion request or when it is no longer needed to provide the service.
When the organizer deletes a card, it disappears from the service at once. A copy of the card, its messages and its photos is held in a recovery store for 30 days, so that a card deleted by mistake can be restored at the organizer’s request, and is then permanently erased.
When a paid card is deleted, a minimal purchase record - the email on the card, the card address, its type and creation date, and the payment transaction reference - is kept for six months and then removed. If the deleted card was used to unlock other cards (a ready-made card pack), the record is kept without the email for as long as a card it unlocked stays unlocked or can still be restored, and is then removed. It exists only for refunds, payment disputes, and fraud prevention, and is never used for marketing. Nothing written on the card is part of it.
A recipient email entered for group-card delivery is kept only while delivery is pending. It is removed from the card after a successful send or when the organizer cancels the schedule. If every delivery attempt fails, the address stays on the card so the organizer can correct it and send again, until a send succeeds or the organizer removes it or deletes the card.
An email address you leave to be told when a product launches, such as the Wedding Guestbook, is kept only to send that one launch notice and is not used for anything else. It is deleted once the notice has been sent, and after twelve months at the latest if the product has not launched by then.
An email address you leave on a group card to be reminded before it closes is used only for those reminders - three days and one day before the deadline - and is deleted when the card closes. Every reminder has a link to stop them, and signing from the same browser stops them too.
Transaction, tax, fraud-prevention, and security records may be retained longer where required by law or needed to establish, exercise, or defend legal claims. Backups may take additional time to cycle out.
Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection, and to complain to a data-protection authority. To make a request, email us from the address connected with the card and include enough information for us to identify the relevant record. We may need to verify your request before acting on it.
You can also ask us to remove content that concerns you. We may preserve limited records when the law requires it or when needed for fraud prevention, payment disputes, or security.
Security, children, and policy changes
We use reasonable technical and organizational safeguards, including restricted management links and avoiding storage of full card-payment details. No online service can guarantee absolute security, so share card and management links carefully.
Lammigo is not intended for children to make purchases on their own. A parent or legal guardian should supervise any child using the creation tools. We may update this policy as the service or law changes; the date at the top will show the latest revision.
Related privacy terms
Questions or privacy requests
Contact Lammigo for questions about this policy or to make a privacy request. Please do not send payment-card details by email.