Back to Home

Privacy Policy

Last updated: July 24, 2026

1. Introduction

GCNhub ("we", "us", "our") operates the GCNhub API platform and website at gcnhub.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

2. Information We Collect

We collect the following categories of information:

  • Account Information: Name, email address, company name, and role when you request API access or create an account.
  • Usage Data: API call volumes, endpoints accessed, timestamps, and IP addresses for analytics, billing, and security monitoring.
  • Technical Data: Browser type, device information, and interaction logs collected via cookies and similar technologies.
  • Transaction Data: Order amounts, brand selections, and wallet addresses associated with gift card purchases.
  • Payment Information: Processed through our PCI-compliant payment partners. We do not store full card numbers on our servers.

3. How We Use Your Information

We process your personal data for the following purposes:

  • Providing, maintaining, and improving the Service, including processing API requests and gift card orders.
  • Managing your account and communicating with you about product updates, security alerts, and support.
  • Processing payments and generating invoices.
  • Monitoring for fraud, abuse, and security threats.
  • Complying with legal, regulatory, and audit obligations.

4. Legal Basis for Processing (GDPR)

Under the GDPR, we process your personal data on the following legal bases:

Performance of a contract: to deliver the Service you requested, including API access and order fulfillment.

Legitimate interests: to monitor security, prevent fraud, and improve our Service.

Legal obligation: to comply with applicable laws and regulations, including AML/KYC requirements.

Consent: for non-essential cookies and marketing communications. You can withdraw consent at any time.

5. Data Sharing and Disclosure

We do not sell your personal data. We share information only with:

Service providers and sub-processors who help us operate the Service (e.g., cloud hosting, email delivery, payment processing). All sub-processors are bound by data processing agreements.

Retail brand partners who fulfill gift card orders — only the minimum data needed to deliver the gift card.

Law enforcement or regulators when required by law or to protect our rights and safety.

6. Data Security

We implement industry-standard security measures to protect your data, including:

Encryption in transit (TLS 1.2+) and at rest (AES-256).

SOC 2 Type II certified infrastructure with regular third-party audits.

Role-based access controls and least-privilege principles.

Continuous security monitoring and automated threat detection.

7. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy or as required by law.

Account data is retained for the duration of your account plus a limited period for legal and audit purposes.

Transaction records are retained for a minimum of five (5) years to comply with financial regulations.

API usage logs are retained for ninety (90) days for security and debugging, then automatically deleted.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Restriction: Request that we limit processing of your data.
  • Portability: Receive your data in a structured, machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw Consent: Withdraw consent for processing that relied on consent at any time.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, for any transfer outside the EEA or UK.

10. Cookies

We use cookies and similar technologies to operate and improve our Service. For details, please see our Cookie Policy.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. We encourage you to review this page periodically.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at support@gcnhub.com.

Our Data Protection Officer (DPO) can be reached at dpo@gcnhub.com for GDPR-related inquiries.