Effective date: October 5, 2025
SantaLetterMagic (“we,” “our,” or “us”) helps families transform handwritten letters to Santa into digital keepsakes. This Privacy Policy explains what information we collect, how we use it, and the choices you have when you use our mobile apps, backend services, and related websites (collectively, the “Services”). If you do not agree with this Policy, please do not access or use the Services.
Information We Collect
- Account details. When you register or sign in, we collect your name, email address, chosen authentication method (email, Google, Apple, or Facebook), and a hashed password if you register with email. We also store the unique identifier that each social login provider assigns to your account so we can recognize you on future sign-ins.
- Child profiles. Parents or guardians can optionally add information about their children (such as name and age) to personalize letters and digital responses.
- Letters and media. Uploaded letters, photos, audio, video, AI-generated feedback, and related metadata are stored so that we can process, deliver, and preserve your family’s Santa memories. Files are saved in an S3-compatible storage bucket, and references to those files are kept in our database.
- Usage and device information. We log basic technical details (such as IP address, device type, operating system version, event timestamps, and error reports) to troubleshoot issues, secure the platform, and understand how families use the Services.
- Payment records. If you purchase premium experiences, we collect order details, pricing, and non-sensitive identifiers (for example, Stripe customer and payment intent IDs). We do not store full payment card numbers; those are handled directly by our payment processor.
- Support communications. Messages you send to our team (including email, in-app feedback, or social media messages) are retained so we can respond and keep a record of your request.
How We Use Information
We use the information we collect to:
- Provide, personalize, and maintain the Services, including processing letter uploads and delivering AI-driven experiences.
- Authenticate users, secure accounts, detect fraud, and prevent misuse of the platform.
- Communicate with you about your account, features, updates, surveys, and support inquiries.
- Analyze usage trends and improve existing functionality.
- Process payments and deliver premium offerings when applicable.
- Comply with legal obligations, enforce our Terms of Service, and protect the rights, safety, and property of SantaLetterMagic, our users, and the public.
How We Share Information
We share information in the following situations:
- Service providers. We rely on trusted vendors to host infrastructure (for example, Amazon Web Services for storage and databases), send transactional communications, verify social login credentials, and process payments (Stripe). These providers only receive the information necessary to perform services on our behalf and must protect it according to contractual obligations.
- Legal and safety purposes. We may disclose information when we believe it is required by law, lawful government request, legal process, or to protect the safety of any person or the integrity of the Services.
- Business transfers. If we participate in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership that affects how your information is used.
We do not sell personal information or share it with third parties for their independent marketing.
Data Retention
We keep personal information for as long as you maintain an account or as needed to deliver the Services. If you request deletion, we will remove or anonymize your data within a reasonable timeframe, except where retention is required for legitimate business purposes or legal obligations. Backup copies stored for security purposes are purged on a rolling schedule.
Your Choices and Rights
- Access and updates. You can update account information within the app. Contact us if you need assistance correcting data that you cannot edit directly.
- Social login management. Manage your linked Google, Apple, or Facebook account through the respective provider settings.
- Opt-out of communications. You may unsubscribe from non-essential emails via the link included in each message. We may still send transactional notices about your account or legal updates.
- Request data deletion. Follow the instructions on our Data Deletion page or contact us at [email protected] to close your account and remove stored content.
Depending on your location, you may have additional rights (such as requesting a copy of your data or objecting to certain processing). We will honor those rights where required by applicable law.
Children’s Privacy
The Services are designed for parents and guardians. We do not knowingly allow children under 13 to create accounts without verifiable adult consent. If we learn that a child has registered independently, we will delete the account and associated data. Parents who believe we collected information from a child without consent should contact us immediately.
Data Security
We implement technical and organizational safeguards to protect personal information, including encryption in transit, role-based access controls, and regular security monitoring. However, no method of transmission or storage is completely secure, so we cannot guarantee absolute security.
International Users
Our infrastructure is primarily located in the United States. By using the Services, you acknowledge that your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the app, email, or website notice, and the “Effective date” will reflect the latest revision. Continued use of the Services after a change constitutes acceptance of the updated Policy.
Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
SantaLetterMagic Privacy Team
[email protected]
We aim to respond to privacy inquiries within 30 days.