BudlingBudling
Find a registryInsightsAbout
Legal

Privacy Policy

Effective: 26 June 2026 · Last updated: 26 June 2026 · Version: 4.0 · View history

The plain-English summary
We collect what's needed to run your registry - and we treat your child's information with more care than most platforms treat adults'.

What we collect: your name and email, your child's first name and (optionally) approximate age, your registry contents, RSVPs, and notes or photos guests choose to share. We do not process payments, so we do not collect payment details.

What we never do: sell your data, share it with advertisers, use it for targeted advertising, use photos or videos guests share for marketing, or use your child's information for any purpose other than running your registry.

Your rights: export your data, delete it, or correct it at any time - from your dashboard or by emailing privacy@getbudling.com. We respond within 45 days; usually much sooner.

For your child: Budling is a parent-directed platform. We do not collect information directly from children. Registries are link-only by default - they are not listed publicly and the public directory only includes a registry if the parent opts in.

Contents
  1. Who we are
  2. Information we collect
  3. How we use your information
  4. Legal bases for processing
  5. Who we share data with
  6. Third-party retailers and 529 plans
  7. Notes, photos and videos
  8. Children's data and COPPA
  9. Parental consent
  10. How long we keep data
  11. How we protect your data
  12. Your privacy rights
  13. California residents (CCPA/CPRA)
  14. Other state privacy laws
  15. International users
  16. Cookies and tracking
  17. Data breach notification
  18. Automated decision-making
  19. Do Not Track and GPC
  20. Changes to this policy
  21. Contact us

1. Who we are

Budling ("Budling," "we," "us," "our") is a free group gift registry for children. Budling is a brand and product operated by its parent company. For our full legal entity details, contact legal@getbudling.com. We operate getbudling.com and related services (the "Service").

Under US privacy laws, we act as a business (California) and a controller (Virginia, Colorado, Connecticut, Utah, Texas, Florida, Oregon, and similar states), and as an operator under the Children's Online Privacy Protection Act (COPPA). Under UK and EU GDPR (where applicable), we act as a controller for your direct information.

You can contact us at privacy@getbudling.com, or by mail to the address on file with legal@getbudling.com.

2. Information we collect

Information you provide directly

  • Account information: your name, email address, and (if you set a password) a password stored only as a one-way hash
  • Registry information: your child's first name, approximate age (optional), planned event date, and the gift items you choose to list
  • Photos you upload: registry cover photos you choose to add
  • Guest information: when someone RSVPs or claims a gift, we collect their name and (if provided) email, plus any note or photo they choose to attach
  • Communications: messages sent to support and feedback you choose to submit

Information we do not collect

  • Payment information. Budling does not process or accept payments. Gift purchases happen on third-party retailer sites (such as Amazon) and 529 contributions happen on the 529 plan's own portal. We never see card numbers, bank account details, or order totals.
  • Social Security numbers, driver's license numbers, or other government identifiers
  • Precise geolocation
  • Racial or ethnic origin, religious beliefs, health information, sexual orientation, or political opinions
  • Biometric identifiers or genetic data

Information we collect automatically

  • Device and browser information: IP address, browser type, operating system, device identifiers, screen dimensions, and time zone
  • Usage information: pages visited, features used, actions taken, timestamps, and referral source
  • Cookies and similar technologies: as described in Section 16

3. How we use your information

We use information only for the specific purposes listed below:

  • Providing the Service: creating and maintaining registries, displaying wishlist items, managing RSVPs, sending reminders, and storing notes or photos guests attach
  • Account security: authenticating logins, detecting fraud or abuse, and enforcing our Terms of Service
  • Customer support: responding to your questions and resolving issues
  • Service improvement: aggregated, pseudonymized analytics to identify bugs, measure feature adoption, and guide product decisions - never tied to individual identities in any reports
  • Communications you've opted into: product updates, feature announcements, and educational content - only with your consent, with a one-click unsubscribe in every email
  • Legal compliance: responses to valid legal process and protecting rights or safety when required
Our binding commitments
  • We will not use your data or your child's data to train advertising profiles or algorithmic targeting systems.
  • We will not share your personal information with data brokers.
  • We will not use the photos or videos guests attach to gifts for marketing, testimonials, or any purpose beyond showing them privately to the registry owner.
  • We will not change these commitments without giving you advance notice and the opportunity to export or delete your data first.

4. Legal bases for processing

For users whose processing is governed by the EU GDPR, UK GDPR, or similar laws, we rely on the following legal bases:

  • Performance of a contract - providing the Service you signed up for
  • Legitimate interests - fraud prevention, security, product improvement, and direct Service communications, balanced against your rights. You can object at any time
  • Consent - marketing communications, non-essential cookies, and any processing requiring affirmative consent. You can withdraw consent at any time
  • Legal obligation - responses to lawful legal process

5. Who we share data with

We share your information only with the categories of recipients below, and only to the extent necessary:

  • Infrastructure and hosting providers - cloud hosting, database, and email-delivery providers, all operating under written data-processing agreements that limit their use of your data to providing services to us
  • Analytics provider - a privacy-respecting provider that does not create advertising profiles or share data with ad networks. We share only pseudonymized usage information, not your identity
  • Professional advisors - accountants, auditors, and lawyers bound by confidentiality obligations
  • Corporate transactions - if Budling or its parent company is involved in a merger, acquisition, reorganization, financing, or sale of substantially all assets, your information may be transferred. We will notify users by email or in-app notice before any transfer completes, and you may export or delete your data first
  • Legal process - when required by valid subpoena, court order, or other legal process, or to protect our rights, property, or users' safety. Where legally permitted, we will notify you before disclosing your information and challenge overbroad requests

6. Third-party retailers and 529 plans

Budling does not process payments. When a guest clicks through to an outside retailer (for example Amazon) or to a 529 plan portal (for example UGift, operated by Ascensus), they leave Budling and complete the transaction on that third-party site.

  • Affiliate links. Budling participates in retailer affiliate programs, including the Amazon Associates Program. When a guest clicks a retailer link from a registry, the retailer sets its own cookie for purchase attribution. We may earn a small commission if a purchase results. We do not share your name, email, or registry contents with the retailer, and the retailer does not share your purchase details with us beyond aggregate, anonymized commission reporting.
  • 529 plan portals. If a guest chooses to contribute to a 529 college savings plan, the contribution flow takes place entirely on the 529 plan administrator's platform under that administrator's privacy policy. We do not receive, hold, or transmit 529 contributions.
  • Third-party privacy. Once a guest leaves Budling for a retailer or 529 portal, the third party's privacy policy and terms govern. We have no control over and accept no responsibility for their data practices.

7. Notes, photos and videos

This section describes how we handle the personal content guests attach to RSVPs or gifts, and the photos parents add to their registry.

Notes from guests

When someone RSVPs or marks a gift as claimed, they can leave a short note. Notes are visible only to the registry owner from the dashboard.

  • Stored at rest: notes are stored on our hosting provider's encrypted database storage
  • Access by the registry owner: the registered parent or guardian can read notes from the dashboard
  • Export: you can export your registry data, including notes, from your dashboard at any time

Photos and videos

Guests may attach a photo or short video to a gift or RSVP, and parents can upload registry cover photos. All of this media is private by default and visible only to the registry owner.

  • Media is never used by Budling for marketing, advertising, or testimonials - binding commitment, not discretionary
  • Media is never shared with third parties, including analytics providers
  • Media is not used as training data for any machine-learning system
  • You can delete any media from your dashboard at any time; backup copies are purged in line with the schedule in Section 10

8. Children's data and COPPA

This is the section that matters most to most of our users. We've designed Budling to align with the Children's Online Privacy Protection Act (COPPA) and the general principles of privacy-by-design for minors.

Our core framing

Budling is a parent-directed platform. All interactions with our Service are performed by adult parents or legal guardians on behalf of their children. We do not have child user accounts. Children do not sign in, browse, or directly interact with Budling.

Information about a child is provided exclusively by the parent, who acts as our authorized source of truth for that information and who retains full control over what is collected, what is displayed, and what is deleted.

What we process about children

  • First name (required to create a registry)
  • Approximate age or date of birth (optional; used for age-appropriate suggestions and countdown displays)
  • Photos that the parent chooses to upload
  • Notes or photos attached to a gift or RSVP by guests

What we don't collect or use about children

Binding commitments regarding children's data
  • We do not collect information directly from children.
  • We do not use children's information for behavioral advertising, targeted marketing, or any advertising purpose.
  • We do not build profiles about children.
  • We do not sell or share children's information for any commercial purpose outside of providing the Service.
  • We do not disclose children's last names in any public-facing area of the Service.
  • We do not use children's photos or information as training data for AI or machine-learning systems.
  • We apply data minimization: we collect only what is needed, we retain it only as long as needed, and we default to the most privacy-protective settings.

Privacy-by-default settings

  • New registries default to link-only visibility. The registry is not findable through our public search or the find-a-registry directory unless the parent opts in.
  • The public directory is opt-in, not opt-out. Parents must take an affirmative action to list a registry publicly.
  • Public listings show first names only. Even when opted in, a registry displays only the child's first name and event type. No last name, no full birth date, no precise location.

Parent controls

The parent can, at any time:

  • Review all information Budling holds about their child through the dashboard
  • Export an archive of their child's registry data
  • Delete specific items or the entire registry, which removes the associated data from our active systems within 30 days
  • Withdraw consent for specific processing activities, such as the public directory listing

9. Parental consent

Because our processing of children's information begins only when a parent creates a registry, we obtain parental consent at the point of account creation.

Our consent mechanism

  1. Email verification: the parent must confirm their email address through a unique link before the registry becomes active
  2. Affirmative consent statement: before creating the registry, the parent must affirmatively confirm they are the parent or legal guardian, are 18 or older, and consent to Budling processing information about their child as described in this policy

Parental access and review

At any time, a parent can:

  • Review everything we hold about their child by logging in to the dashboard
  • Request a full data export by emailing privacy@getbudling.com
  • Delete information or the entire registry
  • Revoke consent, at which point we will delete the child's information within 30 days

If you believe a registry has been created without parental consent, or contains information about a child without proper authorization, contact privacy@getbudling.com and we will investigate promptly.

10. How long we keep data

We retain personal information only as long as necessary for the purposes described in this policy, applicable legal requirements, or the time needed to resolve disputes. Indicative retention periods:

Category of dataRetention period
Account credentials (email, hashed password)Until account closure, then deleted within 30 days
Registry data (child's first name, wishlist, photos)Until you delete the registry or close your account, plus up to 30 days
Backup copies of deleted dataPurged in line with our hosting provider's backup retention, typically within 90 days
Guest RSVPs and notesUntil the parent deletes them or closes the account
Photos and videos attached to giftsUntil the parent deletes them; backups purged within 90 days
Support correspondenceUp to 3 years from last interaction
Server logs and security recordsRolling, typically 90 days
Analytics data (pseudonymized)Up to 26 months
Marketing consent recordsUntil consent is withdrawn, plus a reasonable period for proof of compliance
Legal hold dataAs long as legally required

11. How we protect your data

Technical safeguards

  • Encryption in transit: all connections to getbudling.com use HTTPS with modern TLS
  • Encryption at rest: data is stored on managed cloud infrastructure that encrypts data at rest by default
  • Password handling: passwords are stored only as one-way hashes by our authentication provider. Plaintext passwords are never stored, transmitted, or logged by Budling
  • No payment data: Budling does not process or store payment card information. Gift purchases occur on third-party retailer sites under their own security controls

Administrative safeguards

  • Access controls: access to production data is restricted to authorized personnel and is logged
  • Vendor diligence: we evaluate the security practices of vendors before granting access to personal information and require written data-processing agreements where appropriate

Responsible disclosure

Security researchers can report vulnerabilities to security@getbudling.com. We commit to:

  • Responding to initial reports promptly
  • Working in good faith to remediate verified vulnerabilities
  • Not pursuing legal action against researchers acting in good faith

No security measure is perfect. Despite our efforts, we cannot guarantee absolute security. If a breach occurs, we will follow the procedure in Section 17.

12. Your privacy rights

Depending on where you live, you have some or all of the following rights regarding your personal information. We honor these rights for all users regardless of location, as a matter of policy.

Access
Request a copy of the personal information we hold about you, in a machine-readable format
Correction
Ask us to correct inaccurate or incomplete information
Deletion
Request deletion of your account and associated data, subject to legal retention requirements
Portability
Export your data in a common, machine-readable format
Opt-out of sale or sharing
We do not sell data for money. You can opt out of any disclosure classified as a "sale" or "sharing" under state law
Limit sensitive info
Restrict our use of any sensitive personal information to the minimum necessary to provide the Service
Non-discrimination
We will not discriminate against you for exercising any privacy right
Appeal
If we deny your request, you can appeal. Appeals are handled by a different person than the original reviewer

How to exercise your rights

  • Most rights can be exercised directly from your dashboard (Account → Privacy and data)
  • Alternatively, email privacy@getbudling.com from the email address associated with your account
  • We verify your identity by confirming control of your account email
  • We respond within 45 days. In complex cases, we may extend by up to an additional 45 days with written notice explaining the delay
  • If we deny a request, you can appeal by replying to our denial email
  • There is no fee for these requests except in cases of clearly excessive or repetitive requests

13. California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with the rights described above plus the additional disclosures here.

Categories of personal information collected (preceding 12 months)

  • Identifiers: name, email, IP address, account ID
  • Commercial information: registry contents, RSVP history
  • Internet or network activity: browsing and usage patterns on getbudling.com
  • Inferences: age-category preferences derived from registry configuration
  • Sensitive personal information: account login credentials only, used exclusively to authenticate you

Categories of personal information disclosed for a business purpose

  • Identifiers and usage data to infrastructure providers for hosting and delivery
  • Pseudonymized identifiers to our analytics provider for product improvement

"Sale" and "Sharing" under CCPA

California law defines "sale" and "sharing" broadly. These terms can include non-monetary disclosures of personal information for cross-context behavioral advertising.

  • We do not sell personal information for money.
  • We do not engage in cross-context behavioral advertising.
  • Affiliate cookies (Amazon and similar): when you click an affiliate link, the retailer sets a cookie for attribution. In an abundance of caution, we treat this arrangement as potentially classified as "sharing" under CCPA. You can opt out by (a) disabling third-party cookies in your browser, (b) using a browser that sends a Global Privacy Control (GPC) signal, or (c) emailing privacy@getbudling.com
  • We do not knowingly sell or share the personal information of consumers under 16 without affirmative authorization, as required by CCPA § 1798.120(c)

Sensitive personal information (CPRA)

The only "sensitive personal information" we collect is your account login credentials, used solely to authenticate you. We do not use sensitive personal information beyond the purposes permitted by CCPA § 1798.121(a), so the right to limit use does not apply.

Shine the Light

California Civil Code § 1798.83 ("Shine the Light") permits California residents to request information about disclosures of personal information to third parties for those third parties' direct marketing. We do not disclose personal information to third parties for their direct marketing purposes.

14. Other state privacy laws

Residents of the following states have substantially similar rights to those described above, which we honor for all users:

  • Virginia (Virginia Consumer Data Protection Act)
  • Colorado (Colorado Privacy Act)
  • Connecticut (Connecticut Data Privacy Act)
  • Utah (Utah Consumer Privacy Act)
  • Texas (Texas Data Privacy and Security Act)
  • Florida (Florida Digital Bill of Rights)
  • Oregon (Oregon Consumer Privacy Act)
  • Montana, Delaware, Iowa, Indiana, New Jersey, New Hampshire, Tennessee, and other states with comprehensive privacy laws

To exercise your rights under any of these laws, use the same methods as described for California residents. We do not engage in targeted advertising or profile-based automated decisions that produce legal or similarly significant effects.

Residents of applicable states retain the right to appeal our denial of a rights request by replying to our denial response. If your appeal is denied, you have the right to contact your state attorney general's office.

15. International users

Budling is operated from and hosted in the United States. If you access Budling from outside the United States, your personal information will be transferred to, stored, and processed in the United States, which may have different data-protection laws than your country of residence.

For users in the European Economic Area, the United Kingdom, or Switzerland, where applicable we rely on appropriate legal mechanisms for cross-border transfer, including Standard Contractual Clauses with service providers that process data on our behalf. You may contact privacy@getbudling.com for details.

16. Cookies and tracking

We use a small number of cookies and similar technologies to operate the Service:

  • Strictly necessary: session, authentication, and security cookies required for the Service to work
  • Preferences: remembering your settings, such as theme or saved RSVPs
  • Analytics: a privacy-respecting analytics provider that does not build advertising profiles, using pseudonymized identifiers

We do not use advertising cookies. Third-party retailers you click through to from a registry may set their own cookies for purchase attribution; those are governed by the retailer's own policies.

17. Data breach notification

If we determine that a security incident has resulted in the unauthorized acquisition of personal information, we will notify affected users without undue delay and in accordance with applicable law. Notice will be by email to the address on your account and, where appropriate, by in-app notice. We will describe what happened, what information was involved, what we are doing, and what you can do to protect yourself.

18. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Lightweight automated logic (such as fraud-prevention checks) may be used to protect the Service, with human review available on request.

19. Do Not Track and Global Privacy Control

We honor Global Privacy Control (GPC) signals as an opt-out of any disclosure that may be classified as a "sale" or "sharing" under applicable state law. Because the broader Do Not Track standard is not consistently defined or implemented across browsers, we do not respond to DNT headers as a separate signal; the GPC signal is the standard we honor.

20. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced by email and on the Service before they take effect. Continued use after the effective date constitutes acceptance. Past versions are available on request.

21. Contact us

Budling
Privacy: privacy@getbudling.com
Security: security@getbudling.com
Legal notices: legal@getbudling.com
General inquiries: hello@getbudling.com

Version history

  • Version 4.0 - 26 June 2026. Major rewrite to match the current operating model: Budling does not process or hold payments. Removed payment-data collection, Stripe-as-service-provider, 529-administrator sharing, payout/KYC and related categories. Softened specific security claims to truthful baseline language (no claims about AES-256 at rest, KMS rotation, annual pentests, or EXIF stripping). Softened the COPPA consent mechanism to the two-step flow actually implemented (email verification plus affirmative consent statement). Removed the EU-US Data Privacy Framework certification claim. Replaced specific corporate-entity references with brand-only language (operated by parent company; contact legal@getbudling.com for entity details).
  • Version 3.0 - 20 April 2026. Expanded COPPA/state-privacy disclosures alongside the Stripe-based payment model.
  • Version 2.0 - April 2026. Comprehensive rewrite covering CCPA/CPRA, GDPR, and children's data.
  • Version 1.0 - April 2026. Initial Privacy Policy.
Budling

Gifts, experiences and savings - growing with your child. Real gifts for today, real savings for the future.

Product

Create registryFind a registryHow it works

Resources

InsightsFAQUGift 529 plansSend a giftContact us

Legal

AboutPrivacyTerms

As an Amazon Associate, Budling earns from qualifying purchases.

© 2026 Budling · Not a bank or investment advisor · getbudling.com
PrivacyTerms