Privacy Policy
Effective Date: August 3, 2026
This policy explains how HackSanta LLC collects, uses, and protects information for HackSanta.com. It is written with children's privacy in mind because parents may add child profiles, photos, toy details, and family list content.
1. Overview
HackSanta is a parent-operated family entertainment service. Parents and guardians create accounts, add children to private family lists, and decide whether children may view the Santa portal using parent-controlled access details.
HackSanta also includes adult account profiles, family connections with linked child lists, and gift registries that an account holder may share through a link. The sections below explain how those features affect visibility and data use.
We do not want children under 13 to create accounts or submit personal information directly to us. If you believe a child has provided personal information without a parent or guardian, contact us and we will review and delete it as appropriate.
2. Information We Collect
Account information: parent or guardian email address, authentication details handled by Supabase, display name, profile image if uploaded, membership status, and Stripe customer or subscription identifiers.
Child information provided by parents: child name or nickname, optional birth year, list status, uploaded child photo or selected avatar, toy name, toy image, list entries, Santa portal play code, and Santa letter or certificate details.
Family connection information: user-search results and profile information, connection requests and responses, accepted connections, connection timestamps, mutual-connection counts used for recommendations, dismissed recommendations, and choices to hide a connected child from a recipient's own dashboard.
Friend invite information: a parent may enter a recipient's email address, an optional message, and the child connected with the invitation so HackSanta can send and manage the invitation.
Gift registry information: registry name and description; gift product links, titles, images, retailer names, displayed price information, notes, order, and availability status; the registry share key; and, when a visitor reserves a gift, the visitor-provided name and a cryptographic hash of a browser claim token.
Operational information: security logs, parent-side analytics events, checkout events, email delivery status, and abuse-prevention/rate-limit data. Parent-side analytics may include page URL, referrer, device type, browser, operating system, source/campaign details, anonymous/session identifiers, and logged-in user ID when applicable.
3. Children's Privacy
HackSanta is designed so parents control the family account and child data. Children should use the portal only with parent permission and should not create their own accounts.
We use child information only to provide the family experience: Santa lists, the portal, toy details, letters, certificates, connected family lists, and related account features.
Parents may create a Santa portal play code for children to guess as part of the entertainment experience. This play code is not the parent's account password and is not intended to secure the parent account or private account data.
We do not sell children's personal information, use it for targeted advertising, or knowingly allow third-party advertising networks to track children through the portal.
Accepting a family connection automatically links the two accounts' family child lists. Each connected account holder may see the other account's family child names, list status, profile photo or avatar, and display name. Birth year, toys, toy images, toy requests, and detailed list entries are not included in the connected child card.
The parent or guardian who adds a child is responsible for having authority to provide and share that child's information with accepted family connections. Either adult can remove the family connection to end future access. A recipient may hide a connected child from the recipient's own dashboard without deleting the owner's child record.
Parents may review, edit, or delete child profiles, photos, toy details, list entries, and related account content from the dashboard. Parents may also contact us to request deletion or assistance.
Parents can also use My Account > Privacy & Data to download account and child data, delete individual child records, submit access, correction, deletion, or appeal requests, and permanently delete their HackSanta account.
4. Family Connections, Search, and Linked Lists
Signed-in HackSanta users can search for other account holders by display name. Search results and signed-in user profile pages may show an account holder's display name, profile image, family-connection count, mutual-connection count, and number of kids added. Email addresses, child names, child photos, list status, and other child details are not shown through account search or the visited profile page.
When you send or accept a family connection request, the other participant can see the account information needed to identify and manage the connection. Accepted connections may continue to see each other's display name, email address, profile image, and connection information until the connection is removed.
HackSanta may recommend account holders who share at least two accepted family connections with you. A recommendation may include the recommended user's display name, email address, profile image, and mutual-connection count. We store recommendation dismissals so dismissed suggestions can remain hidden.
Accepting a family connection automatically links each account's limited child-list cards to the other account. Removing the connection ends future access to those cards.
Email invitations are sent at the account holder's direction. Invitation recipients may unsubscribe from future friend-invitation emails, and we maintain suppression information needed to honor that choice.
5. Gift Registries and Shared Links
Gift registries are private-by-link, not restricted to signed-in users. Anyone who obtains a valid registry URL can view that registry without a HackSanta account. Registry pages are configured not to be indexed by search engines, but that setting is not an access-control guarantee. Account holders should share registry links only with people they trust.
A registry visitor can see the registry name and description and each gift's product link, title, image, displayed price, retailer, notes, and availability status. Registry owners should not place sensitive personal information in registry names, descriptions, or gift notes.
A visitor who reserves a gift must provide a name. The registry owner can see that name; other public visitors see the gift's status but not the claimer's name. HackSanta stores a hash of a random claim token and places the token in an HTTP-only browser cookie so that browser can undo its own reservation. The cookie may remain for up to one year. Clearing cookies or changing browsers may remove the visitor's ability to undo a reservation.
Account holders can regenerate a registry share link to invalidate the prior link, clear a gift's reservation status, delete gifts, or delete the registry. A person who previously viewed or copied registry information may retain a copy outside HackSanta even after access is changed.
When an account holder adds a product URL, HackSanta may retrieve the linked page's title, image, price, and retailer information from that third-party website. Clicking a product link takes the visitor to the third party, whose own privacy practices apply.
6. Photos and Uploads
Child, toy, profile, and registry gift-image uploads are stored in protected app storage. Child and toy uploads are served through authenticated or feature-specific access controls; registry gift images may be displayed to anyone with the applicable registry link.
HackSanta attempts to remove common image metadata, including EXIF, GPS, XMP, text, comment, and color-profile metadata, from supported JPG, PNG, and WEBP uploads before storage. GIF uploads are not accepted because metadata stripping is not reliable for that format.
HackSanta may enable automated safety screening intended to block nudity, sensitive-area exposure, swimwear, underwear, and people who are not fully clothed. When enabled, uploaded images are sent to OpenAI before storage without account names or email addresses. HackSanta configures the custom classifier request with storage disabled, though OpenAI may retain limited API data as described in its data controls or when required for safety or legal reasons. If enabled screening cannot be completed, the upload is blocked.
When an account holder removes or replaces an uploaded profile, child, toy, or registry gift image, HackSanta attempts to delete the prior uploaded file promptly from active storage. Some copies may persist temporarily in backups, logs, caches, or provider systems where immediate deletion is not technically available.
Parents should only upload photos they have the right to use and should avoid images containing sensitive details such as addresses, school IDs, medical information, or location metadata.
7. How We Use Information
We use information to provide and secure HackSanta, authenticate accounts, process subscriptions, send transactional emails and invitations, support family connections, linked lists, recommendations, and gift registries, retrieve product metadata, maintain parent-controlled family content, prevent abuse, troubleshoot errors, and improve parent-facing product flows.
We have disabled general child-side portal analytics. The only child-experience measurement is an aggregate count of Santa's Workshop Dashboard views. That event stores only the event name and timestamp; it does not include a child identifier, account identifier, page URL, referrer, device details, interaction data, or session replay. We do not track Santa list views, tracker views, individual workshop camera interactions, or child portal login attempts for analytics reporting.
8. Service Providers
We use trusted providers to operate the service, including Supabase for authentication, database, and storage; Stripe for payments and subscriptions; Resend for transactional email; OpenAI for automated image-upload safety screening; and Vercel or similar hosting/analytics infrastructure for deployment and performance.
These providers process information for HackSanta's operational purposes and are not authorized by us to use child information for their own advertising.
Stripe processes payment details. HackSanta does not collect or store full card numbers. We receive limited payment and subscription records such as Stripe customer ID, subscription ID, payment or subscription status, amount, and limited billing or contact details needed for account, support, tax, fraud-prevention, and recordkeeping purposes.
9. No Sale or Targeted Advertising
HackSanta does not sell personal information, share personal information for cross-context behavioral advertising, or use personal information for targeted advertising.
If our practices change in the future, we will update this policy and provide any choices or notices required by law before using personal information in those ways.
10. Cookies and Local Storage
HackSanta uses authentication cookies and local storage to keep parents signed in, maintain secure portal access, remember app state, and protect accounts.
For gift registries, HackSanta uses an HTTP-only, same-site claim cookie to remember whether the current browser can undo a guest reservation. The corresponding database value is stored as a cryptographic hash rather than the raw browser token.
On non-portal pages, HackSanta uses first-party local storage keys such as hs_anonymous_id, hs_session_id, and hs_attribution for parent-side operational analytics, session continuity, attribution/source reporting, debugging, and product improvement.
These first-party analytics identifiers are not used on child portal pages, are not sold or shared for cross-context behavioral advertising, and are not used for targeted advertising.
You can clear these local storage identifiers through your browser's site-data controls. Clearing them may reset analytics/session continuity but does not prevent you from using your parent account.
11. Retention and Deletion
We keep account and child information until the parent deletes it, closes the account, or requests deletion, subject to legal, security, billing, fraud-prevention, and recordkeeping obligations.
High-volume raw page-view and quiz-answer analytics events are generally retained for 30 days, and other raw analytics events for 180 days, after a completed daily aggregate exists. Privacy-reduced daily aggregate metrics may be retained for long-range reporting. Security, billing, fraud-prevention, and compliance records may follow different schedules when reasonably necessary.
Friend invite recipient emails and invite messages remain associated with the inviting account and child record until the related record or account is deleted, a deletion request is honored, or the information is no longer needed to operate the invitation, suppression, abuse-prevention, security, or compliance process. Invite recipients may contact us to request deletion or suppression of their email address.
Family connection, request, recommendation, hidden-child preference, and recommendation-dismissal records are kept while needed to operate those features, preserve user choices, prevent abuse, or meet legal and security obligations. Removing a connection ends future in-app access as described above, but limited records may remain where needed for those purposes.
Registry data is kept until the owner deletes the gift or registry, deletes the account, or requests deletion. A guest reservation name and claim-token hash remain until the status is cleared or the related gift, registry, or account is deleted, subject to limited legal, security, fraud-prevention, backup, and recordkeeping needs.
Parents can delete child records from the dashboard or from My Account > Privacy & Data. Parents may also permanently delete their HackSanta account from My Account > Privacy & Data, which removes active HackSanta account records, family data, child records, list entries, connections, hidden-child preferences, registries, invite records, drafts, and uploaded images from HackSanta unless limited retention is required for legal, security, billing, or fraud-prevention purposes.
12. Security
We use access controls, row-level security, private storage for uploads, rate limiting, HTTPS-capable hosting, and provider security features to protect account and child information.
The child-facing Santa portal play code is stored so parents can view, manage, and share it with their child for the pretend portal experience. Actual account access is protected separately by parent authentication, account-scoped access controls, and portal session/login-key checks.
Gift registry share keys are designed to be difficult to guess, and guest claim tokens are stored in hashed form. A share link can still be forwarded, copied, or exposed by a recipient, so it should not be treated like an account password or used to share sensitive information.
No online service can guarantee perfect security. Parents should use strong account passwords and should not share parent account credentials with children or others.
13. Parent and State Privacy Rights
Parents may request access, correction, deletion, export, or help limiting future use of their child's information from My Account > Privacy & Data or by contacting contact-us@hacksanta.com.
Depending on where you live, you may also have rights to access, correct, delete, or receive a copy of personal information, and to ask questions about opt-out rights. HackSanta does not sell or share personal information for targeted advertising, but you may still contact us about privacy choices or requests.
Please include the parent account email and enough detail for us to locate the relevant family account. We may need to verify that you control the account before acting on the request.
If we deny a privacy request, you may appeal by replying to our decision email or contacting contact-us@hacksanta.com with "Privacy Appeal" in the subject line.
14. Contact Information
HackSanta.com is operated by HackSanta LLC.
Privacy and parent requests may be sent to contact-us@hacksanta.com.
We are not listing a mailing address at this time. If a law requires a mailing address for a specific notice or request, contact us by email and we will provide the appropriate contact information.
15. Updates
We may update this Privacy Policy as HackSanta changes. If changes materially affect children's information practices, we will provide notice appropriate to the change and, when required, seek updated parental consent.