Privacy
Privacy by product boundary
Private creations stay separate from the public site, with practical controls for recovery, revocation, and deletion.
Effective date: August 27, 2026. In this document, “YoursToOpen” means the YoursToOpen website and service available at yourstoopen.com. Questions may be sent to info@yourstoopen.com.
What this notice covers
This notice explains how YoursToOpen handles personal data on the public site, in creator tools, and while delivering a private recipient experience. It applies to information you provide directly and technical or operational information created when the service is used.
A recipient reveal is not a public profile or gallery entry. The creator decides what to include, and the recipient opens it through a private link or QR code.
Information a creator provides
Depending on the experience and features selected, a creator may provide a recipient name, personal message, one photo, event details, response settings, scheduling choices, a recovery email, and an optional recipient password. A creator who opens an account also provides account credentials and profile information needed for that account.
Please do not include payment card details, account passwords, government identifiers, health information, or other information that is not needed for a personal reveal.
- Recipient and creator content
- Optional recovery or account details
- Support, safety, and removal requests
Information created when the service is used
We create the minimum operational records needed to publish, protect, recover, troubleshoot, and enforce the lifecycle of a private reveal. This includes high-entropy link capabilities, creation status, expiry, revoke or deletion events, security and abuse-prevention signals, and service logs.
Recipient reporting is held as daily aggregate counts such as opens, completions, and responses. Public acquisition reporting uses daily aggregate counts by an allowlisted landing-page key, experience, and starting recipe. It does not store a visitor or session identifier, raw URL, query string, referrer, IP address, user agent, or browser fingerprint.
- Private-link and lifecycle records
- Aggregate recipient and acquisition reporting
- Technical signals needed to secure and operate the service
Why we use information
We use information to provide the experience a creator asks us to make and deliver; let the recipient open it; operate accounts and recovery; understand aggregate acquisition paths; respond to support, safety, removal, and legal requests; prevent fraud, abuse, or harmful use; and improve reliability.
YoursToOpen processes information when it is needed to provide the requested service, protect the service and its users, meet applicable legal obligations, or act with consent where consent is required.
Who may process information
Access is limited to YoursToOpen and service providers that need it to operate hosting and storage, email delivery, support, security, infrastructure, and payments. PMPro records the order and membership; the selected Stripe or PayPal flow collects payment on the provider-hosted surface. YoursToOpen stores upgrade intent and return context, never card or PayPal credentials.
Providers may process information from the countries in which they operate. YoursToOpen requires service-related processing and applies contractual or other safeguards appropriate to the processing. Private recipient content is not made available as a public catalogue or used to build advertising audiences.
Security, private links, and lifecycle
Generated recipient and edit links are high-entropy capabilities. An exact custom recipient path is an alias and always requires a separate password. Sensitive values such as recovery contact details and link material are protected in storage, and recipient passwords are stored as verification values rather than displayed back to us. These controls reduce risk; they do not replace careful sharing by the creator.
Creators can revoke or delete a reveal. A revoked, deleted, or expired reveal should no longer expose its private content. Deletion also triggers removal of associated media, while limited operational records may remain for the configured retention period needed for security, accounting, or legal obligations.
Retention and deletion
A published private link is available for seven days and may be extended once for seven more days unless it is revoked or deleted earlier. Recovery links expire. Deletion and expiry jobs remove associated media and dependent service data according to the active operational lifecycle.
YoursToOpen keeps support, safety, security, and service records only for as long as they are needed for their stated purpose, legal obligations, dispute handling, or protection of the service. Where a fixed period does not apply, necessity and the continuing relationship to an active account, request, or security matter determine retention.
Your choices and privacy requests
Creators can manage a creation through the available creator or account controls, including revocation and deletion. To ask about access, correction, deletion, objection, restriction, portability, or a privacy complaint where applicable, contact info@yourstoopen.com. We may need to verify the request before acting on it.
Recipients can use the safety route to report a reveal or request review without creating an account. If a request concerns a private link, do not post that link publicly; provide it only through the relevant support or safety path.
About YoursToOpen
YoursToOpen is the website and service name used as the controller name in this notice. Privacy questions and requests may be sent to info@yourstoopen.com. If a request concerns a private reveal, use the private support or safety route and do not post the reveal link publicly.