Secure Every eligible gift card is reviewed and verified by our team before payout.
GC SPARK/Legal/Security

1. In transit

All traffic to GC SPARK is served over TLS 1.3. We use HSTS to prevent downgrade attacks.

2. At rest

Card numbers and PINs are encrypted at rest using AES-256. Keys are stored separately, rotated quarterly.

Card images are stored in a private object store with signed, time-limited URLs.

3. Access control

Every admin action is recorded. You can request the audit log for any submission by emailing support@gcspark.com.

Engineers do not have routine access to production card data.

4. Operational

  • Backups are encrypted and stored in a separate region.
  • We rate-limit submissions and login attempts.
  • Full card data is purged after payout.

5. Reporting a vulnerability

Email security@gcspark.com. We respond within 48 hours.

Independent service statement

GC SPARK operates independently from all gift card issuers. The brands featured on this website do not sponsor, authorize, or endorse GC SPARK's services. References to third-party trademarks are made solely for identification purposes.

Questions?

Email us — we read every message.

Anything in this policy unclear? Get in touch.

support@gcspark.com
Got a gift card?Get an estimate in 60s
Sell a card