The card’s code and QR are bearer credentials: someone who obtains them may redeem the gift. Protect every copy, including screenshots, printed cards and messages.
Know which links to share
The redemption link belongs with the recipient’s gift. The buyer’s private order link should stay with the buyer because it also provides access to the order and delivery controls. Neither link should appear in a public post.
The name printed on the card is not a password or identity restriction. Sending a copy to several people does not limit redemption to the person whose name appears on it.
Reduce unnecessary copies
Use a protected email account and a verified private contact channel. Check the destination before sending an attachment. Be mindful of shared photo libraries, cloud folders and printers used by other people.
For a physical gift, keep the full printed card concealed until handover. A photo showing a readable QR can disclose the same access as typing out the code. Blurring only the text while leaving the QR visible is insufficient.
If you suspect exposure
Check the card’s status on the official site and contact support privately. Provide a reference that identifies the order without publishing the bearer code. Support can assess the card state; do not assume an already confirmed payout can be reversed.
Changing a buyer order link does not automatically change the separate card code already printed in old copies. Treat those copies as sensitive unless support has explicitly confirmed the card’s state and the appropriate next step.
