No email required
The core flow is link-first. Participants do not need an account or email address to receive a reveal. Organizers share each link directly with the intended person.
No names in URLs
Participant names should never be placed in URL paths, page titles, analytics events or third-party requests. Reveal links use opaque tokens instead of identity-bearing text.
Links are access
A private reveal link is a bearer link: anyone who receives it can open it. MerryShuffle uses 256-bit random credentials, keyed hashes for stored recovery and reveal credentials, no-store caching, a strict referrer policy, expiry, revoke/rotate controls and organizer deletion.
Assignments are encrypted
The server stores each recipient mapping as AES-256-GCM ciphertext with an authenticated event-and-participant context. The organizer can see the completed draw by design; the recipient is not placed in the reveal URL, token hash, or browser fragment.
Commerce comes later
The reveal screen should stay commerce-free. Optional gift discovery can appear after the assignment with clear affiliate disclosure and non-affiliate alternatives.