Treat a code like a password
It is functionally the same thing: a string that grants access to money, with no second factor and usually no name attached.
That means the same rules apply.
- Not in a group chat.
- Not in a shared photo album. Screenshots sync to family albums more often than people realise.
- Not in a plain note on a shared device.
- Not posted anywhere public, including in a support forum while asking why it does not work.
Where to put them instead
A password manager. Most have a secure note type. You get encryption, search, and sync across devices in one move. This is the whole answer for most people.
Failing that, an email folder. Make one called Gift codes, move them in, and — this is the part people skip — record the brand, amount and date in the subject line. "Your order" is useless in eleven months.
For physical cards, one drawer, not four. The reason people lose plastic cards is that there is no agreed place.
Redeem early where you can
The safest code is one that no longer exists. Once a balance is on an account:
- It cannot be read off a screenshot.
- It cannot be phished.
- It shows up when you shop, instead of being forgotten.
The exception is a code you might give away, which has to stay unredeemed. See how to give a gift card to someone else.
Keep a one-line list
A short list of what you hold beats a folder you never open:
Brand — amount — date received — redeemed yes/no
Four fields. Review it twice a year. This is the single habit that stops balances quietly evaporating, and it takes about two minutes to maintain.
What to do after a code leaks
If a code has been somewhere it should not have been:
- Redeem it immediately if it is still yours to redeem.
- Check the balance and note it.
- Report it if any of it is gone.
Do not wait to see whether anything happens. With bearer credentials, by the time you notice, it is spent.