A gift card image is not an ordinary profile photo. It can contain a redeemable code, a PIN, a receipt, an email address, an order number, and location metadata from the camera. A single authorization bug can therefore expose both personal data and something that behaves like a bearer secret.
Source: [Dev.to](https://dev.to/cardflowng/designing-a-privacy-safe-gift-card-image-submission-pipeline-655)