← Back to home

Privacy Policy

Last updated: 5 August 2026

This Privacy Policy explains how we handle personal data in Wishdea (the "Service") and what rights you have. We process data in line with the GDPR (Regulation (EU) 2016/679). It covers both the Wishdea website and the Wishdea mobile app.

1.Who is the controller

The controller of your personal data is Dawid Job, a private individual who operates Wishdea. You can reach us in data-protection matters at contact@wishdea.com.

2.What data we collect

  • Account data - your e-mail address, an encrypted (hashed) password, your chosen list address (slug) and your language preference.
  • Sign-in data - if you sign in with Apple or Google, we store the identifier that provider gives us so we can recognise you next time, together with the e-mail address they share. If you use Apple's Hide My Email, that address is the anonymous forwarding one Apple generates - we never receive your real address. For Sign in with Apple we also keep a token that lets us ask Apple to revoke the connection when you delete your Account.
  • Wishlist content - the gift names, prices, links and descriptions you add and their order, whether a list is public or private, and any passcode you set to control access to a private list.
  • Reservation data - when you reserve a gift, we record who holds it: your Account if you are signed in, or otherwise a technical token stored in your browser, plus an optional name a Guest may give when reserving.
  • Follow data - which Wishlists you follow, the follow requests you send or receive, and the resulting connection between your account and a Wishlist owner.
  • Communication data - the service e-mails we send you, for example about follow requests and their approval.
  • Technical and usage data - IP address, device and browser type, and (with your consent) analytics about how you use the Service.
  • Diagnostic data - when the mobile app crashes or hits an error, we receive a technical report: what the error was, where in the app it happened, the app version and the device model and operating-system version. These reports are not linked to your Account.

3.Why and on what basis we use it

  • To provide the Service and your Account, including following and follow requests - performance of our agreement with you (Art. 6(1)(b) GDPR).
  • To keep the Service secure and prevent abuse - our legitimate interest (Art. 6(1)(f) GDPR).
  • For analytics and marketing - only with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
  • To meet legal obligations, e.g. handling complaints or requests about your data (Art. 6(1)(c) GDPR).

4.Cookies and analytics

We use cookies and similar technologies. Non-essential cookies (analytics, marketing) load only after you consent in the cookie banner. For details and how to change your choice, see our Cookies Policy.

5.Who we share data with

We share data only with trusted providers that help us run the Service and act on our instructions - hosting, e-mail delivery (Amazon Web Services), crash and error reporting for the mobile app (Sentry) and, subject to your consent, analytics on our website (Google Analytics). We do not sell your personal data. Each of these providers is bound by a contract that requires them to protect your data to at least the same standard as this Policy sets out, to process it only on our instructions and never for their own purposes.

Some data is also visible to other Users as part of how the Service works. When you follow a Wishlist or send a follow request, the owner of that Wishlist can see your account identity (such as your e-mail or name) and that you follow their list. If you own a Wishlist, you can see who follows it or has asked to.

6.International transfers

Some providers may process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.

7.How long we keep data

We keep Account and Wishlist data for as long as you have an Account. After you delete your Account we remove the data, except where we must keep some of it longer to comply with the law or to defend against claims.

8.Your rights

Under the GDPR you have the right to:

  • access your data and receive a copy of it;
  • rectify, erase or restrict the processing of your data;
  • object to processing based on our legitimate interest;
  • data portability;
  • withdraw consent at any time, without affecting processing done before the withdrawal;
  • lodge a complaint with a supervisory authority - in Poland, the President of the Personal Data Protection Office (UODO).

9.Data security

We use technical and organisational measures to protect your data, including encryption in transit and hashed password storage. No method of transmission or storage is completely secure, but we work continuously to keep your data safe.

10.Children

The Service is not intended for children under 16. We do not knowingly collect their data; if you believe a child has provided us with data, contact us and we will delete it.

11.Changes to this Policy

We may update this Policy. We will publish changes in the Service with a new date, and for significant changes we will ask you to review and accept them the next time you sign in.

12.Contact

For any privacy questions or to exercise your rights, write to contact@wishdea.com.