Privacy Policy
This Privacy Policy explains how Wantivo processes personal data on the website, in the web app and in the iOS and Android apps, including share extensions. It is intended for users in the EU / EEA and provides the information required by Art. 13 GDPR.
Bürgerstrasse 22
4300 St. Valentin
Austria
Email: contact@wantivo.com
Web: https://www.wantivo.com
Wantivo is a wishlist app for creating, sharing and managing wishlists. Depending on how you use it, we process in particular:
- Account data: name, email address, login provider, provider ID, password hash for email login, verification, password-reset and deletion codes.
- Profile and content data: profile picture, wishlist name, purpose, description, date, currency, visibility, images, wishes, links, descriptions, prices, priority and reservations.
- Participation and sharing data: memberships, roles, invite links or QR codes, invite tokens, usage counters and expiry dates.
- Communication data: transactional emails, notifications, support requests and mail logs.
- Technical data: IP address, user agent, session and CSRF data, device/push tokens, error and security logs, rate limits, internal product and administration events.
- Premium data: product, plan, platform, transaction or purchase token, subscription status and periods.
Please do not store special categories of personal data under Art. 9 GDPR unless this is necessary for a wishlist.
Wantivo is not specifically directed at children under 16.
- Performance of a contract, Art. 6(1)(b) GDPR: providing account, login, wishlists, sharing, reservations, groups, notifications and Premium status.
- Consent, Art. 6(1)(a) GDPR: push notifications, analytics cookies and similar technologies, and optional device permissions when you enable them.
- Legitimate interests, Art. 6(1)(f) GDPR: IT security, abuse prevention, rate limiting, error analysis, product stability and traceability of important system events.
- Legal obligations, Art. 6(1)(c) GDPR: statutory retention, evidence and response obligations.
Where we rely on legitimate interests, you may object on grounds relating to your particular situation.
Certain data, such as login, account and wishlist data, is required to provide Wantivo. Optional details and consents, for example for push notifications or analytics, are voluntary; without them, only the respective additional features are unavailable or limited.
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
You can sign in with email and password, Sign in with Apple or Google/Firebase. For email login, we do not store your password in plain text but as a hash. For email verification, password reset and account deletion we use time-limited codes and logs so we can deliver the messages and protect the process.
For Sign in with Apple and Google/Firebase we verify identity tokens and receive, depending on the provider, provider ID, email address and name. According to Google, Firebase Authentication may process email address, IP address and user agent for authentication and abuse prevention. More information: Firebase Privacy and Security, Google Privacy Policy and Apple Privacy Policy.
Wishlists can be private, shared or public. Invite links and QR codes contain tokens; anyone who receives the link may gain access depending on the settings. Share these links only with people you trust.
People with access may, depending on their role and feature, see list data, wishes, images, links, descriptions, prices, reservation status and the names and profile pictures of other participants. Public lists can be reachable without login via their URL. Do not use public lists for confidential content.
If you upload profile, list or wish images, we technically check and process the file, convert it into a supported format and store it for display in Wantivo. For link previews, our server fetches the product page you provide. The target website usually sees a request from the Wantivo server, not your app IP address.
Title, description, image, price, currency and merchant can be extracted from the page. The raw page is not stored permanently; in the wishlist we store only data you accept or enter yourself. Share extensions on iOS and Android may temporarily store shared links or text locally until they are imported into Wantivo or discarded.
If you enable push notifications, we store the device or push token, platform, timestamps and assignment to your account. Push messages are delivered via Firebase Cloud Messaging and, on Apple devices, also via Apple Push Notification service. Depending on the event, notifications may contain list names, wish titles or technical IDs. You can disable push notifications at any time in your device settings.
The apps locally store, among other things, login tokens, pending invites, shared content, push-token status and UI states. iOS uses Keychain and UserDefaults, among others; Android uses EncryptedSharedPreferences and SharedPreferences, among others. Android app backups and device transfers are disabled for Wantivo so local tokens and app data are not unnecessarily included in operating-system backups; on iOS, local app data may be included depending on your iCloud and device backup settings.
The native apps currently do not use Firebase Analytics, Crashlytics, AdMob or other advertising/tracking SDKs. iOS uses Firebase for authentication and messaging; Android uses Firebase Auth and Firebase Cloud Messaging.
Premium purchases and subscriptions are processed via Apple App Store or Google Play. We do not receive payment data such as credit card or bank details. To unlock and verify Premium status, we process technical purchase data such as platform, product ID, plan/base plan, transaction ID or purchase token, subscription status, periods and the latest signed or API-based response.
Apple and Google process App Store, Play Store, payment and account data as separate controllers. Cancellation, renewal and payment management take place in your Apple or Google account. More information is available in the Apple Privacy Policy and the Google Privacy Policy.
Public marketing and legal pages do not set session or CSRF cookies on a first visit without an existing Wantivo session. Login, registration, support/privacy request and web-app features use technically necessary cookies and similar storage for login sessions, security, CSRF protection, language settings and consent management. We use technically necessary storage without consent under Section 25(2) TDDDG. Your consent choice is stored canonically in local storage under consent.v2; the legacy cookie wl_consent_v1 may still be used for migration and fallback for up to 180 days.
For web analytics we use Google Tag Manager and Google Analytics 4. The GTM container and GA4 are loaded only after your analytics consent; the legal basis is Section 25(1) TDDDG and Art. 6(1)(a) GDPR. Analytics storage is denied by default. After your consent, GA4 may process page views, clicks, device/browser data, approximate region and cookies or similar identifiers. According to Google Analytics, IP addresses are not logged or stored in GA4. You can withdraw your consent at any time via Cookie settings. More information: Google Analytics privacy information.
In the current web setup we use GA4 conservatively: GA4 data retention is set to 14 months, Google Signals is disabled, ads personalization is disabled, remarketing is not used and there is no Google Ads link. Product links exist only to Google Search Console. We use Google Search Console only for search and SEO analysis; it does not load a tracking tag on the website.
Advertising storage and personalization features such as ad_storage, ad_user_data and ad_personalization remain denied. A separate marketing/ads category is not enabled. A concrete overview of the storage mechanisms used is available in the Cookie settings.
Wantivo logs selected technical and product-related events, for example registration, login, invites, wishes, reservations, Premium checks, push registration, errors and security events. These logs help us operate the service, find bugs, prevent abuse and keep important operations traceable.
We limit free-text content in such events and use technical identifiers instead of plain text where possible. Security measures include TLS encryption, access restrictions, rate limits, upload checks, size and format limits and protections in link previews against private or unsafe destinations.
Recipients of personal data may include in particular:
- easyname GmbH, Fernkorngasse 10, 1100 Vienna, Austria: hosting, server, email and domain-related services as processor.
- Google/Firebase: Firebase Authentication, Firebase Cloud Messaging, Google Play, Google Tag Manager and Google Analytics 4, depending on the feature as processor or separate controller.
- Apple: Sign in with Apple, Apple Push Notification service, App Store and StoreKit, depending on the feature as service provider or separate controller.
- External product websites: only when you request a link preview; these websites are not processors of Wantivo.
- Authorities, courts, advisers: where legally required or needed to establish, exercise or defend legal claims.
Service providers that process personal data on our behalf are contractually bound under Art. 28 GDPR. Google and Apple may process data outside the EU/EEA, especially in the USA. For such transfers we use appropriate safeguards, for example adequacy decisions such as the EU-U.S. Data Privacy Framework, EU Standard Contractual Clauses and additional safeguards provided by the vendors.
We store data only for as long as necessary for the stated purposes or as required by law. Account and wishlist data generally remain stored until you delete them or delete your account. Invites remain until expiry, revocation, use or cleanup; individual invites may be technically long-lived. Verification, reset and deletion codes are time-limited. Session, consent, security, mail, error and event logs are retained only as long as needed for security, evidence, error analysis or legal obligations.
When you delete your account, we remove your account, owned lists and wishes, memberships, invites, notifications, push devices, local subscription assignments, action codes and related uploaded public images. Some technical logs may remain with internal IDs for security, evidence or abuse-prevention purposes.
Under the GDPR you have, in particular, rights of access, rectification, erasure, restriction of processing, data portability and objection. You can withdraw consent at any time with effect for the future. To exercise your rights, contact us at contact@wantivo.com.
You also have the right to lodge a complaint with a data protection supervisory authority. In Austria this is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, email dsb@dsb.gv.at. We update this Privacy Policy when features, providers or legal requirements change.