Last updated: 13 September 2026 · Version 4
This policy describes how the controller identified below processes personal data of users of wiset.es (the “Website”), the Wiset mobile application available on App Store and Google Play (the “Application”), and the Wiset browser extension for Chrome (the “Extension”). Using these services means being aware of this policy. If you disagree with it, please refrain from using them.
1. Data controller
The controller of personal data collected through the Website, Application and Extension is the individual operating under the Wiset brand, with the following contact details:
- Address: Carrer Apotecari Miquel Morey, 2, 07141 Es Pont d'Inca, Illes Balears, Spain.
- Contact email: contacto@wisetgroup.com
- Privacy enquiries: contacto@wisetgroup.com
No Data Protection Officer has been designated because none of the cases under Article 37 of Regulation (EU) 2016/679 (GDPR) applies. Please send data protection enquiries to the email above.
2. Data we process and its source
- Identity and account: email, username, profile photo if uploaded, and authentication method (email, Google or Apple), provided when you register.
- User content: wishlists, saved products (name, URL, image, price, category and comment), gift reservations and saved lists belonging to other users, created by you within the service.
- Wiset Pro subscription: active status, start and end dates, and purchase platform (App Store or Google Play), received through RevenueCat following a store purchase. Wiset does not receive or store card or payment details; Apple or Google processes the transaction.
- Newsletter: email, language, source form (hero/social), consent version and signup date, provided in the Website form. No name is requested.
- Technical and analytics data: connection and operational data such as IP address, User-Agent and technical errors. Depending on the surface and consent, this also includes language, page views, events and pseudonymous identifiers. Necessary technical data arises when using the service. Optional web and extension analytics requires acceptance through the relevant controls, separate from data needed to save or reserve. The viewer and Extension have the specific scopes below.
- Advertising identifiers, mobile free plan only: IDFA on iOS or Advertising ID on Android, within the scope allowed through the operating system, generated by Apple/Google and used by AdMob to show ads.
- Support enquiries: the email address and message contents you provide when contacting us.
We do not process special categories of personal data under Article 9 GDPR or data relating to criminal offences.
2.1 Shared lists and guest reservations
Anyone with a public list link can view its name, available gifts, images, prices, currency, shop links and reservation availability without an account. The guest viewer does not ask for names or display who reserved an item. A public link can also be opened by the list owner, so it does not guarantee that availability stays secret from them. Private or unavailable lists do not expose this content through the viewer.
To recognise reservations from the same browser, Wiset sets the functional HttpOnly cookie wiset_guest_v1 and stores its hash on the server. The cookie lasts one year and is renewed when a shared list is opened. It is not used for analytics or advertising. Clearing cookies or changing browsers removes access to releasing the reservation. Reservations do not silently expire with the cookie. Request limits use a transformed network address and the cookie hash to prevent automated abuse; these values are not sent to PostHog.
Optional viewer analytics sends PostHog (EU) a viewed-list event, confirmed reservation or cancellation, and a click on the create-list button, together with the interface language and whether the viewed list is empty. A random identifier exists only in memory for that consented visit, with a separate event identifier. This measurement does not include list or product identifiers, names, gift contents, URLs, referrers, reservation cookies or the visitor’s IP address, and does not link visits or accounts. Viewer measurement uses neither the PostHog SDK nor Meta Pixel. It honours valid website analytics consent unless you reject it in the viewer; its separate footer control lets you accept or turn it off without enabling advertising. DNT/GPC prevent these events. Declining does not affect viewing or reserving.
Cookie inventory and consent controls
2.2 Browser extension, from version 2.2.0
Version 2.2.0 is not yet available in Chrome Web Store. The optional analytics and pending-save recovery described below apply to that update; they should not be assumed to be available in the currently installed store version.
To save a product, the extension reads information from the page you choose, such as its name, URL, price and images, and lets you review it before sending it to your Wiset account through Supabase. Signing in and downloading product images use the existing browser permissions and may involve session data or site cookies. Those functional operations are separate from optional analytics.
In 2.2.0, analytics is off by default. The avatar → Settings control records your choice separately for each account in that browser. If enabled, the extension sends PostHog in the EU the save result, extension version, shop hostname (without the full URL), an error category when applicable, and your pseudonymous Supabase account identifier (UUID). Each event has a random identifier independent of the product; it is retained with a pending save to avoid counting retries twice. The account identifier can connect use of the same account on PC and mobile; this is pseudonymous, not anonymous, measurement.
These analytics events do not include product names or contents, full URLs, page contents, email addresses, cookies, passwords or a browsing history. They measure saving reliability, not advertising audiences. You can stop future events in Settings; this does not delete events already received. Opening the extension alone sends no usage event, and an analytics failure does not block saving. Unlike viewer events, extension events travel directly from your device to PostHog; the network connection necessarily exposes its source address to the receiving provider. The extension requests that location enrichment be disabled.
For an uncertain save, 2.2.0 stores one pending operation locally, separately by account: operation, account and list identifiers plus the product fields needed to retry, including its name, URL, image references, price, currency and any optional fields you entered. Closing the panel or signing out does not automatically erase it. It has no fixed time expiry: it is kept to recover the result, and the extension attempts to remove it after confirmation or a definite rejection. If local removal fails, it may remain until a later recovery or removal of the extension’s local data. This recovery record is not an analytics queue and its contents are not sent to PostHog.
Wiset limits use of extension data to providing and improving its product-saving function. Information received through Google APIs is used in accordance with the Chrome Web Store User Data Policy, including its Limited Use requirements. Extension data is not sold or used for personalised advertising.
3. Purposes and legal grounds
Processing relies on the following grounds under Article 6(1) GDPR:
- Account and service: creating and maintaining your account, saving lists and products, synchronising, sharing and reserving — performance of a contract, Article 6(1)(b).
- Wiset Pro: managing and verifying subscriptions and the free plan — performance of a contract and legal obligations concerning billing, Articles 6(1)(b) and (c), insofar as Wiset interacts with the stores.
- Support: performance of a contract or, where applicable, legitimate interest in responding to the person contacting us, Article 6(1)(f).
- Newsletter, when sending is enabled: separate express consent, Article 6(1)(a) GDPR and Article 21 LSSI-CE, given through an unticked checkbox and withdrawable at any time.
- Product analytics: measuring use and reliability to improve Wiset through PostHog, within the scopes in section 2 — consent, Article 6(1)(a). Website controls are in the banner and cookie settings; the viewer has a separate footer control. In Extension 2.2.0, pending publication, the avatar → Settings control is off by default and separate for each account.
- Meta Pixel: measuring the effectiveness of Wiset campaigns on Facebook and Instagram and building audiences for later campaigns — consent, Article 6(1)(a), managed through the banner and cookie settings. Wiset and Meta Platforms Ireland Ltd. act as joint controllers for initial collection and transmission, under Article 26 GDPR.
- Mobile advertising: consent managed through Apple ATT and Google UMP. Personalised ads in the EU/EEA require consent; otherwise ads are contextual.
- Preventing automated form abuse: Cloudflare Turnstile — legitimate interest in protection against bots and automated submissions, Article 6(1)(f).
- Legal obligations and claims: responding to authorities, accounting retention, and exercising or defending claims — legal obligation or legitimate interest, Articles 6(1)(c) or (f).
We do not make automated decisions with legal effects on you. Behavioural processing is limited to the analytics and advertising measurement purposes described. Extension 2.2.0 analytics uses a stable pseudonymous account identifier and is not anonymous.
4. Recipients and processors
Wiset uses providers to process data on its behalf under data processing agreements as described in Article 28 GDPR:
- Vercel Inc.: Website hosting and execution of pages and APIs, including the shared-list viewer. It receives navigation requests and technical connection data. US company; the provider states its use of SCCs and participation in the DPF in its privacy notice.
- Supabase Inc.: database, authentication, image storage and server functions. US company, with an EU region configurable; transfers covered by Standard Contractual Clauses (SCCs) and/or the EU–US Data Privacy Framework (DPF).
- Cloudflare, Inc.: Website CDN and Turnstile anti-bot checks on forms, processing IP and technical browser attributes during submission without advertising profiling. US company with global infrastructure; SCCs/DPF.
- PostHog Inc.: product analytics events. The viewer uses ephemeral identifiers; Extension 2.2.0 uses pseudonymous account identifiers with optional acceptance. Analytics data is hosted in the EU (eu.posthog.com); the main processing is in that region.
- Meta Platforms Ireland Ltd., with Meta Platforms, Inc. in the US: advertising campaign measurement through the Website Pixel, including page views and conversions attributed to Facebook/Instagram ads. Joint control with Wiset for initial event collection and transmission; subsequent US transfers under SCCs/DPF.
- RevenueCat, Inc.: intermediary with Apple and Google for Wiset Pro status and subscription dates. US company; SCCs/DPF.
- Google LLC: Google Play distribution, Google Sign-In and Google AdMob on the mobile free plan. US company; SCCs/DPF.
- Apple Inc.: iOS App Store distribution, Sign in with Apple and App Tracking Transparency. US company; SCCs/DPF.
We do not sell or disclose personal data for third parties’ direct marketing. Data may also be disclosed to public authorities, law enforcement or courts where legally required, or where necessary to exercise or defend claims.
5. International transfers
Some providers are based in the United States. Transfers rely on safeguards recognised by GDPR: EU–US Data Privacy Framework certification and/or Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914. You may request a copy of applicable safeguards at contacto@wisetgroup.com.
6. Retention periods
- Account and user content: lists, products and reservations are retained while the account remains active. The policy provides for immediate deletion of associated data from Wiset systems when you delete your account.
- Wiset Pro: during the subscription and, afterwards, the legally applicable periods for billing-related information (up to six years under Article 30 of the Spanish Commercial Code and tax rules applicable to stores acting as seller).
- Newsletter: while consent remains in place; removal from the register is immediate upon unsubscribing.
- PostHog analytics: this policy sets a maximum of 13 months per event.
- Meta advertising measurement: the _fbp cookie expires after 90 days; events sent to Meta follow Meta’s retention policy (up to two years for personalised campaign data under its stated policy). Wiset does not store those events in its own systems.
- Technical logs, including Supabase, Cloudflare and web hosting: this policy sets a maximum of 12 months. This is not attributed to a general retention obligation under Article 12 bis LSSI-CE.
- Support: up to one year from the last interaction unless needed to defend claims.
The functional guest cookie and Extension’s pending operation follow the periods or completion criteria described in section 2. After the applicable periods, data is deleted or irreversibly anonymised. Account deletion does not affect data that must be retained under a legal obligation, which remains restricted to handling such requirements.
7. Your rights
Under Articles 15–22 GDPR and Articles 11–18 of Spain’s Organic Law 3/2018 (LOPDGDD), you may exercise rights of access, rectification, erasure, objection, restriction, portability and withdrawal of consent. You also have the right not to be subject to automated decisions with significant legal effects; Wiset does not make such decisions.
You can modify your profile or delete your account in Application account settings, or write to contacto@wisetgroup.com, indicating the right you wish to exercise and, if needed to establish your identity, providing evidence of identity. We respond within one month, extendable by up to two further months in particularly complex cases under Article 12(3) GDPR. Withdrawal does not affect the lawfulness of prior processing.
You may complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD):
Agencia Española de Protección de Datos (AEPD)C/ Jorge Juan, 6
28001 · Madrid
Telephone: 901 100 099 / 91 266 35 17
https://sedeagpd.gob.es/
8. Children
Wiset is intended for people over 13. Children under 14 living in Spain need consent from a parent or legal guardian to create an account and process personal data, under Article 7 LOPDGDD. If an account was created without required consent, we will delete it. Parents or guardians can contact contacto@wisetgroup.com about such an account.
9. Security
The policy provides for technical and organisational measures appropriate to risk under Article 32 GDPR: encryption in transit (TLS) and at rest in the database, role-based access, encrypted backups, strengthened administrative authentication, access logging and periodic provider reviews. A data breach creating a high risk to your rights will be notified without undue delay under Article 34 GDPR.
10. Cookies and similar technologies
Website cookies and similar technologies are explained in the Cookie policy. Mobile tracking permissions are managed through Apple App Tracking Transparency and Google User Messaging Platform. Without express consent, free-plan ads in the EU are not personalised using your usage history. Extension storage and its optional measurement are described separately in section 2.2.
11. Policy changes
This policy may change to reflect legal, technical or provider changes. Material changes receive a new version in the heading and, where appropriate, a Website banner or Application notice. Please review this page periodically.
12. Applicable law
Processing is governed by Regulation (EU) 2016/679 (GDPR), Spain’s Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE), and other applicable Spanish and European Union law.