Privacy Policy
Last updated: June 20, 2026
1. Information we collect
- Account info — email, username, display name, and (optional) profile picture, banner, and bio.
- Wishlist content — items you add, prices, URLs, images, descriptions, and theme choices.
- Pledge info — pledge amount, optional gift note, optional pledger name and email, and the wishlist item supported.
- Shipping address (Creators only) — collected when a funded item ships to you. Stored encrypted at rest with a key held in a managed secret vault. Never shown to pledgers or to other users.
- Payment info — handled by Stripe. We receive limited tokens and metadata (e.g. charge id, last 4, brand, country). We do not store full card numbers.
- Usage data — log data, device/browser information, IP address, referrer, and basic analytics needed to operate and secure the Service.
- Cookies & similar tech — see our Cookie Notice for details.
2. How we use information
- Provide the Service: create accounts, publish wishlists, process pledges, ship funded items.
- Communicate with you about your account, pledges, security alerts, and policy changes.
- Prevent fraud, abuse, chargebacks, and violations of our Terms.
- Comply with legal obligations and respond to lawful requests.
- Improve and develop new features using aggregated, de-identified information.
3. How we share information
We do not sell personal information. We share it only as follows:
- Service providers — payment processing (Stripe), cloud hosting, database, email delivery, customer support, and analytics. Each is bound by contractual confidentiality and security obligations.
- Public information — your username, display name, avatar, banner, bio, and your public wishlist content are visible to anyone with the link. Don't put anything in a public wishlist that you don't want public.
- Pledgers ↔ Creators — pledge amount, optional pledger display name, and optional gift note may be shown to the Creator. Creator shipping addresses are never shared with pledgers.
- Legal & safety — to comply with law, enforce our Terms, or protect rights, safety, or property.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality safeguards.
4. Security
We use industry-standard practices including TLS in transit, row-level authorization on user data, and column-level encryption for shipping addresses. No system is perfectly secure; we cannot guarantee absolute security and you use the Service at your own risk. Report suspected vulnerabilities to security@wishwizard.app.
5. Data retention
We retain personal information for as long as your account is active or as needed to provide the Service, comply with legal obligations (including tax and anti-fraud), resolve disputes, and enforce our agreements. You can request deletion of your account at any time; some records (e.g. pledge transaction history) may be retained in anonymized or legally required form.
6. Your choices & rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. You can manage profile data on your Settings page. To exercise rights that require our help, email privacy@wishwizard.app. We will verify your identity before acting.
7. International transfers
Wish Wizard is operated from the United States. If you access the Service from elsewhere, your information will be transferred to, processed in, and stored in the U.S. and other countries where our service providers operate. By using the Service, you consent to such transfers where permitted by law.
8. Children
The Service is not directed to children under 13 (or the applicable minimum age in your jurisdiction) and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
9. Changes to this policy
We may update this policy from time to time. We will post the revised version with a new "Last updated" date. Material changes will be communicated as required by law.
10. Contact
Privacy questions? Email privacy@wishwizard.app.