Privacy Policy
Last updated: September 2026
1. Data Controller
The Data Controller for personal data collected through this website is Roberto Tumini, reachable at info@babywish.app.
2. Data Processed and Purposes
We collect and process the following personal data:
- Registered users: name, email address, hashed password and, if you use Google sign-in, Google identifier — needed to create the account, sign in and manage the service.
- Wishlists: baby name, due date, gender, description, gifts, product links, prices and uploaded images — needed to create and share the list. Anyone with the public link can view the list contents; link preview crawlers may read the title and image to generate previews.
- Guest reservations: giver name, optional email address, quantity and optional message — needed to coordinate gift reservations and notify the list owner.
- Collective gift pledges: giver name, optional email address, amount, optional note and management/cancellation token — needed to record, update or cancel the pledge and send related notifications.
- Security and support: password reset tokens, technical logs, IP address and data needed to prevent abuse, protect the service and answer user requests.
- Data stored in the browser: persistent authentication cookies, cookie preferences, language, checklist ticks, name favourites, drafts and interface preferences stored in localStorage or sessionStorage. This data stays on your device unless it is needed for a service feature.
- Analytics with consent: browsing data, page events and interactions collected through Google Analytics 4 and Microsoft Clarity only after consent via the cookie banner.
- Browser extension: when you click the extension icon on a product page, we receive that page's metadata (title, description, price, image address) and its address, in order to create the item in your list. The extension does not access your browsing: it reads the page only at the moment you click. The metadata we receive is neither stored nor written to logs; only the item data you see in your list is kept, including the product address.
- Delivery address (optional): if the list owner enters it, it is stored encrypted and shown to whoever reserves a gift from her list — right after the reservation and in the reminder email — so that the gift can be shipped to her home. It never appears on the public list page nor in link previews. The field is optional and off by default: clearing it removes it, and no new guest will receive it.
- Approximate country: when you register we derive your country (the two-letter code only, e.g. IT) from your IP address, using a database installed on our own server: your IP address is never sent to third parties and is never stored anywhere. It serves only to know, in aggregate form, which countries the service is used from; it does not profile you and does not determine anything you see.
- Affiliate links: shop links shown on wishlists may run through affiliate programmes, currently Amazon Associates, Skimlinks (Skimlinks Ltd, United Kingdom) and Admitad (Mitgo group). When you click one of these links, the programme receives the URL of the product you clicked and sets its own cookie to attribute a possible purchase back to BabyWish. We never send them your name or the wishlist link. If the purchase goes through, BabyWish may earn a small commission from the store, at no extra cost to you — that is how the service stays free.
- Newsletter subscription (optional): email address, language, the place on the site the subscription came from, the dates of consent and confirmation, and the technical tokens used to confirm the subscription and to unsubscribe. The address is stored encrypted. Subscribing requires no account and is never needed to use the service.
3. Legal Basis
- Performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR): account, authentication, lists, reservations, pledges, operational emails and features requested by the user.
- Legitimate interest of the Controller (Art. 6(1)(f) GDPR): security, abuse prevention, technical logs, request handling and correct operation of shared lists.
- Consent (Art. 6(1)(a) GDPR): non-essential analytics cookies and tools, including Google Analytics 4 and Microsoft Clarity, and the newsletter subscription, which only becomes active once you confirm your address through the link we send you (double opt-in).
- Legal obligations (Art. 6(1)(c) GDPR): any retention or disclosure required by applicable law.
- When processing is based on consent, you can withdraw it at any time — from the cookie preferences for analytics tools, from the unsubscribe link in every email for the newsletter — without affecting the lawfulness of processing carried out before withdrawal.
4. Data Recipients
Personal data may be shared with the following providers or recipient categories, acting depending on the service as processors or independent controllers:
- Google LLC — email delivery through Gmail SMTP, Google authentication and Google Analytics 4 (GA4), the latter active only with consent.
- Hetzner Online GmbH — hosting of the application, database and uploaded files on servers located in the European Union.
- Microsoft Corporation — Microsoft Clarity for behaviour analytics and session replay, active only with consent.
5. Transfers Outside the EEA
The application, database and uploaded files are hosted on servers physically located in the European Union. Some providers, such as Google LLC and Microsoft Corporation, may process data outside the EEA for the services listed above; where needed, these transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission under Art. 46 GDPR or by other mechanisms recognised by applicable law.
6. Retention Period
- Account and list data: kept until the user deletes the account or list.
- Reservations, pledges and guest messages: kept until the associated list is deleted or the individual reservation/pledge is removed where available.
- Uploaded images: kept while associated with the list or gift and deleted when the item or list is removed, except for temporary technical copies.
- Password reset tokens: valid for a limited time; previous unused tokens are removed when a new reset flow is requested.
- Cookies, local data, logs and backups: cookies and browser data remain until you delete them or they expire; logs and backups are retained for the technical time needed for security, maintenance and service recovery.
- Newsletter subscription: kept until you unsubscribe or delete the account tied to that address. The confirmation link expires after 7 days: if you never open it, the address is never subscribed and the pending record is deleted automatically by a check that runs every 24 hours.
7. Data Subject Rights
As a data subject, you have the right to (Arts. 15–22 GDPR):
- access your personal data;
- request correction if inaccurate;
- request deletion ("right to be forgotten");
- request restriction of processing;
- receive your data in a portable format;
- object to processing based on legitimate interest;
- lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
To exercise your rights, write to info@babywish.app.
8. Cookies
This website uses necessary technical cookies, including persistent cookies to keep you signed in and store some preferences. With consent, it uses analytics cookies and tools from Google Analytics 4 and Microsoft Clarity to understand and improve website usage. You can accept, reject or change preferences from the cookie banner; without consent, analytics tools are not loaded. We do not use advertising or marketing profiling cookies.
9. Data Deletion
You can delete your account and associated data from the Security page of your profile. Deletion removes the account, lists and linked data from the production environment; residual backup copies may remain for the technical rotation period and are not restored except for security or service continuity needs. Alternatively, you can send a request to info@babywish.app with the subject "Data deletion request"; we will respond within 30 days.