Wisploft
Back

Privacy

Last updated August 2026

Controller. Wisploft is Wisploft, Wilhelminastraat 12, 1432 GC Aalsmeer, registered with the Kamer van Koophandel under 84530383. Questions and privacy requests can be sent to hello@wisploft.com or through the contact form.

Data and purposes. Wisploft works without accounts. We process wishlist titles, gift details, random owner and visitor tokens, reservations, reviews and aggregate outbound-click counts to provide, display, edit and protect the service. The access tokens are pseudonymous; only cryptographic hashes of private tokens are stored.

Legal bases. Providing the wishlist, reservation, invitation and contact services is necessary to perform the agreement with you or take steps you request before it. Publishing an optional review is based on your consent. Security controls, abuse prevention, service logs and aggregate service measurements are based on our legitimate interest in operating a safe and reliable service. We process data when necessary to meet a legal obligation or establish, exercise or defend legal claims.

Optional and required information. A wishlist needs a title; without it we cannot create the list. An invitation needs an email address and the names to print; without those we cannot deliver it. Contact messages need an email address so we can reply. Every other field marked optional may be left blank. Wisploft does not use consent as the legal basis for these core services.

Private-link email. Two screens send a private link to an address you type: the one that appears when a list is made, and the card on your management page that mints a new link when the old one is lost. The address is passed to the email provider for that single delivery and is not stored in the wishlist database. It goes on no mailing list, is used for nothing else, and is shared with nobody. Treat the private link as a password.

Invitations. An invitation request contains its email address, occasion details and any photographs you choose to send. This is the one address the product keeps, because a person draws the invitation and has to send it back to you. We use them only to prepare, discuss and deliver the invitation, and the address goes on no mailing list. Photographs are re-encoded to remove embedded metadata such as location before private storage.

AI-assisted invitation design. We may use digital design tools, including OpenAI, to help create the invitation from the details and optional photographs you provide. Those providers process the brief only to provide the service for us; we do not allow use of invitation data for marketing, advertising profiles or training where the provider gives us that control. OpenAI API data is not used to train OpenAI models by default unless a customer opts in, and Wisploft does not opt in.

Contact. The secure contact form sends your name if supplied, email address, subject and message to our mailbox. We use this correspondence only to answer and handle the request — your address goes on no mailing list and is used for nothing but the reply.

Reviews. You may send a name or nickname, one to five stars and your own words without an account or contact detail. A review remains private until moderation. If approved, those three fields are visible to everyone. An encrypted necessary cookie lets the same browser delete the review; the database stores only a hash of its deletion token. Clearing that cookie removes the self-service proof, but you can still contact us.

Recipients and processors. Data is processed only where needed by Wisploft and service providers acting for us: the hosting and storage provider, email-delivery and mailbox provider, encrypted off-site backup provider, and design or AI providers used to prepare an invitation. Providers may not use it for their own marketing and we do not sell personal data. A shop receives information directly from your browser only when you choose to follow an outbound product link, under that shop's own privacy notice. When you search a shop’s catalogue from your list, we send the words you typed to that shop and your browser does not, and the pictures in the results are fetched by us and served from this site — the shop learns what was searched for, never who searched.

International transfers. If a provider processes data outside the European Economic Area, we use an EU adequacy decision or appropriate safeguards such as the European Commission's standard contractual clauses. You may ask hello@wisploft.com for the current provider and safeguard details.

Retention. Invitation data is removed from the live service 90 days after delivery, or earlier after a verified request. Pending reviews are deleted after 90 days, rejected reviews after 30 days, and published reviews when the author deletes them or withdraws consent. Contact correspondence is normally removed within 12 months after resolution. Inactive wishlists are deleted after 24 months; a list you delete becomes inaccessible immediately and is purged from the live database after 30 days. Encrypted operational backups follow a maximum 12-month rotation and are unavailable for ordinary use; restored backups are immediately subjected to the same deletion rules. Hosting security logs follow the hosting provider's operational retention period.

Cookies. Only necessary first-party cookies are used: CSRF and encrypted session cookies last up to two hours; the owner grant and review-deletion grant up to one year; the pseudonymous visitor reservation token up to 180 days; and a newly issued private-link receipt up to ten minutes and one use. Browser settings can delete them, but doing so may remove editing, deletion or reservation access. None is used for advertising or cross-site tracking.

Technical data. Click counts are stored per gift and day as totals, without an IP address or browser fingerprint. Rate-limit keys are one-way IP hashes that rotate daily. Application sessions are client-side and encrypted; the application session store does not retain IP addresses or user agents. Fonts and application assets are self-hosted, and pages do not contact Google Fonts or an analytics provider.

Your rights. Subject to the GDPR conditions, you may request access, correction, deletion, restriction, portability or object to processing based on legitimate interests, and you may withdraw review consent at any time. Because Wisploft deliberately knows little about you, we may need the private management link, review-deletion cookie or another proportionate check before acting; a public wishlist link or an email address alone is not proof of ownership. We never require a complete identity-document copy for an ordinary request.

Automated decisions. Wisploft does not make decisions producing legal or similarly significant effects through automated processing and does not profile people for advertising.

Complaints. Write to hello@wisploft.com or use the contact form first so we can investigate. You also have the right to complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority, or the supervisory authority where you live or work.