Documents
Privacy policy
We describe which data Wantilo processes, why it is processed and which rights users have.
Version 1.7 · effective from 19 September 2026
Controller
The data controller is Marek Spyrzewski, trading as JSM - IT Architecture Marek Spyrzewski, ul. Krzysztofa Kiersnowskiego 17/13, 03-161 Warszawa, Poland, Polish tax ID (NIP) 7591687416. Contact: kontakt@wantilo.com. No data protection officer has been appointed.
Data we process
Depending on how the service is used, we may process: the organiser's email address and account identifier; list content, date and settings; technical gift data; reservation status and a technical reservation token; the account language preference; the accepted terms version and time, together with the adult confirmation; IP address, request headers, device information and security logs; and correspondence content.
We do not require a child's surname, exact date of birth, home address, identity document or health data. Do not put such data on a list.
Purposes and legal bases
- creating an account, operating lists, reservations and handling requests — performance of a contract or steps before entering into one;
- security, abuse prevention, establishing and defending claims — the controller's legitimate interests;
- handling a voluntary payment, complaints and refunds — performance of a contract or steps before entering into one;
- accounting and tax obligations related to payments — a legal obligation;
- optional advertising or similar technologies — consent, where they are enabled.
Recipients and providers
The current architecture uses Supabase for the database, authentication and application data; Cloudflare for hosting, DNS, security, logs and email routing; and Brevo for transactional activation and sign-in messages and replies sent from kontakt@wantilo.com. Brevo receives sender and recipient addresses, message content and technical sending and delivery data. Messages sent to kontakt@wantilo.com are forwarded to the administrator's Gmail account through Cloudflare Email Routing, and replies are sent from that address through Brevo. Stripe handles voluntary payments. After a Payment Link is opened, Stripe receives the selected amount, email address, payment-method data and ordinary technical connection data. Wantilo does not receive card data such as the full number or CVC and currently has no webhook storing payment results. The controller may run a local script that reads amounts, refunds and payment-method country from Stripe and stores only an aggregated report for VAT accounting and monitoring the EU distance-sales threshold. The operational report contains no email address, transaction identifier or full billing address. Production also uses Google AdSense. Google may receive device and connection data and consent information needed to select, display and measure ads. A Google-certified consent mechanism handles consent, refusal and detailed settings. The advertising slot may remain empty until Google approves the site.
Brevo receives the full content of each message, including its one-time verification address, and may intermediate opening the link and receive technical click data. Wantilo puts this address in the fragment of a secure intermediate page so it is not part of the HTTP request or Referer header when clicked; this does not mean that the email provider cannot see the message content. Opening a store link added by an organiser takes the visitor directly to an external site, which receives ordinary technical request data.
A published list is available to anyone who has its random link. A recipient may pass that link on; Wantilo does not maintain a public list directory or treat the link as a personal invitation.
International transfers
The project's primary database is configured in the Frankfurt region. Stripe may process payment data under its own terms. This does not mean that every operation by every provider takes place only in the EEA. Providers may use appropriate transfer safeguards, including standard contractual clauses; their terms and scope require periodic review.
Retention
We keep account, list and gift data until deletion, termination of the service or the inactivity period described below. Sign-in session data in browser storage remains until sign-out, account deletion, session expiry or clearing site data. A user's reservation token in sessionStorage remains until the tab session ends or it is removed after cancelling the reservation.
Automatic Cloudflare Worker invocation logs containing URLs are disabled so public list tokens are not retained there. On the Free plan currently used, Supabase makes API and database logs available for one day and authentication audit logs for one hour. It does not provide automatic backups or point-in-time recovery. Brevo automatically deletes transactional-message logs after one month and does not save previews of new messages; disabling previews does not retroactively remove earlier previews. Gmail correspondence is labelled for Wantilo and reviewed manually each quarter. Ordinary support correspondence is deleted 12 months after a case is closed. Correspondence about complaints, data-protection requests or the establishment or defence of claims is generally deleted three years after closure. A longer period applies while proceedings are pending or another statutory period applies. After payments are enabled, tax and accounting records are kept until the tax limitation period expires, generally five years from the end of the year in which the tax payment deadline occurred.
Accounts are deleted after 24 months from the last successful sign-in, with warnings 30 and 7 days before deletion. This mechanism has been active since 14 September 2026. A successful sign-in cancels a started cycle and restarts the 24-month period. The first automatic deletion cannot occur earlier than 30 days after the first warning has been sent successfully. A user may also request earlier deletion. We do not promise immediate deletion of every technical copy.
Your rights
Depending on the legal basis, you may request access, rectification, erasure, restriction or portability, or object to processing. You may withdraw consent without affecting earlier processing. You may also lodge a complaint with the President of the Polish Personal Data Protection Office. To exercise your rights, write to kontakt@wantilo.com.
Voluntary provision and automated decisions
Providing an email address is voluntary but necessary to operate an organiser account. A guest does not need an account. Wantilo does not make decisions about users based solely on automated processing that produce legal or similarly significant effects.