Política de Privacidad
willhave está diseñado para respetar tu privacidad. Solo recopilamos lo que eliges proporcionar y nunca lo compartimos sin tu elección activa.
Datos que almacenamos
El correo de tu cuenta, los datos de perfil que introduces (nombre, foto, biografía), los deseos y álbumes que creas, y solo los datos de contacto que añades y marcas como buscables.
Que otros te encuentren
La visibilidad está desactivada por defecto. Tú decides, por cada dato, si otros pueden encontrarte por correo, teléfono o Instagram.
Tus derechos
Puedes hacer tu perfil privado, controlar quién puede encontrarte y eliminar tu cuenta y todos tus datos cuando quieras desde Ajustes.
Contacto
¿Preguntas sobre tus datos? Contáctanos a través de la app.
Seguridad
Si denuncias contenido, guardamos la denuncia (qué denunciaste y tu motivo) para poder revisarla — la persona denunciada nunca ve quién la denunció. Si bloqueas a alguien, guardamos tu lista de bloqueados; solo tú puedes verla.
---
_La política completa y vinculante (inglés):_
willhave — Privacy Policy
Effective Date: 27 June 2026 Last Updated: 27 June 2026 Version: 1.0
Drafting note: This document is provided as a draft for completion and review by qualified counsel prior to publication. Bracketed items must be completed, and each representation confirmed against willhave's actual data-processing practices.
---
1. Introduction and Scope
This Privacy Policy (the "Policy") describes how Henrik Lantz Hedström, a private individual (sole trader) based in Sweden with a registered address at Fiskarfjärdsstranden 36, 127 41 Skärholmen, Sweden ("willhave", "we", "us" or "our"), collects, uses, discloses and otherwise processes Personal Data in connection with the willhave mobile applications, websites, publicly shared list pages and browser extension (collectively, the "Service").
This Policy applies to all users of the Service worldwide. Where mandatory local law affords you greater protection or additional rights, that law prevails, and the region-specific provisions in Section 15 supplement this Policy.
2. Definitions
Capitalized terms have the meanings given below; where applicable, terms such as "Controller", "Processor", "Processing" and "Personal Data" bear the meanings set out in the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR").
- "Personal Data" means any information relating to an identified or identifiable natural person. - "Processing" means any operation performed on Personal Data. - "Controller" means the entity that determines the purposes and means of Processing; willhave is the Controller of Personal Data processed through the Service. - "Processor" means an entity that Processes Personal Data on the Controller's behalf. - "User Content" means content you submit through the Service, including wishes, images, links, descriptions and album titles.
3. Controller and Contact Details
willhave is the Controller responsible for your Personal Data.
- Privacy enquiries: henrik.lantz.hedstrom@gmail.com
- Postal address: Fiskarfjärdsstranden 36, 127 41 Skärholmen, Sweden
- Data Protection Officer (where appointed): none appointed (contact: henrik.lantz.hedstrom@gmail.com)
- EU/UK Representative (Article 27 GDPR, where applicable): not applicable — we are established in the EU (Sweden)
4. Categories of Personal Data We Process
We Process the following categories of Personal Data:
- Account Data: name, email address, hashed password, and, where you provide them, profile photograph and biography. - Discoverability Data: contact identifiers you elect to add and make searchable, such as a telephone number, email address or social handle (e.g. Instagram). You determine which identifiers, if any, are searchable. - User Content: the wishes, images, links, descriptions, prices and albums you create, together with related metadata. - Social and Activity Data: reservations, connections or follows, visibility settings, and interactions within the Service. - Optional Profile Attributes: an age range and gender, if you choose to add them. These are optional, are shown only when your profile is public, and let other users browse public wishlists for gift inspiration by those attributes. You can change or remove them at any time. - Gift-Planning Data: a private gift list of items you reserve or plan to buy, which may include free-text names of intended recipients (including people who do not use the Service) that you enter yourself. This list is visible only to you. - Safety and Moderation Data: if you report content or a profile, we store the report (what you reported, your account, and any reason you give) so our team can review it and act on rule violations. Reports are visible only to our moderation team — never to the person you reported. If you block a user, we store your block list to keep their content out of your search and inspiration; only you can see and change your block list. - Children's Data (Parental Consent): where a user indicates at sign-up that they are under 13, we collect the email address of their parent or guardian and a record that consent was given (the email and a timestamp), used solely to obtain and evidence parental consent. We do not collect the child's date of birth, and this record is kept private (owner-only), never shown on a public profile. - Authentication Data: where you sign in via Google or Meta, the profile information those providers share with your authorization (e.g. name, profile photo, email and, where the provider returns it, a phone number, plus a unique identifier). We use it to pre-fill your profile and your contact details; imported email/phone are kept private and are not used for discovery unless you turn that on yourself. We do not receive your third-party password. - Technical and Usage Data: device and browser type, operating system, application version, language and locale, time zone, identifiers, log data, and interaction data. - Approximate Location Data: derived from your IP address. - Affiliate and Transaction-Attribution Data: records of clicks on affiliate or "buy" links, including the destination merchant.
We do not intend to Process special categories of Personal Data (such as data revealing health, religious or political views) and ask that you not include such information in User Content.
5. Sources of Personal Data
We obtain Personal Data: (a) directly from you; (b) automatically through your use of the Service; (c) from authentication providers when you elect to use them; and (d) from publicly available page metadata when you save a link.
6. Purposes of Processing and Legal Bases
Where the GDPR or equivalent law applies, we rely on the legal bases set out below.
| Purpose | Categories of Data | Legal Basis (GDPR Art. 6(1)) | |---|---|---| | Create, authenticate and administer your account | Account, Authentication | Performance of a contract (b) | | Store and display your wishes and albums | User Content, Account | Performance of a contract (b) | | Make public profiles and shared albums available to others | Account, User Content | Performance of a contract (b) | | Enable people-search by identifiers you make searchable | Discoverability | Consent (a) | | Provide reservations, connections and notifications | Social and Activity | Contract (b) / Legitimate interests (f) | | Operate affiliate links and attribute purchases | Affiliate, Technical | Legitimate interests (f); Consent (a) where required | | Serve personalized advertising | Technical, Usage, Account | Consent (a) | | Produce aggregated, anonymized data products | Aggregated, de-identified data | Consent (a) for inclusion; outputs are not Personal Data | | Analytics and Service improvement | Technical, Usage | Consent (a) where required; Legitimate interests (f) | | Security, fraud prevention and abuse mitigation | Technical, Account | Legitimate interests (f) | | Comply with legal obligations | As relevant | Legal obligation (c) | | Service and, where agreed, other communications | Account | Contract (b) / Consent (a) |
Our legitimate interests include operating, securing, improving and monetizing the Service in a manner consistent with your reasonable expectations. Where we rely on consent, you may withdraw it at any time without affecting prior Processing.
Granular, per-purpose consent. We operate a consent-management layer with separate choices for essential, analytics, advertising and aggregated data products. Essential Processing is necessary to provide the Service; everything else is gated on your choice at runtime — no consent, no use. Region-aware defaults apply: in the EEA/UK non-essential Processing is opt-in (off by default); in the US it is opt-out and we honour the Global Privacy Control and similar signals. You can view and change these choices, including withdrawing consent, at any time in the app's Privacy & data settings. Minors are excluded from advertising personalization and from all data products (see Section 16).
7. Public Profiles and Shared Content
The Service is designed to allow you to publish a profile or album, and the default profile setting is public. Personal Data and User Content you designate as public — including your name, profile photograph, biography and the wishes contained in public albums — may be accessed by any person, including persons who are not registered users, and may be indexed by search engines. You may change your profile or any album to private at any time through your settings. Reservations made by gift-givers are, by design, concealed from the list owner. When you reserve a gift, the name you choose to attach to that reservation (or "anonymous", if you decline to give one) is visible to other gift-givers viewing the same wish, so that two people do not buy the same gift; it is never shown to the list owner.
8. Disclosure of Personal Data
We disclose Personal Data only as described below:
- To other users and the public, in respect of content you designate as public or shared (Section 7). - To Processors that host and operate the Service on our behalf — including our cloud database, storage and hosting provider Supabase (hosted in the United States), and our analytics and communications providers — under written agreements that restrict their use of Personal Data to our documented instructions. - To Cloudflare, Inc. as a Processor, in two respects: (a) the text of a wish (title and description) when you save a wish without a picture, sent to Cloudflare's Workers AI service solely to generate a simple illustration for that wish; and (b) encrypted backup copies of the Service's database and stored images, kept in Cloudflare's R2 storage solely for disaster recovery. Backups are encrypted before they reach Cloudflare with keys Cloudflare does not hold, are retained on a rolling schedule (up to 12 months for monthly archives), and are deleted on that schedule. - To authentication providers (Google, Meta) where you elect to authenticate through them. - To affiliate networks and merchants for purchase attribution when you click an affiliate or "buy" link. - For legal, regulatory and safety purposes, including to comply with law, enforce our terms, or protect rights, property and safety. - In corporate transactions, such as a merger, acquisition, financing or sale of assets, subject to the protections of this Policy.
- To advertising partners, where you have consented to personalized advertising, to deliver and measure ads. Where you have not consented (or are a minor), ads are contextual and non-personalized. - As aggregated, anonymized insights (e.g. "share of users in a region who added a category this month") to brands and retailers. These outputs are aggregated to a minimum group size and de-identified so they are not Personal Data and cannot reasonably be traced to you.
On "selling" data. We do not sell Personal Data about you as an individual. We may (a) share Personal Data with advertising partners where you have consented, and (b) sell aggregated, anonymized (non-personal) insights as described above. Because some US laws define "sale" and "sharing" broadly, we provide the opt-outs in Section 15, and inclusion in advertising and data products is governed by the consent choices described in Section 6.
9. Affiliate Links
The Service contains affiliate links, and we may earn a commission on qualifying purchases at no additional cost to you. We may record that a click occurred and the destination merchant in order to attribute purchases. Purchases are concluded with third-party merchants, not with willhave.
10. Cookies and Similar Technologies
On our websites and shared pages we use cookies and similar technologies for strictly necessary functionality, preferences, security and, subject to your consent where required, analytics. You may manage non-essential technologies through our consent management tool and your browser settings. Further detail is set out in our Cookie Policy at https://willhave.app/cookies.
11. International Transfers
willhave operates globally and Processes Personal Data in the United States, where our hosting infrastructure is located, and may Process it in other jurisdictions. Where we transfer Personal Data from the European Economic Area, the United Kingdom or Switzerland to the United States or another jurisdiction not benefiting from an adequacy decision, we implement an appropriate transfer mechanism, including the European Commission's Standard Contractual Clauses (together with the UK International Data Transfer Addendum, as applicable), supplemented by additional safeguards where necessary. A copy of the relevant safeguards may be requested at henrik.lantz.hedstrom@gmail.com.
12. Data Retention
We retain Personal Data for as long as your account remains active and thereafter only for so long as necessary to fulfil the purposes described in this Policy, to comply with legal, tax and regulatory obligations, to resolve disputes, and to enforce our agreements. Upon deletion of your account, we delete or irreversibly anonymize your Personal Data within 30 days, save where retention is required by law. Retention criteria include the nature of the data, the purpose of Processing and applicable limitation periods.
13. Security
We maintain technical and organizational measures appropriate to the risk, including encryption of data in transit (HTTPS), hashing of credentials, access controls and monitoring. No system is entirely secure; accordingly, we cannot guarantee absolute security. In the event of a Personal Data breach, we will notify affected individuals and competent supervisory authorities where and as required by applicable law.
14. Your Rights — General
You may access and update much of your Personal Data within the Service. To exercise other rights, contact henrik.lantz.hedstrom@gmail.com. We will respond within the period prescribed by applicable law and may take steps to verify your identity. We will not subject you to unlawful discrimination for exercising your rights.
15. Region-Specific Provisions
15.1 European Economic Area, United Kingdom and Switzerland
Subject to applicable law, you have the rights to: access your Personal Data; rectification; erasure; restriction of Processing; data portability; objection to Processing carried out on the basis of legitimate interests; and withdrawal of consent. You also have the right to lodge a complaint with your local supervisory authority in Sweden, the Swedish Authority for Privacy Protection (IMY). willhave acts as Controller in respect of the Processing described in this Policy.
15.2 United States — California (CCPA/CPRA)
In the preceding twelve months we have collected the following statutory categories of Personal Information: identifiers; customer records; commercial information; internet or other electronic network activity; geolocation data (approximate); and inferences. We collect such information for the business and commercial purposes described in Section 6 and disclose it to the recipients described in Section 8.
You have the rights to know, access, correct and delete your Personal Information; to opt out of any "sale" or "sharing" of Personal Information; to limit the use of sensitive Personal Information; and to be free from discrimination for exercising these rights. To opt out, use the consent controls under "Privacy & data" in the app's Settings or contact us. We honor recognized opt-out preference signals (including the Global Privacy Control) where required. You may use an authorized agent to submit requests.
15.3 United States — Other States
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas and others) may have rights to access, correct, delete and obtain a portable copy of their Personal Data, and to opt out of targeted advertising, the sale of Personal Data and certain profiling. To exercise these rights, or to appeal a decision, contact henrik.lantz.hedstrom@gmail.com.
15.4 Other Jurisdictions
Residents of other jurisdictions (including Brazil under the LGPD, Canada under PIPEDA and Australia under the Privacy Act) may have comparable rights. We will give effect to such rights as required by applicable law upon verified request.
16. Children's Privacy
The Service is not directed to, and we do not knowingly collect Personal Data from, children under 13. In the United States we comply with the Children's Online Privacy Protection Act (COPPA). In the EEA and the United Kingdom, where the age of digital consent ranges between 13 and 16 depending on the country, Processing of a child's Personal Data below the applicable threshold requires the consent of a holder of parental responsibility. If you believe a child has provided Personal Data without the requisite consent, contact henrik.lantz.hedstrom@gmail.com and we will take appropriate steps to delete it.
17. Automated Decision-Making
We do not make decisions producing legal or similarly significant effects concerning you based solely on automated Processing. Any feature that suggests gifts is advisory and does not produce such effects.
18. Third-Party Links and Services
The Service contains links to third-party websites, merchants and services that are not operated by us and are governed by their own privacy policies. We are not responsible for the practices of such third parties.
19. Changes to this Policy
We may amend this Policy from time to time. Material changes will be notified by appropriate means, including in-Service notice, and the "Last Updated" date will be revised. Your continued use of the Service following the effective date of any change constitutes acceptance of the amended Policy.
20. How to Contact Us
Henrik Lantz Hedström Fiskarfjärdsstranden 36, 127 41 Skärholmen, Sweden, Sweden Email: henrik.lantz.hedstrom@gmail.com
If you are located in the EEA or the United Kingdom and are not satisfied with our response, you may contact your local supervisory authority.