We collect what's needed to run wishlists, gifting, contributions, fees, refunds and gift delivery.
At checkout we send the seller your address to get live tax and shipping, and never share it with wishers.
Card payments are processed by Stripe, a PCI-DSS Level 1 processor. Your card details go straight to Stripe, never to WishOn.
We never store card numbers; we keep a token, the brand, the last four digits and the outcome of each charge.
We keep an append-only record of every charge, fee, refund and credit, and reconcile it against our payment processor.
WishOn Credits stay inside WishOn: they can't be withdrawn or cashed out.
Contact sync is optional, and ID or selfie images are deleted once a check is done.
1. Introduction
This Privacy Policy describes how WishOn (“Company,” “we,” “our,” or “us”) collects, uses, stores, and shares personal information when Users access or use the WishOn Services. By using the Services, you consent to the practices described in this Policy.
2. What WishOn Is
WishOn is a social gifting app. You create wishlists of things you would love to receive, share them with friends and family, and those people can chip in towards an item or buy it outright.
Wishlists: you add items manually, by photo, or by pasting a product link that we read to fill in the title, image and price. Wishlists carry an expiration date and can be private, shared with chosen people, or public.
Contributions: supporters chip in any amount up to the remaining balance of an item. Contributions are voluntary and are recorded against the item, never sent person to person.
Fulfillment: when an item is fully funded, WishOn buys and ships it to the recipient's verified shipping address. Supporters see delivery milestones, not the address.
Credits: money that cannot be spent as intended, for example after a deletion or an expiration, becomes WishOn Credits in your balance for use inside the app.
Refunds: deleting a funded item or wishlist returns each supporter's contribution to their WishOn Credits, with a receipt.
3. Information We Collect
We may collect the following categories of information:
Account information: phone number, email address, name or display name, username, date of birth, profile photo and profile details.
Wishlist & contribution information: wishlist items, external product links, captions, item and cover photos, contribution amounts, love notes, gift activity and expiration dates.
Media: item photos, wishlist cover images, Wish Story videos, generated thumbnails, and the file metadata that comes with them.
Payment information: payment tokens from our Payment Processors, card brand and last four digits, transaction metadata and contribution history. WishOn never stores full payment card numbers.
Balances and ledger: your WishOn Credits balance, contribution receipts, refund receipts and one ledger entry for every financial action on your account.
Shipping information: the delivery addresses you add for fulfillment, their verification status, and the tracking data returned by carriers.
Verification information: identity document images, selfie images and the results of the automated checks run on them, where you choose to verify.
Social graph: friend requests, connections, contact matches and the people you share a wishlist with.
Device & technical information: IP address, device identifiers, device model and operating system, app version, locale, log files, performance metrics, crash reports and runtime errors.
Contacts (optional): if you choose to sync contacts, we process phone numbers solely to help you find friends. You may revoke access at any time.
Analytics information collected via first-party and third-party tools to improve functionality and performance.
4. How We Use Information
Provide and maintain the Services, including wishlists, contributions, credits and delivery
Facilitate gifting, contributions, refunds and fulfillment of funded gifts
Sync wishlists and user interactions across your devices
Send notifications about activity that concerns you
Prevent fraud, abuse and impersonation, and enhance security
Diagnose crashes, errors and performance problems
Improve user experience and measure feature usage
Provide customer support
Comply with legal, tax, accounting and record keeping obligations
5. Legal Bases for Processing (GDPR and equivalent laws)
Where the GDPR or a comparable law applies, we rely on the following legal bases. Where processing rests on consent, you may withdraw that consent at any time without affecting processing already carried out.
Contractual necessity: running your account, wishlists, contributions, credits, refunds and the purchase and delivery of funded gifts.
Legitimate interests: preventing fraud and abuse, securing the Services, debugging crashes, measuring aggregate product usage, and protecting our legal rights, balanced against your interests and rights.
Consent: contact sync, biometric and identity verification processing, optional push notifications, camera and photo library access, and any optional analytics that require consent in your region.
Legal obligations: financial record keeping, responding to lawful requests, and complying with anti-fraud and consumer protection requirements.
6. WishOn Credits
WishOn Credits are an in-app balance denominated in United States dollars. Credits are created when a funded item expires without being purchased, when an item or wishlist you contributed to is deleted, or when WishOn issues an adjustment or goodwill amount.
Credits are non-withdrawable and are not convertible to cash, and they have no value outside the app.
Credits may only be used inside WishOn, to fund contributions or to buy a gift outright.
Every issuance and every use of Credits writes a ledger entry recording the amount, reason, related item or wishlist and timestamp.
We retain those ledger entries as financial records even after the related wishlist or item is removed.
7. Refunds, Reversals and Chargebacks
Refunds occur when the owner deletes a funded item or a wishlist containing funded items, when a seller cancels or refunds a purchase, when a fulfillment order cannot be placed, when you ask us to look at a contribution and we agree to reverse it, and when WishOn reverses a payment for fraud, error or dispute reasons. Expired items are converted to Credits under the same mechanics.
Refund amounts are recalculated rather than simply mirrored: we work out which portions of a payment (the gift amount, the WishOn support fee, any tip, the processing fee, any dispute fee) should be reversed based on what caused the refund, and we record each of those adjustments separately.
Processing: refunds are applied automatically and atomically. Each affected contribution is marked refunded and the amount is returned to that payer's WishOn Credits balance rather than to a bank account or card, unless the law or the original payment method requires otherwise.
Metadata stored: the original payment, refund amount, currency, refund reason and fault category, the seller refund reference where one exists, the item and wishlist involved, the initiating account, the processor event identifiers and the timestamps, all retained as financial records.
Requests: where you email us to request a refund, we store your request, the correspondence needed to handle it and the outcome, and link them to the contribution in question.
Chargebacks: where a bank disputes a payment, we record the dispute, its evidence and its outcome, and the resulting fee adjustments, and we may use this information for fraud prevention and account restriction.
Notification: everyone affected receives an in-app notification and, where enabled, a push notification, with a receipt visible in their activity and transaction history.
8. Wallet and Activity Ledger
Your balance screen shows your WishOn Credits and, where applicable, funds held for pending contributions. WishOn stores the balance, not the underlying card.
Contribution receipts: amount, item, wishlist, date and payment method descriptor such as brand and last four digits.
Refund receipts: amount, reason, source item or wishlist and date.
Ledger entries: an append-only record of every financial action, including contributions, purchases, refunds, credit issuance and credit spend.
Activity log: adds, deletions, reorders and contributions are logged with timestamp, acting account and amount so that you and our support team can audit your account.
9. No Cash-Out
WishOn Credits cannot be withdrawn, transferred to another person, or redeemed for cash. Contributions cannot be cashed out by the recipient: they can only be applied to the purchase of wishlist items or converted to Credits for use inside the app.
WishOn is not a bank, money transmitter, or money transfer service, and does not provide stored-value accounts that can be paid out.
10. Payment, Fee and Reconciliation Information
Card payments in WishOn are processed by Stripe, Inc., a PCI-DSS Level 1 certified payment processor, acting as our Payment Processor. Your card details are entered into Stripe's own secure payment fields and are transmitted directly to Stripe; they never pass through or rest on WishOn's servers. Stripe processes that data as an independent controller for its own fraud-prevention and legal obligations, and as our processor for taking the payment, under Stripe's privacy policy at https://stripe.com/privacy.
Sensitive payment information is therefore handled exclusively by Stripe. WishOn receives only non-sensitive tokens and transaction metadata such as card brand, last four digits, expiry month and year, authorization result and amount. WishOn never sees, stores or logs a full card number, the security code, or your banking credentials, and no WishOn employee or administrator can retrieve them.
If we ever change or add a Payment Processor, we will update this Policy and the Terms to name the new provider before it begins processing payments for you.
For every payment we also store the fee breakdown that was shown to you — the amount funding the gift or the tax and shipping, the WishOn support or service fee, any tip, and the processing fee — together with the processor's payment intent, charge, refund and dispute identifiers. We receive event notifications (webhooks) from our processor and match them against our own ledger so that our records and the processor's records agree.
This reconciliation data, including mismatches and their resolution, is used for accounting, tax, audit, fraud detection and support. Our finance administrators can view it, and exports of it are themselves logged with the filters and date range used, so downloads are traceable.
Where you scan a card with your camera, the image is processed on your device to extract the card fields and is not retained after the fields are confirmed.
11. Identity Verification Data (ID and Selfie)
Where you elect to complete Enhanced Verification (“EV-Tier”), WishOn and its verification providers may collect and process the following additional categories of information:
Government identification data: images of an official identity document, together with the legal name, date of birth, document number, and expiry date extracted from it.
Biometric data: a selfie image, liveness detection results, and the face match score produced by comparing the selfie against the identity document.
Automated checks: document authenticity, expiry, data consistency and face comparison are assessed automatically. A negative result can restrict features, and you may ask us to review the outcome.
Residential address information: address documents you submit, or address confirmation obtained through postal or financial data providers.
Payment method verification data: card tokenization results and bank account verification status returned by our providers.
Social graph signals: verified friendships, mutual connections, contact matches, and contribution history used as trust indicators.
Fraud-prevention signals: device fingerprints, IP address consistency, velocity of attempts, and fraud pattern indicators observed during verification.
12. Purpose and Lawful Basis for Verification Processing
Verification data is processed solely for identity confirmation, fraud and impersonation prevention, calculation of your Trust Score and Trust Level, determination of eligibility for higher contribution and funding limits, public contributions and creator functionality, and compliance with financial crime, anti-fraud, and record keeping obligations.
Where consent is the lawful basis for processing, including the processing of biometric data, that consent is obtained expressly before verification begins and may be withdrawn at any time. WishOn also relies on its legitimate interests in preventing fraud and protecting Users, and on compliance with legal obligations, where those bases apply.
WishOn does not sell verification data, does not use it for advertising or profiling unrelated to trust and safety, and does not disclose it to advertisers.
13. Identity Verification Providers
WishOn engages specialist identity verification providers, which may include Stripe Identity, Persona, Veriff, Plaid for bank and address verification, and the USPS address validation service. These providers act as processors or service providers on WishOn's behalf under written agreements imposing confidentiality, security, purpose limitation, and compliance obligations.
A provider may independently be a controller of certain records for its own regulatory purposes. In that case its own privacy notice applies to that processing, and WishOn encourages you to review it.
14. Friend Search and Social Graph
WishOn is social by design, and some information is visible to people you connect with.
Search: other Users can find you by display name or by your @username. Your username, display name and profile photo are discoverable in search results.
Requests: friend requests carry a state of pending, connected or declined. Both accounts can see the state of a request between them.
Visibility to connections: connected Users can see your profile details, your birthday where you have chosen to display it, and any wishlist that is public, shared with connections, or shared with them specifically.
Contributor lists: people who chip in to the same item may appear to each other by display name and avatar, with an option to add each other as friends. Contribution amounts are shown according to your public contribution setting.
You can disconnect from someone at any time, which removes their access to wishlists shared only with connections.
15. Wish Story Videos and Media
You may record or upload a short Wish Story video and add photos to items and wishlist covers.
Storage: media files and their generated thumbnails are stored in our hosted object storage, with access controlled by the sharing settings of the wishlist they belong to.
Processing: uploads may be resumable, and videos are transcoded and thumbnailed after upload, so a short processing delay before playback is normal.
Metadata: we store file size, format, duration, dimensions, upload timestamp and the owning item or wishlist. We do not require or use precise location metadata, and we strip location data from images where technically possible.
Playback: stories play in the app to people who can see the wishlist. Deleting the item, story or wishlist removes the media from active use, and copies are cleared from backups on our normal backup cycle.
16. Shipping Addresses and Gift Fulfillment
To create a wishlist you must add a delivery address, which we validate against a postal address service so that funded gifts can actually arrive.
We store the address, its verification status and the fulfillment orders created against it.
Recipients see full order detail, including carrier, tracking number and estimated delivery. Contributors see only milestones such as funded, purchased and delivered, and never see the recipient's address.
We share the delivery address with the retailer or carrier that has to deliver the gift, and with our fulfillment operations team where an order needs manual attention.
17. Fulfillment Checkout, Tax and Shipping
When a wish reaches one hundred percent of its item price, WishOn prepares checkout with the seller using the product link on the wish. To obtain accurate figures we send the seller, or the checkout system acting for that seller, your saved delivery address, the product link and variant details, the quantity, and any metadata the seller requires to calculate tax and shipping. WishOn does not estimate tax or shipping: those values come from the seller's own checkout, because they depend on your location and the seller's rules.
Before checkout opens we check that your address is verified and eligible for the seller's delivery network, and once funding completes we lock the address to the order. If you change it, we discard the old quote and request a fresh one.
We then show you the available shipping speeds and prices, the sales tax, the WishOn service fee on that amount, the card processing fee and the total due. Contributors have already funded the item price, so we never charge you for it. If the seller's figures change before your payment settles, we block the charge, log the difference for audit and show you the updated total to approve.
You pay through Stripe, our PCI-DSS Level 1 certified payment processor. Your card details are entered into Stripe's secure fields and go directly to Stripe. WishOn does not store full card numbers or other sensitive payment credentials; we keep only a token, the card brand, the last four digits, the fee breakdown and the outcome of the charge, plus your recipient contact email so the gift can be reached about delivery.
Once that payment succeeds, WishOn purchases the item from the seller using its own merchant payment method, such as a virtual merchant card or a business purchasing account, and the seller ships the item to your saved address. We do not purchase the item before your payment succeeds, and we record the purchase in a merchant purchase ledger kept separately from WishOn's own revenue and from funds held for Users.
From the seller we receive the order reference, tracking number, carrier, shipping status, delivery or return confirmation and any refund reference, and we use them to update the wish, to notify you, and to settle refunds back to you and to contributors as Credits. Sales tax on the purchase is charged and remitted by the seller at checkout; WishOn does not remit sales tax on wishlist items.
Shared with sellers and fulfillment providers: your delivery address, recipient contact email where the seller or carrier requires it, the selected shipping option, the product details, a checkout reference, and WishOn's own merchant payment credentials.
Never shared with sellers for this purpose: contributor identities, your payment method details, your WishOn credits or contribution history, or contact details beyond what delivery requires.
Never shared with contributors: your address, recipient email, the tracking number, the carrier, or the seller order reference. Contributors see funded, purchased and delivered milestones only.
Kept for audit: address changes and address locks, quote drift between the figures we showed you and the seller's final charge, checkout retries and failures, fraud checks, and every ledger movement tied to the order.
Protected with encrypted transmission and storage, tokenized payment methods, role-based access to fulfillment records, audit logging of every purchase and ledger movement, and automated fraud checks.
18. Notifications
Push notifications are delivered through the operating system push services provided by Apple and Google. Enabling them requires your permission, which you can revoke in your device settings at any time.
In-app notifications appear in your notification centre inside WishOn and remain until you clear them.
Categories include contributions and gifts, refunds and credits, funding milestones, friend requests and connections, fulfillment and delivery updates, verification outcomes, security alerts and product announcements.
You control categories under Settings, and security-critical messages such as sign-in alerts may still be sent because they protect your account.
19. Crash Reporting, Error Logs and Analytics
Crash reporting: when the app crashes or a server request fails we record the error type, message, stack trace, app version, build, device model, operating system version and the screen you were on.
Performance metrics: load times, request durations and failure rates, used to find slow or broken paths.
Analytics: we use privacy-respecting product analytics and our own server logs to count screen views, feature usage and funnel completion in aggregate. Analytics data is used to improve the product, not to build advertising profiles, and it is never sold.
We ask crash and analytics tooling to redact payment fields, verification data and message content, and financial values in logs are recorded as amounts, not as card data.
20. Contact Sync
Contact sync is optional and is never enabled without your explicit permission.
Phone numbers and email addresses from your address book are normalized and hashed on your device, and only the hashes are sent to us for matching.
We use the matches solely to suggest people you may know who already use WishOn.
We do not store your contact list, and unmatched hashes are discarded after matching.
We do not sell, rent or share contact data with advertisers or data brokers, and revoking the permission in your device settings stops all further syncing.
21. Cookies and Similar Technologies
Session cookies and local storage keep you signed in and remember in-progress actions such as an unfinished wishlist.
Security cookies support authentication, step-up checks and abuse prevention.
Analytics cookies or identifiers measure aggregate usage, where permitted and, in regions that require it, only with your consent.
WishOn does not use cross-site tracking, does not run third-party advertising trackers, and does not participate in ad networks.
22. How We Share Information
We share only what a recipient needs, for a defined purpose, under contract or legal requirement. WishOn does not sell personal information and does not share it for cross-context behavioural advertising.
Other Users: your profile, wishlists and activity are shared according to your sharing and privacy settings, as described in the social graph section.
Payment Processors: transaction data needed to authorize, capture, refund or dispute a payment.
Verification and fraud-prevention partners: the data needed to run an identity check or assess risk.
Retailers and carriers: the delivery address, product and shipping details needed to quote tax and shipping, purchase a funded gift and ship it. We never send them contributor identities or your payment details.
Infrastructure and service providers: hosting, database, object storage, email and push delivery, error monitoring and analytics vendors acting on our instructions.
Legal authorities: where required by law, subpoena or court order, or to protect the rights and safety of Users.
Corporate transactions: in a merger, acquisition or asset sale, under equivalent privacy commitments and with notice to affected Users.
23. Third-Party Retailers
When you add a product link, we fetch the public product page to read its title, image and price. When you tap through to a retailer, you leave WishOn and the retailer receives standard web request information such as your IP address, browser or in-app browser details, and the referring link.
We do not pass your name, contact details or payment details to a retailer when you click out. WishOn does not control the data practices of External Retailers, and you should review their privacy policies before interacting with them.
24. International Data Transfers and Hosting
WishOn is operated from and hosted in the United States, and our database, object storage and application infrastructure are provided by third-party cloud providers, including our managed database and storage platform and our edge hosting and content delivery provider.
If you access WishOn from outside the United States, your information is transferred to and processed in the United States and other countries where our providers operate. Where required, those transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and equivalent UK and Swiss mechanisms.
Data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers.
25. Security Practices
Encryption: TLS in transit and encryption at rest for databases, backups and stored media.
Access control: row-level security on user data, least-privilege internal access, and audit logging of privileged and verification events.
Fraud detection: device fingerprinting, IP consistency checks, velocity limits and automated pattern detection on contributions and verification attempts.
Rate limiting: applied to authentication, verification, search, scraping and payment endpoints to blunt abuse and brute force attempts.
Session management: signed sessions with expiry and refresh, biometric or passcode step-up before sensitive payment actions, and the ability to forget a remembered device.
Payment integrity: idempotency keys on contribution, purchase and refund operations so a retried request cannot charge or refund twice, plus server-side validation and redaction of sensitive fields in logs.
No system is completely secure, and we cannot guarantee absolute protection.
26. Data Retention
We keep information only as long as we need it, on the following schedule:
Account and profile data: for the life of your account, then removed within 30 days of deletion except where a longer period is required below.
Wishlist content, items and media: for the life of the wishlist, with deleted or trashed wishlists purged after their grace period, and backup copies cycled out within 30 days.
Financial metadata, receipts and ledger entries: retained for up to 7 years to meet accounting, tax, chargeback and anti-fraud obligations, even after account deletion.
Verification data: raw identity document and selfie images are deleted once verification concludes, unless retention is required by law or is necessary to investigate suspected fraud. Address documents are deleted once the address is confirmed. Decision outcomes and audit logs are retained for up to 5 years.
Crash logs, error logs and performance data: retained for up to 90 days.
Security and activity logs: retained for up to 12 months, and longer where an investigation is open.
Deleted account remnants: an irreversible hash of your identifiers may be kept to enforce bans and prevent fraudulent re-registration, together with the financial records above.
27. Account Deletion
You can delete your account from Settings. Deletion is permanent, and this is what happens to each part of your account:
Funded items: items that have been funded but not yet purchased are cancelled, and each contributor is refunded to their WishOn Credits. Items already purchased and shipped cannot be reversed.
Your credits: unspent WishOn Credits are forfeited on deletion because they cannot be withdrawn or transferred. Spend them before deleting your account.
Contributions you made: they stay attached to the items you supported, and your name is replaced with a removed-user placeholder to the recipient and other contributors.
Shared wishlists: your own wishlists are deleted and disappear for everyone they were shared with. Wishlists other people shared with you simply lose your access.
Records we must keep: financial ledger entries, receipts and required compliance records survive deletion for the periods described above.
28. Your Rights and How to Exercise Them
Depending on your jurisdiction, you may have rights to access your data, correct inaccurate data, request deletion, request an export in a portable format, object to or restrict certain processing, opt out of sale or sharing (we do neither), withdraw consent to biometric and identity verification processing, and appeal a decision we make about your request.
To exercise a right, use the tools in Settings or contact us at the address in the Contact section. We verify a request against your signed-in account, and for higher-risk requests such as deletion or export we may require re-authentication or a biometric step-up. We do not require you to complete identity verification in order to exercise a privacy right.
We respond within 30 days, or 45 days where the law allows an extension and we tell you why. We will not discriminate against you for exercising a right.
Two consequences are worth knowing before you ask for deletion: contributions you made remain recorded against the items you supported as an anonymized financial record, and unspent WishOn Credits are forfeited because they cannot be paid out.
29. Children's Privacy
WishOn does not knowingly collect data from children under 13. If such data is discovered, it will be deleted promptly. Enhanced Verification is available only to Users aged 18 or over.
30. International Compliance
We strive to comply with applicable privacy laws, including GDPR (EU and UK), CCPA/CPRA (California), and DPDP (India), and to align our verification programme with know your customer and anti money laundering guidance and with applicable biometric privacy statutes.
31. Contact Us
Questions, privacy requests and complaints can be sent to our support team at support@wishon.app, or to our data protection contact at privacy@wishon.app.
Postal mail: iCirculate LTD, Registered Office: the offices of iCirculate Inc. — Attn: Data Protection.
If you are in the EEA or the UK and believe we have not resolved your concern, you may also lodge a complaint with your local supervisory authority.
32. Changes to Privacy Policy
WishOn may update this Policy at any time. Material changes are announced in the app and require you to review and accept the updated version. Continued use of the Services constitutes acceptance of the updated Policy.