Privacy Policy
Last updated April 2026
1. Who we are
Wishlist is a personal wishlist app developed and operated by NoobVenture, available at wishlist.noobventure.com. We're a small independent operation based in Norway. For privacy-related questions, contact us at noobventure.com.
2. What data we collect
When you create an account or use Wishlist we collect:
- Account information — your name, email address, and a bcrypt-hashed password. Your plaintext password is never stored.
- Wishlist data — the wishlists you create (title, description, visibility setting) and the items in them (title, URL, image URL, price, currency, notes, priority, position).
- Reservations on shared wishlists— when a gift-giver clicks “I'll get this” on a publicly-shared wishlist, we store the name they typed, an optional email if provided, and the timestamp. We also store a SHA-256 hash of an opaque cookie value (see “Cookies” below) so the same browser can undo its own reservation.
- Password reset tokens — when you request a password reset, we store a SHA-256 hash of a one-time token and an expiry timestamp on your account. Both are cleared after use or expiry.
We do not collect analytics, telemetry, advertising identifiers, social tracking pixels, or IP addresses beyond what is incidentally logged by standard web server operation.
When you paste a product URL into the “Auto-fill” field, our server fetches that URL once to extract title / image / price metadata. The page contents are not stored — only the extracted preview values, briefly cached in memory.
3. How we use your data
- To provide, operate, and improve Wishlist.
- To send transactional emails via Mailjet — currently just password reset links — when you request them.
- To keep you logged in via a secure session cookie.
- To let gift-givers reserve items on your shared wishlists without registering an account themselves (the reservation cookie is set on their browser only).
Your data is never sold, rented, or shared with third parties for marketing purposes.
4. Where your data is stored
All data is stored on infrastructure operated by NoobVenture:
- Database — MongoDB running on private NoobVenture infrastructure hosted in the EU (Norway).
- Email delivery — Mailjet (mailjet.com) is used solely to deliver transactional emails. Mailjet receives the recipient email address and email content. See Mailjet's privacy policy for details.
5. Cookies and local storage
Wishlist uses small cookies for authentication, CSRF protection, and to let visitors undo their own reservations on shared wishlists. No tracking, analytics, or advertising cookies are used. See our Cookie Policy for the full list and what each one does.
We also use your browser's localStoragefor one thing only: remembering which app version you last saw the changelog for, so the “new” dot in the footer pulses until you open it. This data never leaves your device.
6. Your rights (GDPR)
If you are in the European Economic Area you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your account and all associated data.
- Restriction — request that we limit processing of your data.
- Objection — object to processing based on legitimate interests.
To exercise any of these rights, contact us at noobventure.com. We will respond within 30 days.
7. Data retention
Your data is retained for as long as your account is active. If you request deletion of your account, all personal data and wishlist data owned by you will be permanently deleted within 30 days.
Reservations on shared wishlists are deleted when the wishlist is deleted, or when the owner removes the wishlist's share token (which invalidates all existing reservations on it).
8. Children
Wishlist is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, please contact us and we will delete it promptly.
9. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top of this page will reflect any changes. Continued use of Wishlist after changes constitutes acceptance of the updated policy.