1. Who controls your data
The data controller is Andrea Bellotto, operating the Lystia service.
Geographic address: Via Augusto del Noce, 5, Samarate (VA), Italia. Contact: privacy@lystia.it. Partita IVA: 03931630127
No Data Protection Officer has been appointed at this stage. If that changes, this notice will be updated.
2. Scope of this notice
This notice applies to the Lystia website, web application, backend API, account services, wishlist sharing, gift reservations, product-link previews, and service emails.
Retailers and other websites linked from a wishlist operate under their own privacy notices. Lystia does not control how those third parties process data after you visit them.
3. Personal data we process
- Account data: name, surname, email address, password hash, account identifiers, and—where enabled—phone number or social-login identifiers.
- Session and device data: access and refresh tokens, session identifiers, device model, operating system, app version, browser user-agent, IP address, push-notification token, security events, and technical logs.
- Wishlist content: titles, descriptions, deadlines, visibility settings, invite tokens, wish items, notes, prices, currencies, store names, product links, and image URLs.
- Sharing and reservation data: lists you own or join, sharing relationships, reservation or purchase status, the reserving account identifier, and relevant timestamps.
- Preferences stored on your device: theme, language, active session data, and identifiers of shared wishlists you have opened.
- First-party product analytics: account identifier, event name, timestamp, and limited server-selected dimensions such as visibility or group-gift split type. Analytics events never include wishlist or item titles, descriptions, email addresses, product links, invite tokens, or entity identifiers.
- Communications: messages and information you send when requesting help, exercising privacy rights, or reporting a problem.
4. Why we use data and our legal bases
Where processing is based on legitimate interests, we balance those interests against your rights and expectations. You may object as described below.
- Provide your account and the wishlist service, authenticate you, save content, share lists, and manage reservations: necessary to perform our contract with you (GDPR Article 6(1)(b)).
- Protect accounts, prevent abuse, debug failures, maintain service integrity, and defend legal claims: our legitimate interests in operating a safe and reliable service (Article 6(1)(f)).
- Respond to legal requests and comply with accounting, consumer, data-protection, or other legal duties: compliance with a legal obligation (Article 6(1)(c)).
- Send operational messages such as password resets, security alerts, and service notices: performance of the contract or our legitimate interests, depending on the message.
- Send push notifications where you enable them: performance of the requested service and your device-level notification choice.
- Understand adoption of core product features using minimized first-party events: our legitimate interest in improving and operating a useful service (Article 6(1)(f)). These events are not used for advertising or cross-site tracking.
5. Who can see wishlist information
Do not place sensitive personal data, confidential information, or another person’s data in a wishlist unless you have a lawful reason and their permission where required.
- Private lists are intended to be visible only to their owner.
- Invite-only lists are visible to signed-in users who receive and redeem a valid invitation. Anyone who receives an invitation link may be able to use or forward it, so share it carefully.
- Public lists may be visible to any signed-in Lystia user.
- Reservation visibility depends on the list owner’s settings. Lystia may hide reservation details from the owner to preserve a surprise while showing status or identity to permitted viewers.
6. Service providers and other recipients
When you ask Lystia to import a product link, the backend contacts the retailer’s public page to read available product metadata. When a remote product image is displayed, your browser may connect directly to that image host, which can receive your IP address and browser information under its own privacy terms. Lystia requests these images without a referrer header.
Lystia does not sell personal data.
- Hosting, content-delivery, backend, database, security, and technical infrastructure providers acting on our instructions.
- Email delivery providers, including Mailgun where configured, for transactional service messages.
- Google when you choose Google sign-in, and Firebase Cloud Messaging when you enable push notifications.
- Professional advisers, auditors, insurers, or public authorities where reasonably necessary or legally required.
- Other Lystia users according to the visibility and sharing choices described above.
7. International transfers
Some infrastructure or service providers may process data outside the EEA. Where a destination is not covered by an adequacy decision, we use an available lawful safeguard, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate.
You may request information about the applicable transfer safeguard using the contact details above.
8. How long we keep data
Where a fixed period is not listed, retention is based on the purpose, sensitivity, legal limitation periods, security needs, and whether the data can be safely deleted or anonymised.
- Account and wishlist data: while your account is active, then deleted or anonymised after account deletion, subject to backup cycles and legal obligations.
- Deleted wishlists and wish items: removed from the live service when deletion is completed; residual copies may remain temporarily in protected backups until overwritten.
- Authentication tokens and sessions: until expiry, logout, revocation, or account deletion, subject to short security retention where necessary.
- Theme and language cookies: up to 12 months unless you replace or delete them.
- First-party product analytics: while your account is active. Events linked to your account are deleted when the account is deleted; aggregate reports that no longer identify an account may be retained for longer.
- Browser local storage: until you sign out, clear site data, or the application removes it. Redeemed shared-list identifiers may remain until site data is cleared.
- Security and diagnostic logs: only for as long as needed to investigate incidents, maintain the service, and meet legal requirements.
9. Cookies and storage on your device
The lystia-theme and lystia-locale cookies remember appearance and language for up to one year and use SameSite=Lax. Browser local storage keeps your session credentials and remembered shared-list identifiers so the requested service can work.
Lystia's first-party product analytics is recorded on the server and does not use analytics cookies, browser identifiers, or local storage. The web app does not load Firebase Analytics or Google Analytics.
You can remove cookies and local storage through your browser; removing session storage signs you out and removing preference storage resets your choices.
10. Your GDPR rights
To exercise a right, contact privacy@lystia.it. We may request enough information to verify your identity and protect the account. We normally respond within one month, subject to the extensions allowed by law.
You may also complain to the supervisory authority in the EEA country where you live or work, or where the issue occurred. If the controller is established in Italy, the lead authority is the Garante per la protezione dei dati personali.
- Access your personal data and receive a copy.
- Correct inaccurate or incomplete data.
- Request deletion where the legal conditions apply.
- Restrict processing in certain circumstances.
- Receive data you provided in a structured, commonly used, machine-readable format and ask for portability where applicable.
- Object to processing based on legitimate interests, including any direct marketing.
- Withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Lystia currently makes no such decisions.
11. Security
We use proportionate technical and organisational measures intended to protect data, including access controls, password hashing, authenticated API requests, transport encryption in production, and restricted infrastructure access. No online service can guarantee absolute security.
Keep invitation links and account credentials confidential. Contact us promptly if you believe your account or an invitation has been compromised.
12. Children
Lystia is not directed to children under 16 and they should not create an account. If you believe a child has provided data contrary to applicable law, contact us so we can investigate and delete it where required.
13. Changes and contact
We may update this notice when the service, providers, or legal requirements change. Material changes will be communicated through the service or another appropriate channel before they take effect where required.
Questions, requests, and privacy concerns can be sent to privacy@lystia.it or to Via Augusto del Noce, 5, Samarate (VA), Italia.