Privacy policy

Last updated: August 2026

Who we are

Wishd (wishd.co.uk) is a UK gifting platform. This policy explains what personal data we collect, why, and your rights over it.

The data controller is Wishd Ltd, a company registered in England and Wales, company number 17446647, registered office 20 Wenlock Road, London N1 7GU. Contact us at hello@wishd.co.uk.

What we collect

Account holders (organisers, and recipients who have an account): name, email address, and password (stored hashed with bcrypt), or your Google name and email if you sign in with Google. We don't receive your Google password.

Gifters: name, email address, your message and reel if you add one, a profile photo if you upload one, and payment details, which go directly to Stripe; Wishd never sees or stores your full card number. When you contribute we also create a private link, included in your emails, that lets you see your gift and re-record your reel without logging in. Changes are possible until the Wishd date (or, where the organiser is buying the gift, until they release the fund); the link keeps working after that so you can see what happened to your gift, but nothing can be changed.

Recipients: name and email address as provided by the organiser, and, for children, the parent or guardian's account details, the parent or guardian acting as the child's representative.

Reels: the video and audio recordings you choose to make, stored so they can be shown to the recipient. We do not use facial recognition or biometric analysis.

Technical: limited data such as your IP address and browser type, used for security and fraud prevention.

Usage: anonymous, cookieless product analytics. See Cookies and analytics below.

Emails: to avoid sending the same message twice, we record when key service emails (such as your reveal and claim links) were sent, against the relevant Wishd. We don't store the content of the emails we send, only that an email of a given kind went out; delivery is handled by Resend under its own policy.

Why we use it (and our lawful basis)

To run your Wishd, take contributions, and deliver reveals: performance of our contract with you.

To send service emails (verification, reveal-ready, claim links, reminders): contract and legitimate interests.

To keep the service safe (fraud prevention, moderation, account security): legitimate interests and legal obligations.

Analytics to improve the product: legitimate interests, using no personal identifiers.

Guardian oversight of children's Wishds: legitimate interests. We have weighed this against the child's own interests: giving a parent or guardian sight of everything meant for the child, before the child sees it, is what protects the child, involves only the child's name and content that others chose to send them, and is what a parent would expect of a service that lets other people send their child messages and videos. We consider that protection clearly outweighs any intrusion.

Children

Wishds may be created for children, but only by an adult parent or guardian, who holds the account and manages the Wishd on the child's behalf. The parent or guardian acts as the child's representative: they provide the child's name, they can see and remove any reel or message before the child sees it, and they exercise the child's rights under this policy on the child's behalf. Responsibility for the child's data stays with Wishd Ltd as the data controller; it does not pass to the parent or guardian. A child never creates an account or gives us data directly. We collect only the child's name, used to personalise their Wishd, and we handle a child's data to a stricter standard than an adult's: the parent or guardian can see everything meant for the child at all times, anything sent to a child can be reported and is hidden immediately at every stage, and a child's data is never used for analytics or for any purpose beyond running their Wishd.

Who we share it with

We share data with a small number of other organisations, in two different roles.

Providers that process data only on our instructions (our processors), each under a data processing agreement: Cloudflare R2 stores reels and images; Resend sends our service emails; PostHog runs our anonymous, cookieless analytics and is hosted in the EU; Replit hosts the Wishd application. None of them may use your data for purposes of their own.

Organisations that are data controllers in their own right for the data you give them directly, under their own privacy policies: Stripe, which takes your payment details on its own pages and decides for itself how it uses them for payment processing, fraud prevention and its regulatory obligations; Wishd never sees or stores your full card number. And Google, if you choose to sign in with Google, which handles the sign-in itself and passes your name and email address to us.

We don't sell your data and don't share it with advertisers.

Cookies and analytics

Wishd uses cookies only for essential functions: a session cookie (wishd_session) that keeps you signed in, and a token cookie (x-csrf-token) that protects forms from cross-site request forgery. Stripe, our payment provider, sets two fraud-prevention cookies of its own (__stripe_mid and __stripe_sid) on pages that load its payment script, under its own policy. No other cookies are set.

Our analytics (PostHog, hosted in the EU) run in cookieless mode: no cookies, no cross-site tracking, and no persistent identifier stored in your browser: each page load is anonymous, with no memory of previous visits. We collect only anonymous, aggregate usage events (for example "event created", "reel recorded", "reveal opened") with a few non-identifying properties such as the gifting flow, the occasion category, and contribution amounts grouped into broad bands (never an exact figure). We never send names, email addresses, Wishd links or slugs, gifter tokens, or the contents of any message or reel to our analytics provider, and no personal profile is ever created. Because nothing here sets a cookie or tracks you across sites, no cookie consent banner is required under UK PECR.

How long we keep it

Reels: 30 days after the Wishd date, then permanently deleted. We don't send a separate reminder before that, so save anything you want to keep within those 30 days.

Gift funds and payment records: a fund is held until it's claimed, or refunded to gifters after 30 days if it's never claimed. Stripe retains payment records under its own policy, and we keep our own transaction records only as long as the law requires.

Saved cards for gifts set up in advance: when you set up a gift more than 30 days ahead, Stripe saves your card so it can be charged on the agreed date. We remove that saved card from our records within a day of the charge, or as soon as the gift is cancelled or can no longer be charged. After that we can't charge it again. Stripe keeps its own payment records under its own retention policy; your full card number never reaches us.

Account data: kept until you delete your account. Deleting it hides your Wishds immediately and, after a 30-day window in which you can reactivate, permanently removes your account, the Wishds you created, and their reels.

Contributions to other people's Wishds: these stay with those gifts after you delete your account: they belong to the recipients, not to your account.

Your rights

Under UK GDPR you can ask us to access, correct, or delete your personal data, object to or restrict processing, and take your data elsewhere. Email hello@wishd.co.uk and we'll respond within one month. You can also complain to the Information Commissioner's Office (ico.org.uk). Note that some data, payment records, we must keep for legal reasons even after a deletion request.

Security

Passwords are hashed with bcrypt, connections are encrypted (HTTPS), payment details never touch our servers, and access to reels is protected by unguessable links and tokens. Repeated failed logins lock an account and email its owner.

Changes

We'll notify registered users by email of significant changes.