Who we are
Wishing.ai is a trading name of Property Investments (UK) Limited, a company registered in
England and Wales (Company No. 08852962). Our registered office is Westminster House, 10
Westminster Road, Macclesfield, SK10 1BX.
For the purposes of UK GDPR and the Data Protection Act 2018, the data controller is
Property Investments (UK) Limited. If you have questions about how we handle your data,
contact us at hello@wishing.ai.
What we collect
We collect the minimum data needed to make the service work:
- Account data. If you sign in, we store your email
address and authentication credentials via Supabase Auth. Signing in is optional — the core
experience works without an account.
- Saved destinations. If you use the Passport feature,
we store which destinations you've saved. This data is tied to your account.
- Payment data. If you subscribe to Wishing Premium,
payment is processed by Stripe. We store your Stripe customer ID and subscription status. We
never see or store your card details — Stripe handles all payment information directly.
- Local storage. We use browser local storage
to remember your ritual answers, saved destinations and visit streak. If you don't sign
in, this data stays on your device. If you sign in, your saved destinations and streak are
synced to your account so they follow you across devices, and a
wishing_streak cookie carries your
current streak with each request (see Cookies below). - Streak reminder emails. These are off by
default. We only send them if you turn on the "Streak reminder emails" toggle on your profile page, and you
can turn them off again at any time.
Lawful basis for processing
Under UK GDPR (Article 6), we process your personal data on the following bases:
- Contract. Account data and payment data are processed
to deliver the service you've signed up for.
- Legitimate interest. Analytics data is processed
to improve the service. We've assessed that this does not override your rights — our analytics
are cookieless and we do not build profiles of individual users.
- Consent. Email notifications are sent based on
your consent, which you can withdraw at any time via your profile settings.
What we don't collect
- We use Matomo Analytics, an open-source, privacy-focused analytics platform, configured without cookies. It
records page views and product events (for example, whether a wish was completed, a
destination was shared, or an upgrade was started), which we review as aggregate counts. A
random, session-local attempt code links the steps of one wish so repeat wishes are not
mistaken for new visitors; it contains no name, email address or payment information. We
do not build profiles of individual users, and we do not use Matomo to track you across
other websites.
- We do not serve advertisements.
- We do not sell or rent your data. It is shared only with the service providers listed
under Hosting and infrastructure, who process it on our behalf to run Wishing.ai.
- We do not use advertising trackers or follow you across other websites.
Cookies
We use essential cookies only. These are strictly necessary for the service to work. We do
not use advertising, analytics, or preference cookies.
- Authentication. Session cookies managed by Supabase,
required for the sign-in feature.
- Wish tracking. A
wishing_session cookie tracks your daily wish count (expires after 24 hours) and a wishing_streak cookie tracks your
visit streak (expires after 8 days). Both are functional cookies with no personal data.
Hosting and infrastructure
We use the following third-party services to operate Wishing.ai. Each processes data under
their own privacy policies:
- Vercel (USA) — frontend hosting and deployment.
- Supabase (USA) — database, authentication, and
server-side functions.
- Stripe (USA) — payment processing for subscriptions.
Stripe is PCI DSS Level 1 certified.
- Matomo (EU) — privacy-focused, cookieless analytics.
No advertising trackers, no cross-site tracking.
- Resend (USA) — transactional emails (streak reminders
and account notifications).
International data transfers
Our infrastructure providers (Vercel, Supabase, Stripe) may process data outside the United
Kingdom. Where this occurs, transfers are protected by appropriate safeguards including
Standard Contractual Clauses (SCCs) or adequacy decisions recognised by the UK Government.
Your data is always handled in accordance with UK GDPR standards regardless of where it is
processed.
Data retention
We keep your data only as long as it's needed:
- Account data. Retained while your account is active.
Deleted within 30 days of account deletion.
- Payment records. Retained for 7 years after the
end of your subscription, as required by UK tax and accounting law.
- Analytics events. Matomo Cloud retains raw visitor
and action data, including session-local attempt codes, for up to 24 months. Aggregated reports
may be retained for longer so we can compare product trends over time.
- Local storage. Stays on your device until you
clear it. For signed-in users, the synced copy of your saved destinations and streak is part
of your account data above.
Age restriction
Wishing.ai is not intended for anyone under 16 years of age. We do not knowingly collect
personal data from anyone under 16. If you believe we have collected data from a child under
16, please contact us and we will delete it promptly.
Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data we
hold about you.
- Correction — ask us to correct inaccurate or incomplete
data.
- Deletion — ask us to delete your data. We will
do so unless we have a legal obligation to retain it.
- Restriction — ask us to limit how we process your
data.
- Portability — request your data in a structured,
machine-readable format.
- Objection — object to processing based on legitimate
interest.
- Withdraw consent — where processing is based on
consent, you may withdraw it at any time.
We will respond to any request within 30 days. To exercise your rights, email hello@wishing.ai.
If you are not satisfied with our response, you have the right to lodge a complaint with the
Information Commissioner's Office (ICO) at ico.org.uk.
Data breaches
In the event of a personal data breach that poses a risk to your rights, we will notify the
Information Commissioner's Office within 72 hours of becoming aware of the breach, as
required by UK GDPR (Article 33). If the breach is likely to result in a high risk to you,
we will also notify you directly without undue delay.
Changes
If we change this policy, we'll update the date at the top. Material changes will be noted
on the site.
Contact
Questions about your privacy: hello@wishing.ai