Privacy policy
If the language versions differ, the Italian text prevails.
This page explains what data Wingmigo collects, why, and what you can do with it. Regulation (EU) 2016/679 (GDPR) applies.
Who processes the data
Controller: Wingmigo, to be completed.
For any privacy request: ciao@wingmigo.com.
What data and why
- Account: name, email and password (stored only in irreversibly encrypted form). They are needed to let you sign in. Legal basis: performance of the contract.
- Trip content: itineraries, bookings, notes, lists, expenses, polls and the details of the documents you choose to enter (type, number, expiry date, insurance policies). They are needed to provide you with the service. Legal basis: performance of the contract.
- Imported confirmations: from the text or PDF you paste or forward we extract only the booking details; the original message is not stored.
- Technical data: IP address and time of requests, for security and to limit abuse, and the date of your last activity, to know how many accounts are in use. Legal basis: legitimate interest.
- Payments: card details are processed only by Paddle. We receive the outcome of the payment, the amount, the date, the plan purchased and the status of the subscription. They are needed to give you what you bought and to keep our accounts. Legal basis: performance of the contract and legal obligations.
We do not sell data and we do not carry out advertising profiling.
The people who run Wingmigo can see account data (name, email, plan, payments, last activity) for support and accounting. Trip content does not appear in the administration tools.
Who sees what in a group
Anything you mark as “whole group” is visible to everyone taking part in that trip. Anything you mark as “only me”, and reminders, remain visible only to you. Documents and insurance policies are private unless you choose otherwise. The organiser of a trip on the Groups plan sees, for each participant, how many items of their personal list are done, how many documents they have added and whether one is a valid identity document, whether they have voted in open polls, and their balance in shared expenses: never the content of lists or documents. Answers of "going", "maybe" or "not going" to activities are visible to participants, with first names. If the organiser creates a public link, anyone with that link sees the titles, times and places of the group's activities: not codes, prices, notes, documents or names. On the Groups plan the organisers also see form answers, payments into the shared kitty, the room and group arrangement, and the history of who changed shared items. If you use the artificial intelligence features (plan, import, questions about the trip, chat, phrasebook, story), the text you write and a summary of what you can see of the trip are sent to the AI provider to get the answer: never booking codes or document numbers. You can turn off automatic email reminders from the Account page. Anyone taking part in a trip can see the name and email of the other participants.
Providers that process data on our behalf
- Railway (website hosting), with servers in Amsterdam, in the European Union.
- Neon (database), with data stored in Frankfurt, in the European Union.
- GitHub (database backups, encrypted before they are stored).
- Cloudflare (domain and incoming mail): receives the emails you write to our contact addresses.
- Paddle (payments and invoicing), which acts as an independent controller for the sale.
- Resend (sending service emails: address confirmation, password, reminders, alerts).
- Anthropic (artificial intelligence features): when you ask for a plan or import a confirmation with AI, the necessary text is sent to be processed.
- Google, Apple, Microsoft (only if you choose to sign in with one of them): we receive your name, your email and an account identifier; we don't receive your password or any other data.
- OpenStreetMap (place search): it receives the name of the city searched for, not your personal data.
Some providers are based outside the EU: in those cases the transfer takes place with the safeguards provided for by the GDPR (standard contractual clauses or an adequacy decision).
Links to booking sites
When you open a link to an external site (for example to book a flight or accommodation) you leave Wingmigo: that site's privacy policy applies. Some links may be affiliate links: if you book, we may receive a commission, at no extra cost to you.
Cookies
We use a single technical cookie, necessary to keep you signed in. We do not use tracking or advertising cookies, so no consent banner is needed. The Paddle checkout, when you open it, may set Paddle's technical cookies.
For how long
The data is kept for as long as you have the account. If you delete it, we erase your data, the trips you created and what you wrote in other people's trips; backups are overwritten within 30 days. Payment records are kept, no longer linked to your account, for the period required by tax law. Trial accounts without registration are deleted after 7 days.
Your rights
You can access your data, rectify it, erase it, restrict or object to its processing and receive a copy of it. From the Account page you can download your data and delete your account yourself. You can lodge a complaint with the Austrian data protection authority (Datenschutzbehörde, dsb.gv.at) or with the authority in your own country.
Last updated: 11 October 2026.