1. Who controls your data
The data controller is Andrea Bellotto, operating the Lystia service.
Geographic address: Via Augusto del Noce, 5, Samarate (VA), Italia. Contact: privacy@lystia.it. Partita IVA: 03931630127
No Data Protection Officer has been appointed at this stage. If that changes, this notice will be updated.
2. Scope of this notice
This notice applies to the Lystia website, web application, backend API, Chrome and Safari browser extensions, account services, wishlist sharing, gift reservations, product-link previews, and service emails.
The browser extensions act when you deliberately open Lystia from Safari or Chrome. They use access to the active tab to read the current page’s URL, title, and favicon, local extension storage to keep the session and last selected wishlist, and access to https://lystia.it to communicate with the Lystia API. They do not inject content scripts, monitor browsing in the background, or read other tabs.
Retailers and other websites linked from a wishlist operate under their own privacy notices. Lystia does not control how those third parties process data after you visit them.
3. Personal data we process
- Account data: name, surname, email address, password hash, account identifiers, and—where enabled—phone number or social-login identifiers.
- Session and device data: access and refresh tokens, session identifiers, device model, operating system, app version, browser user-agent, IP address, push-notification token, security events, and technical logs.
- Wishlist content: titles, descriptions, deadlines, visibility settings, invite tokens, wish items, notes, prices, currencies, store names, product links, and image URLs.
- Sharing and reservation data: lists you own or join, sharing relationships, reservation or purchase status, the reserving account identifier, and relevant timestamps.
- Preferences stored on your device: theme, language, active session data, and identifiers of shared wishlists you have opened.
- Browser-extension data: when you open an extension, it reads the active page’s URL, title, and favicon and sends the URL to Lystia to request a product preview. The editable preview and saved wish may include a title, description, price, currency, store name, product link, and image URL. The extension stores access and refresh tokens, limited account and session details, and the last selected wishlist identifier in extension-local storage. Your password is sent to the Lystia API over an encrypted connection for authentication and is not stored by the extension.
- First-party product analytics: account identifier, event name, timestamp, and limited server-selected dimensions such as visibility or group-gift split type. Analytics events never include wishlist or item titles, descriptions, email addresses, product links, invite tokens, or entity identifiers.
- Communications: messages and information you send when requesting help, exercising privacy rights, or reporting a problem.
4. Why we use data and our legal bases
Where processing is based on legitimate interests, we balance those interests against your rights and expectations. You may object as described below.
- Provide your account and the wishlist service, authenticate you, save content, share lists, and manage reservations: necessary to perform our contract with you (GDPR Article 6(1)(b)).
- Protect accounts, prevent abuse, debug failures, maintain service integrity, and defend legal claims: our legitimate interests in operating a safe and reliable service (Article 6(1)(f)).
- Respond to legal requests and comply with accounting, consumer, data-protection, or other legal duties: compliance with a legal obligation (Article 6(1)(c)).
- Send operational messages such as password resets, security alerts, and service notices: performance of the contract or our legitimate interests, depending on the message.
- Send push notifications where you enable them: performance of the requested service and your device-level notification choice.
- Operate the browser extensions, authenticate your account, create a product preview from the page you selected, show your available wishlists, and save the wish you confirm: necessary to perform our contract with you (Article 6(1)(b)).
- Understand adoption of core product features using minimized first-party events: our legitimate interest in improving and operating a useful service (Article 6(1)(f)). These events are not used for advertising or cross-site tracking.
5. Who can see wishlist information
Do not place sensitive personal data, confidential information, or another person’s data in a wishlist unless you have a lawful reason and their permission where required.
- Private lists are intended to be visible only to their owner.
- Invite-only lists are visible to signed-in users who receive and redeem a valid invitation. Anyone who receives an invitation link may be able to use or forward it, so share it carefully.
- Public lists may be visible to any signed-in Lystia user.
- Reservation visibility depends on the list owner’s settings. Lystia may hide reservation details from the owner to preserve a surprise while showing status or identity to permitted viewers.
6. Service providers and other recipients
When you ask the website, app, or browser extension to import a product link, the backend reads publicly available product information from the retailer’s page (such as title, price, and image) using standard page metadata and, where necessary, automated parsing of the page. If the retailer blocks direct access, the request is instead carried out by Zyte on our behalf, using the same product page URL. When a remote product image or favicon is displayed, your browser may connect directly to the relevant host, which can receive your IP address and browser information under its own privacy terms. Lystia requests product images without sending the referrer header.
The extensions send active-page information to Lystia only after you open the extension. They do not sell data, use it for advertising or cross-site tracking, or disclose it to data brokers.
Lystia does not sell personal data.
- Hosting, content-delivery, backend, database, security, and technical infrastructure providers acting on our instructions.
- Email delivery providers, including Mailgun where configured, for transactional service messages.
- Apple when you choose Sign in with Apple, Google when you choose Google sign-in, and Firebase Cloud Messaging when you enable push notifications.
- Zyte, a web-page retrieval and rendering provider, when a retailer’s page cannot be read directly (for example, when the retailer blocks automated requests). Only the product page URL is shared with Zyte for this purpose.
- Professional advisers, auditors, insurers, or public authorities where reasonably necessary or legally required.
- Other Lystia users according to the visibility and sharing choices described above.
7. International transfers
Some infrastructure or service providers may process data outside the EEA. Where a destination is not covered by an adequacy decision, we use an available lawful safeguard, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate.
You may request information about the applicable transfer safeguard using the contact details above.
8. How long we keep data
Where a fixed period is not listed, retention is based on the purpose, sensitivity, legal limitation periods, security needs, and whether the data can be safely deleted or anonymised.
- Account and wishlist data: while your account is active, then deleted or anonymised after account deletion, subject to backup cycles and legal obligations.
- Deleted wishlists and wish items: removed from the live service when deletion is completed; residual copies may remain temporarily in protected backups until overwritten.
- Authentication tokens and sessions: until expiry, logout, revocation, or account deletion, subject to short security retention where necessary.
- Theme and language cookies: up to 12 months unless you replace or delete them.
- First-party product analytics: while your account is active. Events linked to your account are deleted when the account is deleted; aggregate reports that no longer identify an account may be retained for longer.
- Browser local storage: until you sign out, clear site data, or the application removes it. Redeemed shared-list identifiers may remain until site data is cleared.
- Browser-extension storage: session credentials are removed when you sign out and may also cease to work after expiry or revocation. The last selected wishlist identifier remains until extension data is cleared or the extension is uninstalled. Server-side wishes and account data follow the retention periods described above.
- Security and diagnostic logs: only for as long as needed to investigate incidents, maintain the service, and meet legal requirements.
9. Cookies and storage on your device
The lystia-theme and lystia-locale cookies remember appearance and language for up to one year and use SameSite=Lax. Browser local storage keeps your session credentials and remembered shared-list identifiers so the requested service can work.
The Chrome and Safari extensions request only the activeTab and storage permissions and host access to https://lystia.it. activeTab is used after you invoke the extension, storage keeps the session and last wishlist locally, and host access permits authenticated requests to the Lystia API. The extensions include no content scripts or remotely hosted executable code.
The extensions include no advertising or analytics SDK. Actions completed through them may produce the same minimized first-party product events described above, but those events are not used for advertising or cross-site tracking.
Lystia's first-party product analytics is recorded on the server and does not use analytics cookies, browser identifiers, or local storage. The web app does not load Firebase Analytics or Google Analytics.
The native iOS app keeps Apple's tracking authorization separate from Lystia product analytics. That authorization applies only to partner functionality that falls within Apple's definition of tracking; it does not disable the minimized first-party events recorded by Lystia's backend.
You can remove cookies, website storage, and extension-local storage through your browser. Removing session storage signs you out, removing preference storage resets your choices, and uninstalling an extension removes its local data from that browser profile.
10. Your GDPR rights
To exercise a right, contact privacy@lystia.it. We may request enough information to verify your identity and protect the account. We normally respond within one month, subject to the extensions allowed by law.
You may also complain to the supervisory authority in the EEA country where you live or work, or where the issue occurred. If the controller is established in Italy, the lead authority is the Garante per la protezione dei dati personali.
- Access your personal data and receive a copy.
- Correct inaccurate or incomplete data.
- Request deletion where the legal conditions apply.
- Restrict processing in certain circumstances.
- Receive data you provided in a structured, commonly used, machine-readable format and ask for portability where applicable.
- Object to processing based on legitimate interests, including any direct marketing.
- Withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Lystia currently makes no such decisions.
11. Security
We use proportionate technical and organisational measures intended to protect data, including access controls, password hashing, authenticated API requests, transport encryption in production, and restricted infrastructure access. No online service can guarantee absolute security.
Keep invitation links and account credentials confidential. Contact us promptly if you believe your account or an invitation has been compromised.
12. Children
Lystia is not directed to children under 16 and they should not create an account. If you believe a child has provided data contrary to applicable law, contact us so we can investigate and delete it where required.
13. Changes and contact
We may update this notice when the service, providers, or legal requirements change. Material changes will be communicated through the service or another appropriate channel before they take effect where required.
Questions, requests, and privacy concerns can be sent to privacy@lystia.it or to Via Augusto del Noce, 5, Samarate (VA), Italia.