Privacy Policy
Last updated: July 15, 2026
Privacy is one of Wombato's founding principles. We collect only what the service needs, we run error monitoring on our own servers, we enable analytics only with your consent, and we never sell your data or show ads. This policy explains what we process, why, and what rights the GDPR gives you.
1. General provisions
This Privacy Policy (the “Policy”) sets out how the personal data of users of the Wombato website (the “Service”) is processed and protected. It complies with applicable law, in particular:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR),
- the Polish Personal Data Protection Act of 10 May 2018,
- the Polish Telecommunications Act of 16 July 2004.
2. Data controller
The controller of your personal data is Kamil Grabowski, operating at: ul. Bydgoska 6, 30-056 Kraków, Poland, NIP: 6612220368, REGON: 260231175.
Direct any questions about the processing of personal data to: support@wombato.com.
3. Categories of data we process
In providing the service we process the following categories of data:
3.1. Data you provide
Data required when registering an account:
- display name (pseudonym),
- e-mail address,
- password (stored only as a cryptographic hash).
Data you provide voluntarily while using the service:
- profile picture (avatar) and profile description,
- places, reviews, comments and check-ins you add,
- photos.
We do not require or collect your phone number or date of birth.
3.2. Data collected automatically
- IP address,
- browser type and operating system, device information,
- date and time of the visit, pages viewed, traffic source (referrer),
- approximate location based on IP address (see section 4.8),
- GPS coordinates - only after your explicit action and consent (see section 4.7),
- minimal anti-bot verification data (protecting forms against bots) and application error diagnostics processed on our own server.
3.3. Data obtained through cookies
In line with the separate Cookie Policy, we process cookie data to keep your session, for security and - only with consent - for analytics.
We do not offer login through social accounts (Google, Facebook). Registration and login are only by e-mail address, so we do not obtain data from external identity providers.
4. Purposes and legal bases of processing
4.1. Providing the service
Data: name, e-mail, content, subscription data. Basis: Art. 6(1)(b) GDPR (performance of a contract). Purpose: running your account, publishing your content, handling the Pro plan.
4.2. Communicating with users
Data: e-mail. Basis: Art. 6(1)(b) GDPR. Purpose: replying to enquiries, technical support, notifications about important changes.
4.3. Newsletter
Data: e-mail. Basis: Art. 6(1)(a) GDPR (consent). Purpose: sending the newsletter (news, tips, featured spots), sent on our behalf by an e-mail service provider. You can subscribe without an account. You can withdraw consent in settings or via the link in every message.
4.4. Analytics and optimisation
Data: IP, browser data, usage statistics. Basis: Art. 6(1)(a) GDPR (consent to analytics cookies). Purpose: traffic analysis and improving the service. Tools: Google Analytics (USA, SCC), Microsoft Clarity (USA, SCC - session recordings and heatmaps), PostHog (EU region) and our own Umami instance hosted in the EU. Enabled only after consent.
4.5. Meeting legal obligations
Basis: Art. 6(1)(c) GDPR. Purpose: tax accounting, record keeping, handling reports of unlawful content (DSA).
4.6. Pursuing claims
Basis: Art. 6(1)(f) GDPR. Purpose: pursuing claims and enforcing the terms of service.
4.7. GPS geolocation (on your action)
Data: GPS coordinates. Basis: Art. 6(1)(a) GDPR (consent). Purpose: checking in at a place and finding spots nearby. Consent is obtained by your browser or system during the specific action. We do not track you in the background or keep a location history - the position is used once to carry out your action.
4.8. Approximate location from IP address
Data: IP address, approximate region. Basis: Art. 6(1)(f) GDPR. Purpose: an initial match of language/region and a recommendation of nearby spots. We derive the region from a local geolocation database running on our server - your IP address is not sent to an external provider. You have the right to object.
4.9. Protection against abuse
Data: minimal verification signals. Basis: Art. 6(1)(f) GDPR. Purpose: checking that login, registration or password reset is done by a human and not a bot. We use a privacy-friendly anti-bot solution that does not track you across sites or build an advertising profile.
4.10. Maps and address search
Basis: Art. 6(1)(b) GDPR. Purpose: displaying maps and searching for addresses. Geocoding requests pass through our server (proxy), so the external map provider does not receive your IP address.
4.11. Error monitoring
Basis: Art. 6(1)(f) GDPR. Purpose: diagnosing errors and keeping the service stable. Monitoring runs on our own server in the EU - error data does not go to an external provider.
4.12. Contact form
Data: e-mail, subject and message content. Basis: Art. 6(1)(a) GDPR. Purpose: replying to your enquiry.
5. Data retention period
5.1. Account data
- Active account: for the whole time you hold it.
- Deleted account: personal data is erased and the authorship of published content (places, reviews, photos) is anonymised immediately after deletion. Anonymised content stays in the Service as a community resource.
5.2. Marketing and newsletter data
Kept until you withdraw consent; after withdrawal it is erased or anonymised without undue delay.
5.3. Analytics data (with consent)
- Google Analytics: 26 months from the last interaction,
- Microsoft Clarity: 13 months,
- PostHog / Umami (EU): up to 12 months,
- server security logs: 12 months.
5.4. Legal data
- invoices and accounting documents: for the period required by tax law,
- correspondence: up to 3 years after the matter is closed.
6. Recipients and transfers of data
6.1. Infrastructure providers
To run the Service we use trusted providers that process data on our behalf under data processing agreements (Art. 28 GDPR):
- a hosting provider - with data centres in the European Union,
- a provider of CDN, protection and anti-bot verification,
- an e-mail service provider - transactional messages and the newsletter (with consent),
- Paddle - payment handling as Merchant of Record; it is the seller shown on your statement, and we do not receive your card numbers.
We provide the full, current list of processors on request at support@wombato.com. Error monitoring and analytics statistics (the latter only with consent) are described in sections 4.4 and 4.11.
6.2. Transfers outside the EEA
With your consent, the analytics tools Google Analytics and Microsoft Clarity (USA) may transfer data outside the European Economic Area - based on the European Commission's Standard Contractual Clauses (Art. 46 GDPR). Umami, PostHog and our own error monitoring run in the EU - this data does not leave the EEA.
6.3. Other parties
Data may be shared with bodies authorised by law (for example state authorities). There are no advertising networks, no social pixels and no data brokers. We do not sell or rent personal data.
7. Your rights
- Access (Art. 15 GDPR) - confirmation and insight into your data and information about the processing.
- Rectification (Art. 16 GDPR) - correcting inaccurate data.
- Erasure (Art. 17 GDPR) - the “right to be forgotten”.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) - in a machine-readable format.
- Objection (Art. 21 GDPR) - to processing based on a legitimate interest or for marketing purposes.
- Withdrawal of consent - at any time, without affecting the lawfulness of earlier processing.
To exercise these rights, write to support@wombato.com. You also have the right to lodge a complaint with a supervisory authority - in Poland this is the President of the Personal Data Protection Office (UODO, uodo.gov.pl), and in other countries your local data protection authority.
8. Data security
8.1. Technical measures
- encrypted connections (TLS),
- passwords stored only as a cryptographic hash,
- regular backups,
- monitoring systems for security,
- anti-bot protection on login and registration forms.
8.2. Organisational measures
- restricted access to data on a need-to-know basis,
- internal security and incident response procedures,
- confidentiality agreements with any subcontractors.
9. Cookies
Essential cookies (session, security, anti-bot verification, remembering your consent) always work and do not require consent. Analytics cookies (Google Analytics, Microsoft Clarity, PostHog, Umami) are enabled only after your consent and you can refuse without losing any features. We do not use advertising cookies. See the Cookie Policy for details.
10. Automated decision-making
We do not make decisions producing legal or similarly significant effects on you based solely on automated processing, including profiling. Account sanctions are always decided by a human. Any profiling for marketing purposes requires your explicit consent.
11. Data of minors
The Service is intended for people aged 16 and over. We do not knowingly collect data of younger people. If you believe a child has given us their data, write to support@wombato.com and we will delete it promptly.
12. Changes to this policy
This policy may be updated as the service evolves. We will announce significant changes through a banner in the Service and, for logged-in users, also by e-mail. The current version is always available on this page, and the date of the last change is shown above.
13. Contact and final provisions
Contact regarding personal data: support@wombato.com, address: ul. Bydgoska 6, 30-056 Kraków, Poland.
This policy is published in several languages. In case of any discrepancy, the Polish version prevails.