Privacy Policy
Last updated: August 21, 2026
Privacy is one of Wombato's founding principles. We collect only what the service needs, we run error monitoring on our own servers, we enable analytics only with your consent, and we never sell your data or show ads. This policy explains what we process, why, and what rights the GDPR gives you.
1. General provisions
This Privacy Policy (the “Policy”) sets out how the personal data of users of the Wombato website (the “Service”) is processed and protected. It complies with applicable law, in particular:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR),
- the Polish Personal Data Protection Act of 10 May 2018,
- the Polish Telecommunications Act of 16 July 2004.
2. Data controller
The controller of your personal data is Kamil Grabowski, operating at: ul. Bydgoska 6, 30-056 Kraków, Poland, NIP: 6612220368, REGON: 260231175.
Direct any questions about the processing of personal data to: support@wombato.com.
3. Categories of data we process
In providing the service we process the following categories of data:
3.1. Data you provide
Data required when registering an account:
- display name (pseudonym),
- e-mail address,
- password (stored only as a cryptographic hash).
Data you provide voluntarily while using the service:
- profile picture (avatar) and profile description,
- places, reviews, comments and check-ins you add,
- photos.
When you publish in the Service, you also provide us with: the content of your posts in the community feed (including photos and links), the polls you create and the votes you cast in them (votes are public - see the Terms), the other users you tag in posts, and the list of people, tags and regions you follow. The list of accounts you follow is visible on your public profile.
We do not require or collect your phone number or date of birth.
3.2. Data collected automatically
- IP address,
- browser type and operating system, device information,
- date and time of the visit, pages viewed, traffic source (referrer),
- approximate location based on IP address (see section 4.8),
- GPS coordinates - only after your explicit action and consent (see section 4.7),
- minimal anti-bot verification data (protecting forms against bots) and application error diagnostics processed on our own server.
For accounts permanently blocked for a breach of the Terms we additionally store irreversible hashes of technical identifiers (see section 4.16).
3.3. Data obtained through cookies
In line with the separate Cookie Policy, we process cookie data to keep your session, for security and - only with consent - for analytics.
We do not offer login through social accounts (Google, Facebook). Registration and login are only by e-mail address, so we do not obtain data from external identity providers.
4. Purposes and legal bases of processing
4.1. Providing the service
Data: name, e-mail, content, subscription data. Basis: Art. 6(1)(b) GDPR (performance of a contract). Purpose: running your account, publishing your content, handling the Pro plan.
4.2. Communicating with users
Data: e-mail. Basis: Art. 6(1)(b) GDPR. Purpose: replying to enquiries, technical support, notifications about important changes.
4.3. Newsletter
Data: e-mail. Basis: Art. 6(1)(a) GDPR (consent). Purpose: sending the newsletter (news, tips, featured spots), sent on our behalf by an e-mail service provider. You can subscribe without an account. You can withdraw consent in settings or via the link in every message.
4.4. Analytics and optimisation
Data: IP, browser data, usage statistics. Basis: Art. 6(1)(a) GDPR (consent to analytics cookies). Purpose: traffic analysis and improving the service. Tools: Google Analytics (USA, SCC) and PostHog (EU region). Enabled only after consent.
4.5. Meeting legal obligations
Basis: Art. 6(1)(c) GDPR. Purpose: tax accounting, record keeping, handling reports of unlawful content (DSA).
4.6. Pursuing claims
Basis: Art. 6(1)(f) GDPR. Purpose: pursuing claims and enforcing the terms of service.
4.7. GPS geolocation (on your action)
Data: GPS coordinates. Basis: Art. 6(1)(a) GDPR (consent). Purpose: checking in at a place and finding spots nearby. Consent is obtained by your browser or system during the specific action. We do not track you in the background or keep a location history - the position is used once to carry out your action.
4.8. Approximate location from IP address
Data: IP address, approximate region. Basis: Art. 6(1)(f) GDPR. Purpose: an initial match of language/region and a recommendation of nearby spots. We derive the region from a local geolocation database running on our server - your IP address is not sent to an external provider. You have the right to object.
4.9. Protection against abuse
Data: minimal verification signals. Basis: Art. 6(1)(f) GDPR. Purpose: checking that login, registration or password reset is done by a human and not a bot. We use a privacy-friendly anti-bot solution that does not track you across sites or build an advertising profile.
4.10. Maps and address search
Basis: Art. 6(1)(b) GDPR. Purpose: displaying maps and searching for addresses. Geocoding requests pass through our server (proxy), so the external map provider does not receive your IP address.
4.11. Error monitoring
Basis: Art. 6(1)(f) GDPR. Purpose: diagnosing errors and keeping the service stable. Monitoring runs on our own server in the EU - error data does not go to an external provider.
4.12. Contact form
Data: e-mail, subject and message content. Basis: Art. 6(1)(a) GDPR. Purpose: replying to your enquiry.
4.13. People suggestions
In the feed and during onboarding we may suggest profiles of other community members. Suggestions are based solely on publicly visible information: published places (including their region), reviews, and recent activity in the service. Every suggestion shows the reason you are seeing it. We do not use your device location or other users' IP addresses for this.
You can opt out of your profile appearing in suggestions at any time in Settings (Privacy, "Show me in suggestions"); a dismissed suggestion never returns. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in helping community members connect.
4.14. womba.to short links
When we publish content outside the service we use our own short links on the womba.to domain, which redirect to wombato.com. On a click we store only aggregated statistics: the link code, country, referring site domain, client type (human or bot) and the time of the click. We do not store your IP address, full browser identifier or cookies, and we do not link this data to your account. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in measuring the effectiveness of our publications.
4.15. Content tailored to you (personalisation)
To suggest places, tags and posts close to your interests, we process signals coming solely from your deliberate actions in the Service while you are logged in: following people, tags and regions, saving and visiting places, publishing reviews and comments, reactions, votes in polls, and selected clicks on content (for example opening a post, clicking a tag, hiding content with "Not interested"). On this basis we maintain an internal, aggregate interest profile (for example "interested in the Bieszczady region"). This constitutes profiling within the meaning of the GDPR; it produces no legal effects concerning you and does not similarly significantly affect you - it only influences the order and the selection of the content shown to you.
We do not collect data about how long you look at content, about scrolling or about cursor movements; we do not profile logged-out visitors; the signals do not contain your IP address.
Basis: Art. 6(1)(f) GDPR (legitimate interest - delivering relevant content within the Service). You can object at any time (Art. 21 GDPR) using the "Content tailored to you" toggle in Settings (Privacy and data) - with immediate effect: we stop collecting signals, the interest profile is deleted, and content is presented on the basis of recency and your surroundings. Retention details: section 5.6.
4.16. Security and abuse prevention
Data: IP address, device and browser information, login history and, in the case of a permanent account block, irreversible hashes (salted) of the IP address and the device identifier. Basis: Art. 6(1)(f) GDPR (legitimate interest - protecting the Service and the community against abuse, including the circumvention of blocks). Purpose: detecting unauthorised access attempts, enforcing account blocks, preventing accounts from being created in order to evade sanctions.
The hashes do not allow the original value to be reconstructed and are not used for any other purpose. We carried out a balancing test (LIA) for this processing - we make its summary available on request.
4.17. Push notifications
Data: the notification subscription identifier in your browser or your device token, the platform type, the chosen language and the device time zone. Basis: Art. 6(1)(a) GDPR (consent) - you turn notifications on yourself in the Service and additionally confirm the permission in your browser or in your device system. For notifications about your account, payments and moderation decisions, sent once notifications are on, the basis is Art. 6(1)(b) GDPR (performance of a contract). Purpose: delivering the notification to your device, in your language and at a time that takes the device time zone into account.
You can turn notifications off at any time in the Service settings or in your browser or system settings; that is also where you choose what you want to be notified about. Once you turn notifications off or the subscription expires, we stop using the identifier and mark it as inactive, and we delete it permanently together with your account.
The notification reaches your device through the push service of your browser or operating system provider - push technology does not work without that intermediary. It receives only the notification content and the subscription identifier, without your e-mail address or account data. We do not use the identifier for marketing or to track you outside the Service.
5. Data retention period
5.1. Account data
- Active account: for the whole time you hold it.
- Deleted account: personal data is erased and the authorship of published content (places, reviews, photos) is anonymised immediately after deletion. Anonymised content stays in the Service as a community resource.
5.2. Marketing and newsletter data
Kept until you withdraw consent; after withdrawal it is erased or anonymised without undue delay.
5.3. Analytics data (with consent)
- Google Analytics: 26 months from the last interaction,
- PostHog (EU): up to 12 months,
- server security logs: 12 months.
5.4. Legal data
- invoices and accounting documents: for the period required by tax law,
- correspondence: up to 3 years after the matter is closed.
5.5. Security data
- login history and known devices: up to 90 days for active accounts, up to 12 months for blocked accounts,
- identifier hashes linked to an account block: up to 12 months from the entry (blocks of IP addresses additionally expire automatically sooner),
- records of moderation decisions (including the reasons given): for the period required by digital services law and for the defence of claims.
5.6. Content personalisation data
We keep raw interest signals for a maximum of 90 days (older ones are permanently deleted), and the aggregate interest profile until you object or delete your account. Once you turn content personalisation off we delete the profile immediately and keep the raw signals for a further 30 days, solely so that turning personalisation back on within that time restores its quality (during that period the signals are not used); after 30 days they are permanently deleted. Deleting your account deletes all of this data.
6. Recipients and transfers of data
6.1. Infrastructure providers
To run the Service we use trusted providers that process data on our behalf under data processing agreements (Art. 28 GDPR):
- a hosting provider - with data centres in the European Union,
- a provider of CDN, protection and anti-bot verification,
- an e-mail service provider - transactional messages and the newsletter (with consent),
- automated content analysis providers - OpenAI and Anthropic (USA) - checking published content against the Terms, on-request translations and suggested place descriptions and names; they receive only the content itself (text and photos stripped of metadata, including location), without your e-mail address or account details,
- Paddle - payment handling as Merchant of Record; it is the seller shown on your statement, and we do not receive your card numbers.
We provide the full, current list of processors on request at support@wombato.com. Error monitoring and analytics statistics (the latter only with consent) are described in sections 4.4 and 4.11.
6.2. Transfers outside the EEA
Content analysed by OpenAI and Anthropic (USA) is processed outside the EEA on the basis of the European Commission's Standard Contractual Clauses (Art. 46 GDPR) and is not used to train these providers' models. With your consent, the analytics tool Google Analytics (USA) may transfer data outside the European Economic Area - based on the European Commission's Standard Contractual Clauses (Art. 46 GDPR). PostHog and our own error monitoring run in the EU - this data does not leave the EEA.
6.3. Other parties
Data may be shared with bodies authorised by law (for example state authorities). There are no advertising networks, no social pixels and no data brokers. We do not sell or rent personal data.
6.4. Visibility of your content to others
When you publish in the Service, you share content with other people. Other users can see: your profile (display name, profile picture, description, follower and following counts), the places, reviews, photos and comments you add, your posts in the community feed, the polls you create together with the votes cast in them (votes are public), the people you tag and the list of accounts you follow. Public content - places, reviews and public profiles - is also visible to logged-out visitors, and search engines may index it and show it in their results.
Once published, content can be copied or saved by third parties, which is beyond our control. Publish thoughtfully and do not include information you do not want to reveal, in particular the exact location of your home or other people's details.
Private messages are visible only to the sender and the recipient. The exception is a message reported by its recipient - the reported message is then passed to the moderation team so that the report can be handled.
You can switch off parts of your profile in Settings (among others the list of followed tags, the activity status, your presence in the leaderboard and in suggestions). Saved places are visible only to you by default.
6.5. Legal succession
If the Service or a part of it is transformed, merged or sold, data may pass to the legal successor, who then takes over the role of controller. This happens on the terms described in this Policy - for the same purpose and to the same extent, with no extension of the processing. We will inform you about such a change in advance in the Service and by e-mail, before it takes effect, so that your rights, including deleting your account, can be exercised beforehand.
7. Your rights
- Access (Art. 15 GDPR) - confirmation and insight into your data and information about the processing.
- Rectification (Art. 16 GDPR) - correcting inaccurate data.
- Erasure (Art. 17 GDPR) - the “right to be forgotten”.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR) - in a machine-readable format.
- Objection (Art. 21 GDPR) - to processing based on a legitimate interest or for marketing purposes.
- Withdrawal of consent - at any time, without affecting the lawfulness of earlier processing.
The right to erasure is subject to the exceptions set out in Art. 17(3) GDPR: we may retain limited data where this is necessary to comply with a legal obligation (Art. 17(3)(b) GDPR) or for the establishment, exercise or defence of legal claims (Art. 17(3)(e) GDPR) - in particular the irreversible hashes linked to an account block (so that deleting an account cannot be used to evade sanctions) and the records of moderation decisions.
You exercise your objection to content personalisation (Art. 21 GDPR) yourself and instantly, using the toggle in Settings (Privacy and data, "Content tailored to you"); you can also write to support@wombato.com. You will receive a copy of your interest profile and signals in your data export (Settings, Privacy and data, "Export your data").
To exercise these rights, write to support@wombato.com. You also have the right to lodge a complaint with a supervisory authority - in Poland this is the President of the Personal Data Protection Office (UODO, uodo.gov.pl), and in other countries your local data protection authority.
8. Data security
8.1. Technical measures
- encrypted connections (TLS),
- passwords stored only as a cryptographic hash,
- regular backups,
- monitoring systems for security,
- anti-bot protection on login and registration forms.
8.2. Organisational measures
- restricted access to data on a need-to-know basis,
- internal security and incident response procedures,
- confidentiality agreements with any subcontractors.
8.3. Personal data breaches
If, despite these measures, a personal data breach occurs, we assess its consequences and the risk to your rights and freedoms. Where the law requires it, we notify the President of the Personal Data Protection Office (UODO) within 72 hours of becoming aware of the breach, and if the breach is likely to result in a high risk to you - we inform you directly.
9. Cookies
Essential cookies (session, security, anti-bot verification, remembering your consent) always work and do not require consent. Analytics cookies (Google Analytics, PostHog) are enabled only after your consent and you can refuse without losing any features. We do not use advertising cookies. See the Cookie Policy for details.
10. Automated decision-making
We do not make decisions producing legal or similarly significant effects on you based solely on automated processing, including profiling (Art. 22 GDPR). Account sanctions are always decided by a human; automated systems may only pre-screen published content. The identifier hashes linked to a permanent account block (section 4.16) serve solely to enforce a decision taken earlier by a human.
The selection and order of content in the community feed may be personalised on the basis of your interest profile (section 4.15). This is profiling that produces no legal effects concerning you and does not similarly significantly affect you - it only determines what you see and in what order. You can turn personalisation off at any time in Settings (Privacy and data, "Content tailored to you").
Any profiling for marketing purposes requires your explicit consent.
11. Data of minors
The Service is intended for people aged 16 and over. We do not knowingly collect data of younger people. If you believe a child has given us their data, write to support@wombato.com and we will delete it promptly.
12. Changes to this policy
This policy may be updated as the service evolves. We will announce significant changes through a banner in the Service and, for logged-in users, also by e-mail. The current version is always available on this page, and the date of the last change is shown above.
13. Contact and final provisions
Contact regarding personal data: support@wombato.com, address: ul. Bydgoska 6, 30-056 Kraków, Poland.
This policy is published in several languages. In case of any discrepancy, the Polish version prevails.