WAKE

Privacy Policy

Ultimo aggiornamento: 2026-05-13

1. Data Controller

The data controller for the personal data collected through the Wake mobile application (the "App", "Service") is Ruggiero Spera, operating under the brand "Wake Mobile", based in Italia. For any request please write to ruggierospera@icloud.com.

2. What Wake is

Wake is a mobile application for creating, sharing and discovering travel itineraries. It also offers subscriptions to the premium "Wake Pro" plan and one-off purchases of signature itineraries published by verified creators. This Privacy Policy describes what data we collect, why, how long we keep it, and what rights you have.

3. Categories of personal data

3.1 Information you provide

3.2 Information collected automatically

4. Purposes and legal basis

PurposeLegal basisRetention
Service delivery (account, itineraries sync, authentication, operational notifications)Performance of a contract (Art. 6.1.b GDPR)Life of the account + 30 days after deletion
Wake Pro subscriptions and premium itinerary purchasesPerformance of a contract (Art. 6.1.b GDPR) + tax obligations10 years (Italian tax law)
Creator payouts via Stripe ConnectPerformance of a contract (Art. 6.1.b GDPR) + legal obligation (Art. 6.1.c)10 years for accounting records
Sending push notificationsConsent (Art. 6.1.a GDPR), revocable at any timeUntil account is active
Security and abuse preventionLegitimate interest (Art. 6.1.f GDPR)90 days for security logs
Diagnostics and bug fixingLegitimate interest (Art. 6.1.f GDPR)90 days
Compliance with authorities' requestsLegal obligation (Art. 6.1.c GDPR)As required by law

5. Third parties (data processors)

Wake relies on the following third-party services to deliver the Service. Each processor handles personal data according to its own privacy policy, which we encourage you to read.

ServicePurposeLocationPrivacy Policy
Supabase Inc.Database hosting, authentication, backups, edge functionsUSA (EU servers, eu-central-1)supabase.com/privacy
Apple Inc.Sign in with Apple, App Store In-App Purchase, Apple Push Notifications, App Store distributionUSA, EUapple.com/legal/privacy
Google LLCSign in with Google (OAuth)USA, EUpolicies.google.com/privacy
RevenueCat, Inc.Subscription and IAP management, receiptsUSArevenuecat.com/privacy
Stripe, Inc. / Stripe Payments Europe Ltd.Creator onboarding and payouts (Stripe Connect Express)USA, Irelandstripe.com/privacy
Mapbox, Inc.Maps, tiles, geocodingUSAmapbox.com/legal/privacy
Expo / 650 Industries, Inc.Push notification delivery (APNs gateway)USAexpo.dev/privacy

Transfers of personal data outside the European Economic Area are covered, where applicable, by Standard Contractual Clauses adopted by the European Commission and/or adequacy decisions in force.

6. Your rights (GDPR Arts. 15-22)

To exercise your rights, write to ruggierospera@icloud.com. We respond within 30 days. Account deletion is also available in-app: Settings → Delete account.

7. Minors

The Service is not intended for users under the age of 16. We do not knowingly collect personal data from minors. If you believe a minor has signed up, contact us and we will delete the account.

8. Security

We adopt reasonable technical and organisational measures to protect personal data: TLS 1.2+ in transit, encryption at rest on Supabase databases, Row Level Security to isolate user data, JWT-based access control, continuous monitoring. In the event of a breach we will notify users as required by GDPR Art. 34.

9. Cookies and similar technologies

The App uses local storage only for session tokens and user preferences. No third-party cookies or cross-app advertising tracking. The NSPrivacyTracking property in our privacy manifest is set to false.

10. Changes

We may update this Policy. The "Last updated" date at the top reflects the most recent change. Material updates will be communicated via in-app notification or email.