WibloWiblo
HomePricing
πŸ‡¬πŸ‡§EN

PRIVACY POLICY β€” WIBLO

Last updated: January 24, 2026

Wiblo is committed to protecting your privacy and processing your personal data in a transparent, secure manner that complies with the General Data Protection Regulation (GDPR - EU 2016/679) and applicable laws in France.

This document explains:

  • What data we collect
  • Why and how we use it
  • Who we share it with
  • Your rights and how to exercise them
  • Our security measures
  • Cookie management

Contact: hello.wiblo@gmail.com

1. DATA CONTROLLER

Data Controller: SAS Hapy
Address: 60 Rue FranΓ§ois 1er, 75008 Paris, France
Personal data contact: hello.wiblo@gmail.com

Wiblo processes data as:

  • Data controller for its own operational needs
  • Data processor for certain specific data (e.g., reviews transmitted to Creators)

2. PERSONAL DATA COLLECTED

2.1 β€” IDENTIFICATION DATA (mandatory)

Collected during registration and account creation:

DataWhy?Legal basis
Phone numberAnti-multi-account verification, 2FA, contactLegitimate interest (security), consent
Email addressPrimary identifier, notifications, account recoveryNecessary for contract
First name/Last name or pseudonymUser profile, public display (optional)Legitimate interest (community functioning)
PasswordAuthentication (hashed, never stored in plain text)Necessary for contract

2.2 β€” PAYMENT DATA (managed by third parties)

DataWhy?Legal basis
Banking information (card, IBAN)Project publication paymentNecessary for contract (via Apple/Google)
Billing historyTax compliance, supportNecessary for contract

IMPORTANT: Wiblo NEVER stores banking information. It is processed exclusively by Apple (App Store), Google (Play Billing), and Paddle (web payments).

2.3 β€” USAGE & ACTIVITY DATA

DataWhy?Legal basis
Test historyPoints allocation, levels, anti-fraudNecessary for contract
Published reviewsPublic display, quality analysisConsent, legitimate interest
Points/LevelsGamification, user progressionNecessary for contract
Claimed rewardsDelivery management and trackingNecessary for contract

2.4 β€” TECHNICAL DATA

DataWhy?Legal basis
IP addressSecurity, anti-fraud geolocationLegitimate interest (security)
Device type/OSCompatibility, analyticsLegitimate interest
Device identifierUser sessionsLegitimate interest
Cookies (see section 9)Website/app functioningConsent

2.5 β€” OPTIONAL / SENSITIVE DATA

DataWhy?Legal basis
Geolocation (opt-in)Reward eligibility verificationExplicit consent
ID document (rare)Age/identity verification for Rewards >€50Legitimate interest + consent
Marketing preferencesCommunication personalizationConsent

NO SENSITIVE DATA: Wiblo does not collect health data, religion, sexual orientation, political opinions, etc.

3. PROCESSING PURPOSES

We process your data ONLY for:

3.1 β€” PRIMARY PURPOSES (necessary for contract)

1. Wiblo service provision:

  • Account creation and management
  • Points/Levels allocation based on your actions
  • Project publication (Creators)
  • Test and Review management (Testers)
  • Payment processing via IAP

2. Rewards management:

  • Eligibility verification (level, review quality, geolocation)
  • Reward delivery (partners)
  • Delivery and claim tracking

3. Security & integrity:

  • Fraud detection (multi-accounts, bots)
  • Abuse protection (IP monitoring, patterns)
  • Critical data backup

3.2 β€” SECONDARY PURPOSES (legitimate interest)

1. Platform improvement:

  • Anonymized trend analysis
  • Internal statistics (Testerβ†’Creator conversion rate)
  • UX/UI optimization (analytics)

2. Customer support:

  • Response to your tickets and claims
  • History of your interactions with support

3. Legal compliance:

  • Tax obligations (invoices)
  • Response to authorities (judicial orders)

3.3 β€” MARKETING PURPOSES (consent)

1. Marketing communications:

  • Newsletter (new Projects, Rewards, events)
  • Special promotions (partner promo codes)
  • MANDATORY OPT-IN: You can unsubscribe at any time

4. LEGAL BASES FOR PROCESSING

PurposeGDPR legal basisDetails
Service provisionArticle 6.1.b β€” Necessary for contractWithout this data, no service possible
SecurityArticle 6.1.f β€” Legitimate interestPlatform security priority
ImprovementArticle 6.1.f β€” Legitimate interestAnonymized A/B tests
MarketingArticle 6.1.a β€” ConsentExplicit opt-in required
ComplianceArticle 6.1.c β€” Legal obligationInvoices, authorities
Sensitive rewardsArticle 6.1.a β€” ConsentGeolocation, identity verification

5. DATA RECIPIENTS

5.1 β€” INTERNAL RECIPIENTS

  • Wiblo team (support, moderation, development)
  • Restricted access by role (principle "need to know")

5.2 β€” SUB-CONTRACTORS / TECHNICAL PARTNERS

PartnerRoleData sharedContract type
Apple/GoogleIAP paymentsBanking dataStore contracts
Firebase/AWSHostingTechnical dataSigned GDPR DPA
PaddleWeb Merchant of RecordPayment dataSigned DPA
Reward Partners (Amazon)Gift deliveryName, email, addressSpecific contract
Google AnalyticsAnalyticsAnonymized dataAnalytics DPA

ALL SUB-CONTRACTORS SIGN A GDPR DPA (DATA PROCESSING AGREEMENT).

5.3 β€” SHARING WITH CREATORS

  • Public reviews: Your published Reviews are visible to the Project Creator and the community
  • No sensitive identifiers: The Creator does not see your email, phone, IP, etc.
  • Aggregated statistics: The Creator sees anonymized stats (e.g., "50 French Testers, average rating 4.2")

5.4 β€” AUTHORITIES & LEGAL OBLIGATIONS

  • Judicial orders, police, tax authorities
  • Only upon legally founded request

WIBLO NEVER SELLS YOUR PERSONAL DATA TO THIRD PARTIES.

6. INTERNATIONAL DATA TRANSFERS

6.1 β€” DATA LOCATION

  • Main servers: Europe (AWS Frankfurt, Firebase EU)
  • Analytics: Google Analytics EU (not USA except anonymization)
  • Payments: Apple/Google (GDPR compliant)

6.2 β€” TRANSFERS OUTSIDE EU

DestinationLegal basisGuarantees
USA (Google Analytics)SCC (Standard Contractual Clauses)IP anonymization + DPA
Partners outside EUConsent + SCCCase by case

7. DATA RETENTION PERIOD

Data typeRetention periodReason
Active accountDuration of your use + 3 yearsSupport, legal, reactivation
Points/Rewards5 years after last activityTax, disputes
Invoices/Payments10 yearsFrench tax obligations
Security logs6 monthsGDPR + security
Public reviewsIndefinitely (except deletion request)Historical value
Deleted data30 days max (backup)Complete deletion

AFTER ACCOUNT DELETION: All personal data is deleted within 30 days, except legal obligations or security backups (anonymized).

8. YOUR GDPR RIGHTS

You have the following rights (Articles 15 to 22 GDPR):

RightDescriptionHow to exercise
ACCESS (Art. 15)Obtain a copy of your dataForm in app or email hello.wiblo@gmail.com
RECTIFICATION (Art. 16)Correct inaccurate dataAccount settings or support
OBJECTION (Art. 21)Refuse marketing/analytical processingUnsubscribe link or settings
ERASURE (Art. 17)Request deletion of your dataForm in app or email
PORTABILITY (Art. 20)Retrieve your data in a structured format (JSON, CSV)Request by email
RESTRICTION (Art. 18)Temporarily freeze processing of your dataRequest by email
COMPLAINTFile a complaint with CNIL if rights not respectedcnil.fr/fr/plaintes

RESPONSE TIME: Maximum 30 days after receipt of your request.

9. COOKIES & TRACKING TECHNOLOGIES

9.1 β€” WHAT IS A COOKIE?

A cookie is a small text file stored on your device when you visit our application or website. It allows us to remember your preferences and improve your experience.

9.2 β€” COOKIES USED

TypePurposeDurationLegal basis
ESSENTIAL COOKIESUser session, Login, SecuritySessionNecessary for contract
ANALYTICAL COOKIESGoogle Analytics (anonymized), Usage statistics13 monthsConsent
MARKETING COOKIES (if applicable)Targeted advertising, Retargeting13 monthsConsent

9.3 β€” COOKIE MANAGEMENT

You can refuse non-essential cookies:

  • In Wiblo application settings
  • Via your browser (if using web app)
  • Via your mobile device settings (iOS/Android)

9.4 β€” SIMILAR TECHNOLOGIES

Wiblo may also use:

  • Tracking pixels (analytics)
  • Mobile advertising identifiers (IDFA iOS, GAID Android)
  • Local storage / session storage

10. DATA SECURITY

Wiblo implements technical and organizational measures to protect your personal data against unauthorized access, loss, destruction or alteration.

10.1 β€” TECHNICAL MEASURES

  • βœ… Communication encryption (HTTPS/TLS)
  • βœ… Passwords hashed with bcrypt (never stored in plain text)
  • βœ… Two-factor authentication (2FA) available
  • βœ… Sensitive data encryption in database
  • βœ… Encrypted and regular backups
  • βœ… DDoS attack protection

10.2 β€” ORGANIZATIONAL MEASURES

  • βœ… Restricted data access (limited team, "need to know" principle)
  • βœ… Mandatory GDPR training for all employees
  • βœ… Regular security audits (internal and external)
  • βœ… Continuous anti-fraud monitoring (logs, patterns)
  • βœ… Security incident response procedures
  • βœ… DPA contracts with all sub-contractors

10.3 β€” IN CASE OF DATA BREACH

In case of a data breach affecting your rights and freedoms, Wiblo commits to:

  • Notify CNIL within 72 hours (GDPR Article 33)
  • Inform you directly by email if high risk (GDPR Article 34)
  • Take all necessary corrective measures
  • Publish a transparency report

11. MODIFICATIONS TO THIS POLICY

11.1 β€” CHANGE NOTIFICATIONS

In case of IMPORTANT changes (new data collected, new recipients, purpose change):

  • Email notification 7 days before effective date
  • In-app notification (pop-up on launch)
  • New version published with visible update date
  • Acceptance required to continue using Wiblo

11.2 β€” MINOR CHANGES

For minor modifications (corrections, clarifications):

  • Update of "Last updated" date
  • Publication without prior notification

11.3 β€” VERSION HISTORY

Previous versions of this Policy are archived and available upon request by email at hello.wiblo@gmail.com.

12. CONTACT & COMPLAINTS

12.1 β€” QUESTIONS ABOUT YOUR PERSONAL DATA

  • πŸ“§ Email: hello.wiblo@gmail.com
  • πŸ“ Postal address: SAS Hapy - 60 Rue FranΓ§ois 1er, 75008 Paris, France

Email subject: [GDPR] followed by your request (e.g., [GDPR] Access request)

We commit to responding within a maximum of 30 calendar days.

12.2 β€” COMPLAINT TO CNIL

  • πŸ”— cnil.fr/fr/plaintes
  • πŸ“§ plaintes@cnil.fr
  • πŸ“ CNIL - 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07

13. COMPLIANCE

This Privacy Policy complies with:

  • βœ… General Data Protection Regulation (GDPR - EU 2016/679)
  • βœ… Data Protection Act (France, amended in 2018)
  • βœ… Apple App Store Review Guidelines (Section 5.1.1)
  • βœ… Google Play Store Data Safety Requirements
  • βœ… ePrivacy Directive (cookies and electronic communications)

Wiblo β€” Your privacy is our priority.
Last updated: January 24, 2026

Wiblo
HomePricingPrivacyTerms
Wiblo Β© 2026πŸ‡¬πŸ‡§EN