Privacy Policy
Last updated: June 22, 2026
1. Data Controller
The controller responsible for processing your personal data is:
Mon CGP SAS
SIREN: 880 295 696
Registered office: 49, Rue de Ponthieu — 75008 Paris, France
Publication director: Nelson Castaneda
For any question regarding the protection of your personal data, please contact us at: privacy@wowiin.app
2. Data Collected and Purposes
Wowiin APP collects the following personal data for the purposes described below.
2.1 Account data
Data: email address, first name (required), last name (optional).
Purpose: account creation and management, authentication, transactional communications.
2.2 Extended profile data
Data: nationality, time zone, preferred currency, interests, dietary preferences, mobility needs, pet (type and name).
Purpose: personalisation of your travel experience and AI concierge recommendations.
2.3 Travel data
Data: destinations, departure and return dates, title, description, trip type, planned steps and activities.
Purpose: management of your travel journal and planning features.
2.4 Travel documents
Data: document type (passport, visa, etc.), expiry date, country of issue, document title.
Purpose: tracking the expiry dates of your travel documents.
Important: Wowiin does not collect any document number, scanned image, or biometric data. Only the expiry date is stored.
2.5 Travel companions
Data: first name and nationality only.
Purpose: management of trips involving other people (GDPR data minimisation principle).
2.6 Consent data
Data: consent to marketing communications, consent to security alerts, date and version of accepted terms.
Purpose: compliance with your communication preferences and regulatory traceability.
2.7 AI conversation data (Phase 3)
Data: content of exchanges with the AI concierge, number of tokens used, associated trip.
Purpose: provision of the AI concierge service and message quota management.
These features will be available from Phase 3 of the application.
2.8 Subscription data (Phase 3)
Data: subscribed plan, billing cycle, Stripe identifiers (customer_id, subscription_id), period dates.
Purpose: subscription management and billing.
This data will be processed from the activation of payments (Phase 3).
3. Legal Bases for Processing
In accordance with Article 6 of the General Data Protection Regulation (GDPR), each processing activity relies on an explicit legal basis:
Performance of a contract (Art. 6.1.b):
- Creation and management of your user account
- Provision of travel planning features
- Subscription management and billing (Phase 3)
Legitimate interest (Art. 6.1.f):
- Improvement and security of the service
- Fraud and abuse prevention
Consent (Art. 6.1.a):
- Sending marketing communications (explicit opt-in at registration)
- Receiving travel security alerts (explicit opt-in)
- Use of non-essential cookies (managed via the cookie banner)
Legal obligation (Art. 6.1.c):
- Retention of accounting and billing data (10 years, French Commercial Code art. L.123-22) — Phase 3
4. Recipients of Data
Your personal data is accessible only to:
- The team of Mon CGP SAS, limited to what is strictly necessary for the management of the service.
- Our technical subcontractors (see section 5 below), under contracts ensuring a level of protection equivalent to the GDPR.
Your data is never sold to third parties or shared with commercial partners for advertising purposes.
5. Subcontractors
We use the following subcontractors for hosting and operating the application:
5.1 Supabase (Supabase Inc.)
Role: database hosting and authentication service.
Processing region: European Union — Ireland (eu-west-1).
Transfer outside EU: none.
Contractual basis: Data Processing Agreement (DPA) signed.
5.2 Vercel (Vercel Inc.)
Role: front-end hosting and content delivery network (CDN).
Processing region: global network, including the United States.
Transfer outside EU: yes — see section 6.
Contractual basis: Data Processing Agreement (DPA) signed, incorporated into Pro plan terms.
5.3 Resend (Resend Inc.)
Role: sending transactional emails (account confirmation, password reset).
Processing region: European Union — Ireland (eu-west-1).
Transfer outside EU: none.
Contractual basis: applicable data processing terms.
5.4 OVH (OVH SAS)
Role: registrar for the wowiin.app domain and hosting of company email accounts (privacy@wowiin.app, support@wowiin.app, etc.).
Processing region: France (EU).
Transfer outside EU: none.
Note: OVH does not process personal data of Wowiin users in connection with this service.
5.5 Anthropic (Anthropic PBC) — planned for Phase 3
Role: provision of the AI concierge service.
Processing region: United States.
Transfer outside EU: planned — Standard Contractual Clauses (SCCs) will be documented upon activation.
This subcontractor will only be active from Phase 3 of the application.
5.6 Stripe (Stripe Inc.) — planned for Phase 3
Role: payment processing and subscription management.
Processing region: United States and European Union.
Transfer outside EU: applicable — Standard Contractual Clauses (SCCs) will be documented upon activation.
This subcontractor will only be active from Phase 3 of the application.
6. Transfers Outside the European Union
6.1 Vercel — active transfer
Data processed by Vercel may be transferred to the United States as part of the use of its global content delivery network.
This transfer is governed by Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision 2021/914 of 4 June 2021), in accordance with Article 46 of the GDPR. These clauses constitute an adequate protection mechanism guaranteeing a level of data protection equivalent to that applicable within the European Union.
6.2 Anthropic and Stripe — planned transfers (Phase 3)
Transfers to the United States will be established upon activation of Phase 3. Standard Contractual Clauses (SCCs) will be documented and made available in this policy at that time.
7. Data Retention Periods
We retain your personal data for the following periods:
Email address and account closure date
Retention: 3 years after account closure (intermediate archiving).
Basis: standard civil limitation period (French Civil Code art. 2224).
Other account data (first name, last name, profile)
Retention: deleted upon account closure.
Basis: data minimisation (GDPR art. 5).
Travel data (destinations, dates, steps)
Retention: duration of the account, deleted upon closure.
Basis: data minimisation (GDPR art. 5).
Travel documents (expiry date only)
Retention: duration of the account, deleted upon closure.
Basis: data minimisation (GDPR art. 5).
Reminder: no document number or image is collected or retained.
Travel companions (first name and nationality)
Retention: duration of the account, deleted upon closure.
Basis: data minimisation (GDPR art. 5).
Technical logs (Supabase authentication logs)
Retention: 12 months maximum.
Basis: French data protection authority (CNIL) recommendation.
Consent data
Retention: 3 years from the date of consent collection.
Basis: civil limitation period (French Civil Code art. 2224) and CNIL recommendation.
Subscription and billing data (Phase 3)
Retention: 10 years from the transaction date.
Basis: legal obligation to retain accounting documents (French Commercial Code art. L.123-22).
Aggregated and non-reidentifiable statistical data
Upon account deletion, personal data is irreversibly anonymised. The resulting aggregated data — which cannot be re-identified — no longer constitutes personal data under the GDPR (recital 26). It may be retained and used for statistical purposes.
Note: these retention periods have been defined in accordance with CNIL recommendations and may be subject to change. They have not been reviewed by external legal counsel. Legal advice is recommended before any public launch.
8. Your Rights
In accordance with the GDPR (Articles 15 to 22), you have the following rights regarding your personal data:
Right of access (Art. 15): you may obtain a copy of all personal data we hold about you.
Right to rectification (Art. 16): you may correct or update inaccurate or incomplete data via the Settings page of your account.
Right to erasure (Art. 17): you may request deletion of your account and all your personal data. This deletion is irreversible and results in the anonymisation of all data associated with your account.
Right to data portability (Art. 20): you may request an export of your data in a structured, commonly used, machine-readable format (JSON format). See section 10 for details.
Right to restriction of processing (Art. 18): you may request a temporary suspension of the processing of your data, for example while verifying a dispute regarding its accuracy.
Right to object (Art. 21): you may object at any time to the processing of your data based on our legitimate interest, as well as to processing for direct marketing purposes.
Right to withdraw consent: where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal.
Right to define post-mortem instructions: you may define instructions regarding the fate of your data after your death.
9. Response Time and Contact
We undertake to respond to any request relating to the exercise of your rights within one month of receiving your request. This period may be extended by two additional months in the case of complex or high-volume requests, after notification within the initial one-month period.
To exercise your rights or for any question regarding data protection, contact us at:
privacy@wowiin.app
Any request must enable us to identify the account concerned (login email address). We may ask for proof of identity if there is reasonable doubt.
If you believe your rights have not been respected, you also have the right to lodge a complaint with your national data protection authority. In France: Commission nationale de l'informatique et des libertés (CNIL) — www.cnil.fr
10. Data Portability — JSON Format
In accordance with Article 20 of the GDPR, you may request an export of your personal data in a structured, commonly used, machine-readable format.
The chosen format is JSON (JavaScript Object Notation), an open and standardised format, interoperable with the majority of data processing tools.
The export includes the following data: profile information, travel data and associated steps, travel documents (expiry date only, no document number or image), travel companions (first name and nationality).
To request your export, send your request to privacy@wowiin.app indicating the email address associated with your account.
11. Profiling and Automated Processing
11.1 Current situation (V1)
The current version of Wowiin APP does not carry out any profiling within the meaning of Article 22 of the GDPR. No automated decision-making producing legal effects or similarly significantly affecting you is performed.
11.2 Phase 3 — AI Concierge
From Phase 3, Wowiin APP will integrate an AI concierge (service provided by Anthropic) to answer your travel-related questions. This service will use data from your profile and trips to personalise responses.
This processing does not constitute profiling within the meaning of Article 22 (no automated decision-making with legal effects), but you have the right to object to it at any time in accordance with Article 21 of the GDPR.
You may exercise this right by contacting privacy@wowiin.app or by disabling the AI concierge from your account settings when Phase 3 is activated.
12. Personal Data Breach Procedure
In accordance with Article 33 of the GDPR, in the event of a personal data breach likely to result in a risk to your rights and freedoms, we undertake to:
- Notify the breach to the relevant supervisory authority (CNIL in France) within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
- Notify you directly, without undue delay, if the breach is likely to result in a high risk to your rights and freedoms (Art. 34 GDPR).
The notification will be sent to the email address associated with your account. It will set out the nature of the breach, the data concerned, the measures taken to address it, and, where applicable, the steps you can take to limit the consequences.
If you have concerns about the security of your data, please contact us at privacy@wowiin.app.
13. Data Security
We implement appropriate technical and organisational measures to protect your personal data against any unauthorised access, disclosure, alteration or destruction:
- Encryption of data in transit (HTTPS/TLS) via Vercel.
- Encryption of data at rest via Supabase infrastructure.
- Per-user access control (Row Level Security): each user can only access their own data.
- Secure authentication managed by Supabase Auth.
- Restricted access to data by the Mon CGP SAS team.
These measures are regularly reassessed and improved in line with evolving risks and best practices.
14. Changes to This Policy
We reserve the right to modify this privacy policy at any time, in particular to reflect changes in regulation or in our processing practices.
In the event of a material change, you will be informed by email at the address associated with your account and/or by a notification in the application, with reasonable notice before the changes take effect.
The date of last update is shown at the top of this page. The previous version is available on request at privacy@wowiin.app.