Onmylist

Privacy and GDPR

Privacy Policy

This notice explains how Onmylist processes personal data on the Onmylist website, including the landing page, registration, login, and web app surfaces available at www.onmylist.site.

Last updated: 22 June 2026

Controller

Onmylist GmbH, Stephansplatz 8 / 20, 1010 Vienna, Austria, is responsible for the processing described in this notice.

Privacy contact: office@onmylist.site

Scope

This notice covers the website only: the public landing page, registration, login, captcha, and browser-based Onmylist web app. The native mobile app may process additional data or use platform features not covered here.

Data We Process

  • Registration and login When you create or access an account, we process username, email address, password, verification code input, authentication data, user ID, and timestamps. Passwords are stored as hashes. Email addresses are stored in encrypted and/or hashed form for account verification and lookup.
  • Security and website delivery We process technical metadata such as IP address, date and time, requested URL, referrer, user agent, request headers, captcha signals, and security tokens to deliver the website, protect accounts, prevent abuse, and troubleshoot problems.
  • Wishlist, list, and product data If you use the web app, we process product links, titles, images, categories, list names, ordering, public/private list settings, shared-list hashes, "I want" and "I have" states, price/currency/discount fields, image display settings, and deletion or update actions.
  • Public and shared content Public lists, public items, shared-list links, usernames, profile images, and public profile information can be shown to other visitors depending on the visibility choices you make in the service.
  • Discovery, search, and recommendations The web app can process search terms, recent searches stored in the browser, discovery feed activity, recommendation data, and popularity/trend data derived from product and list interactions.
  • Optional profile data If provided, profile-related data may include social usernames or links, bio, profile image, gender, birthdate, and email-related fields.
  • Browser storage The web app stores authentication state, recent list usage, recent searches, profile image references, and wishlist/product cache in localStorage or sessionStorage. This storage remains in your browser until it expires by browser behavior, the session ends, you log out where supported, or you clear it.

Purposes and Legal Bases

Purpose Examples Legal basis under GDPR
Provide the website and account features Display pages, create accounts, log users in, save lists and products, show shared lists. Article 6(1)(b), performance of a contract or pre-contractual steps.
Security and abuse prevention Captcha, rate and replay protection, request signatures, session keys, access logs, suspicious request handling. Article 6(1)(f), legitimate interests in securing the service and preventing abuse.
Email verification and service communication Send and validate registration codes and account-related messages. Article 6(1)(b) and Article 6(1)(f).
Public sharing and discovery features Public lists, shared links, profile display, search, discovery feeds, trendsetter and recommendation features. Article 6(1)(b) where you request these features, and Article 6(1)(f) for operating and improving discovery.
Legal compliance and claims Responding to lawful requests, protecting rights, keeping evidence where necessary. Article 6(1)(c) for legal obligations and Article 6(1)(f) for legal defense.

Recipients

  • Hosting, database, relay, backend, and operational infrastructure These systems process website traffic, account data, product/list data, logs, sessions, and security data.
  • Apple App Store links may send you to Apple. The backend also contains a Sign in with Apple endpoint used by native Apple authentication flows.
  • Product and merchant websites If you add, display, or open product links or externally hosted product images, your browser or our backend may contact the relevant external website. Those sites may receive normal request metadata such as IP address, user agent, referrer, and requested resource URL.
  • Public visitors Data you choose to make public or share through public links can be visible to other website visitors.
  • Authorities and advisors We may disclose data if required by law or where necessary to protect rights and handle legal claims.

Retention

  • Account and list data Kept while your account exists or while needed to provide the service, then deleted or anonymized unless retention is required for legal, security, backup, or legitimate operational reasons.
  • Verification, session, and security data Kept for the period needed to verify accounts, keep sessions active, protect the service, prevent replay or abuse, and troubleshoot issues.
  • Browser storage localStorage stays in your browser until removed by logout code where available or by clearing browser data. sessionStorage usually remains until the browser tab or session ends.
  • Server logs Kept only as long as necessary for security, troubleshooting, abuse prevention, and legal or operational needs, according to the applicable server log rotation and retention settings.

Cookies and Browser Storage

The inspected website code does not set analytics or advertising cookies. The web app does use localStorage and sessionStorage for authentication state, cached product/list data, recent searches, and recent list usage.

You can clear browser storage through your browser settings. Clearing storage may log you out or remove local app preferences and cached data.

Automated Processing

Onmylist uses automated security checks for captcha, proof-of-work, token verification, rate-abuse detection, and bot prevention. These checks can require a challenge or prevent a suspicious registration attempt.

The web app may automatically sort, rank, or recommend products and lists based on product and list activity. These features only affect what content is displayed or suggested; they do not make decisions about your rights, eligibility, pricing, or access to the service.

Your Rights

Subject to the conditions in the GDPR, you may have the right to request access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time with effect for the future.

To exercise rights, contact office@onmylist.site. You also have the right to lodge a complaint with a supervisory authority. In Austria, the competent authority is the Austrian Data Protection Authority: www.dsb.gv.at.