Privacy notice
Last updated: 2 October 2026 · Version 2.0
This notice explains how eWibe S.r.l. processes your personal data when you use our websites, our app and our services, under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and the Italian Personal Data Protection Code (Legislative Decree 196/2003, “Italian Privacy Code”). Cookies and similar technologies are described in our Cookie policy. This notice is also available in Italian; if the two versions differ, the Italian one prevails.
At a glance
| Question | Short answer |
|---|---|
| Who processes your data? | eWibe S.r.l., Milan. Write to info@ewibe.com. |
| Why? | To run your account and your bottles (purchase, storage, sale, delivery), to answer your requests, to meet legal obligations and to keep things secure. Statistics, advertising, profiling and some promotional messages only with your consent. |
| Do we sell your data? | No. |
| Where is it? | The database and servers of our API are in Germany (Frankfurt). Our websites and web app are hosted by Netlify; almost all our emails are sent from the United States; some other providers process data in the United States. Always with the safeguards described in section 8. |
| For how long? | As long as each purpose requires (section 9). Accounting records for 10 years, as the law requires. |
| Can you object? | Yes, at any time: see “Your right to object” below. |
| What other rights do you have? | Access, rectification, erasure, restriction, portability, withdrawal of consent and a complaint to the Italian Data Protection Authority (section 11). |
Your right to object
You can object at any time, free of charge and without giving reasons, to our promotional messages and to the way we choose who receives them (purposes 8 and 12 in section 5): use the “Unsubscribe” link at the bottom of every promotional email or write to info@ewibe.com.
You can also object to our other processing based on legitimate interest (purposes 7 and 15) on grounds relating to your particular situation: we will then stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims (Article 21 GDPR).
1. Controller and contact details
The controller is eWibe S.r.l., registered office at Via Maurizio Gonzaga 2, 20123 Milan, Italy, VAT number IT11884500965.
For any question about your data or to exercise your rights, write to info@ewibe.com. You can also write to us by post at our registered office.
2. Data protection officer (DPO)
We have not appointed a data protection officer, because our core activities do not consist of regular and systematic monitoring of people on a large scale, nor of large scale processing of special categories of data (Article 37 GDPR). For any data protection matter, please use the address in section 1.
3. Who and what this notice covers
This notice covers:
- visitors to ewibe.com, blog.ewibe.com and risorse.ewibe.com (help centre);
- users of the web app at app.ewibe.com and of the eWibe app for iOS and Android;
- anyone who contacts us (support form, email, WhatsApp, booking a consultation with our wine advisor);
- recipients of our emails and push notifications, including newsletter subscribers;
- people whose data we receive from others (section 6).
eWibe staff using our internal tools receive a separate notice.
4. What data we process
| Category | Examples |
|---|---|
| Account data | First name, surname, email, password (handled by Amazon Cognito: we never see it in clear text), language, how you signed up (email, Google, Apple, Facebook). |
| Profile and delivery data | Date of birth (to check that you are an adult), phone number, delivery address. The profile used to ask for your gender too: we no longer ask for it and we will delete the values already stored. |
| Contract data | Bottles bought, stored, sold and delivered; purchase, sale and delivery requests; prices, commissions, storage fees; invoices and payments; bank details (IBAN), if you give them to us to receive the proceeds of a sale. The details of the card you use to pay the storage fee are handled by Stripe: we do not see them. |
| Communications with us | The content of support requests and emails, WhatsApp messages, consultation bookings (name, email, date), account closure requests and the reason, if you give one. |
| Technical and security data | IP address, browser and operating system, pages and functions requested with date and time, your account identifier in our logs, app and server error reports, the app installation identifier used for updates, tokens for push notifications. |
| Promotional communications data | Newsletter subscription and confirmation, consents given and withdrawn, emails and push notifications sent, unsubscribes and bounces, email opens and clicks (section 5, purpose 11). |
| Statistics and advertising data (only with consent) | Pages and screens viewed, referral source, device, actions in the app (login, sign up, wines viewed and saved), linked to a random identifier and, when you are logged in, to your eWibe account identifier (for Google Analytics only); which push notifications you open; the advertising identifier of your device (on iPhone only if you allow tracking). We do not send Google or Meta your name, your email, your age, your gender or the value of your bottles, and we do not send Meta even your account identifier. |
We do not ask for, and do not want to receive, special categories of data (for example health data) or criminal records data: please do not include them in your messages. We do not collect copies of identity documents.
What is required. Account data and the data we need to buy, store, sell and deliver your bottles are required: without them we cannot provide the service. Your date of birth is required because we only sell alcoholic drinks to adults. Data for statistics, advertising, profiling and promotional messages is optional: if you do not provide it or you withdraw your consent, the service still works. Optional fields are marked as such in our forms.
5. Why we process your data and on what legal basis
| # | Purpose | Legal basis |
|---|---|---|
| 1 | Create and manage your account, let you log in (also with Google, Apple or Facebook), protect access (verification codes by email). | Performance of the contract (Article 6(1)(b) GDPR). |
| 2 | Check that you are an adult. | Legal obligation: the ban on selling alcoholic drinks to minors (Article 14-ter of Italian Law 125/2001) (Article 6(1)(c) GDPR). |
| 3 | Purchase, storage in our vault, sale and delivery of your bottles; collection of storage fees; payment of the proceeds of your sales. | Performance of the contract (Article 6(1)(b)). |
| 4 | Invoicing, accounting, tax obligations, answering requests from public authorities. | Legal obligation (Article 6(1)(c)). |
| 5 | Answer your requests (form, email, WhatsApp, app) and arrange the consultations you book. | Performance of the contract or steps taken at your request before entering into it (Article 6(1)(b)). |
| 6 | Service messages by email and push notification (confirmations, status of your requests, security alerts, changes to our terms). | Performance of the contract (Article 6(1)(b)) and, for notices required by law, legal obligation (Article 6(1)(c)). |
| 7 | Security of our services: technical logs, backups, error reporting, prevention of abuse and fraud, automatic blocking of anomalous access (section 10). | Legitimate interest in protecting our services, your data and your bottles (Article 6(1)(f)). |
| 8 | Promotional emails to customers about eWibe products and services similar to those they bought. | Legitimate interest and Article 130(4) of the Italian Privacy Code (“soft opt in”). You can object at any time, including through the link in every email. |
| 9 | Newsletter and promotional emails to people who are not customers. With a separate consent, offers from partners that sell wine or wine related services, such as Vinodoo: we send them ourselves, without giving your data to the partner. | Consent (Article 6(1)(a) GDPR and Article 130 of the Italian Privacy Code). |
| 10 | Promotional push notifications in the app. | Consent. We do not currently send promotional push notifications. |
| 11 | Measure whether you open our emails and which links you click (invisible image and personalised links), and use this to choose what to send you. | For newsletter subscribers, consent (art. 6.1.a GDPR), which covers measuring opens and clicks. For customers, legitimate interest in knowing which communications are of interest and in not writing to people who do not read them (art. 6.1.f). You can object at any time by switching off open tracking from the “Gestisci le preferenze email” (email preferences) link at the bottom of our emails, or by writing to info@ewibe.com: you keep receiving the emails, with nothing measured. |
| 12 | Choose who receives which communications using simple criteria: whether you are a customer or a newsletter subscriber, your language, whether you hold bottles in storage and which wines. | Legitimate interest in sending relevant communications (Article 6(1)(f)). You can object at any time. |
| 13 | Statistics on the use of our websites and app (Google Analytics and Firebase Analytics) and on which push notifications are opened. | Consent (Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code). |
| 14 | Measure how well our ads work (Meta Pixel and Google Ads) and, through Meta, show you eWibe ads on Facebook and Instagram. | Consent (Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code). |
| 15 | Establish, exercise or defend our legal claims, including debt recovery. | Legitimate interest (Article 6(1)(f)). |
| 16 | Profiling for promotional messages: choosing them based on the value of the bottles you hold in storage and on when you last used eWibe. | Specific and optional consent, separate from the others (Article 6(1)(a) GDPR). We do not collect this consent at present, so we do not use these criteria. |
Our legitimate interests are: protecting our services and our customers’ data and goods from unauthorised access and fraud; keeping our services working; telling customers about products similar to those they have already chosen; not sending pointless messages; defending our rights. We have assessed that, for this processing, your interests and rights do not override these interests, also because it is processing you can reasonably expect and can object to at any time. You can ask us for the details of this assessment at the address in section 1.
If you withdraw your consent, we stop processing your data for that purpose from that moment. Processing carried out before remains lawful.
6. Where your data comes from
We receive almost all data from you. Some comes from others (Article 14 GDPR):
- Google, Apple and Meta (Facebook), if you sign up or log in with their account: name, email and identifier. With Sign in with Apple you can hide your email from us: we then receive an Apple relay address.
- Your device and browser: technical data and, with your consent, statistics and advertising data.
- Our former CRM (HubSpot): contacts collected since 2022 through website forms, subscriptions and events, moved into our own CRM.
- Stripe: payment outcomes and invoice data.
7. Who we share your data with
We share data only with those who need it for the purposes in section 5. We do not sell your data and we do not pass it to others for their own marketing.
Within eWibe, data is processed by authorised and trained staff (Article 29 GDPR), each only for the data their work requires.
Providers that process data on our behalf (processors, Article 28 GDPR), bound by a contract with us:
| Provider | What for | Where the data is |
|---|---|---|
| Amazon Web Services EMEA SARL (Luxembourg) | Servers and database of our API, sign up and login (Amazon Cognito), sending emails and receiving unsubscribes (Amazon SES), file and log storage | Germany (Frankfurt). The emails we send you, except verification and password recovery codes, are sent from the United States (Virginia), where opens and clicks are also measured. |
| Google (Google Workspace) | Company email, shared documents, consultation calendar | EU and United States |
| Google Ireland Limited (Google Analytics, Firebase Analytics) | Statistics, only with your consent | EU and United States |
| Netlify, Inc. | Hosting of websites and web app, domain management | United States and global delivery network |
| 650 Industries, Inc. (Expo) | Sending push notifications (through Apple and Google) and app updates | United States |
| Functional Software, Inc. (Sentry) | App and server error reporting: errors only, without identifying data | European Union (Germany) |
| Stripe Payments Europe, Limited (Ireland) | Collection of the storage fee. For some processing (fraud prevention, legal obligations) Stripe acts as an independent controller | EU and United States |
| Grafana Labs | Internal monitoring dashboards | EU |
| Vault operator, couriers and insurer | Storage, delivery and insurance of your bottles. Couriers and the insurer may also act as independent controllers for their own obligations; the current list is available by writing to info@ewibe.com | European Union; for deliveries outside the EU, also the destination country |
| HubSpot Ireland Limited | Our former CRM: it no longer collects data or receives exports, and the account is being closed | EU |
Discord Inc. (United States). The purchase and sale requests you send from the app also reach our staff as an alert in a private Discord channel. Discord processes this data under its own terms, which do not include a processor contract. Support and account closure requests, by contrast, reach only our own email.
Joint controllers (Article 26 GDPR):
- Meta Platforms Ireland Limited (Ireland). If you consent to marketing on app.ewibe.com, the Meta Pixel sends Meta your actions in the web app (pages viewed, login, sign up, wines viewed and saved), without your name, your email or your account identifier. For the collection and transmission of this data, eWibe and Meta are joint controllers (Court of Justice of the EU, case C-40/17). The essence of the arrangement: eWibe informs you and collects your consent before the data is sent; Meta then processes the data as an independent controller, including to show you eWibe ads on Facebook and Instagram, and is responsible for that processing; for your rights over the collection and transmission you can contact us or Meta, and each passes requests on to the other. The text is in Meta’s Controller Addendum. The contact details of Meta and of its data protection officer are in Meta’s privacy policy.
Recipients that act as independent controllers:
- Google Ireland Limited for Google Ads: conversion measurement on app.ewibe.com and in the app, only with your statistics and marketing consent. Google does not use this data to show you personalised ads.
- Google, Apple and Meta for logging in with their account; Apple and Google for the app stores and notification services (APNs, Firebase Cloud Messaging).
- Google (YouTube), only if you start a video embedded in our website.
- Google (Google Maps Platform), to suggest your address while you type it.
- WhatsApp Ireland Limited, if you write to us on WhatsApp.
- Banks and payment institutions; accountants, lawyers and auditors; public and judicial authorities where the law requires it; any buyer of our business or part of it, with the same safeguards as this notice.
8. Transfers outside the European Union
Some providers process data in the United States. We transfer it only with one of the safeguards provided by the GDPR:
- The Data Privacy Framework between the EU and the United States: the European Commission adequacy decision of 10 July 2023 (Article 45 GDPR), for certified providers. As of 2 October 2026, Amazon, Google, Meta, Netlify, Expo (650 Industries), Sentry (Functional Software), Stripe, Grafana Labs, HubSpot and Discord are certified.
- Standard contractual clauses of the European Commission (Decision (EU) 2021/914, Article 46 GDPR), for providers that are not certified (for example Apple) and as an additional safeguard in the contracts that include them.
You can ask us for a copy of these safeguards at the address in section 1.
9. How long we keep your data
| Data | How long |
|---|---|
| Account and profile | While your account is open. When you close it, after 30 days we delete your personal data or make it anonymous, except what we must keep under the rows below (section 12). |
| Incomplete sign ups (email never confirmed) | 30 days. |
| Inactive accounts with no bottles in storage | Closed after 36 months without logins, with a notice 30 days before. |
| Contracts, orders, invoices and payments (including the IBANs used to pay you) | 10 years from the date of the last accounting entry (Article 2220 of the Italian Civil Code) or, for contracts, from the end of the relationship. |
| Support requests and consultation bookings | 24 months after the request is closed. |
| Promotional emails to customers (soft opt in) | Until you object, and in any case no longer than 24 months after your last purchase or interaction with us. |
| Newsletter subscription and consents | Until you withdraw your consent; we delete subscribers who have had no interaction with us for 24 months. Subscription requests not confirmed within 30 days are deleted. |
| List of people who no longer want our emails (unsubscribes and invalid addresses) | As long as needed to stop writing to you; we keep only the address, the date and the reason. |
| Proof of email consents and of their withdrawal | For as long as the processing lasts and for 5 years after withdrawal, to show that we acted correctly; we keep only the address, the date, the text accepted and the channel. Your cookie choice, by contrast, stays only on your device, for 6 months. |
| Email opens and clicks | 12 months, then only in aggregate form. |
| Profiling (purpose 16, with consent) | Segments are recalculated for every sending and use no data older than 12 months. |
| Notifications sent, push opens and tokens | Notification and open history 12 months; the token while you stay logged in on the device and notifications are allowed. |
| Technical and security logs | Up to 12 months. |
| Error reports (Sentry) | Up to 90 days. |
| Database backups | 7 days; manual copies taken before work on the database 12 months at most: a closed account may remain in one until then, without being used. |
| Statistics (Google Analytics) | 14 months at most. |
| Data needed in case of a dispute | Until it is settled, for the applicable limitation period. |
At the end of these periods we delete the data or make it anonymous.
10. Automated decisions and profiling
Automatic blocking of anomalous access. To protect our customers’ accounts and bottles, a system checks the use of the service every 10 minutes. If an account makes more than 10,000 requests in an hour, far more than a person needs, access is suspended automatically. This is an automated decision necessary to perform the contract securely (Article 22(2)(a) GDPR). The suspension is temporary: one of our staff reviews it and you can always ask for human intervention, express your point of view and contest the decision by writing to the address in section 1.
Choosing who receives our communications. Using simple criteria (purpose 12) we choose who receives a message: for example only customers who hold a certain wine in storage. We would use the value of your bottles and when you last used eWibe only with your consent to profiling (purpose 16), which we do not collect at present; we use email opens and clicks only as described in purpose 11. None of these choices has legal or similarly significant effects on you.
Statistics and advertising. With your consent, Google receives your actions on our websites and in our app for statistics and advertising measurement, and Meta receives your actions in the web app to measure our ads and to show you eWibe ads on Facebook and Instagram (purposes 13 and 14). We do not use Google for personalised advertising.
11. Your rights
You have the right to:
- access your data and receive a copy (Article 15);
- have it rectified if it is inaccurate or incomplete (Article 16);
- have it erased where the law provides (Article 17);
- restrict its processing where the law provides (Article 18);
- receive it in a structured, commonly used and machine readable format and transmit it to another controller (portability, Article 20);
- object to processing based on legitimate interest and to direct marketing, as explained in “Your right to object” (Article 21);
- withdraw your consent at any time, without affecting processing already carried out (Article 7(3));
- not be subject to decisions based solely on automated processing, within the limits of Article 22 (section 10).
How to exercise them. Write to info@ewibe.com. We reply free of charge within one month; for complex or numerous requests we may extend this by two further months, and we will tell you. If we are unsure of your identity, we may ask for information to verify it.
How to withdraw consent or object straight away:
- cookies and statistics and advertising tools: “Cookie preferences” at the bottom of the website and web app pages, or Profile > Privacy preferences in the app;
- promotional emails: the “Unsubscribe” link at the bottom of every email, or Profile > Communications in the app and the web app;
- profiling: an email to info@ewibe.com;
- push notifications: your phone settings;
- tracking on iPhone: Settings > Privacy and Security > Tracking.
Complaints. If you believe that our processing infringes the GDPR, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia 11, 00187 Rome, Italy, www.garanteprivacy.it, protocollo@gpdp.it, certified email protocollo@pec.gpdp.it, or with the authority of the EU country where you live or work. You can also go to court.
12. Closing your account and deleting your data
You can close your account in the app or the web app (Profile > Delete account) or by writing to info@ewibe.com. We send you a confirmation email.
- If you have no bottles in storage, no open purchase or sale requests and no money to receive, your account is closed straight away: you can no longer log in, we remove you from promotional messages and from the newsletter, and you no longer receive notifications. After 30 days we delete your personal data or make it anonymous, except what the law requires us to keep, such as invoices and payments for 10 years (section 9). Statistics already sent to Google Analytics with your account identifier stay with Google until they expire (14 months at most).
- Otherwise (bottles in storage, an open request, money to receive, or an account of our staff or of a seller), your request reaches our staff, who will contact you within two working days to decide how to handle whatever is still open (for the bottles, sale or delivery); we then close the account in the same way.
13. Minors
Our services are for adults only: we sell alcoholic drinks and do not accept sign ups from anyone under 18. If we find that we have collected data from a minor, we delete it. If you think a minor has given us their data, please write to us.
14. Security
We apply technical and organisational measures appropriate to the risk (Article 32 GDPR), including: encrypted connections (HTTPS); passwords handled by Amazon Cognito, which stores them in a form that cannot be read; access to data limited to authorised staff, with strong authentication for internal tools; the database and servers of our API in the European Union; backups; access logging; automatic blocking of anomalous access (section 10). If a personal data breach puts you at risk, we notify the Italian Data Protection Authority and, if the risk is high, you as well (Articles 33 and 34 GDPR).
15. Cookies and similar technologies
Details of cookies, app SDKs and the measurement of emails and notifications, with names, providers, duration and how to give or withdraw consent, are in our Cookie policy.
16. Changes to this notice
We may update this notice when our services, providers or the law change. The date at the top shows the latest version. If the changes are significant, we will tell you beforehand by email or in the app; if a change requires your consent, we will ask for it.
Versions: 2.0, 2 October 2026 (full rewrite: app, providers, transfers, retention, cookies); 1.0, previous undated version.