Wisp — Privacy Policy
Effective date: 24 August 2026
This Privacy Policy explains how Poblado Labs Ltd (company number 16089775), registered office 13 Bolingbroke Grove, London SW11 6ER, United Kingdom, trading as "Wisp" ("Wisp", "we", "us", "our"), collects and uses your personal data when you use the Wisp app, our website, and related services (the "Service").
Wisp is a checkout-convenience service: we store the details you choose to save so that checkout with participating merchants is fast and easy. We are the controller of the personal data described in this Policy. We take your privacy seriously — a key part of how Wisp is built is not holding sensitive data we don't need to.
If you have any questions, contact us at info@pobladolabs.co.uk.
1. A note on your card details
Wisp does not store your full card number. When you save a card, the card details are tokenised by our specialist provider, VGS (Very Good Security). Wisp receives and stores only a token — a secure reference that stands in for the card — never the raw card number. This reduces risk and keeps your most sensitive data out of our systems.
Your actual payment is processed by the payment service provider (PSP) that the merchant has contracted with — not by Wisp. Wisp does not process, hold, or move your money.
2. The personal data we collect
Information you give us - Identity & contact details: name, email address, phone number. - Delivery/billing address(es) you choose to save. - Payment method reference: a token representing your card (via VGS) and non-sensitive details such as card type and last four digits — not the full card number. - Loyalty cards and favourites you add. - Cart and shared-cart contents you create or share. - Communications you send us (for example, support requests).
Information we collect automatically - Device & technical data: device type, operating system, app version, and identifiers. - Usage data: how you interact with the Service, such as features used and actions taken. - Approximate/general location derived from your IP address (not precise GPS unless you turn it on).
Information from others - From merchants you shop with and their PSPs (for example, confirmation that an order or payment succeeded). - From service providers such as VGS and our hosting and analytics providers.
We do not seek to collect special-category data (such as health or biometric data) and ask that you don't provide it.
3. How and why we use your data — and our lawful bases
Under UK data protection law (the UK GDPR and the Data Protection Act 2018) we must have a lawful basis to use your personal data. We use it to:
| What we do | Why | Lawful basis |
|---|---|---|
| Create and manage your account | To give you the Service | Contract |
| Store your details and autofill them at checkout | The core feature you asked for | Contract |
| Pass your saved details to a merchant / its PSP so you can check out | To complete your request | Contract |
| Enable cart-sharing, loyalty, and favourites | Features you use | Contract |
| Keep the Service secure and prevent fraud and abuse | To protect you and us | Legitimate interests; legal obligation |
| Fix problems, improve, and develop the Service | To run and improve Wisp | Legitimate interests |
| Respond to your support requests | To help you | Contract; legitimate interests |
| Send service messages (e.g. security or account notices) | To operate the Service | Contract; legitimate interests |
| Send marketing about Wisp (if you opt in) | To tell you about the Service | Consent |
| Comply with legal, tax, and regulatory duties | Because we must | Legal obligation |
Where we rely on legitimate interests, we've weighed them against your rights. Where we rely on consent (for example, optional marketing), you can withdraw it at any time.
4. Who we share your data with
We share personal data only as needed to run the Service:
- Merchants you choose to shop with — we pass the saved details needed to complete your order.
- The merchant's PSP — to process the payment (Wisp itself does not process payments).
- VGS (Very Good Security) — our card-tokenisation provider.
- Our service providers — for example, cloud hosting, IT security, customer support, and analytics tools that act on our instructions under contract.
- People you choose — for example, anyone you share a cart with.
- Authorities and advisers — where we're legally required to, or to establish, exercise, or defend legal claims.
- A successor — if our business is reorganised, sold, or transferred, subject to this Policy.
We do not sell your personal data.
5. International transfers
We're based in the UK. Some of our service providers may process data outside the UK. Where they do, we make sure appropriate safeguards are in place — such as UK "adequacy" regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — so your data stays protected. You can ask us for more detail using the contact below.
6. How we keep your data secure
We use technical and organisational measures to protect your data, including:
- Tokenisation of card data via VGS, so full card numbers are never stored on Wisp's systems;
- encryption of data in transit and at rest where appropriate;
- access controls that limit who can see personal data; and
- monitoring and safeguards against unauthorised access.
No system can be guaranteed 100% secure, but we work hard to protect your data and to keep our security up to date. If a data breach occurs that is likely to be a high risk to you, we'll tell you and the relevant regulator as the law requires.
7. How long we keep your data
We keep your personal data for as long as you have a Wisp account and use the Service. When you close your account, we delete or anonymise your data within a reasonable period, except where we need to keep some of it to meet a legal obligation (for example, tax or fraud-prevention records) or to establish, exercise, or defend legal claims. Card tokens are deleted with your saved cards or when your account is closed.
8. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- ask us to correct inaccurate or incomplete data;
- ask us to delete your data ("right to erasure");
- restrict or object to certain processing;
- ask for a copy of certain data in a portable format (data portability);
- withdraw consent at any time where we rely on it (for example, marketing); and
- complain to a data protection authority.
To exercise any of these, email info@pobladolabs.co.uk. We'll respond within the time the law allows (usually one month). Using these rights is free in most cases.
If you're unhappy with how we've handled your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We'd appreciate the chance to help first.
9. Children
The Service is for people aged 13 and over. If you are under 18, you must have a parent or guardian's permission to use it. We do not knowingly collect data from children under 13. If you believe a child under 13 has given us personal data, contact us at info@pobladolabs.co.uk and we'll delete it.
10. Cookies and similar technologies
Our website and app may use cookies and similar technologies (such as SDKs and device identifiers) to make the Service work, remember your preferences, keep it secure, and understand usage. Where required, we'll ask for your consent to non-essential cookies and you can manage your choices in your browser or device settings.
11. Automated decisions
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. We may use automated tools to help detect and prevent fraud and abuse; if that ever materially affects you, you can ask us to review it.
12. Google Play data disclosures
If you install Wisp from Google Play, the app's Data safety section on its store listing summarises the data the app collects and shares, consistent with this Policy: identity and contact details, delivery address, order/cart and loyalty information, a card token (not the full card number), and device/usage data — used to provide and secure the Service and shared with merchants, their PSPs, VGS, and our service providers as described above.
13. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we'll give you reasonable notice (for example, in the app or by email) and update the "Effective date" above. Please check back so you stay informed.
14. Contact us
Poblado Labs Ltd (trading as Wisp) 13 Bolingbroke Grove, London SW11 6ER, United Kingdom Email: info@pobladolabs.co.uk
This Privacy Policy was last updated on 24 August 2026.