Version 1.0 — Last updated: 10 May 2026
1. Data Controller
Company name: I Speak Web di Davide Mancuso
Registered address: Via Giuseppe Di Vittorio, 21A — 53019 Castelnuovo Berardenga (SI), Italy
VAT number: IT02547920849
Tax code: MNCDVD83L27Z103Z
Privacy email: contact@spesary.com
No Data Protection Officer (DPO) has been appointed, as the processing does not fall within the cases of mandatory appointment under Article 37 GDPR.
2. Personal data processed
2.1 Account and profile data
Username, email address, password (stored as a secure hash, never in plain text), sign-in provider (Apple or Google), and optional profile data (name). When signing in via Apple Sign-In, the email address may be an anonymised relay address provided by Apple.
2.2 Country/Region
The Country field is required for the profile to function. It may be provided directly by the user or auto-filled using technical signals (device locale, HTTP headers). Auto-filling is approximate; the user may change it at any time in their profile settings.
2.3 Service usage data
Data relating to shopping lists, items, notes, sections, stores, loyalty cards, invitations, shared lists and other App features.
2.4 Barcode scanning data
When you use the camera to scan barcodes, the captured frame is processed locally on your device to recognise the code. No image is transmitted to or stored on our servers.
2.5 List sharing data
When you invite another user to a list, we process the data needed to identify the recipient (e.g. email address or user ID) in order to manage the invitation. You are responsible for sharing lists only with people who have authorised you to do so.
2.6 Technical and security data
Technical logs (IP address, user agent, timestamps, authentication events, errors, last access) collected for security and abuse prevention purposes.
2.7 Push notifications
If enabled by the user: push token, platform (iOS/Android), language and technical metadata required for token registration, delivery and removal.
2.8 Subscription and in-app purchase data
When you purchase a subscription, Apple or Google send us a receipt (encrypted token) that our backend validates directly with Apple’s or Google’s servers to confirm the validity of the purchase. We store the metadata required to manage the subscription: store platform, purchase date, expiry and renewal date. No payment data (credit card, bank account, etc.) passes through or is stored on our servers.
2.9 Legal and versioning data
Versions of accepted legal documents (terms_version, privacy_version) and associated timestamps, retained for compliance tracking and proof of contractual acceptance.
2.10 Account lifecycle
Account status (active/deactivated), deactivation date and management of the technical reactivation window (30 days). After this window, data is deleted or anonymised as described in Section 8.
3. Purposes and legal bases
| Purpose | GDPR legal basis |
|---|---|
| Service delivery and account management | Art. 6(1)(b) — performance of a contract |
| Security, abuse prevention, operational continuity | Art. 6(1)(f) — legitimate interest |
| Subscription and in-app purchase management | Art. 6(1)(b) — performance of a contract |
| Functional push notifications | Art. 6(1)(b) — performance of a contract |
| Promotional notifications (if enabled by the user) | Art. 6(1)(a) — consent |
| Legal and fiscal obligations | Art. 6(1)(c) — legal obligation |
| Tracking acceptance of legal documents | Art. 6(1)(f) — legitimate interest (contractual proof) |
4. Nature of data provision
Providing the data required for registration, authentication, security and use of the Service is mandatory: without it, we cannot deliver the Services. Extended profile data (e.g. full name) is optional.
5. Processing methods
Data is processed primarily using electronic tools, with appropriate technical and organisational measures in place: TLS encryption in transit, secure password hashing, access controls, security logging, privacy by design and data minimisation principles.
6. Recipients of processing
Data is processed directly by the Data Controller. For specific features, some data passes through the following third parties, who act as independent data controllers:
Apple Inc. and Google LLC — manage in-app purchases, authentication (Apple Sign-In / Google Sign-In) and push notification services. Purchase receipts are validated directly between our backend and Apple’s or Google’s servers, without intermediaries. For information on their data processing, please refer to their respective privacy policies.
Transactional emails are sent via an SMTP server managed directly by the Data Controller. If additional technical providers are involved in the future, this policy will be updated with reasonable notice.
7. Transfers outside the EEA
Apple and Google process data in countries outside the European Economic Area (EEA), in particular the United States. Such transfers take place within the framework of the contractual guarantees provided by each supplier (Standard Contractual Clauses adopted by the European Commission) and, for Apple and Google, within the EU–US Data Privacy Framework.
8. Data retention
Data is retained for the time strictly necessary for the stated purposes and to comply with legal obligations.
- Active accounts: for the duration of the contractual relationship
- Deactivated accounts: 30-day reactivation window, after which data is deleted or anonymised
- Technical and security logs: maximum 12 months, unless required for legal protection
- Subscription data: retained for fiscal and accounting obligations (generally 10 years)
- Aggregated and anonymised data: may be retained indefinitely for statistical purposes
9. User rights
You may exercise the rights provided under Articles 15–22 GDPR: access to your data, rectification, erasure (“right to be forgotten”), restriction of processing, data portability (where applicable) and objection to processing based on legitimate interest.
To exercise your rights, write to: contact@spesary.com. We will respond within 30 days.
You always have the right to lodge a complaint with the Italian Data Protection Authority (https://www.garanteprivacy.it) or the supervisory authority competent in your EU country of residence.
10. Security
We implement appropriate technical and organisational measures (encryption in transit, password hashing, access controls, security logging) to protect your data against unauthorised access, loss or disclosure. No system can guarantee zero risk.
In the event of a personal data breach that may pose a risk to your rights and freedoms, we will notify you in the manner and within the timeframes required by Article 34 GDPR.
11. Minors
The Service is not intended for persons under the age of 14. We do not knowingly collect data from children under 14. If you believe we have received data relating to a minor, please contact us at contact@spesary.com for immediate deletion.
12. Changes to this policy
This policy may be updated to reflect legislative, technical or organisational changes. Updated versions will be made available in the App with the update date clearly indicated. For material changes, we will use in-app re-acceptance mechanisms.
13. References
Italian Data Protection Authority (Garante Privacy): https://www.garanteprivacy.it
EU ODR platform (online dispute resolution): https://ec.europa.eu/consumers/odr