LEGAL DOCUMENT

Privacy Policy

Version 1.0 — Last updated: 10 May 2026

1. Data Controller

Company name: I Speak Web di Davide Mancuso
Registered address: Via Giuseppe Di Vittorio, 21A — 53019 Castelnuovo Berardenga (SI), Italy
VAT number: IT02547920849
Tax code: MNCDVD83L27Z103Z
Privacy email: contact@spesary.com

No Data Protection Officer (DPO) has been appointed, as the processing does not fall within the cases of mandatory appointment under Article 37 GDPR.

2. Personal data processed

2.1 Account and profile data

Username, email address, password (stored as a secure hash, never in plain text), sign-in provider (Apple or Google), and optional profile data (name). When signing in via Apple Sign-In, the email address may be an anonymised relay address provided by Apple.

2.2 Country/Region

The Country field is required for the profile to function. It may be provided directly by the user or auto-filled using technical signals (device locale, HTTP headers). Auto-filling is approximate; the user may change it at any time in their profile settings.

2.3 Service usage data

Data relating to shopping lists, items, notes, sections, stores, loyalty cards, invitations, shared lists and other App features.

2.4 Barcode scanning data

When you use the camera to scan barcodes, the captured frame is processed locally on your device to recognise the code. No image is transmitted to or stored on our servers.

2.5 List sharing data

When you invite another user to a list, we process the data needed to identify the recipient (e.g. email address or user ID) in order to manage the invitation. You are responsible for sharing lists only with people who have authorised you to do so.

2.6 Technical and security data

Technical logs (IP address, user agent, timestamps, authentication events, errors, last access) collected for security and abuse prevention purposes.

2.7 Push notifications

If enabled by the user: push token, platform (iOS/Android), language and technical metadata required for token registration, delivery and removal.

2.8 Subscription and in-app purchase data

When you purchase a subscription, Apple or Google send us a receipt (encrypted token) that our backend validates directly with Apple’s or Google’s servers to confirm the validity of the purchase. We store the metadata required to manage the subscription: store platform, purchase date, expiry and renewal date. No payment data (credit card, bank account, etc.) passes through or is stored on our servers.

2.9 Legal and versioning data

Versions of accepted legal documents (terms_version, privacy_version) and associated timestamps, retained for compliance tracking and proof of contractual acceptance.

2.10 Account lifecycle

Account status (active/deactivated), deactivation date and management of the technical reactivation window (30 days). After this window, data is deleted or anonymised as described in Section 8.

3. Purposes and legal bases

PurposeGDPR legal basis
Service delivery and account managementArt. 6(1)(b) — performance of a contract
Security, abuse prevention, operational continuityArt. 6(1)(f) — legitimate interest
Subscription and in-app purchase managementArt. 6(1)(b) — performance of a contract
Functional push notificationsArt. 6(1)(b) — performance of a contract
Promotional notifications (if enabled by the user)Art. 6(1)(a) — consent
Legal and fiscal obligationsArt. 6(1)(c) — legal obligation
Tracking acceptance of legal documentsArt. 6(1)(f) — legitimate interest (contractual proof)

4. Nature of data provision

Providing the data required for registration, authentication, security and use of the Service is mandatory: without it, we cannot deliver the Services. Extended profile data (e.g. full name) is optional.

5. Processing methods

Data is processed primarily using electronic tools, with appropriate technical and organisational measures in place: TLS encryption in transit, secure password hashing, access controls, security logging, privacy by design and data minimisation principles.

6. Recipients of processing

Data is processed directly by the Data Controller. For specific features, some data passes through the following third parties, who act as independent data controllers:

Apple Inc. and Google LLC — manage in-app purchases, authentication (Apple Sign-In / Google Sign-In) and push notification services. Purchase receipts are validated directly between our backend and Apple’s or Google’s servers, without intermediaries. For information on their data processing, please refer to their respective privacy policies.

Transactional emails are sent via an SMTP server managed directly by the Data Controller. If additional technical providers are involved in the future, this policy will be updated with reasonable notice.

7. Transfers outside the EEA

Apple and Google process data in countries outside the European Economic Area (EEA), in particular the United States. Such transfers take place within the framework of the contractual guarantees provided by each supplier (Standard Contractual Clauses adopted by the European Commission) and, for Apple and Google, within the EU–US Data Privacy Framework.

8. Data retention

Data is retained for the time strictly necessary for the stated purposes and to comply with legal obligations.

  • Active accounts: for the duration of the contractual relationship
  • Deactivated accounts: 30-day reactivation window, after which data is deleted or anonymised
  • Technical and security logs: maximum 12 months, unless required for legal protection
  • Subscription data: retained for fiscal and accounting obligations (generally 10 years)
  • Aggregated and anonymised data: may be retained indefinitely for statistical purposes

9. User rights

You may exercise the rights provided under Articles 15–22 GDPR: access to your data, rectification, erasure (“right to be forgotten”), restriction of processing, data portability (where applicable) and objection to processing based on legitimate interest.

To exercise your rights, write to: contact@spesary.com. We will respond within 30 days.

You always have the right to lodge a complaint with the Italian Data Protection Authority (https://www.garanteprivacy.it) or the supervisory authority competent in your EU country of residence.

10. Security

We implement appropriate technical and organisational measures (encryption in transit, password hashing, access controls, security logging) to protect your data against unauthorised access, loss or disclosure. No system can guarantee zero risk.

In the event of a personal data breach that may pose a risk to your rights and freedoms, we will notify you in the manner and within the timeframes required by Article 34 GDPR.

11. Minors

The Service is not intended for persons under the age of 14. We do not knowingly collect data from children under 14. If you believe we have received data relating to a minor, please contact us at contact@spesary.com for immediate deletion.

12. Changes to this policy

This policy may be updated to reflect legislative, technical or organisational changes. Updated versions will be made available in the App with the update date clearly indicated. For material changes, we will use in-app re-acceptance mechanisms.

13. References

Italian Data Protection Authority (Garante Privacy): https://www.garanteprivacy.it
EU ODR platform (online dispute resolution): https://ec.europa.eu/consumers/odr