Privacy Policy
Effective date: October 2, 2026
This Privacy Policy explains how 'WIXO App' collects, processes, stores, and protects personal data from visitors of wixo.app, users of our administration portal (dashboard.wixo.app), merchants using our service, and end users of client mobile apps, in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR).
Who controls your data (Controller vs. Processor)
The Data Controller for personal data collected through the wixo.app website, the merchant portal dashboard.wixo.app, and for Merchant business accounts is 'WIXO App', UIC: BG207772298, Shipka Blvd 23 D, Plovdiv, Republic of Bulgaria, contact email: info@wixo.app ('Controller', 'we', or 'Wixo').
Clarification of GDPR Roles: Regarding the end customers and shoppers who install and interact with the mobile app of a Merchant's store, the Merchant acts as the Data Controller. Wixo operates strictly as a Data Processor under Article 28 of the GDPR, providing technical application execution, notification delivery, and platform infrastructure.
What data we collect
1. Merchant Account & Dashboard Data: Full name, business email address, encrypted login password, direct phone number, IP address upon login, session authentication tokens, system audit logs, store URL, corporate billing information (company name, VAT/tax ID, registered legal address, authorized signatory).
2. Website Browsing Data: IP address, approximate geolocation, browser type and version, operating system, visited pages, duration of visits, referrer sources, and essential cookies.
3. Technical Mobile Application Data for End Users: Unique device push notification tokens (Apple Push Notification token / Firebase Cloud Messaging token), hardware specifications (device model, iOS/Android OS version, interface language), push permission state, and anonymized engagement identifiers for interactive modules (such as promotional wheel spins or scratch card plays).
Wixo DOES NOT collect, process, or store credit card numbers, CVV codes, or shopper checkout passwords. Financial transactions inside the app are processed directly by the payment gateways integrated into the Merchant's own store.
Why we collect it (Purposes of processing)
We process personal data strictly for legitimate and specified business purposes:
a) Generating and delivering a working 72-hour preview of the native mobile app for your brand;
b) Administering, executing, and fulfilling the technical integration and ongoing software subscription agreement;
c) Delivering technical, transactional, and promotional push notifications to app users who have explicitly opted in;
d) Issuing invoices, processing recurring payments, and fulfilling statutory accounting duties under Bulgarian tax legislation;
e) Providing customer support, resolving technical incidents, and responding to inquiries;
f) Ensuring network and system security, detecting malicious activity, and preventing fraud or abuse.
Our legal basis for processing (GDPR)
We process personal data in full compliance with Article 6 of the GDPR:
1. Performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR) — preparing your demo, providing the app platform, and delivering technical support;
2. Compliance with legal obligations (Art. 6(1)(c) GDPR) — fulfilling tax, corporate accounting, and record-keeping mandates under Bulgarian law;
3. Legitimate interests (Art. 6(1)(f) GDPR) — safeguarding infrastructure security, debugging system performance, and defending against legal claims;
4. Consent (Art. 6(1)(a) GDPR) — where required for marketing communications or when end users opt in to receive push notifications via native iOS/Android device prompts.
The free preview and contact forms
Information entered into our demo request and contact forms (name, work email, phone, store URL) is used exclusively to contact you, configure your preview app, and conduct a walkthrough demonstration.
We never sell, rent, or trade your contact information to external lead generation networks or third-party marketing brokers.
Cookies and analytics
The wixo.app website utilizes cookies — small text files stored on your device to ensure core site navigation, remember language preferences, and analyze aggregated traffic trends.
We deploy essential technical cookies required for site operation, alongside analytics tags (such as Google Tag Manager and Google Analytics) configured to evaluate high-level performance without personally identifying visitors.
On-Site Consent Management: Upon your first visit to the site, an interactive GDPR consent banner is presented, allowing you to accept all cookies, restrict them to strictly essential cookies only, or customize your preferences (analytics and marketing). You may adjust or withdraw your consent at any time using the 'Cookie settings' button available in the footer of every page.
You can also manage, restrict, or delete cookies at any time via your browser settings. Disabling essential cookies may impact certain site capabilities.
Who we share data with (Recipients and Processors)
We only share data with trusted technical partners under binding data processing and confidentiality agreements:
a) Tier-1 cloud hosting and managed server infrastructure providers located within the European Union;
b) Mobile push notification delivery networks: Apple Inc. (Apple Push Notification service) and Google LLC (Firebase Cloud Messaging);
c) Professional legal, audit, and accounting advisors in compliance with fiscal obligations;
d) Public regulatory, tax, or law enforcement authorities, solely upon verified legal mandate.
How long we keep it (Retention periods)
We retain personal data only for as long as necessary to satisfy the purposes for which it was gathered:
1. Demo requests and general inquiries: up to two (2) years following the conclusion of communication;
2. Invoicing, billing records, and executed contracts: ten (10) years in compliance with statutory Bulgarian accounting laws;
3. Mobile push notification tokens: until the end user uninstalls the application or the Merchant terminates the subscription;
4. Technical server logs: up to twelve (12) months for cybersecurity monitoring and incident auditing.
Transfers outside the EEA
Primary data storage and hosting infrastructure are maintained within the European Economic Area (EEA).
Where technical transmission through global networks (such as Apple APNs or Google FCM for push notification routing) involves transfer to the United States, such transfers are secured under the EU-U.S. Data Privacy Framework or European Commission-approved Standard Contractual Clauses (SCCs).
Your rights under GDPR
Under European data protection law, you possess enforceable rights regarding your personal data:
1. Right of access: to obtain confirmation of whether we process your data and receive a copy;
2. Right to rectification: to request correction of inaccurate or incomplete personal information;
3. Right to erasure ('Right to be forgotten'): to obtain deletion of your data when retention grounds no longer apply;
4. Right to restriction of processing: to limit processing under specific legal conditions;
5. Right to data portability: to receive your data in a structured, machine-readable format;
6. Right to object: to object at any time to processing based on legitimate interest;
7. Right to withdraw consent: to revoke previously given consent freely without penalty.
To exercise any of these rights, please email your written request to: info@wixo.app.
Changes to this policy
We may periodically revise this Privacy Policy to reflect technical platform enhancements or statutory updates.
Any modifications will be published on this page with an updated effective date. We encourage regular review of this policy.
How to contact us and supervisory authority
If you have inquiries or requests regarding personal data protection, please contact: 'WIXO App', Shipka Blvd 23 D, Plovdiv, Bulgaria. Email: info@wixo.app, Phone: +359 899 879 134.
Supervisory Authority in Bulgaria: If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP): Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria. Website: www.cpdp.bg, Email: kzld@cpdp.bg.





