Do Not Wish LLC ("Do Not Wish," "we," "our," or "us") is the data controller responsible for personal information collected through our website, mobile applications, and marketplace platform (collectively, the "Services"). Our participating brands, boutiques, and sellers are referred to as "Partners."
This Privacy Policy explains how we collect, use, retain, disclose, transfer, and protect personal information in connection with the Services. It also describes the rights you have over your information and how to exercise them.
The Services are not directed to individuals under 13 years of age, or under 16 in jurisdictions with a higher minimum age. We do not knowingly collect personal information from children without verifiable parental consent.
When you create an account, make a purchase, list an item on the marketplace, or contact us, you may provide:
When you interact with the Services, we and our technology partners automatically collect:
We may receive information about you from:
Where businesses, brands, boutiques, suppliers, or marketplace participants engage with the Services as Partners, we may collect business registration details, operational contacts, inventory submissions, fulfillment information, payout and billing details, account credentials, communications, and marketplace performance information.
We use personal information primarily to operate, maintain, and improve the marketplace and related Services. This includes facilitating transactions, supporting order fulfillment and returns, coordinating Partner operations and inventory redistribution, managing accounts, providing customer support, maintaining marketplace integrity, and supporting platform functionality.
We may also use operational and marketplace data to support inventory positioning, marketplace performance, fraud monitoring, and platform optimization.
We use behavioral and transactional data to surface relevant inventory, power recommendation systems, and improve marketplace experiences. We may also use third-party analytics and demographic insights to improve platform performance, inventory discovery, and user engagement.
We may use automated systems, machine learning, and personalization technologies to support marketplace experiences, product recommendations, fraud prevention, and platform functionality. Where required by law, we will provide additional notice and the opportunity to object.
We use personal information to verify identities, detect and prevent fraud, and protect the safety of users, Partners, and the marketplace.
Where you have consented or where applicable law permits, we send promotional communications about products, services, and marketplace activity. You may opt out at any time through your account preferences or the unsubscribe mechanism in any marketing message.
We use personal information to comply with applicable laws, respond to legal process, enforce our agreements, and retain records as required.
We process personal information on the basis of: (a) contractual necessity, to provide the Services you have requested; (b) legal obligation, where required by applicable law; (c) legitimate interests, to operate and improve the marketplace, prevent fraud, and communicate relevant information, balanced against your privacy rights; and (d) consent, where specifically required and revocable at any time.
Our primary legitimate interests include: operating and securing the marketplace platform; detecting and preventing fraud and abuse; improving platform performance and user experience; and sending relevant communications to existing users. A summary of our Legitimate Interests Assessment (LIA) is available on request at privacy@donotwish.com.
We do not sell your personal information for monetary compensation. We share information only as described below.
When you transact through the marketplace, we share information with the applicable Partner as necessary to support that transaction, including fulfillment, delivery, returns, refunds, customer support, fraud prevention, tax, and legal compliance. This may include your name, delivery address, contact details, and order details. Partners are responsible for their own privacy practices with respect to information they independently process.
Partners are independently responsible for the information they collect, process, or retain outside the Services or beyond the scope of transaction fulfillment and marketplace operations. We require all Partners to agree to data handling standards as a condition of participation; however, we encourage you to review the privacy policies of Partners you transact with directly.
We engage service providers to support marketplace operations, such as payment processing, logistics and delivery, fraud prevention, customer service infrastructure, cloud hosting, marketing technology, and analytics. These providers access personal information only as necessary to perform their contracted functions.
With your consent or where otherwise permitted, we may share limited identifiers with advertising and social media platforms to deliver relevant advertising on our behalf. Text messaging opt-in data and mobile information will not be shared with third parties for marketing purposes.
We may disclose personal information to law enforcement, regulators, or courts when required by law or legal process, or to protect the rights, property, or safety of Do Not Wish, our users, or others. Where permitted, we will notify you of such requests.
In connection with a merger, acquisition, reorganization, or asset sale, personal information may be transferred as part of that transaction. We will provide notice as required by applicable law.
We may share aggregated, anonymized data that cannot identify individual users with Partners, investors, and service providers to support marketplace research and operational planning.
We use cookies and similar technologies to operate the Services, remember your preferences, measure performance, and support personalized experiences.
The table below lists the non-essential cookies and similar technologies we deploy. Strictly necessary cookies, required for authentication, session management, and fraud prevention, cannot be disabled and are not listed here. This inventory is reviewed and updated periodically; the current version reflects our cookie stack as of the date of this Policy.
| Cookie name | Provider | Category | Purpose | Retention |
|---|---|---|---|---|
| _ga | Performance | Google Analytics — distinguishes users and tracks sessions for platform analytics. | 2 years | |
| _ga_[ID] | Performance | Google Analytics 4 — persists session state for GA4 measurement. | 2 years | |
| _fbp | Meta | Targeting | Meta Pixel — identifies browsers for ad conversion tracking and retargeting. | 90 days |
| ttclid | TikTok | Targeting | TikTok Pixel — tracks ad clicks and conversions from TikTok campaigns. | Session / 13 months |
| dnw_locale | Do Not Wish | Functional | Stores language and regional preferences to deliver a consistent browsing experience. | 1 year |
| dnw_cookie_consent | Do Not Wish | Functional | Records your cookie consent choices to avoid re-prompting on return visits. | 6 months |
We may use advertising and analytics technologies, including tools provided by Meta, TikTok, and similar platforms, to evaluate campaign performance, understand audience engagement, and support relevant advertising experiences.
You may accept or decline non-essential cookies through our cookie preference banner or through your browser settings. To opt out of interest-based advertising, visit youronlinechoices.eu or aboutads.info/choices. Do Not Wish does not currently respond to browser Do Not Track (DNT) signals; however, we do honor Global Privacy Control (GPC) signals as described in the US State Privacy Rights Addendum. Disabling certain cookies may affect the functionality of the Services.
Do Not Wish operates globally. Your personal information may be transferred to and processed in jurisdictions outside your country of residence, where data protection laws may differ from those in your jurisdiction. Where such transfers occur, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, adequacy decisions, or contractual necessity for transaction fulfillment.
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, satisfy legal and regulatory requirements, and support any disputes or enforcement actions.
As a general guide: account data is retained while your account is active and for a reasonable period thereafter; transaction, billing, and operational records may be retained for up to ten years where required by applicable tax, accounting, fraud prevention, or legal obligations; marketing data is retained for up to two years from your last interaction or until you withdraw consent; and application data such as job submissions is retained for up to six months.
When data is no longer required, it is permanently deleted or irreversibly anonymized.
Subject to applicable law, you have the following rights with respect to your personal information:
Residents of California, Virginia, and Texas have additional rights under applicable state law, including the right to opt out of the sale or sharing of personal information. See the US State Privacy Rights Addendum below.
To submit a rights request, contact us at privacy@donotwish.com. We respond within the timeframes required under applicable law. Identity verification may be required before we process your request.
We apply industry-standard technical and organizational safeguards to protect personal information, including encryption in transit and at rest, access controls, tokenization of payment credentials, regular security monitoring, and periodic penetration testing. Our infrastructure and security controls are designed and maintained in alignment with SOC 2 Type II principles; documentation of our security practices is available to enterprise Partners on request under NDA.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach and will inform affected individuals without undue delay where required by law. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
The Services are not intended for individuals under 13, or under 16 in jurisdictions with a higher minimum age. Jurisdictions with a higher age threshold include EU and EEA member states under the GDPR (where member states may set the threshold between 13 and 16), the United Kingdom under the UK GDPR and Age Appropriate Design Code (13, with heightened protections up to 18), and US states including Texas and Florida that have enacted children's online safety laws establishing heightened protections for minors up to 18.
In the United States, our practices are designed to comply with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children. If we become aware that a child has provided information without appropriate consent, we will promptly delete it. Contact us at privacy@donotwish.com if you have concerns.
Do Not Wish LLC
New York, New York
privacy@donotwish.com
If your concern is not resolved to your satisfaction, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.
EU and UK residents with data protection enquiries, including requests relating to Article 27 GDPR and UK GDPR, may contact us at privacy@donotwish.com.
Data protection enquiries may be submitted to privacy@donotwish.com.
We may update this Policy periodically to reflect changes in our practices, legal requirements, or the evolution of the marketplace. Material changes will be communicated by email or through a notice on the Services. The date at the top of this document reflects the most current version.
As the marketplace evolves, certain features, services, technologies, or operational processes described in this Policy may change, expand, or be replaced.
Applicable to residents of California, Virginia, and Texas.
This Addendum supplements the Privacy Policy above and applies to residents of California, Virginia, and Texas, in compliance with the CCPA/CPRA, VCDPA, and TDPSA. Capitalized terms carry the meanings defined in those laws.
Over the preceding 12 months, we have collected:
We do not sell biometric personal information or use sensitive personal information beyond the purposes described in this Policy.
Certain advertising technologies we use may constitute a sale or sharing of personal information under State Privacy Laws. You may opt out via the Do Not Sell or Share My Personal Information link in our website footer, or by broadcasting a Global Privacy Control (GPC) signal from your browser. Opt-outs are device and browser specific.
We do not use automated decision-making in ways that produce legal or similarly significant effects on users. Where we introduce such systems in the future, we will provide notice and, where required, an opportunity to opt out.
Exercising any of your privacy rights will not result in denial of goods or services, different pricing, or a reduced level of experience.
Submit rights requests by contacting privacy@donotwish.com. We respond in compliance with applicable State Privacy Law timelines. Denied requests may be appealed by contacting us directly.
You may designate an authorized agent to submit requests on your behalf. To verify an agent-submitted request, we require: (a) written and signed permission from you authorizing the agent to act on your behalf, or a valid power of attorney; and (b) independent verification of your identity directly with you, unless a power of attorney has been provided. We may deny a request from an agent who cannot satisfy these requirements. Agent requests may be submitted to privacy@donotwish.com.
California residents who share business contact details with Do Not Wish in a professional context retain the same privacy rights described above. This processing is based on our legitimate interest in maintaining professional relationships.