Wishlish Studio Policy

This Privacy Policy describes how Wishlist Studio ("the App", "we", "us", or "our") collects, uses, and discloses personal information when you install or use the App in connection with your Shopify-supported store, or when store visitors interact with wishlist functionality.

1. Information We Collect

When you install and use Wishlist Studio, we collect both merchant information and data from store visitors to provide seamless wishlist functionality.

A. Information Collected from Merchants

When you install the App, we automatically access certain information from your Shopify account via Shopify’s APIs, including:

  • Store Details: Store name, store URL (.myshopify.com), primary email address, store owner name, currency, and primary language.

  • App Configuration: Wishlist settings, custom styling preferences, email template preferences, and integration settings.

B. Information Collected from Store Customers / Visitors

When customers interact with Wishlist Studio on your storefront (e.g., adding products to a wishlist, saving items, or sharing lists), we collect:

  • Wishlist Activity: Selected product IDs, variant IDs, date/time items were added or removed, and custom list names (if enabled).

  • Customer Identifiers:

    • For logged-in users: Shopify Customer ID, email address, and name.

    • For guest users: An anonymous browser token or cookie ID used to persist wishlist items across sessions.

  • Technical Data: IP address, browser type, device type, and referring URL (used for diagnostic and security purposes).

2. How We Use Your Information

We use the collected information strictly to deliver, maintain, and improve Wishlist Studio:

  • Core App Functionality: Enabling visitors to save, view, manage, and share product wishlists across sessions.

  • Merchant Dashboard & Analytics: Providing store owners with aggregate insights on popular wishlist items, customer engagement, and conversion metrics.

  • Automations & Reminders: Sending low-stock, price-drop, or saved-item reminder notifications (if configured by the merchant).

  • Support & Maintenance: Troubleshooting technical issues, responding to support inquiries, and maintaining system security.

3. Data Sharing & Third Parties

We do not sell, rent, or trade personal data to third parties for marketing purposes. We share data only with trusted service providers essential to app operation, including:

  • Hosting & Infrastructure Providers: Secure cloud hosting services (e.g., AWS, DigitalOcean, Google Cloud, or Vercel) to store database records.

  • Email Service Providers: Service providers (e.g., SendGrid, Postmark) strictly to dispatch wishlist-related notifications on your behalf.

  • Legal Requirements: If required by applicable law, court order, or governmental regulation.

4. Shopify Mandatory Webhooks & Data Rights (GDPR / CCPA)

Wishlist Studio fully supports Shopify's mandatory GDPR and data privacy webhooks:

  1. Customer Data Request (customers/data_request): Upon receiving a request from Shopify, we aggregate all personal data associated with the requested customer ID and deliver it to the merchant.

  2. Customer Redact (customers/redact): Upon receiving a request from Shopify, we permanently delete all personal data and saved wishlist items tied to the specified customer ID within 30 days.

  3. Shop Redact (shop/redact): 48 hours after you uninstall Wishlist Studio, Shopify triggers a shop redaction request, and we permanently remove all store configuration and associated customer wishlist data from our primary databases within 30 days.

Customer Rights

If you are a store visitor seeking to access, correct, or delete personal data collected via Wishlist Studio, please contact the merchant (store owner) directly, as they are the Data Controller. We assist merchants in fulfilling these requests.

5. Data Security & Retention

  • Security: We employ industry-standard encryption protocols (HTTPS/SSL in transit, encrypted storage at rest) and strict access controls to safeguard your data.

  • Retention: We retain merchant and customer data only for as long as the App remains installed on your store, or as required by law. Once uninstalled, data is purged in accordance with Shopify’s shop redaction guidelines.

6. Cookies & Local Storage

Wishlist Studio utilizes browser cookies or local storage (localStorage) on your storefront to remember guest users' wishlist contents without requiring immediate login. These cookies contain non-personally identifiable session tokens.

7. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or operational, legal, or regulatory requirements. Any updates will be posted on this page with an updated "Last Updated" date.

8. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at: