Privacy Policy
Stashlist ("we", "our", or "us") provides a wishlist app for Shopify merchants. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
When a merchant installs Stashlist, we collect and store:
- Shop information: your Shopify store domain and access token, used to authenticate API requests.
- Customer wishlist data: the product and variant IDs that customers save to their wishlists, associated with their Shopify customer ID or an anonymous guest ID, together with the customer's email address, first and last name, and email marketing consent state (used to display wishlists in the merchant admin and to send wishlist events to integrations the merchant enables).
- Order data: when a wishlisted product is purchased, we record the conversion for analytics (requires optional orders/paid webhook).
- App configuration: settings the merchant configures inside the app (API keys for enabled integrations, display preferences, etc.).
We do not collect payment card details, passwords, or sensitive personal information beyond what is necessary to operate the wishlist service.
2. How We Use Data
- To save and retrieve each customer's wishlist across sessions and devices.
- To provide merchants with analytics on wishlisted products and conversion rates.
- To send wishlist events to marketing, analytics, and loyalty integrations the merchant enables, using the merchant's own API credentials.
- To operate and improve the Stashlist service.
3. Data Sharing
We do not sell, rent, or share personal data with third parties except:
- Merchant-enabled integrations: if the merchant enables an integration (Klaviyo, Omnisend, Attentive, Mailchimp, Maestra, Meta Pixel, GA4, Shopify Flow, Judge.me, Yotpo Reviews, Reviews.io, LoyaltyLion, Rivo, or Gorgias), wishlist events are sent to that provider using the merchant's own API key, at the merchant's direction.
- Infrastructure providers: we use Railway (application hosting and database), Cloudflare (website and content delivery), Resend (transactional email), and Upstash (job scheduling), which process data on our behalf under appropriate data processing agreements.
4. Data Retention and Deletion
When a merchant uninstalls Stashlist:
- Auth sessions are deleted immediately.
- All remaining merchant and customer data (wishlist items, analytics, settings) is permanently deleted within 48 hours, in accordance with Shopify's GDPR requirements.
Customers may request deletion of their wishlist data by contacting the merchant, who can action this via the Stashlist admin or by uninstalling the app.
5. GDPR and Privacy Rights
We comply with Shopify's mandatory GDPR webhook requirements:
- customers/data_request: we log data access requests.
- customers/redact: we delete all wishlist data for a specific customer on request.
- shop/redact: we permanently delete all shop data 48 hours after uninstall.
6. Cookies and Local Storage
Stashlist uses browser localStorage to store wishlist data for guest (non-logged-in) customers. No tracking cookies are set. On login, guest data is merged with the customer's server-side wishlist.
7. Security
All data is transmitted over HTTPS. Data and backups are encrypted at rest. Staff access to customer personal data is logged. We maintain a security incident response policy: affected merchants are notified without undue delay, and within 72 hours, of a confirmed personal data breach. We follow Shopify's security guidelines for app development, including Shopify's protected customer data requirements.
8. Contact
For privacy questions or data requests, contact us at support@stashlist.net.