Privacy Policy
Last updated: August 12, 2026This policy explains how Wyshlist ("Wyshlist," "we," "us," or "our"), a Shopify app provided by Wynkoop Consulting LLC, collects, uses, stores, and deletes data. It applies to merchants who install Wyshlist on a Shopify store ("you," "merchant") and to the merchant's customers who interact with wishlist features on the merchant's storefront ("shoppers").
Wyshlist acts as a data processor / service provider on behalf of the merchant for shopper data, and as a data controller for the merchant's own account and billing information. If you are a shopper with a question about a specific wishlist, please contact the store you shopped with — they control that relationship. If you are a merchant, contact us directly at support@wyshlist.app.
The short version
A shopper's wishlist is stored on their Shopify customer record — a metafield named wishlist.items (type list.product_reference) — not in Wyshlist's own database. Shopify remains the system of record for what a shopper has saved. Wyshlist's own database keeps only a working mirror of which products are currently saved, plus aggregate counts used for the merchant's analytics dashboard.
Concretely: when a shopper removes an item from their wishlist, the corresponding row in Wyshlist's database is deleted immediately. There is no historical event log of past adds and removes — Wyshlist cannot tell a merchant what a shopper saved and later removed, only what is saved right now.
Data we collect
Shopper data
| Data | Where it's stored | Retention |
|---|---|---|
| Which products are currently saved | Shopify customer metafield wishlist.items (list.product_reference) | Owned by Shopify; removed the moment the shopper removes the item |
| Wishlist entry: customer ID, product ID, variant ID, product title, date saved | Wyshlist's database (a working mirror of the metafield above) | Deleted the moment the item is removed. No historical log is kept. |
| Campaign recipient record: customer ID, email address, discount code, whether an email was sent | Wyshlist's database | Kept for campaign reporting; deleted on customer or shop data-deletion request |
| Campaign purchase record: customer ID, order ID, order name, purchased product IDs | Wyshlist's database | Same as above |
Merchant data
| Data | Where it's stored |
|---|---|
| Shop domain, OAuth access tokens, and — for staff logins — name, email, locale, and account-owner flag | Wyshlist's database; deleted when the app is uninstalled |
| Campaign configuration and merchant-authored email templates | Wyshlist's database |
| Total saves per shop (an aggregate count — no customer data) | Wyshlist's database |
| Support request: shop name/email/plan, contact name, contact email, message | Wyshlist's database |
| The merchant's own Klaviyo private API key — encrypted at rest with AES-256-GCM before it is stored | Wyshlist's database |
| Custom email sending domain and DKIM tokens (for merchants who set up their own sending domain) | Wyshlist's database |
| Audit log of data-subject requests received from Shopify, including the raw webhook payload | Wyshlist's database; survives shop deletion because it holds no wishlist data, only a record that a request was handled |
Why we collect it
- Customer ID — key the wishlist metafield and the database records that mirror it.
- Customer email — deliver campaign email that the merchant explicitly creates and launches.
- Order data — attribute a purchase back to the campaign that drove it, so the merchant can see whether a campaign converted.
- Product data — hydrate wishlist items for display (product title, image, price). This is not customer data.
- Merchant account data — operate the app, authenticate admin requests, and bill through Shopify's Billing API.
Subprocessors
Wyshlist uses the following subprocessors:
- Shopify — the commerce platform. Shopify provides customer, product, order, and discount data, and remains the system of record for the wishlist itself.
- Amazon Web Services (AWS) — application hosting and container registry (in the
us-west-2region), and Amazon SES for sending transactional and campaign email. - Klaviyo — only when a merchant chooses to connect their own Klaviyo account. This is merchant-initiated and entirely optional; if a merchant doesn't connect Klaviyo, no shopper data is shared with it. When connected, wishlist list membership, wishlist events, and profile properties are synced to the merchant's own Klaviyo account.
We do not use Shopify Messaging as a subprocessor — it is Shopify's own product, and any email sent through it is covered by the merchant's existing relationship with Shopify, not by Wyshlist.
Your rights and requests
Wyshlist implements Shopify's three mandatory compliance webhooks:
- Data request (
customers/data_request) — when a shopper asks a merchant what data is held about them, Shopify notifies Wyshlist. Wyshlist compiles that shopper's current wishlist entries and any campaign records held in its own database into a report and sends it to the merchant, who forwards it to the shopper. (The wishlist itself is not included in this report — it lives on the Shopify customer metafield and is part of Shopify's own data export.) Fulfilment of every request is logged for audit purposes. - Customer deletion (
customers/redact) — when a shopper's data must be deleted, Wyshlist deletes that shopper's wishlist entries and campaign records from its database. The shop's aggregate save count is not touched by a customer deletion, because it holds only an anonymous total and no customer-identifying data. - Shop deletion (
shop/redact) — when a merchant's store data must be deleted (typically some time after uninstalling), Wyshlist deletes all wishlist entries, campaign data, email templates, aggregate counts, and support requests associated with that shop.
Merchants can also reach us directly at support@wyshlist.app with a data request on behalf of one of their shoppers.
Cookies and tracking
Wyshlist uses session cookies only to operate the embedded admin application inside Shopify's admin. We do not use advertising cookies, and we do not run third-party tracking scripts on merchant storefronts.
Security
Data is encrypted in transit (TLS). Requests from the storefront and incoming webhooks are cryptographically verified (HMAC) before being processed. Klaviyo private API keys are encrypted at rest with AES-256-GCM before storage, in addition to disk-level encryption on our hosting provider.
International data transfers
Wyshlist's infrastructure is hosted in the United States (AWS us-west-2). If you or your shoppers are located outside the United States, your data will be transferred to and processed in the United States.
Children's data
Wyshlist is not directed at children, and we do not knowingly collect data from children. Wyshlist's data is entirely a function of a merchant's own storefront and its customer base.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of Wyshlist after a change becomes effective constitutes acceptance of the revised policy.
Contact us
Questions about this policy, or about the data we hold, can be sent to Wynkoop Consulting LLC at support@wyshlist.app. We aim to respond within five business days.
Merchants who need to action a shopper’s data request should do so through Shopify, which forwards the request to us automatically.
