Privacy Policy

Stashlist ยท Last updated: July 2026

Stashlist ("we", "our", or "us") provides a wishlist app for Shopify merchants. This policy explains what data we collect, how we use it, and your rights.

1. Data We Collect

When a merchant installs Stashlist, we collect and store:

We do not collect payment card details, passwords, or sensitive personal information beyond what is necessary to operate the wishlist service.

2. How We Use Data

3. Data Sharing

We do not sell, rent, or share personal data with third parties except:

4. Data Retention and Deletion

When a merchant uninstalls Stashlist:

Customers may request deletion of their wishlist data by contacting the merchant, who can action this via the Stashlist admin or by uninstalling the app.

5. GDPR and Privacy Rights

We comply with Shopify's mandatory GDPR webhook requirements:

6. Cookies and Local Storage

Stashlist uses browser localStorage to store wishlist data for guest (non-logged-in) customers. No tracking cookies are set. On login, guest data is merged with the customer's server-side wishlist.

7. Security

All data is transmitted over HTTPS. Data and backups are encrypted at rest. Staff access to customer personal data is logged. We maintain a security incident response policy: affected merchants are notified without undue delay, and within 72 hours, of a confirmed personal data breach. We follow Shopify's security guidelines for app development, including Shopify's protected customer data requirements.

8. Contact

For privacy questions or data requests, contact us at [email protected].