Privacy Policy
Effective 18 September 2026
This policy describes how SRH Web Agency (“we”, “us”, “Wishlist Plus”) handles information when merchants install and use the Shopify app Wishlist Plus (wishlist icons, buttons, wishlist page, and merchant analytics). It is written for Shopify’s App Store listing and for merchants who need to know what the app accesses on their shop.
Wishlist Plus is a merchant tool. Shoppers on a merchant’s storefront can save products to a wishlist; they do not create a Wishlist Plus account.
1. Who is responsible
SRH Web Agency operates Wishlist Plus and the production app at https://wishlistplus.srhwebagency.com. Shopify remains responsible for the merchant’s store, Admin, and Checkout. Merchants remain responsible for their own storefront privacy notices to shoppers.
2. Shopify permissions we request
Wishlist Plus uses the Shopify Admin GraphQL API only (not the REST Admin API). After install, the app requests these access scopes:
read_products— product and variant data used for top wishlisted products and dashboard enrichment.read_themes— detect whether the wishlist theme embed is active and help merchants finish setup.read_inventory— availability context for wishlist inventory checks on the storefront.
Current scopes string: read_products,read_themes,read_inventory. Wishlist Plus does not request read_customers, read_orders, or similar customer-profile scopes. We do not read customer names, emails, addresses, payment methods, or order history from Shopify.
3. Merchant data we store
All application data is scoped to the installing shop (multi-tenant). We store:
- Shop identity and sessions. Shop domain, install time, plan label, and OAuth session records (offline access token and, for online sessions, staff first name, last name, email, and user id as provided by Shopify’s session storage).
- Wishlist settings. Icon style, colors, button copy, placement, wishlist page layout, translations, and related configuration. Settings are also written to a shop metafield so the Online Store theme can read them.
- Anonymized wishlist activity. Event type, product/variant ids, optional value in cents, shop domain, and timestamp — used for Home metrics, Top 10 Products, and Analytics.
- Support drafts. If a merchant uses Contact in the admin, the message is emailed to our support inbox. We do not use Contact content for advertising.
4. Shopper (customer) data
Wishlist Plus does not create shopper accounts and does not store Shopify customer profiles. Shopper wishlists are stored in the shopper’s browser (localStorage) by the Theme App Extension by default and are not stored as customer personal information on our servers.
Storefront widgets may send limited usage events (product ids, event type, and an optional price in cents) so merchants can see wishlist activity. Events are sent only when Shopify’s Customer Privacy API allows analytics processing. If consent is missing or denied, the wishlist still works in the browser and no activity event is sent. Those events do not include customer names or emails. Merchants should mention wishlist widgets in their own privacy policy if required by their region.
5. How we use this data
- Provide wishlist icons, buttons, and the wishlist page on the theme.
- Show merchants settings, analytics, and top wishlisted products.
- Respond to uninstall and mandatory compliance webhooks.
- Deliver merchant support messages when Contact is used.
We do not sell personal data. We do not use shopper data for advertising networks. We do not train third-party AI models on merchant catalog or wishlist events.
6. Where data is stored
- Application database — sessions, shop tenant rows, wishlist settings, anonymized events, and compliance audit rows. Development and production use Postgres via
DATABASE_URL(including Hostinger when Postgres runs on the same server). - Shopify — OAuth, shop metafields for wishlist settings, and the merchant’s own product data remain on Shopify.
- Email — if the merchant submits Contact, the message is sent to our support inbox over SMTP.
Access tokens are stored in the shop’s session row and are used only to call Shopify Admin GraphQL for that shop.
7. GDPR and Shopify mandatory webhooks
Wishlist Plus implements Shopify’s mandatory compliance webhooks. Shopify authenticates each request before we process it.
customers/data_request— we record an audit row and respond that we do not hold customer personally identifiable information from the Customers API.customers/redact— we record an audit row. This handler must be extended if a later product feature stores customer PII.shop/redact— we delete sessions, shop tenant data, wishlist settings, related events/jobs for that shop, and return an error if purge fails so Shopify can retry. Compliance audit rows are kept.app/uninstalled— we purge that shop’s sessions and tenant data without waiting for shop redact.
Audit rows (ComplianceRequest) store shop domain, webhook request id, topic, status, and timestamp only — never the raw webhook body or customer payload fields.
8. Data retention
- While installed: sessions, settings, and analytics events are kept so the app works.
- After uninstall or shop redact: shop-scoped sessions, settings, and events are deleted as described above.
- Compliance audit logs may be retained after purge for App Store compliance evidence.
9. Cookies and similar technology
The embedded admin uses Shopify’s session cookies to keep the merchant logged in. The storefront Theme App Extension stores wishlist items in browser localStorage on the merchant’s storefront domain. It does not set a separate Wishlist Plus first-party cookie for shopper identity.
10. International transfers
The app process is intended to run on Hostinger (Node.js) with a Postgres database (often on the same host at localhost). Shopify remains the merchant’s store and Admin host. If a merchant or shopper is in the EEA, UK, or another region, data described above may be processed outside that region to provide the app. Shopify also processes data under the merchant’s Shopify agreement.
11. Your choices and requests
Merchants can:
- Uninstall Wishlist Plus, which starts deletion of shop-scoped data.
- Use Shopify Admin → Apps to review permissions, or Shopify’s customer data request / redaction tools (those trigger the webhooks above).
- Contact us using Wishlist Plus → Contact in the app, or email sohilhunani11@gmail.com.
Shoppers should contact the merchant first. The merchant can use Shopify’s customer privacy tools; we will receive the corresponding webhook.
12. Children
Wishlist Plus is a B2B Shopify app. We do not knowingly collect personal information from children.
13. Changes
We will update this page when our data practices or Shopify requirements change. The effective date at the top will change. The current version is always at this URL.
14. Contact
SRH Web Agency — Wishlist Plus
Email: sohilhunani11@gmail.com
Site: https://wishlistplus.srhwebagency.com
In-app: Wishlist Plus → Contact