Privacy Policy

Amplify Wishlist App

Effective Date: September 15, 2025

Last Updated: September 15, 2025

1 Introduction

Amplify Wishlist ("we," "our," or "the App") is committed to protecting the privacy and security of personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Shopify application.

By installing and using the Amplify Wishlist app, you agree to the collection and use of information in accordance with this policy.

2 Information We Collect

2.1 Store Information

When a merchant installs our app, we collect:

  • Store domain and Shopify store ID
  • Store owner email address and name
  • Store locale and settings
  • Access tokens for API communication

2.2 Customer Information

For customers using the wishlist functionality, we collect:

  • Customer ID and email address (when logged in)
  • Session identifiers (for guest users)
  • IP address and user agent (for consent tracking)
  • Wishlist items including:
    • Product information (ID, title, handle, image, price)
    • Variant information (ID, title)
    • Product metadata (vendor, type, tags, collections)
    • Customer notes and priority settings
    • Quantity preferences

2.3 Usage Information

We automatically collect:

  • Timestamps of wishlist creation and updates
  • Product interaction data (views, additions, removals)
  • QR code scan metrics (if QR codes are used)

3 How We Use Information

3.1 Provide Core Services

  • Enable wishlist functionality for customers
  • Synchronize wishlist items across sessions
  • Display product information accurately
  • Process wishlist sharing features

3.2 Improve Services

  • Analyze usage patterns to enhance features
  • Debug issues and improve performance
  • Generate analytics for merchants

3.3 Communications

  • Send email notifications about wishlist items (with consent)
  • Notify customers about price changes or product availability
  • Provide customer support

4 Information Sharing and Disclosure

We do not sell, trade, or rent personal information. We may share information:

4.1 With Merchants

  • Wishlist analytics and customer engagement data
  • Aggregated reports about product popularity

4.2 Service Providers

  • Cloud hosting providers (for data storage)
  • Email service providers (for notifications)
  • Analytics services (in aggregated form)

4.3 Legal Requirements

  • When required by law or legal process
  • To protect rights, privacy, safety, or property
  • To enforce our terms and conditions

5 Data Storage and Security

5.1 Storage

  • Data is stored using PostgreSQL databases
  • We use industry-standard encryption for data at rest and in transit
  • Data is stored in secure cloud infrastructure

5.2 Security Measures

  • SSL/TLS encryption for all data transmissions
  • Regular security audits and updates
  • Access controls and authentication mechanisms
  • Secure API tokens and session management

5.3 Data Retention

  • Customer wishlist data: Retained while account is active
  • Deleted customer data: Removed within 30 days of deletion request
  • Store data: Retained until app uninstallation

6 Customer Rights (GDPR Compliance)

Customers have the right to:

6.1 Access

Request a copy of personal information we hold

6.2 Rectification

Request correction of inaccurate information

6.3 Erasure

Request deletion of personal information

6.4 Portability

Receive data in a structured, machine-readable format

6.5 Objection

Object to processing of personal information

6.6 Consent Withdrawal

Withdraw consent for marketing communications

To exercise these rights, customers can contact us at the email provided below.

7 GDPR and CCPA Compliance

7.1 Legal Basis for Processing

  • Consent: For marketing communications
  • Legitimate interests: For service provision and improvement
  • Contract performance: To provide wishlist services

7.2 International Transfers

  • Data may be transferred to countries outside the EU/EEA
  • We ensure appropriate safeguards are in place

7.3 California Privacy Rights

  • California residents have additional rights under CCPA
  • Right to know about personal information collected
  • Right to delete personal information
  • Right to opt-out of sale (we do not sell personal information)
  • Right to non-discrimination

8 Cookies and Tracking

8.1 Session Management

  • We use session cookies to maintain wishlist state
  • Essential cookies for app functionality

8.2 Analytics

  • We may use analytics tools to understand usage patterns
  • Aggregated and anonymized data only

9 Children's Privacy

Our services are not directed to individuals under 16. We do not knowingly collect personal information from children under 16. If we become aware of such collection, we will delete the information immediately.

10 Third-Party Services

10.1 Shopify Integration

  • We integrate with Shopify's APIs and services
  • Shopify's privacy policy applies to their services

10.2 Payment Processing

  • We do not directly process payments
  • All transactions occur through Shopify's checkout

11 Data Breach Notification

In the event of a data breach that may affect personal information:

  • We will notify affected merchants within 72 hours
  • We will cooperate with merchants to notify customers as required
  • We will take immediate steps to mitigate harm

12 Changes to Privacy Policy

We may update this Privacy Policy periodically. Changes will be posted with an updated "Last Updated" date. Continued use of the app after changes constitutes acceptance of the updated policy.

13 Contact Information

For privacy-related questions or to exercise your rights, contact us at:

Email: [email protected]

For Shopify merchants: You can also contact us through the Shopify App Store support system.

14 Data Protection Officer

[email protected]

15 Dispute Resolution

Any disputes relating to this Privacy Policy will be resolved through:

  1. Good faith negotiations
  2. Mediation if necessary
  3. Binding arbitration as a last resort

Acknowledgment

By using the Amplify Wishlist app, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.