Privacy Policy
Last updated: May 3, 2026
1. Information We Collect
When you install and use Magic Wishlist, we collect the following types of information:
- Store information: your Shopify store domain, store name, shop owner name, primary email address, plan, and timezone (provided by Shopify when you install the app.
- Product catalog data: product titles, variants, prices, images, and stock levels, accessed through Shopify's APIs so the app can render wishlist items and trigger price-drop and back-in-stock alerts.
- Wishlist data: the items each shopper has saved, including the variant (size, color), the time it was saved, and the wishlist event history used to fire recovery emails.
- Shopper identifiers: for logged-in shoppers, the Shopify customer ID; for guest shoppers, an email address and a hashed device identifier, used solely to attribute saves and send the recovery emails the merchant has enabled.
- App configuration: the colors, copy, branding, email templates, display mode, and rules you configure inside the app dashboard.
- Usage analytics: aggregate, non-personally-identifiable data about how app features are used, to help us fix bugs and improve the product.
2. How We Use Your Information
We use the information we collect exclusively to provide and improve the Magic Wishlist service:
- Saving items to wishlists and rendering wishlist UI on your storefront
- Sending the automated recovery emails you enable: abandonment reminders, price drop alerts, low stock warnings, and back in stock alerts
- Generating per-shopper discount codes used inside recovery emails
- Showing you analytics, top saved products, and revenue attribution inside the app dashboard
- Providing customer support when you contact us
- Improving app performance, fixing bugs, and shipping new features
We do not sell, rent, or trade your data or your shoppers' data to third parties. We do not use your data for advertising on other platforms.
3. Data Storage & Security
Your data is stored on secure cloud infrastructure with encrypted databases. We follow industry-standard security practices including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Encrypted storage at rest for sensitive configuration and shopper data
- Access controls limiting data access to authorised personnel only
- Regular security reviews of our codebase and infrastructure
We retain your data for as long as Magic Wishlist is installed on your store. When you uninstall the app, we delete your store data within 30 days as required by Shopify's app policies, unless retention is required by law.
4. Third-Party Services
Magic Wishlist integrates with the following third-party services to operate:
- Shopify: we access your store via Shopify's official Admin and Storefront APIs under their Partner Program terms.
- Email delivery: we use a transactional email provider to send the recovery emails configured by the merchant. Only the data needed to deliver the email (recipient address, template, and content) is shared.
- Optional integrations you enable: if you connect Klaviyo, Omnisend, Mailchimp, Yotpo, Meta Ads, Google Analytics 4, Shopify Flow, n8n, or Make, the relevant wishlist events are pushed to those tools using your account credentials. You control which integrations are active.
5. Your Shoppers' Data
When shoppers add items to their wishlist, Magic Wishlist processes limited identifiers (Shopify customer ID for logged-in shoppers, email and hashed device ID for guests) solely to operate the wishlist feature on the merchant's behalf. We act as a data processor. The merchant is the data controller. We do not:
- Use shoppers' data for any purpose other than operating the wishlist and recovery emails the merchant has enabled
- Sell or share shoppers' data with third parties
- Store shoppers' payment details, postal addresses, or any data unrelated to the wishlist feature
Magic Wishlist is fully GDPR compliant and implements all of Shopify's required data
webhooks: customers/data_request, customers/redact, and
shop/redact.
6. Cookies & Tracking
On your storefront, Magic Wishlist uses a small first-party cookie or local-storage entry to remember a guest shopper's wishlist between visits. No third-party tracking cookies are set by the app on your storefront.
The Magic Wishlist admin dashboard uses session cookies required by Shopify's authentication system. Our marketing website does not use third-party advertising or behavioural tracking scripts.
7. Your Rights
Depending on your location, you may have rights regarding your personal data, including the right to access, correct, port, or delete your data. To exercise these rights, contact us at support@getmagicapps.com. As a merchant, you can also fulfil shopper data requests directly through Shopify's customer privacy tools. Magic Wishlist will respond to the standard webhooks within the Shopify-mandated timeframe.
8. Children's Privacy
Magic Wishlist is a business-to-business service intended for Shopify merchants and the shoppers visiting their stores. We do not knowingly collect information from individuals under the age of 13 (or the equivalent minimum age in the relevant jurisdiction). If you believe a child has provided us with personal information, please contact us and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or through a notice in the app dashboard before the change takes effect.
10. Contact Us
If you have questions about this Privacy Policy:
- Email: support@getmagicapps.com
- Website: getmagicwishlist.com