Wishday Privacy Policy
Wishday is a Shopify app that lets a store's shoppers save products into gift lists and receive an email reminder on a date they choose. This policy explains what data Wishday accesses, why, on what legal basis, where it is stored, for how long, and how it is protected and deleted. It addresses both the merchants who install the app and the shoppers of those merchants whose data the app processes.
1. Where Wishday is offered, and the laws it follows
Wishday is offered to merchants whose business address is outside the European Economic Area (EEA), the United Kingdom, the British Crown Dependencies and Gibraltar, the Norwegian territories of Svalbard and Jan Mayen, and Turkey. This is not a disclaimer: it is enforced by Shopify itself, through the business-address install requirement on our App Store listing, so a store based in any of those places cannot install Wishday.
This policy is written to meet, at a minimum: the LGPD (Lei Geral de Proteção de Dados, Law 13.709/2018, Brazil), which is the law of the party responsible for the processing; PIPEDA (Personal Information Protection and Electronic Documents Act, Canada); and the CCPA/CPRA in California and equivalent United States state laws. Where more than one of them covers the same subject, we apply whichever is more protective of the individual.
About the GDPR and the laws built on it. Because the app is not offered to merchants in the places listed above, we have not designated a representative in the Union under Article 27 of the GDPR, nor a representative under the equivalent duty in the laws of the United Kingdom, Gibraltar, the Crown Dependencies or Norway. Turkey is excluded for the same reason: the KVKK requires a local representative with no size threshold at all. Nothing else in this policy changes: a merchant outside the EEA may still be subject to the GDPR through its own shoppers, and the transfer safeguards in section 8, the response deadlines in section 11 and the technical measures in section 10 apply to that merchant's shoppers just the same.
2. Roles: who is the controller and who is the processor
Wishday's role changes with the data, and that is what decides who you should write to.
Shopper data, meaning the Shopify customer ID, the lists and items saved and the reminder date: Wishday is the processor and the store you shopped at is the controller. This policy complements the store's own privacy policy; it does not replace it.
Store configuration created by the merchant: Wishday is the processor and the merchant is the controller.
The Shopify session, the access token and the identity of the person who installed the app: Wishday is the controller.
Installing the app on a store is the data processing agreement between merchant and Wishday, under article 39 of the LGPD and article 28 of the GDPR: we process shopper data only on the merchant's documented instructions, which are the features the app offers.
3. What the app stores
For each shopper who saves a product, Wishday stores the shopper's Shopify customer ID and references to what was saved: product and variant IDs, the list name, the type of list and the reminder date. Nothing about the product itself is stored. Title, price and image are read from Shopify every time a screen needs them.
The list name is free text written by the shopper, and a gift list is usually named after a person, for example "Ana's birthday". That text is stored exactly as typed, so a name can end up in our database that way. It is only ever shown back to the shopper who wrote it and included in the reminder email sent to that same shopper. The shopper can rename or delete the list at any time. The database also has a field for the name of the person a gift list is for; no screen fills it today, so it is empty on every list.
For each store, Wishday stores the shop domain, the store name that signs the reminder email, the time zone, the admin language, the language chosen for reminder emails and the storefront button settings.
Wishday counts three kinds of event to build the merchant's dashboard: an item was saved, a list was created, a reminder was sent. Each record holds the store, the type of event and the instant. It holds no customer ID and no product reference.
When the app is installed, Shopify gives us a session: the shop domain, the access token and, when Shopify provides them, the name, email address and user ID of the person on the merchant's team who authorized the app. These are used only to authenticate the app's calls to Shopify's API on behalf of that store. Access tokens are never exposed to the browser and never written to logs.
4. How the shopper's email address is used (Protected Customer Data)
Wishday does not store the shopper's email address. To send a reminder, the app reads the address from Shopify's Customer API at the moment the reminder falls due, hands it to the email provider to deliver that one message, and discards it. It is never written to our database and never written to a log. The query we send Shopify asks for a single field, the email address, and nothing else.
Shopify classifies the customer email address as Protected Customer Data. We requested access to that one field, for app functionality, which is delivering the reminder the shopper asked for. If a reminder falls due and the customer has no reachable email address, the app records the failure with the customer ID, never with an address.
The reminder email itself carries the list name, the products on the list, the store name and a link to turn the reminder off. It carries no data about anyone other than the shopper who asked for it.
We do not use the address for marketing, we do not sell or rent it, and we do not share it with anyone other than the email provider needed to deliver the reminder the shopper asked for.
5. What Wishday does not collect
No shopper name and no shopper email address in our database. This is a design decision, not a promise we hope to keep: there is no column for either one. The only shopper identifier we store is the Shopify customer ID. The one way a personal name can reach our database is the free text of a list name, described in section 3.
No payment data. Billing for the app is handled by Shopify, which passes us no card or payment method data.
No browsing tracking, no profiling and no advertising. The app loads no tracking JavaScript on the storefront, sets no cookie of its own there and uses no third-party analytics service.
No sensitive personal data (art. 5, II of the LGPD; art. 9 of the GDPR), from anyone. No data is deliberately collected from children: the app addresses merchants, and the shopper data it reads is always an identifier provided by the store itself.
6. Purposes and legal bases
Customer ID, saved items, list name and reminder date, to run the wishlist and deliver the reminder the shopper asked for: art. 7, V of the LGPD (performance of a contract), processed as a processor on the merchant's instruction; art. 6(1)(b) of the GDPR through the merchant as controller, with processing as a processor under art. 28.
The shopper's email address, in transit only, to deliver that one reminder: the same bases.
Store configuration and settings, to apply what the merchant chose: art. 7, V of the LGPD; art. 6(1)(b) of the GDPR.
Session and access token, to authenticate calls to Shopify's API on behalf of the store: art. 7, V of the LGPD; art. 6(1)(b) of the GDPR.
Technical error records with no personal content, to keep the app working and secure: art. 7, IX of the LGPD (legitimate interest); art. 6(1)(f) of the GDPR. The dashboard counters hold no personal data, so they need no legal basis.
Wishday does not sell personal data, does not share it for marketing or advertising, does not use it to train models and does not use it for any purpose beyond those above. For the CCPA/CPRA: we neither sell nor share personal information, and there is no financial incentive programme.
7. Where the data is processed, and who else touches it
Wishday shares personal data with no third party other than the infrastructure sub-processors below, strictly to operate the service, and when required by law or by an order from a competent authority.
Shopify Inc., the platform the app runs on and the source of every product and customer read, processing in Canada and the United States.
Google Cloud (Cloud Run, Secret Manager, Cloud Scheduler and Cloud Logging), which runs the app, in region southamerica-east1, São Paulo, Brazil.
Neon Inc., the managed PostgreSQL database that holds customer IDs, lists, items and reminders, in region AWS sa-east-1, São Paulo, Brazil.
Resend, which delivers the reminder emails, processing in the United States. It receives the shopper's email address, the list name and the product names, only to deliver that message. Resend publishes its own sub-processor list at resend.com/legal/subprocessors.
That is the whole list. The app uses no error-monitoring, analytics or customer-support vendor at all. Runtime errors are written to the app's own log inside Google Cloud, already named above, and go nowhere else.
8. International transfers
The app runs in Brazil. Both the application (Google Cloud, southamerica-east1) and the database (Neon, AWS sa-east-1) are in São Paulo, so the lists, the customer IDs and the reminders are not stored outside the country.
Two flows do cross a border. Each safeguard below was read in the supplier's own contract, not assumed from market custom.
Resend, United States. Resend's Data Processing Addendum binds on contracting the service, with no separate signature ("This DPA becomes legally binding upon Customer's acceptance of the Agreement"), and it incorporates the European Standard Contractual Clauses of Implementing Decision (EU) 2021/914, modules one, two and three, together with the UK International Data Transfer Addendum issued by the ICO. Resend states that its primary processing operations take place in the United States.
Shopify, Canada and the United States. Shopify does not receive a transfer from us. Store and customer data already live in Shopify under the contract the merchant itself has with Shopify, and the app only reads and writes in that same place. The Shopify Partner Program Agreement, which is the contract between Shopify and whoever develops this app, contains no data processing addendum and no standard contractual clauses. Canada holds an adequacy decision from the European Commission.
Neon and Google store in Brazil, but both are United States companies and may access the data to operate the service. Neon's Data Processing Agreement is entered into by contracting the service, without a separate signature: clause 10(a) reads "By signing the Agreement, you enter into this DPA (including, where applicable, the Standard Contractual Clauses)". It carries the Standard Contractual Clauses of Decision (EU) 2021/914 and the ICO's International Data Transfer Addendum, version B1.0. Neon is a wholly owned subsidiary of Databricks, Inc., and a separate Databricks addendum exists, by signature, which would replace the one already in force; it carries the same safeguards, so we have not signed it. Google's Cloud Data Processing Addendum is incorporated into the Google Cloud agreement with no separate signature and states that Google is the processor and the customer the controller.
From Brazil (LGPD, articles 33 to 36), the transfer is necessary for the performance of a contract to which the data subject is a party, which is the case in article 33, IX, referring back to article 7, V. It stands on its own and never depended on contractual clauses. None of the contracts above incorporates the standard clauses of ANPD Resolution CD/ANPD 19/2024. If a transfer ever comes to rest on those clauses, they will be signed first.
The technical measures in section 10 are kept as a complementary safeguard. The addenda are public: Resend's at resend.com/legal/dpa, Neon's at neon.com/pdf/DPA.pdf and Google's at cloud.google.com/terms/data-processing-addendum.
9. Retention and deletion
Lists, items and reminders are kept while the app is installed and while the shopper keeps them. A shopper can delete any item or any whole list at any time from inside the store.
Uninstalling deletes everything, immediately. When Shopify notifies the app that it was uninstalled, Wishday deletes that store's session and access token and then deletes the store record, which cascades to every list, item, reminder and dashboard counter belonging to it. Nothing is archived and nothing is kept in a marked-as-deleted state.
Store deletion (shop/redact), which Shopify sends about 48 hours after uninstall, runs the same deletion again. It is written to be safe to repeat, so a store already cleared on uninstall is not an error.
Shopper deletion (customers/redact): Wishday deletes every list that customer has in that store, and the items and the reminder go with them. Because the only shopper identifier we store is the Shopify customer ID, this is a single complete removal, with no name or address to chase down.
Shopper data request (customers/data_request): the app assembles what it holds for that customer, which is the lists, their dates and the product references, and records the request. This app has no automatic delivery channel to the merchant, so a store that receives one of these requests should write to the address in section 14 and we send what we hold.
The shopper's email address has no retention at all: it exists only in memory during the delivery of a single message.
Technical error records follow the hosting provider's retention, at most 30 days. Backup copies of the managed database follow the provider's cycle and are overwritten within 30 days of deletion.
10. Security
Data in transit is protected by TLS. Data at rest is encrypted by the database provider's native encryption.
Access tokens live only in the database, never in logs and never on the client side. Runtime secrets (database URL, Shopify secret, email provider key, scheduler secret) live in Google Secret Manager and are injected into the service at deploy time; the repository holds only their names.
Every webhook request is verified by HMAC signature before any processing, and every request arriving from the storefront is verified by Shopify's app proxy signature before any logic runs.
Every read and write is scoped by store and by shopper: one shopper cannot reach another shopper's list, and one store cannot reach another store's data.
The shopper's email address is never written to the database or to a log. Error messages carry the customer ID instead of the address, and the email provider's key never appears in an error.
Incidents. As a processor, we notify the affected merchant without undue delay after becoming aware, which is the processor's duty under article 33(2) of the GDPR, so that the merchant, as controller, can notify its own authority within the 72 hours of article 33(1). For the data we control ourselves (session and access token) we notify the competent authority ourselves, without undue delay and, where applicable, within 72 hours of becoming aware, and we notify the ANPD within a reasonable period under the rules in force.
11. Your rights
You have the right to confirmation that we process your data; access to it; correction of incomplete, inaccurate or out-of-date data; anonymisation, blocking or deletion of unnecessary or excessive data; portability; deletion of data processed on consent; information about who we share it with; withdrawal of consent; and objection to processing based on legitimate interest. Under the GDPR, restriction of processing (art. 18) and the right not to be subject to an automated decision (art. 22) are added. Under the CCPA/CPRA, the rights to know, delete, correct and not be discriminated against for exercising them are added.
Two of these need no request at all. A shopper can review and delete their own lists and items from inside the store at any time, and can switch off or reschedule a reminder from the list or from the opt-out link at the foot of every reminder email. The opt-out link works without signing in.
How to exercise the rest: write to support@trywishday.com. We answer within 15 days for requests under the LGPD and within 1 month for requests under the GDPR, extendable by a further 2 months in complex cases, with notice. Exercising your rights is free. We may ask for additional information only to confirm your identity.
If you are a shopper at a store that uses Wishday, the controller of your data is the store, not us. Send your request to the store; if the store passes it to us, we act on it as its processor. The store is responsible for its own privacy policy towards its shoppers.
Complaint. You may complain to a data protection authority: the ANPD in Brazil (gov.br/anpd), the authority of your country in the EEA, the ICO in the United Kingdom (ico.org.uk), or the Office of the Privacy Commissioner of Canada (priv.gc.ca).
12. Cookies
The app sets no cookie of its own on the store's storefront. The heart button and the list dialog that shoppers see store nothing in the browser: no cookie, no local storage, no session storage. Inside the Shopify admin we use only strictly necessary session and CSRF cookies, without which the app cannot authenticate. There is no analytics, advertising or cross-site tracking cookie, and so there is no consent banner to show.
13. Automated decisions
The app makes no decision about people. It sends the reminder the shopper scheduled, on the date the shopper chose, and that is the only thing it does on its own. It does not score, profile or rank anyone, and it does not decide anyone's access to anything. This is not automated decision-making in the sense of article 22 of the GDPR.
14. Changes to this policy, and contact
We may update this policy. The version in force is always at this URL, with the effective date at the top, and a material change is published here before it takes effect.
The app has no channel for announcing a change to merchants. It sends email to shoppers only, and only the reminder they asked for. So this URL is the place to check, and the effective date at the top is what tells you whether anything changed.
Questions about this policy, about how we process data, or to exercise your rights: support@trywishday.com. The party responsible for the processing is Fernanda Tiemy Yoshida, a natural person established in Brazil, who is also the person in charge of personal data processing (art. 41 of the LGPD) and the contact point for data protection matters under the GDPR.