Wishlist Pro Privacy Policy
Last updated: 29 August 2026
Wishlist Pro is operated by NICCOS GmbH, Freiburg im Breisgau, Germany (NICCOS, we). Contact: kontakt@niccos.com.
Scope and roles
This policy explains how Wishlist Pro handles personal data from Shopify merchants, their staff, customers, prospective customers, and storefront visitors. For storefront customer data, the merchant is generally the controller and NICCOS processes data on the merchant’s instructions. NICCOS is responsible for account, security, billing, and support data it processes for its own purposes.
Data we process
Depending on enabled features, we process the shop domain, Shopify customer ID, customer email address and locale, wishlist items and actions, product and variant identifiers, alert delivery status, order and purchase-attribution identifiers, app settings, encrypted integration credentials, and security/access records. Guest wishlists remain in the visitor’s browser until they sign in and merge them.
Purposes
We use this data to provide wishlists, sharing, customer-requested price and stock notifications, merchant reports and attribution, Shopify Flow and optional Klaviyo events, billing, security, support, and legal privacy-request handling. We do not sell personal data and do not use it for decisions that produce legal or similarly significant effects.
Choice and consent
Email notifications and related Klaviyo event processing are disabled by default. A signed-in customer must actively enable them on the wishlist page and can disable them there at any time. Disabling cancels pending notifications and prevents new marketing integration events. Merchants remain responsible for configuring their own marketing tools and notices lawfully.
Service providers and transfers
We use Shopify for the commerce platform and authentication, Heroku/Salesforce for application and database hosting, Resend for email delivery, and Klaviyo only when a merchant connects it. These providers may process data in countries outside the customer’s country under their applicable transfer safeguards and contractual terms.
Retention
Customer-linked wishlists are anonymized after 24 months of inactivity. Operational events are deleted after 400 days, completed integration jobs after 30 days, email recipients in alert history after 90 days, and personal-data access logs after 365 days. Uninstalled-shop data is deleted when Shopify sends the mandatory shop-redaction request. Backups follow the hosting provider’s rolling backup lifecycle.
Security
Data is encrypted in transit and at rest. Integration secrets use authenticated AES-256-GCM encryption. Access is limited by role, personal-data report views and exports are logged, production and test data are separated, and documented incident-response and recovery procedures apply.
Requests
Customers should normally contact the Shopify merchant where they used Wishlist Pro. Merchants and data subjects may also contact kontakt@niccos.com. We support Shopify’s mandatory customer data request, customer redaction, and shop redaction workflows.
Changes
We may update this policy as the app or legal requirements change. The date above identifies the current version.