Skip to content

Privacy policy

Last updated 28 August 2026

This policy explains what the Picklist app for Shopify collects, why, and what happens to it. It covers the app, its storefront extension, this website and the support address. Picklist is operated by Swonie Creative Design (“we”).

Who we are

Swonie Creative Design is the data controller for the data described in this policy, and under Law No. 6698 on the Protection of Personal Data is the veri sorumlusu.

Swonie Creative Design
Aksoy Mah. Yalı Bul. No: 386, Kat: 2 D: 2, Karşıyaka / İzmir, Türkiye
Privacy and data protection enquiries: [email protected]
App support: [email protected]
Telephone: +90 (850) 309 62 78

We are established in Türkiye. We have not appointed a representative under Article 27 of the GDPR, because our processing is not directed at individuals in the EU or UK — merchants install this app themselves. Requests from anywhere are answered at the address above.

Who is responsible for what

For data about shoppers, the merchant running the store is the controller and we are a processor acting on their instructions. If you are a shopper wanting your data corrected or erased, contact the store you saved products in — although you can also write to us and we will act on it.

For data about the merchant account and the app configuration, we are the controller.

Shopper data

The only piece of personal data Picklist stores about a shopper is an email address, and only when there is a reason to have one. No name, no postal address, no phone number, no payment details, and no order history.

DataWhyKept for
Email addressTo send a back-in-stock, price-drop or reminder email about a product the shopper saved. Given by the shopper in the capture prompt, or resolved from their Shopify customer record when they are signed inUntil the list is deleted, the shopper is redacted, or the shop is redacted
Shopify customer id, for a signed-in shopperTo attach the list to the right account across devicesSame
A random guest token, for a shopper with no accountTo recognise the same browser again. It identifies a list, not a person — we cannot tell who holds oneRetired when the shopper signs in and their list is merged
Saved products, and events on them — saved, removed, added to cart, sharedTo show the list back to the shopper, and to produce the merchant’s demand reportsSame

Emails we send shoppers

Only about products the shopper themselves saved: back in stock, price dropped, or a reminder that a list has gone quiet. These are transactional in nature and are not marketing campaigns. Every one is recorded in a send ledger with deduplication, so a retried webhook cannot email someone twice.

A shopper who no longer wants them can delete the saved items, ask the merchant to remove the list, or write to us.

What is never collected

  • Browsing behaviour beyond the products a shopper saved
  • Cross-site tracking, of any kind
  • Payment information
  • Order contents. Revenue attribution, when enabled, records only that a saved product was purchased and its value

Merchant data

DataWhyKept for
Your shop’s .myshopify.com domain and your app settingsTo run the app for your storeUntil 48 hours after uninstall
A Shopify session record, including the access token Shopify issuedTo call Shopify’s API on your behalfDeleted the moment the app is uninstalled
Product snapshots — title, handle, price, image and stock stateSo a saved item can be shown with a current price without calling Shopify on every page loadUntil 48 hours after uninstall
Integration credentials you enter, and API tokens you issueTo deliver events to destinations you configureUntil you delete them. API tokens are stored as SHA-256 hashes and shown once
Error and delivery logs for your shopTo show you on the Health page why something failedUntil dismissed or superseded

Access we request from Shopify

PermissionUsed for
read_products, read_inventoryThe saved-item snapshot, and the triggers behind restock and price-drop emails
read_customersResolving an email address for a signed-in shopper, so they do not have to type one they have already given the store

We do not request access to orders, checkouts or payment data. read_customers is protected customer data under Shopify’s programme and is used only as described above.

Server logs

Our hosting provider records ordinary web server logs — IP address, timestamp, path and user agent — used for security and fault diagnosis, not combined with anything else, and discarded on the provider’s rolling schedule, within 30 days.

Who else sees the data

We do not sell data and we do not share it for advertising.

ProcessorRoleWhere
Shopify Inc.The platform the app runs insidePer Shopify’s own terms
Railway Corp.Application hosting and the databaseUnited States
Resend, Inc.Delivering the alert emails. Receives the recipient address and the messageUnited States

Destinations you configure yourself. If you connect Klaviyo, Omnisend, Attentive or your own webhook endpoint, Picklist sends the events you select to it — which for most events includes the shopper’s email address. You choose those destinations and you are the controller for what happens to the data once it arrives. Custom endpoints must be HTTPS and must resolve to a public address.

We will update this list before adding a processor. We may also disclose data where legally required.

International transfers

The app is hosted in the United States. Where data originating in the European Economic Area, the United Kingdom or Türkiye is transferred there, the transfer relies on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or explicit consent, as applicable.

Deletion and retention

A single shopper

When Shopify sends a customer redaction request, we erase that shopper’s lists, items, events and captured email — and nothing else. This is deliberately surgical and is tested as such: other shoppers’ lists in the same store are untouched.

A whole store

On uninstall, your session is deleted immediately. Picklist data is then erased when Shopify sends the shop redaction request, up to 48 hours later.

Between uninstall and redaction, saved lists are deliberately kept. A merchant who uninstalls and reinstalls — while switching plan, or by mistake — would otherwise destroy every list their shoppers had built, and those shoppers have no way to get them back. If you would rather your data were erased immediately rather than at the 48-hour mark, write to us and we will do it.

Data requests

We implement all three of Shopify’s mandatory privacy webhooks — customer data request, customer redaction and shop redaction.

Your rights

European Economic Area and United Kingdom (GDPR / UK GDPR)

You have the right to access, rectify, erase, restrict processing of and port your data, and to object to processing. For merchant data our lawful basis is performance of a contract. For shopper data we act as a processor for the merchant, whose own lawful basis applies. Email [email protected], or complain to your local supervisory authority.

California (CCPA / CPRA)

You have the right to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not use it for cross-context behavioural advertising. We will not discriminate against you for exercising these rights.

Türkiye (KVKK)

Under Article 11 of Law No. 6698 you may learn whether your personal data is processed, request information about it, request correction or erasure, and object to results produced solely by automated analysis.

Everyone

Write to [email protected]. We answer within 30 days, usually within two business days. Tell us the store domain and the email address concerned.

Security

All traffic is served over HTTPS. Storefront requests are cryptographically signed by Shopify through its app proxy, and a signed-in shopper’s identity is taken only from that signature — never from a value the browser could set. Access tokens and integration credentials are stored in a database encrypted at rest by the hosting provider and are never exposed to a browser. API tokens are stored as hashes. Access to production is limited to the people who operate the app.

If you believe you have found a vulnerability, email [email protected] rather than disclosing it publicly. We confirm receipt within two business days.

Children

Picklist is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child’s data has been collected through a store using Picklist, tell us and we will erase it.

Cookies and browser storage

The storefront extension stores a guest token and a short-lived cache in the shopper’s browser. Neither is a tracking cookie. See the cookie policy for the detail, including what it means for your own consent banner.

Changes

If this policy changes materially we will update the date at the top and, where the change affects merchants with the app installed, say so in the app.

Contact

Full contact details are under Who we are at the top of this page. For anything about the app itself, the support page says what to include so the first reply is useful.