Privacy policy
Last updated 28 August 2026
This policy explains what the Picklist app for Shopify collects, why, and what happens to it. It covers the app, its storefront extension, this website and the support address. Picklist is operated by Swonie Creative Design (“we”).
Who we are
Swonie Creative Design is the data controller for the data described in this policy, and under Law No. 6698 on the Protection of Personal Data is the veri sorumlusu.
Swonie Creative Design
Aksoy Mah. Yalı Bul. No: 386, Kat: 2 D: 2, Karşıyaka / İzmir, Türkiye
Privacy and data protection enquiries: [email protected]
App support: [email protected]
Telephone: +90 (850) 309 62 78
We are established in Türkiye. We have not appointed a representative under Article 27 of the GDPR, because our processing is not directed at individuals in the EU or UK — merchants install this app themselves. Requests from anywhere are answered at the address above.
Who is responsible for what
For data about shoppers, the merchant running the store is the controller and we are a processor acting on their instructions. If you are a shopper wanting your data corrected or erased, contact the store you saved products in — although you can also write to us and we will act on it.
For data about the merchant account and the app configuration, we are the controller.
Shopper data
The only piece of personal data Picklist stores about a shopper is an email address, and only when there is a reason to have one. No name, no postal address, no phone number, no payment details, and no order history.
| Data | Why | Kept for |
|---|---|---|
| Email address | To send a back-in-stock, price-drop or reminder email about a product the shopper saved. Given by the shopper in the capture prompt, or resolved from their Shopify customer record when they are signed in | Until the list is deleted, the shopper is redacted, or the shop is redacted |
| Shopify customer id, for a signed-in shopper | To attach the list to the right account across devices | Same |
| A random guest token, for a shopper with no account | To recognise the same browser again. It identifies a list, not a person — we cannot tell who holds one | Retired when the shopper signs in and their list is merged |
| Saved products, and events on them — saved, removed, added to cart, shared | To show the list back to the shopper, and to produce the merchant’s demand reports | Same |
Emails we send shoppers
Only about products the shopper themselves saved: back in stock, price dropped, or a reminder that a list has gone quiet. These are transactional in nature and are not marketing campaigns. Every one is recorded in a send ledger with deduplication, so a retried webhook cannot email someone twice.
A shopper who no longer wants them can delete the saved items, ask the merchant to remove the list, or write to us.
What is never collected
- Browsing behaviour beyond the products a shopper saved
- Cross-site tracking, of any kind
- Payment information
- Order contents. Revenue attribution, when enabled, records only that a saved product was purchased and its value
Merchant data
| Data | Why | Kept for |
|---|---|---|
Your shop’s .myshopify.com domain and your app settings | To run the app for your store | Until 48 hours after uninstall |
| A Shopify session record, including the access token Shopify issued | To call Shopify’s API on your behalf | Deleted the moment the app is uninstalled |
| Product snapshots — title, handle, price, image and stock state | So a saved item can be shown with a current price without calling Shopify on every page load | Until 48 hours after uninstall |
| Integration credentials you enter, and API tokens you issue | To deliver events to destinations you configure | Until you delete them. API tokens are stored as SHA-256 hashes and shown once |
| Error and delivery logs for your shop | To show you on the Health page why something failed | Until dismissed or superseded |
Access we request from Shopify
| Permission | Used for |
|---|---|
read_products, read_inventory | The saved-item snapshot, and the triggers behind restock and price-drop emails |
read_customers | Resolving an email address for a signed-in shopper, so they do not have to type one they have already given the store |
We do not request access to orders, checkouts or payment data. read_customers is protected customer data under Shopify’s programme and is used only as described above.
Server logs
Our hosting provider records ordinary web server logs — IP address, timestamp, path and user agent — used for security and fault diagnosis, not combined with anything else, and discarded on the provider’s rolling schedule, within 30 days.
Who else sees the data
We do not sell data and we do not share it for advertising.
| Processor | Role | Where |
|---|---|---|
| Shopify Inc. | The platform the app runs inside | Per Shopify’s own terms |
| Railway Corp. | Application hosting and the database | United States |
| Resend, Inc. | Delivering the alert emails. Receives the recipient address and the message | United States |
Destinations you configure yourself. If you connect Klaviyo, Omnisend, Attentive or your own webhook endpoint, Picklist sends the events you select to it — which for most events includes the shopper’s email address. You choose those destinations and you are the controller for what happens to the data once it arrives. Custom endpoints must be HTTPS and must resolve to a public address.
We will update this list before adding a processor. We may also disclose data where legally required.
International transfers
The app is hosted in the United States. Where data originating in the European Economic Area, the United Kingdom or Türkiye is transferred there, the transfer relies on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or explicit consent, as applicable.
Deletion and retention
A single shopper
When Shopify sends a customer redaction request, we erase that shopper’s lists, items, events and captured email — and nothing else. This is deliberately surgical and is tested as such: other shoppers’ lists in the same store are untouched.
A whole store
On uninstall, your session is deleted immediately. Picklist data is then erased when Shopify sends the shop redaction request, up to 48 hours later.
Between uninstall and redaction, saved lists are deliberately kept. A merchant who uninstalls and reinstalls — while switching plan, or by mistake — would otherwise destroy every list their shoppers had built, and those shoppers have no way to get them back. If you would rather your data were erased immediately rather than at the 48-hour mark, write to us and we will do it.
Data requests
We implement all three of Shopify’s mandatory privacy webhooks — customer data request, customer redaction and shop redaction.
Your rights
European Economic Area and United Kingdom (GDPR / UK GDPR)
You have the right to access, rectify, erase, restrict processing of and port your data, and to object to processing. For merchant data our lawful basis is performance of a contract. For shopper data we act as a processor for the merchant, whose own lawful basis applies. Email [email protected], or complain to your local supervisory authority.
California (CCPA / CPRA)
You have the right to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not use it for cross-context behavioural advertising. We will not discriminate against you for exercising these rights.
Türkiye (KVKK)
Under Article 11 of Law No. 6698 you may learn whether your personal data is processed, request information about it, request correction or erasure, and object to results produced solely by automated analysis.
Everyone
Write to [email protected]. We answer within 30 days, usually within two business days. Tell us the store domain and the email address concerned.
Security
All traffic is served over HTTPS. Storefront requests are cryptographically signed by Shopify through its app proxy, and a signed-in shopper’s identity is taken only from that signature — never from a value the browser could set. Access tokens and integration credentials are stored in a database encrypted at rest by the hosting provider and are never exposed to a browser. API tokens are stored as hashes. Access to production is limited to the people who operate the app.
If you believe you have found a vulnerability, email [email protected] rather than disclosing it publicly. We confirm receipt within two business days.
Children
Picklist is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child’s data has been collected through a store using Picklist, tell us and we will erase it.
Cookies and browser storage
The storefront extension stores a guest token and a short-lived cache in the shopper’s browser. Neither is a tracking cookie. See the cookie policy for the detail, including what it means for your own consent banner.
Changes
If this policy changes materially we will update the date at the top and, where the change affects merchants with the app installed, say so in the app.
Contact
Full contact details are under Who we are at the top of this page. For anything about the app itself, the support page says what to include so the first reply is useful.