Privacy Policy for RM Wishlist Plus
§ Overview & Scope
RM Web Apps (“RM Web Apps,” “we,” “our,” or “us”) develops and operates the RM Wishlist Plus application (the “App” or “Services”) for Shopify merchants worldwide. We provide this Privacy Policy to inform you of our policies and procedures regarding the collection, use, maintenance, and disclosure of information we receive from users of our application, our website, and storefront visitors who interact with our wishlist features.
We provide our merchant clients (“Clients” or “Merchants”) with wishlist management tools, cross-device synchronization, and business-to-business data analysis regarding their customers and visitors (“Customer Data”).
If you are a merchant installing our App, a website visitor, or a customer browsing a merchant’s store, this Privacy Policy describes your options for accessing, limiting the use, disclosure, and deletion of your personal information.
Under global data protection regulations—including the Digital Personal Data Protection Act, 2023 (DPDP Act, India), the Information Technology Act, 2000 (India), the European Union General Data Protection Regulation (GDPR), and the California Consumer Privacy Act as amended by the CPRA (CCPA):
- Our Merchants are Data Fiduciaries (or “Data Controllers” / “Businesses”): The merchant whose store you visit determines the purposes and lawful grounds for collecting and processing your personal data.
- RM Wishlist Plus is a Data Processor (or “Service Provider”): When processing personal data submitted through our Clients’ use of our Services, we act strictly as a Processor/Service Provider. We process personal information solely on our Clients’ documented instructions and as permitted by our agreements, Shopify API terms, and applicable law.
1 Categories of Information We Collect
A. Information You Provide Directly to Us
We collect information that you directly provide when installing or interacting with our Services:
- Merchant Account Information: Store owner name, business email address, Shopify store domain (
.myshopify.comdomain and custom domain), phone number, and support communications. - Subscription and Billing Information: Details regarding your active plan tier. All billing transactions are processed securely through Shopify’s App Billing and Managed Pricing infrastructure; we never collect or store credit card numbers, CVVs, or banking credentials.
- Customer Communications: Information provided when contacting our support team for technical assistance or privacy inquiries.
B. Customer and Storefront Data (Collected on Client Websites)
When shoppers interact with wishlist functionality on a merchant store powered by RM Wishlist Plus, we process:
- Logged-in Customer Identity (Protected Customer Data): Shopify Customer ID (GID), Full Name (First and Last Name / Display Name), and Customer Email Address.
- Wishlist Activity Data: Product IDs, variant IDs, and product handles saved or removed; custom wishlist names and user-created list categorizations; timestamps of wishlist interactions (adds, removals, moves to cart).
C. Information Collected Automatically (Device & Usage)
Aside from information directly provided, we automatically collect certain technical data when merchants access our admin dashboard or shoppers interact with wishlist features:
- Device Information: Browser type, operating system, device manufacturer/model, push notification identifiers (if enabled), and Internet Protocol (IP) address (used strictly for localized storefront rendering, network diagnostics, and security rate limiting).
- Usage Information: Interactions with wishlist buttons, floating drawers, modal popups, and dedicated wishlist pages. This data is collected in server log files and analytics monitors to ensure operational reliability.
- Cookies and Local Storage: We utilize browser HTML5 LocalStorage and first-party session cookies. These allow shoppers to save wishlist items as guests without requiring an immediate account login, preserve active wishlist sessions across page navigations, and seamlessly synchronize guest items into a shopper’s profile once they log in.
2 How We Use Information (Purposes of Processing)
We use the information collected through our Services exclusively for legitimate business and technical purposes:
- Wishlist Operation & Cross-Device Synchronization: To process requests initiated by shoppers (saving products, removing items, transferring saved items to the cart) and linking saved items to a customer profile so wishlists persist across phones, tablets, and desktop browsers.
- Merchant Dashboard Analytics: To provide merchants with aggregated and item-level demand analysis (e.g., top-wishlisted products, inventory demand signals, customer preference trends) enabling better inventory planning and customer experience.
- Identity Verification & Privacy Protection: To verify user identity and ensure that only authenticated shoppers can view, modify, or delete their personal saved lists.
- Service Communications: To notify merchants of critical service alerts, security updates, feature announcements, and changes to our policies.
- Customer Support: To respond to technical inquiries, resolve bug reports, and assist with theme integration.
- Security & Fraud Prevention: To detect, investigate, and prevent malicious requests, automated scrapers, unauthorized API calls, and fraudulent activity.
- Compliance: To satisfy our legal, regulatory, and Shopify platform obligations.
We never use customer personal data for automated profiling, legal decision-making, or behavioral advertising.
3 Sharing and Disclosure of Information
We disclose information only in the limited circumstances described below:
- As Necessary to Deliver the Services: Data is stored and processed on secure cloud hosting infrastructure and managed database clusters (PostgreSQL) required to operate the App.
- Third-Party Service Providers: We work with trusted infrastructure providers (cloud hosting, database management, and error logging) who are bound by strict confidentiality and data protection obligations and may only process data on our behalf.
- Legal and Regulatory Compliance: We may disclose information if required by law, subpoena, court order, or official governmental request.
- Protection of Rights and Safety: When necessary to investigate potential violations of our terms, enforce our agreements, or protect the security, property, or safety of RM Web Apps, our merchants, shoppers, or the public.
- Business Transfers: In connection with or during negotiations of any merger, sale of company assets, financing, or acquisition of all or a portion of our business.
- With Your Explicit Consent: Where you have given explicit authorization to share information for a specific purpose.
4 Data Security and Standards
We maintain high standards of security, availability, and confidentiality for all merchant and customer data:
- Encryption in Transit: All communications between merchant stores, shoppers, and our servers are encrypted using industry-standard TLS 1.2/1.3 and HTTPS.
- Encryption at Rest: Databases, persistent storage volumes, and backup snapshots are encrypted using modern cryptographic standards (AES-256).
- Access Control & Principle of Least Privilege: Internal production access is restricted strictly to authorized engineering personnel using multi-factor authentication (MFA) and SSH key authentication.
- Environment Isolation: Development and test environments are strictly isolated from production customer databases.
While we implement rigorous safeguards, no method of transmission over the Internet or electronic storage is completely impenetrable, and we cannot guarantee absolute security.
5 Policy Towards Children
Our Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from children under the age of 16. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at rmwebapps@gmail.com, and we will promptly delete such data.
6 International Data Transfers
RM Wishlist Plus services and databases are hosted on secure cloud infrastructure located in the United States and other global cloud regions. If you access the Services or browse a merchant store from outside the United States, your information may be transferred to, stored, and processed in jurisdictions where data protection laws may differ from those of your home country.
Where applicable, we rely on standard contractual clauses (SCCs) and appropriate data transfer mechanisms to provide adequate protection for cross-border transfers.
7 EU, UK, and Swiss Data Subject Rights (GDPR)
If you reside in the European Economic Area (EEA), the United Kingdom, or Switzerland, you hold specific rights under the General Data Protection Regulation (GDPR):
- Lawful Grounds for Processing: Performance of a contract, legitimate business interests (app performance, security, fraud prevention), and consent.
- Individual Rights: Access, Rectification, Erasure (“Right to be Forgotten”), Restriction of Processing, Data Portability, and Right to Withdraw Consent.
- Exercising Rights: Because we act as a Data Processor on behalf of our merchants, shoppers should first contact the specific Shopify merchant directly. If you contact us at rmwebapps@gmail.com, we will forward your request to the relevant merchant and assist them in fulfilling the request within 30 days.
8 Data Retention and Shopify Compliance Webhooks
We retain customer wishlist records for as long as the merchant maintains an active installation of RM Wishlist Plus. When a merchant uninstalls our app, our systems retain records for up to 365 days unless an earlier erasure request is received, after which all customer wishlist records and store session configurations are permanently purged.
We fully automate and honor Shopify’s mandatory compliance webhooks:
customers/data_request— Generates and delivers all personal data held for a requested customer ID.customers/redact— Permanently deletes all wishlist items, events, and personal records associated with the customer ID within 30 days.shop/redact— Deletes all merchant account data, settings, and customer wishlist records within 48 hours of app uninstallation or platform notification.
9 Your Choices, Cookies, and Local Storage
- Declining Information: You may choose not to submit personal data, though doing so may limit your ability to synchronize wishlists across devices.
- Managing Cookies & Local Storage: Most web browsers allow you to manage or block cookies and clear local storage via browser settings. If you block local storage, guest wishlist items will not persist between browsing sessions.
- Unsubscribing from Communications: Merchants who receive service emails may opt out or unsubscribe at any time via instructions in the email or by contacting us.
10 United States State Privacy Rights
California (CCPA / CPRA): When processing customer personal information through our Clients’ stores, RM Wishlist Plus acts strictly as a Service Provider. Our Clients act as Businesses and determine collection purposes. We do not sell personal information or share it for cross-context behavioral advertising. California residents may exercise their rights through the merchant or by contacting rmwebapps@gmail.com.
Virginia (VCDPA) and Other States (CO, CT, UT, TX, etc.): RM Wishlist Plus acts as a Processor, and our merchant Clients act as Controllers. We limit processing strictly to the merchant’s documented instructions.
11 Indian Law Compliance & Grievance Redressal
In accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 read with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, RM Web Apps has established a formal Grievance Redressal mechanism.
Indian Data Principals hold the right to access a summary of personal data processed, seek correction and completion of inaccurate data, request erasure of data no longer necessary for the specified purpose, and register grievances with our Grievance Officer.
12 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our legal obligations, platform requirements, or operational practices. If we make material changes, we will notify merchants by email or by displaying a prominent notice on our website or within the app prior to the changes taking effect. We encourage you to periodically review this page.
13 Contact Information
If you have questions, feedback, or privacy-related requests regarding this Privacy Policy, please contact our privacy team: