Home
Features
Case Studies
Pricing
Docs
Book a demo
Swish - Return to homepage

DATA PROCESSING AGREEMENT

Last Modified: 28 September 2026

This Data Processing Agreement (the "DPA") forms part of the Customer Terms and Conditions of Service (the "Terms") between Swish App Limited, trading as Swish ("Swish", "we", "us"), and the merchant who installs Swish (the "Customer", "you"). It applies automatically, without signature, to every Customer from the moment the Swish app is installed on a Shopify store, and for as long as Swish processes Customer Personal Data.

1. Definitions

1.1 Terms defined in the Terms have the same meaning in this DPA. In addition:

  • "Controller", "Processor", "Data Subject", "Personal Data Breach", "processing" and "Supervisory Authority" have the meanings given in the GDPR.
  • "Customer Personal Data" means Personal Data contained in Customer Data that Swish processes on the Customer's behalf in providing the Subscription Service, as described in Annex 1.
  • "Shopify Privacy Requests" means the privacy requests Shopify sends to Swish for the Customer's store: a shopper's request for a copy of their data, a shopper's request for erasure, and the store's erasure request after the Customer uninstalls the app.
  • "Data Protection Laws" has the meaning given in the Terms, and includes the UK GDPR and the UK Data Protection Act 2018 where they apply.
  • "Sub-processor" means a third party engaged by Swish that processes Customer Personal Data.
  • "Standard Contractual Clauses" means the clauses annexed to Commission Implementing Decision (EU) 2021/914.

2. Roles and scope

2.1 For Customer Personal Data, the Customer is the Controller and Swish is the Processor. Swish processes it on the Customer's behalf and for no purpose of its own. Swish does not sell Customer Personal Data, and does not retain or use it for any purpose other than as permitted by this DPA and the Terms.

2.2 This DPA does not cover information Swish holds as a Controller in its own right: the merchant's account and contact details, support conversations, how merchants use the Swish admin, and visitors to the Swish website. The Privacy Policy governs that information.

2.3 Annex 1 describes the subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects.

2.4 The Customer is responsible for having a lawful basis for the processing it instructs, including for shoppers' use of wishlist, back-in-stock and marketing features on its store, and for the notices it gives its shoppers. The Customer is also responsible for the accuracy, quality and legality of the Personal Data it makes available to Swish, the means by which it acquired that data, and the instructions it gives Swish, and will ensure that following those instructions does not put Swish in breach of Data Protection Laws.

2.5 Each party will comply with its obligations under Data Protection Laws for as long as this DPA applies, and will ensure that its staff and subcontractors do the same.

2.6 California. Where the California Consumer Privacy Act applies, Swish is a service provider receiving personal information from the Customer for a business purpose. Swish does not sell that personal information, and does not retain, use or disclose it except as necessary to provide the Subscription Service or as the CCPA permits. Swish understands these restrictions.

3. Processing on instructions

3.1 Swish processes Customer Personal Data only on the Customer's documented instructions. The Customer's complete instructions at the date of this DPA are:

(a) the Terms and this DPA;

(b) the Customer's configuration and use of the Swish app, including any marketing platform the Customer connects; and

(c) Shopify Privacy Requests sent on the Customer's behalf.

3.2 Swish may process Customer Personal Data otherwise only where required by EU or Member State law. In that case Swish will tell the Customer of the requirement before processing, unless the law prohibits it.

3.3 Swish will tell the Customer immediately if, in its opinion, an instruction infringes Data Protection Laws.

4. Confidentiality

4.1 Swish ensures that every person it authorises to process Customer Personal Data, whether an employee or a contractor, is bound by a written obligation of confidentiality, and receives access only to the extent needed for their role.

5. Security

5.1 Swish implements and maintains the technical and organisational measures in Annex 2, which are designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

5.2 Swish may update those measures over time, provided the overall level of protection is not reduced.

6. Sub-processors

6.1 The Customer gives Swish general authorisation to engage Sub-processors. The Sub-processors engaged at the date of this DPA are listed in Annex 3. The Swish Trust Center at trust.swish.app/subprocessors shows the current list.

6.2 Swish imposes on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA. Swish remains liable to the Customer for each Sub-processor's performance of those obligations.

6.3 Notice of changes. Swish will give at least 30 days' notice before a new Sub-processor begins processing Customer Personal Data, by recording it in the change log at the end of Annex 3, by updating the list on the Trust Center, and by email to the Customer's store contact address.

6.4 Objection. The Customer may object to a new Sub-processor on reasonable data protection grounds by writing to privacy@swish.app within the notice period. Swish will try in good faith to resolve the objection. If it cannot, the Customer may terminate the Subscription Service by uninstalling the app, and will receive a pro-rata refund of any prepaid fee for the period after termination.

6.5 A new Sub-processor to which the Customer has not objected within the notice period is authorised under this DPA. On request, Swish will provide copies of its Sub-processor agreements as the Standard Contractual Clauses require, with commercial information removed.

6.6 In an emergency affecting the security or availability of the Subscription Service, Swish may replace a Sub-processor with shorter notice, and will give notice as soon as reasonably practicable.

7. International transfers

7.1 Swish processes Customer Personal Data in the European Union, the United States and the other locations listed in Annex 3, which sets out which Sub-processor processes it where.

7.2 Where Customer Personal Data is transferred outside the European Economic Area, Swish ensures the transfer is covered by one of the following:

(a) an adequacy decision of the European Commission;

(b) the recipient's certification under the EU-U.S. Data Privacy Framework; or

(c) the Standard Contractual Clauses, Module Three (Processor to Processor), entered into between Swish and the Sub-processor.

7.3 Where a party located outside the EEA, the UK or an adequate country receives Customer Personal Data from the other, that party acts as data importer, the other as data exporter, and the Standard Contractual Clauses apply, with the UK International Data Transfer Addendum for data protected by UK law.

7.4 Where the Standard Contractual Clauses apply: Module Two applies where the Customer is a controller and Module Three where it is a processor; the optional docking clause in Clause 7 does not apply; Option 2 (general written authorisation) applies in Clause 9, with the notice period in clause 6.3; the optional language in Clause 11 does not apply; the clauses are governed by Irish law (Clause 17) and disputes go to the Irish courts (Clause 18); and Annexes 1, 2 and 3 of this DPA complete Annexes I, II and III of the clauses. For transfers from Switzerland, references to the GDPR include the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent authority for those transfers.

7.5 Swish transfers Customer Personal Data outside the EEA, the UK or an adequate country only on the Customer's documented instructions, which include this DPA and the Customer's use of the Subscription Service, unless the law requires otherwise.

7.6 If a transfer mechanism is not sufficient to protect the transferred data, the data importer will promptly put in place supplementary measures so that the data is protected to the standard Data Protection Laws require.

7.7 If a public authority asks Swish or a Sub-processor for access to Customer Personal Data, Swish will first try to redirect the request to the Customer. If disclosure is compelled, Swish will, where the law allows, challenge the request, notify the Customer promptly so it can seek a protective order, disclose only the minimum required, and keep a record of the disclosure. Swish will not disclose Customer Personal Data to a public authority voluntarily.

8. Assistance to the Customer

8.1 Data Subject requests. Swish provides the Customer with the means to answer shoppers' requests for a copy of their data and for erasure received as Shopify Privacy Requests, and completes each within 30 days of receipt. Swish will pass to the Customer, without undue delay, any request it receives directly from a shopper of the Customer's store, and will not answer it itself except on the Customer's instruction or as the Privacy Policy describes.

8.2 Other assistance. Taking into account the nature of the processing and the information available to it, Swish will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with a Supervisory Authority, to the extent they concern Swish's processing.

9. Personal Data Breaches

9.1 Swish will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

9.2 The notice will be sent to the Customer's store contact address and will describe, as far as then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Where not all of this is known, Swish will provide it in phases as it becomes available.

9.3 Swish will take reasonable steps to contain and remedy the breach and will cooperate with the Customer's investigation. Notifying a breach is not an admission of fault or liability. Clauses 9.1 and 9.2 do not apply to a breach caused by the Customer's own acts or omissions.

10. Return and deletion

10.1 A shopper who asks for a copy of their data through Shopify receives it within 30 days, as clause 8.1 describes. The Customer may request a copy of all of its store's Customer Personal Data by writing to support@swish.app before uninstalling.

10.2 When the Customer uninstalls the app, Swish stops accessing the store at once and deletes the store's Customer Personal Data within 30 days, normally within a few days of Shopify's redaction request. If the Customer reinstalls the app before that request is received, the data is retained for the reinstalled store.

10.3 Clause 10.2 does not apply to Customer Personal Data that Swish must retain by law. Where deletion is prohibited or impracticable, Swish will block that data from further processing and continue to protect it under this DPA for as long as it is retained. Swish will certify deletion on the Customer's request. Swish's Customer Data Deletion Procedure, available on request, describes how deletion is carried out.

11. Audit and information

11.1 Swish will keep records sufficient to demonstrate its compliance with this DPA, and will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR. Once Swish holds a SOC 2 report, it will provide the current report on request, under confidentiality, and the Customer agrees that the report is the primary means of demonstrating Swish's compliance.

11.2 Where the Customer reasonably needs more, including where a Supervisory Authority requires it, the Customer may carry out an audit no more than once in any 12-month period, on at least 30 days' written notice, during business hours, at the Customer's cost, and by an auditor bound by confidentiality. Swish may first propose a remote audit or written answers.

12. Liability

12.1 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms.

13. General

13.1 This DPA lasts for as long as Swish processes Customer Personal Data, and survives termination of the Terms until deletion is complete.

13.2 In the event of conflict on the processing of Customer Personal Data, this DPA takes precedence over the Terms and the Privacy Policy. Where the Standard Contractual Clauses apply, they take precedence over this DPA. Where the Customer has signed a separate data processing agreement with Swish, that agreement takes precedence over this DPA for as long as it is in force.

13.3 Swish may update this DPA by posting a revised version, as clause 8.1 of the Terms provides, but no update will reduce the protection given to Customer Personal Data without the Customer's agreement.

13.4 This DPA is governed by the law of Ireland, and the Irish courts have jurisdiction, as set out in clause 8.14 of the Terms.

13.5 Notices under this DPA must be in writing. Notices to Swish go to privacy@swish.app. Notices to the Customer go to the store contact email address held in Shopify.

Annex 1: Description of the processing

Subject matterProviding the Swish wishlist, back-in-stock, saved-items and messaging features on the Customer's Shopify store.
DurationWhile the app is installed, then until deletion under clause 10.
NatureCollection through the storefront and Shopify APIs, storage, retrieval, organisation, analysis to produce the Customer's reports, transmission to marketing platforms the Customer connects, sending email on the Customer's behalf, and erasure.
PurposeTo provide the Subscription Service to the Customer as described in the Terms.
Data SubjectsShoppers of the Customer's store who use Swish features.
Personal DataShopify customer identifier; session identifiers; IP address and browser details; name and email address of the wishlist owner; wishlist, saved-for-later, recently viewed and shared-list contents with dates; back-in-stock and marketing subscriptions and consents; messages sent and their delivery status; interaction events on the storefront.
Special categoriesNone. Terms clause 2.9 prohibits the Customer from using the Subscription Service to process Sensitive Information.
FrequencyContinuous.

Annex 2: Technical and organisational measures

  • Encryption. Customer Personal Data is encrypted in transit and at rest.
  • Access control. Access to production systems is granted on the principle of least privilege and requires multi-factor authentication.
  • Vulnerability management. Swish identifies vulnerabilities and tracks their remediation against deadlines set by severity.
  • Incident response. Swish maintains a documented incident response plan covering detection, containment and notification of customers and authorities.
  • Personnel confidentiality. Everyone with access to Customer Personal Data is bound by a written confidentiality obligation.
  • Deletion. Swish deletes Customer Personal Data in response to Shopify Privacy Requests, as clauses 8.1 and 10 describe.

Current technical specifics of these measures are published on the Swish Trust Center at trust.swish.app.

Annex 3: Sub-processors

The Sub-processors below process Customer Personal Data. The change log at the end of this Annex is the dated record of every change to this list. The Swish Trust Center shows the current list.

Sub-processorPurposeCustomer Personal DataLocation
Google Cloud EMEA LimitedHosting, databases, storage, messaging and key managementAll data in Annex 1European Union and United States
MongoDB, Inc. (MongoDB Atlas)Application database for wishlists, saved items, notifications and subscriptionsShopper identifiers and wishlist dataUnited States
Mailgun Technologies, Inc.Sending emailShopper email address and message contentEuropean Union
Volentio JSD Limited (jsDelivr)Content delivery network that serves the Swish storefront scriptShopper IP address and browser detailsUnited Kingdom, global network

Where the Customer connects a marketing platform (Klaviyo, Brevo, Omnisend, Ometria, Bloomreach, Attentive or Braze), Swish sends shopper contact details and wishlist events to the Customer's own account on that platform, on the Customer's instructions. That platform processes the data for the Customer under the Customer's own agreement with it, and is not a Swish Sub-processor.

Change log

DateChange
28 September 2026Initial list published.
Swish app icon
HomeFeaturesCase studiesPricingBook a demoContact
Privacy policyTerms of serviceData processing agreementSecurityCompany

ⓒ Swish 2025