DATA PRIVACY POLICY
Last Modified: 19 September 2026
The below terms (together with the documents referred to) tell you how we store customer data.
Swish App Limited, trading as Swish ("we", "our", "us" or "Swish"), is committed to protecting the privacy of all users of our app, services and platform (the "Services" and "Platform(s)"). Please read the following privacy policy ("Privacy Policy") carefully which explains how we use and protect your information.
Swish is the controller of the information we collect about merchants who subscribe to our Services and about visitors to our own website. Where a merchant installs Swish on their Shopify store, the shoppers' information we handle for that store is processed on the merchant's instructions: the merchant is the controller of that information and Swish acts as their processor. If you are a shopper and you want to exercise your rights over that information, you may contact either the store you shopped with or us, and we will work with the store to answer you.
By using our Services and Platform(s), you agree and where required, you consent, to the collection, use, transfer, disclosure, retention and protection of, your information as set out in this policy (together with any other documents referred to on it).
1. CONTACT DETAILS
If you have any queries or requests concerning this privacy policy or how we handle your data more generally, please get in touch with us using the following details.
Swish App LimitedRegistered in Ireland, company number 669893
13 Adelaide Rd
Dublin 2 D02 P950
Ireland
Email Address: privacy@swish.app
2. HOW WE COLLECT YOUR INFORMATION
2.1 We collect certain information when you interact with us or when you use our Services. We may from time to time, also look at how visitors use our Site(s), to help us improve our services and optimise customer experience.
2.2 We collect information:
- when you install the Swish app;
- when you contact us directly via email, phone, post, message or via any chat function we may offer from time to time; and
- when you browse our Platform and use our Services (before and after you create an account with us).
2.3 As an app available through Shopify, most of the information we handle reaches us from Shopify rather than from you directly. When a merchant installs Swish, we read the information the merchant's Shopify store makes available to us under the permissions the merchant grants, and we store the parts of it we need in order to provide the Services. Section 3 sets out what we store.
3. INFORMATION THAT WE COLLECT FROM YOU
3.1 As part of our commitment to the privacy of our customers and visitors to our Platform more generally, we want to be clear about the sorts of information we will collect from you.
3.2 When a merchant subscribes for the Services, we need a name and contact details for the store. We do not usually ask you for these separately: we read them from Shopify for as long as the app is installed.
3.3 We also collect information when you contact us or provide us with feedback, including via e-mail, letter, phone via any chat function we may offer from time to time.
3.4 The information we store includes:
- products added to a wishlist;
- product variants added to a wishlist;
- references to products, variants added to wishlist;
- partial product data, partial product metafields;
- the date a product is added to a wishlist;
- the details of the owner of the wishlist;
- the Shopify customer ID of the wishlist owner;
- partial information about your Shopify store (e.g. domain).
3.5 We store the information listed in section 3.4, together with the credentials that let the app connect to the store. We do not keep our own copy of the store's Shopify account or of its full product catalogue or order history. Where we need information of that kind to carry out a particular task, we read it from Shopify at the time and do not retain it afterwards.
3.6 Some of the information described above is personal data that a shopper originally provided to Shopify or to the store. We handle it on the store's instructions, as set out at the start of this policy.
4. USE OF YOUR INFORMATION
4.1 We will only process the data we collect about you if there is a reason for doing so, and if that reason is permitted under data protection law. We will have a lawful basis for processing your information:
- if we need to process your information in order to provide you with the service you have requested or to enter into a contract;
- we have your consent;
- we have a justifiable reason for processing your data; or
- we are under a legal obligation to do so.
4.2 Where we need to, in order to provide you with the Service(s) you have requested or to enter into a contract, we use your information:
- to supply the Service(s) you have requested;
- to enable us to collect payment from you save that as at the date hereof, we don't collect payments, Shopify does;
- to contact you where necessary concerning our Service(s), such as to resolve issues you may have with your order.
4.3 We also process your data where we have a justifiable reason for doing so - for example, personalisation of our Service(s), including processing data to make it easier and faster for you to do certain things. We have listed these reasons below:
- to improve the effectiveness and quality of Service(s) that our customers can expect from us in the future;
- to enable our customer support team to help you with any enquiries or complaints in the most efficient way possible;
- to contact you for your views and feedback on our Service(s) and to notify you if there are any important changes or developments to the Site(s), Platform or our Service(s), including letting you know that our services are operating in a new area, where you have asked us to do so;
- to analyse your activity so that we can administer, support, improve and develop our business and for statistical and analytical purposes and to help us to prevent fraud;
- to enforce our contractual terms with you and any other agreement, and for the exercise or defence of legal claims and to protect the rights of Swish or others (including to prevent fraud);
- if you submit comments and feedback regarding the Service(s), we may use such comments and feedback on our app and in any marketing or advertising materials. We will only identify you for this purpose by your first name and the city in which you live.
4.4 Where we rely on legitimate interest as a basis for processing your personal information, we carry out a ‘balancing test’ to ensure that our processing is necessary and that your fundamental rights of privacy are not outweighed by our legitimate interests.
4.5 Where we are under a legal obligation to do so we may use your information to:
- create a record of your Order(s) and Subscription(s); and/or
- comply with any legal obligation or regulatory requirement to which we are subject.
4.6 Some features, such as a CSV export or a dashboard view, need information from Shopify that we do not otherwise keep. We read that information from Shopify when the feature runs, use it to produce the result you asked for, and do not store it afterwards.
5. COOKIES
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of the Platform may become inaccessible or not function properly.
6. DIRECT MARKETING
Where you have given your consent or where we have a justifiable reason for doing so (and are permitted to do so by law) we will use your information to let you know about our other products and services that may be of interest to you and we may contact you to do so by email.
7. RETENTION OF YOUR INFORMATION
7.1 We keep your information only for as long as we need it. The periods and triggers set out below are the ones that apply in practice.
7.2 Uninstalling the app. When a merchant uninstalls Swish, we immediately delete the credentials that allowed the app to connect to the store. Shopify then sends us a store redaction request 48 hours after the uninstall, and we delete the store's data, including the shopper wishlist data we held for that store, when it arrives, unless the merchant has reinstalled Swish before then, and except where we are required to keep it under section 7.7 or by law.
7.3 Erasure requests. A shopper's request to have their data erased reaches us either through the store, as a customer redaction request sent by Shopify, or directly at privacy@swish.app. We then delete the personal data we hold about that shopper, except where we are required to keep it under section 7.7 or by law. Shopify allows an app 30 days to complete such a request. That is an outer limit rather than a grace period: we begin the deletion when the request reaches us, and once it has run the only copy left is the encrypted backup described in section 7.4, which is itself deleted after 14 days. If you want a copy of your data, ask for it before you ask us to erase it.
7.4 Rollback window. Erasure cannot be undone, so before we run one we write an encrypted backup. That backup is deleted automatically after 14 days. The window exists so that an erasure made in error can be reversed, and it is deliberately not longer.
7.5 Data requests. Where we prepare a copy of a shopper's data in response to a request, the copy is deleted automatically after 14 days and the download link stops working after 7 days.
7.6 Wishlist and usage data. We keep the information listed in section 3.4, and the usage data we derive from it, for as long as the store uses Swish. It is deleted with the rest of the store's data under section 7.2.
7.7 Record of deletion. We keep a record that a deletion or erasure was carried out, so that we can demonstrate what was done and when. That record holds the store's domain and, for an erasure request, the shopper's Shopify customer identifier. It is not a copy of your wishlist or your contact details, and we keep it for as long as we may need to demonstrate the deletion.
7.8 Information that we collect will be retained for as long as needed to fulfil the purposes outlined in the "Use of Your information" section above, in line with our legitimate interest or for a period specifically required by applicable regulations or laws, such as retaining the information for regulatory reporting purposes.
7.9 When determining the relevant retention periods, we will take into account factors including:
- our contractual obligations and rights in relation to the information involved;
- legal obligation(s) under applicable law to retain data for a certain period;
- statute of limitations under applicable law(s);
- our legitimate interests;
- (potential) disputes; and
- guidelines issued by relevant data protection authorities.
7.10 Otherwise, we securely erase your information where we no longer require your information for the purposes collected.
8. DISCLOSURE OF YOUR INFORMATION
8.1 The information we collect about you will be stored safely. We are very careful and transparent about who else your information is shared with.
Sharing your information internally
8.2 We may share your information with our other group companies only where necessary for the purposes set out in section 4.
Who we share your information with
8.3 We use a small number of service providers to run the Services. They may only process your information on our instructions, or on the instructions of the store where the store is the controller, and they are bound by contract to protect it. They are:
- Shopify: the platform the store runs on, and the source of the merchant and shopper information we read;
- Google Cloud: hosting, storage and analytics for the Services;
- Google Analytics: measuring how visitors use our website, as described in section 2.1;
- MongoDB Atlas: an application database;
- Mailgun: sending transactional and campaign email, through its European service;
- Front and Intercom: handling customer support conversations;
- Anthropic: the model provider behind the AI assistant in the Swish admin, which processes the conversation content and store theme data a merchant sends to it;
- the marketing platform a store connects to Swish, which may be Klaviyo, Brevo, Omnisend, Ometria, Bloomreach, Attentive or Braze. Where a merchant connects one of these, wishlist and contact information is sent to it on that merchant's instructions, for that merchant's own marketing.
8.4 We do not sell your personal data, and we do not share it with advertising partners for our own marketing.
8.5 Swish will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy when it is transferred to third parties.
8.6 If our business enters into a joint venture with, purchases or is sold to or merged with another business entity, your information may be disclosed or transferred to the target company, our new business partners or owners or their advisors.
8.7 We may also share your information:
- if we are under a duty to disclose or share your information in order to comply with (and/or where we believe we are under a duty to comply with) any legal obligation or regulatory requirement. This includes exchanging information with other companies and other organisations for the purposes of fraud protection and prevention;
- in order to enforce our contractual terms with you and any other agreement;
- to protect the rights of Swish, or others, including to prevent fraud;
- with such third parties as we reasonably consider necessary in order to prevent crime, e.g. the police.
Where your information is stored
8.8 We store personal data in the European Union and in the United States. Our application infrastructure, including our Spanner database, file storage and analytics, runs in Google Cloud's European regions, and our email service sends through its European service. Our MongoDB Atlas database, and parts of the Swish API, are hosted in the United States.
International transfers of data
8.9 Because of this, some of the personal data we collect from you is processed or transferred outside the European Economic Area ("EEA"), to the United States. That applies to our own infrastructure in the United States and to any of the service providers named in section 8.3 that are established there. These countries may not have the same protections for personal data as the EEA has, which protection includes the General Data Protection Regulation ("GDPR"). We are obliged to ensure that personal data processed by us and our suppliers outside the EEA is protected in the same ways as it would be if it were processed within the EEA, and there are therefore safeguards in place when your data is processed outside the EEA.
8.10 We ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- your personal data is transferred to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission;
- where your personal data is transferred to a provider in the United States, that provider is certified under the EU-U.S. Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection; or
- we use the EU approved Standard Contractual Clauses.
9. SECURITY
9.1 We adopt robust technologies and policies to ensure the personal information we hold about you is suitably protected.
9.2 We take steps to protect your information from unauthorised access and against unlawful processing, accidental loss, destruction and damage.
9.3 Where you have chosen a password that allows you to access certain parts of the Platform, you are responsible for keeping this password confidential. We advise you not to share your password with anyone.
9.4 Unfortunately, the transmission of information via the internet is not completely secure. Although we will take steps to protect your information, we cannot guarantee the security of your data transmitted to the Platform; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
10. YOUR RIGHTS
Under data protection law, you may have a number of rights concerning the data we hold about you. If you wish to exercise any of these rights, please contact us using the contact details set out above. For additional information on your rights, please contact your data protection authority and see below.
10.1 The right to be informed. You have the right to be provided with clear, transparent and easily understandable information about how we use your information and your rights. This is why we’re providing you with the information in this policy.
10.2 The right of access. You have the right to obtain access to your information (if we’re processing it). This will enable you, for example, to check that we’re using your information in accordance with data protection law. If you wish to access the information we hold about you in this way, please get in touch (see Contact Details).
10.3 The right to rectification. You are entitled to have your information corrected if it is inaccurate or incomplete. You can request that we rectify any errors in information that we hold by contacting us (see Contact Details).
10.4 The right to erasure. This is also known as "the right to be forgotten" and, in simple terms, enables you to request the deletion or removal of certain information that we hold about you by contacting us (see Contact Details). Section 7.3 explains how we handle such a request.
10.5 The right to restrict processing. You have rights to "block" or "suppress" further use of your information. When processing is restricted, we can still store your information, but will not use it further.
10.6 The right to data portability. You have the right to obtain your personal information in an accessible and transferrable format so that you can re-use it for your own purposes across different service providers. This is not a general right however and there are exceptions. To learn more please get in touch (see Contact Details).
10.7 The right to lodge a complaint. You have the right to lodge a complaint about the way we handle or process your information with the national data protection authority.
10.8 The right to withdraw consent. If you have given your consent to anything we do with your information (i.e. we rely on consent as a legal basis for processing your information), you have the right to withdraw that consent at any time. You can do this by contacting us (see Contact Details). Withdrawing consent will not however make unlawful our use of your information while consent had been apparent.
10.9 The right to object to processing. You have the right to object to certain types of processing, including processing for direct marketing and profiling. You can object by changing your marketing preferences or disabling cookies as set out in sections 5 and 6 above.
11. CHANGES TO OUR PRIVACY POLICY
Any changes to our privacy policy will be posted to the Platform and, where appropriate, we will notify you of the changes for example by email or push notification.
12. COMPLAINTS
If you’re not satisfied with our response to any complaint or believe our processing of your information does not comply with data protection law, you can make a complaint to the Data Protection Commission, the supervisory authority in Ireland, using the following details:
Data Protection Commission
Postal Address
6 Pembroke Row
Dublin 2
D02 X963
Telephone
+353 (0)1 765 0100
1800 437 737
Website
www.dataprotection.ie