Negai Wishlist — Privacy Policy
Last updated: September 11, 2026
Negai Wishlist is operated by Hakori. Contact us at contact@hakori.fr for support or privacy requests. This policy describes the data used to save and recover wishlists, send price drop alerts and report wishlist activity.
1. Data we process
For merchants, we store the shop domain, store name, currency, installation credentials, subscription status and app settings. Shopify staff session records may include the staff member’s identifier, name and email.
For shoppers, we store wishlist names and saved products and variants, saved prices, country and currency context, customer identifiers when signed in, and email addresses supplied for saving or recovery or obtained through the customer account. We also store email verification status, alert preferences, access credentials and share links.
Analytics include wishlist activity, product identifiers and attributed order line identifiers, quantities, revenue, cancellations and refunds. Email delivery records contain the recipient, message content and delivery state. Operational records support request limits, webhook processing and security. Admin access logs contain the shop, route, date, result and staff identifier when supplied by Shopify.
2. How we use data
We use this information to save and recover lists, merge guest and customer lists, share lists at the shopper’s request, send verification emails and opted-in price drop alerts, enforce subscription limits and report wishlist activity. Purchase attribution is limited to products added to the cart from the wishlist using an attribution token valid for 30 days.
3. Service providers
The merchant controls the use of customer data in their store; Hakori processes wishlist data to provide the app. Shopify supplies store, product, customer account, subscription and order information. Railway hosts the application and database. Resend processes outgoing emails. These providers process information needed to deliver their services; processing locations depend on their infrastructure and service configuration.
4. Sharing and browser storage
Guest access credentials are kept in browser local storage so shoppers can return to their lists. Server-side access and email verification tokens are hashed. Email verification links expire after 30 minutes and are single use. Anyone holding an enabled shared-list link can view the selected list; the public shared-list response does not include the owner’s email. The owner can disable sharing.
5. Retention and deletion
Wishlist and associated records are retained while the store uses the app, so saved lists remain available between visits. Application email records and admin access logs are deleted after 90 days by the scheduled cleanup. Expired access tokens and email verification challenges are also removed. Wishlists and order analytics do not currently have an automatic inactivity expiry; their continued necessity is reviewed periodically. Token expiry limits access and is separate from record deletion. On a customer erasure request through Shopify, matching owners, lists, access tokens and associated email records are deleted, and owner links are removed from analytics and conversion records. On Shopify’s store-redaction event following uninstallation, shop-specific app records are deleted.
Contact the merchant or Hakori to request earlier access or erasure. Infrastructure logs and backups are subject to the hosting providers’ retention and deletion processes.
6. Your choices and requests
Saving a guest wishlist does not send a confirmation email. Recovering a private list on another device requires an email link or an authenticated customer account. Price drop alerts require opt-in and are limited to three per email address per store per day. Shoppers can turn alerts off from their wishlist or use the unsubscribe link in an alert. Merchants can use the app’s customer export workflow to respond to requests. For access, correction or erasure, contact the store or contact@hakori.fr. We may need to verify the request before acting.
7. Changes
We update this policy when the app’s data practices change. The date above identifies the latest revision.