Data Processing Addendum

Wishlist Power Data Processing Addendum

This Data Processing Addendum (the "DPA") forms part of the Wishlist Power Terms of Service and any other agreement governing a merchant’s installation of and access to Wishlist Power (collectively, the "Agreement"). It is entered into between:

  • the Shopify merchant that installs or uses Wishlist Power ("Customer"); and
  • Maestrooo SAS, 11 rue René Goscinny, 75013 Paris, France ("Maestrooo").

This DPA applies where Maestrooo processes Personal Data on behalf of Customer in connection with Wishlist Power. By accepting the Agreement, installing or using Wishlist Power, Customer enters into this DPA on behalf of itself and, where applicable, its authorised affiliates.

If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA prevails.

1. Definitions

For this DPA:

  • "Applicable Data Protection Law" means the laws applicable to the processing of Customer Personal Data under the Agreement, including Regulation (EU) 2016/679 (the "GDPR").
  • "Customer Personal Data" means Personal Data processed by Maestrooo on behalf of Customer through Wishlist Power.
  • "Personal Data," "Controller," "Processor," "Data Subject," "Processing," "Personal Data Breach" and "Supervisory Authority" have the meanings given to them by Applicable Data Protection Law.
  • "Services" means the Wishlist Power application and related services provided by Maestrooo.
  • "Subprocessor" means a third party engaged by Maestrooo to process Customer Personal Data on behalf of Customer in connection with the Services.

2. Roles and scope

2.1. Customer is the Controller of Customer Personal Data and Maestrooo is the Processor, except where Applicable Data Protection Law provides otherwise.

2.2. Customer determines the purposes and essential means of the processing. Maestrooo processes Customer Personal Data only to provide, secure, maintain and support the Services, and as further described in Annex 1.

2.3. Customer is responsible for:

  • ensuring that its instructions comply with Applicable Data Protection Law;
  • providing all required notices and obtaining any required permissions or consents from Data Subjects;
  • ensuring that its use and configuration of the Services is lawful; and
  • not submitting special-category or other sensitive Personal Data to the Services unless expressly agreed in writing with Maestrooo.

3. Documented instructions

3.1. Maestrooo will process Customer Personal Data only on Customer’s documented instructions, including with regard to international transfers, unless processing is required by Union or Member State law. The Agreement, this DPA, Customer’s configuration and use of the Services, and Customer’s written support requests constitute documented instructions.

3.2. If Maestrooo is legally required to process Customer Personal Data other than on Customer’s instructions, Maestrooo will inform Customer before processing unless the applicable law prohibits that information on important grounds of public interest.

3.3. Maestrooo will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Maestrooo may suspend the affected processing until Customer modifies or confirms the instruction.

4. Confidentiality

Maestrooo will ensure that persons authorised to process Customer Personal Data:

  • are subject to an appropriate duty of confidentiality;
  • receive access only where necessary for their responsibilities; and
  • process Customer Personal Data only in accordance with this DPA and Customer’s documented instructions.

5. Security

5.1. Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, Maestrooo will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

5.2. The current measures are described in Annex 2. Maestrooo may update those measures provided that the overall level of protection is not materially reduced.

6. Subprocessors

6.1. Customer gives Maestrooo general written authorisation to engage the Subprocessors identified in Annex 3.

6.2. Maestrooo will provide notice of an intended addition or replacement of a Subprocessor that may process Customer Personal Data, normally by updating the published Subprocessor list or by email where available, at least 30 days before the change takes effect where reasonably practicable. Customer may object during that period on legitimate data-protection grounds.

6.3. If Customer makes a reasonable objection and the parties cannot resolve it, Maestrooo may offer a commercially reasonable configuration that avoids the relevant Subprocessor. If no such alternative is reasonably available, either party may terminate the affected Services in accordance with the Agreement.

6.4. Maestrooo will enter into a written agreement with each Subprocessor that imposes data-protection obligations substantially equivalent to those applicable to Maestrooo under this DPA, to the extent relevant to the services performed by that Subprocessor.

6.5. Maestrooo remains responsible to Customer for the performance of its Subprocessors’ data-protection obligations as required by Applicable Data Protection Law.

7. Assistance with Data Subject requests

7.1. Taking into account the nature of the processing, Maestrooo will provide reasonable assistance to Customer through appropriate technical and organisational measures to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

7.2. If Maestrooo receives a request directly from a Data Subject concerning Customer Personal Data, Maestrooo will, where legally permitted, direct the Data Subject to Customer or notify Customer. Maestrooo will not independently respond to the substance of the request unless instructed by Customer or required by law.

7.3. Wishlist Power supports Shopify’s mandatory privacy webhooks for customer data access and deletion requests. Customer may also contact Maestrooo at app-wishlist-power@maestrooo.com for assistance.

8. Personal Data Breaches and compliance assistance

8.1. Maestrooo will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2. To the extent reasonably available, the notification will describe:

  • the nature of the breach;
  • the categories and approximate number of affected Data Subjects and records;
  • the likely consequences; and
  • the measures taken or proposed to address and mitigate the breach.

Information may be provided in phases where it is not possible to provide it at the same time. A notification does not constitute an acknowledgement of fault or liability.

8.3. Taking into account the nature of the processing and the information available to Maestrooo, Maestrooo will reasonably assist Customer with its obligations under Articles 32 to 36 GDPR, including security assessments, breach notifications, data protection impact assessments and prior consultation with Supervisory Authorities.

9. Deletion and return

9.1. Customer Personal Data used for live wishlist functionality is retained while the Services remain installed and active, subject to Customer’s instructions and the retention schedule in Annex 4.

9.2. Following uninstall or termination, Maestrooo retains Customer Personal Data in active systems for a 30-day grace period so that wishlist data can be restored if Customer reinstalls the Services. If Customer reinstalls during that period, the scheduled deletion is cancelled. If Customer does not reinstall, deletion begins promptly after the grace period expires. A valid Shopify shop-redaction request records the deletion requirement and is completed within the period required by Shopify and Applicable Data Protection Law, unless Applicable Law requires retention.

9.3. Maestrooo will process a valid individual customer-deletion request without undue delay after receiving the applicable Shopify privacy webhook or Customer’s verified written instruction.

9.4. Customer Personal Data contained in backups will be deleted through the ordinary backup-expiration cycle within 30 days and will remain protected and unavailable for ordinary use until deletion.

9.5. At Customer’s choice and where technically feasible, Maestrooo will return or make available Customer Personal Data before deletion. Maestrooo may retain information where Union or Member State law requires it, in which case Maestrooo will isolate and protect the retained information and process it only for the legally required purpose.

10. Information and audits

10.1. Maestrooo will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the security measures in Annex 2 and relevant third-party compliance materials.

10.2. Customer may request a reasonable audit of Maestrooo’s compliance with this DPA. Audits must:

  • be conducted on reasonable prior written notice;
  • take place no more than once in any 12-month period, unless required by a Supervisory Authority or following a material Personal Data Breach;
  • be limited to systems and information relevant to Customer Personal Data;
  • avoid unreasonable interference with Maestrooo’s operations; and
  • protect the confidentiality and security of other customers and Maestrooo’s systems.

10.3. The parties will first use available documentation and remote responses where these can reasonably satisfy the request. Customer is responsible for its audit costs, and Maestrooo may charge reasonable costs for assistance exceeding the ordinary scope of the Services, unless the audit identifies a material breach by Maestrooo.

10.4. Maestrooo will inform Customer if it believes an audit instruction infringes Applicable Data Protection Law or would compromise another customer’s confidentiality or the security of the Services.

11. International transfers

11.1. The primary Wishlist Power production infrastructure and database are hosted in the AWS Europe (Paris) region, France.

11.2. Some supporting providers may process limited Customer Personal Data outside the European Economic Area. Maestrooo will ensure that any restricted transfer is supported by a lawful transfer mechanism, such as:

  • an adequacy decision adopted by the European Commission;
  • the EU–US Data Privacy Framework where the recipient is validly certified and the framework applies; or
  • the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914, together with supplementary measures where required.

11.3. Information about current processing locations and transfer mechanisms is set out in Annex 3. On reasonable request, Maestrooo will provide further information about applicable transfer safeguards, subject to confidentiality restrictions.

12. Liability and order of precedence

12.1. Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, to the extent permitted by Applicable Data Protection Law.

12.2. Nothing in this DPA limits any rights of Data Subjects or Supervisory Authorities that cannot lawfully be limited.

12.3. If this DPA conflicts with the Standard Contractual Clauses applicable to a restricted transfer, the Standard Contractual Clauses prevail for that transfer.

13. Duration and termination

This DPA remains in effect for as long as Maestrooo processes Customer Personal Data on Customer’s behalf. Provisions that by their nature must survive termination—including confidentiality, deletion, audit and international-transfer obligations—will continue to apply until all Customer Personal Data has been deleted or returned in accordance with this DPA.

14. Contact

Questions and requests relating to this DPA may be sent to:

Maestrooo SAS
11 rue René Goscinny
75013 Paris, France
Email: app-wishlist-power@maestrooo.com


Annex 1 — Details of processing

Item Description
Subject matter Provision of Wishlist Power, including creation, storage, display, synchronisation and management of customer wishlists and related merchant-enabled functionality.
Duration For the term of Customer’s use of the Services and the limited deletion periods described in Annex 4.
Nature of processing Receiving, recording, organising, storing, retrieving, consulting, displaying, associating, updating, transmitting where instructed, restricting and deleting Customer Personal Data.
Purposes Providing wishlist functionality; associating wishlists with registered or guest shoppers; displaying wishlist information to Customer; maintaining wishlist product information; enabling Customer-configured integrations and alerts; providing support; protecting and maintaining the Services; and complying with lawful privacy requests.
Data Subjects Customers and prospective customers of the Shopify merchant, including registered and guest shoppers.
Persistently stored personal data Shopify customer ID; pseudonymous guest wishlist identifier; wishlist name and public/private sharing status; wishlist product and variant identifiers; wishlist contents; wishlist creation and update times; and wishlist activity such as product additions and removals.
Personal data accessed but not stored in the primary Wishlist Power database Customer first and last name may be retrieved from Shopify and displayed to authorised merchant users. Customer email may be retrieved for merchant-enabled Klaviyo alerts and wishlist imports. Import and result files may temporarily store customer IDs, email addresses, product and variant identifiers, dates and validation results in Amazon S3 for up to 30 days. Shopify privacy-request payloads may include customer identifiers, email address and phone number. Operational and security telemetry may include IP address, browser user-agent, request path and error context. These fields are not stored as customer profile fields in Wishlist Power’s primary database.
Data not intentionally collected for the wishlist service Wishlist Power does not intentionally collect shopper geolocation or use IP addresses or browser details to provide wishlist functionality. Infrastructure and approved service providers may process limited IP address, browser user-agent, request-path and error information for security, troubleshooting and operational monitoring.
Special-category data None intended. Customer must not submit special-category data through the Services.
Frequency Continuous or as initiated by Customer, its Shopify store, or a Data Subject using the wishlist.

Wishlist product identifiers and item counts for registered shoppers may be written to Shopify customer metafields, and customer and product identifiers may be sent to Shopify Flow, under Customer’s direction. If Customer enables Klaviyo, Google Analytics 4, Meta Pixel or TikTok Pixel, relevant customer, wishlist, product or event information may be transmitted to Customer’s own account with that provider. Maestrooo does not store customer names or email addresses in Wishlist Power’s primary database.

Annex 2 — Technical and organisational measures

Maestrooo maintains measures appropriate to the risks presented by the processing, including:

1. Infrastructure and encryption

  • Production application infrastructure and the production database are hosted in the AWS Europe (Paris) region.
  • Customer Personal Data is encrypted at rest in the production database, Amazon S3 storage and backups.
  • External network communications are protected using HTTPS/TLS.
  • Connections to the production database are protected in transit.
  • Secrets and production credentials are stored separately from application source code using access-controlled secret-management facilities.

2. Access control

  • Production administrative access is protected by multi-factor authentication.
  • Access is granted according to least-privilege principles and limited to personnel who require it for their responsibilities.
  • Access rights are reviewed and can be revoked when no longer required.
  • Personnel with authorised access are subject to confidentiality obligations.

3. Environment separation

  • Development, staging and production environments are logically separated.
  • Production access and credentials are not used for ordinary development activities.

4. Operational security

  • Security and operational logs are used to monitor the availability and security of the Services.
  • Software dependencies and application components are regularly reviewed and updated.
  • Identified security deficiencies are assessed and remediated according to risk.
  • Subprocessors are selected with regard to their ability to provide appropriate data-protection and security safeguards.

5. Data minimisation and deletion

  • Wishlist Power’s primary database stores Shopify customer identifiers and wishlist records but does not persist customer names or email addresses.
  • Access to Shopify customer information is limited to the functions for which it is required.
  • Customer and store deletion requests are processed using Shopify’s mandatory privacy mechanisms and Maestrooo’s deletion procedures.
  • Partial import files are removed as the import workflow completes. Completed import result files are automatically deleted after 30 days.

Annex 3 — Subprocessors and processing locations

The following providers support Wishlist Power. The data actually processed by a provider depends on Customer’s configuration and use of the Services.

Provider Purpose Principal processing location Data and safeguards
Amazon Web Services EMEA SARL and affiliates Application hosting, database, object storage, queues, backups, logging and secret management France — AWS Europe (Paris), eu-west-3; limited global support processing may occur under AWS contractual safeguards Shopify customer identifiers, guest identifiers, wishlist records, product data, operational logs and encrypted backups. Restricted transfers are governed by AWS’s DPA and applicable SCCs or adequacy mechanisms.
Mixpanel, Inc. Product analytics and application experience monitoring European Union data residency; limited processing by Mixpanel or its subprocessors may occur in the United States or other published locations Merchant application usage and merchant identifiers. Production session replay is configured so that shopper personal and sensitive information is not captured. The production Mixpanel project uses EU data residency. Mixpanel relies on the EU–US Data Privacy Framework and EU SCCs where applicable for any restricted support or subprocessor transfers. Retention: two years.
Mantle RevOps Inc. Merchant subscription, entitlement, usage and business analytics Canada and locations used by Mantle’s published subprocessors Merchant store identifiers, plan, feature and aggregate usage information; Wishlist Power does not intentionally send customer wishlist contents to Mantle. Transfers rely on applicable adequacy decisions or contractual safeguards. Retention: two years.
Help Scout PBC Merchant support communications and documentation United States, hosted on AWS Merchant support contact details and support content supplied by Customer. Customers should not include unnecessary shopper Personal Data in support messages. Restricted transfers are protected under Help Scout’s DPA and applicable transfer safeguards.
Slack Technologies, LLC and affiliates Operational and security notifications United States and other locations described by Slack Merchant shop domain, operational and error context, and Shopify privacy-webhook information. Depending on the webhook or error, this may include customer identifiers, email address, phone number, IP address or browser user-agent. Access is limited to authorised Maestrooo personnel. Restricted transfers are protected under Slack’s DPA and applicable transfer safeguards.
Twenty CRM, operated by Maestrooo Internal merchant relationship and entitlement management France Merchant store and commercial account information. Wishlist contents and customer names or emails are not intentionally stored in Twenty CRM. Because the service is operated by Maestrooo, it is not an independent third-party Subprocessor.

Customer-directed integrations

If Customer enables Klaviyo, Google Analytics 4, Meta Pixel or TikTok Pixel, Wishlist Power may transmit relevant customer, wishlist, product or event information to Customer’s own account with that provider. Customer may also direct Wishlist Power to store wishlist product identifiers and item counts in Shopify customer metafields or send customer and product identifiers to Shopify Flow. These integrations are selected and independently configured by Customer and are governed by Customer’s agreements with the applicable providers. They are not appointed by Maestrooo as general Subprocessors for the core Wishlist Power service.

Annex 4 — Retention schedule

Data category Retention
Live customer and guest wishlist records While Wishlist Power remains installed and active, unless deleted earlier on Customer’s instruction or in response to a valid Data Subject request.
Store and customer data after uninstall Retained for a 30-day reinstall grace period after uninstall. Reinstallation during that period cancels deletion. Otherwise, deletion begins promptly after the grace period and is completed during the next scheduled cleanup cycle.
Individual customer deletion requests Processed without undue delay after receipt of Shopify’s valid privacy webhook or Customer’s verified instruction.
Database and encrypted backups Backups expire and are deleted within 30 days.
API Gateway access logs Seven days.
Failed background-job messages Up to 14 days.
Wishlist import files Partial working files are deleted as the workflow completes. Completed import result files are automatically deleted after 30 days.
Slack operational and security notifications Up to 30 days, unless a longer period is required to investigate a security incident or comply with law. Access remains limited to authorised Maestrooo personnel.
Mixpanel and Mantle analytics Two years.
Help Scout support conversations Up to three years after the support conversation is closed, then deleted or anonymised, unless a longer period is required by law or necessary for an unresolved legal claim. Verified deletion requests are handled earlier where required by Applicable Data Protection Law. Customer should not submit unnecessary shopper Personal Data in support conversations.

Where Maestrooo is legally required to retain particular information for a longer period, that information will be isolated, protected and processed only for the legally required purpose.