Giftpin · Gift Registry for Shopify
Giftpin is a gift-registry app for Shopify stores. This page explains what information the app and its browser extension handle, why, and what happens to it — for merchants who install Giftpin, and for the guests who use a registry it creates.
Giftpin is installed by a merchant on their Shopify store. A registrant (the person the registry is for) creates and manages a registry through the merchant's storefront. A guest views a registry link, claims, and buys gifts. This policy covers all three, and applies wherever Giftpin operates — the Shopify app itself, the guest-facing registry page, and the optional browser extension.
When a registrant creates a registry, Giftpin stores what they enter directly: names, an event label and date, an optional message and cover image, and any items they add. If ship-to-registrant is used, it stores the shipping address the registrant enters into Giftpin's own form — never one pulled from a Shopify customer record.
A registry's guest-facing page is deliberately minimal: it shows first names only, never a registrant's surname, email, phone number, or address.
When a guest claims or buys an item, Giftpin records that a claim/purchase happened and, where the checkout provides it, a first name to attribute the gift to ("From Taylor") — not a full identity profile of the guest.
If a guest asks for a reminder before the event, Giftpin stores the email address they enter, encrypted, uses it only for that one reminder, and deletes it once the event has passed. Every reminder has a one-click unsubscribe link.
Giftpin's core feature is letting a registry hold gifts from any store, not only the merchant's. For an item from another site, Giftpin reads that page's own publicly displayed information — title, image, price — the same data shown to any visitor, via the page's standard product metadata (JSON-LD, Open Graph, or similar). This is read-only display data:
Giftpin's optional browser extension reads the current page's already-rendered product information only when a registrant clicks the extension icon — never in the background, never on pages they don't actively choose. It sends what it reads to the registrant's own registry, authenticated by the same private "manage" link/token the registrant already has; the extension introduces no separate login or credential. Its only network permission is to the merchant's own Shopify store domain — it does not send data anywhere else.
To attribute a purchase back to the right registry item — including
through Shop Pay, Apple Pay, Google Pay, or the Shop app — Giftpin
receives the merchant's orders/create webhook. From it,
Giftpin uses:
Giftpin does not read or store a buyer's email address, phone number, or street address from Shopify. When a registrant has turned on ship-to-registrant, Giftpin writes the address the registrant entered into Giftpin's own form onto the matching order, and reads only that order's country and province/state code to check that the new address is in the same tax jurisdiction before changing it.
Giftpin keeps personal data only as long as it is needed. A daily automated job removes data once it passes these limits:
When a merchant uninstalls Giftpin, Shopify sends a
shop/redact request 48 hours later and Giftpin erases all
of that store's data; if that request never arrives, Giftpin erases the
store's data itself 30 days after uninstall. When a customer asks a
merchant to erase their data, Shopify sends
customers/redact and Giftpin erases that customer's
registries and buyer details. Encrypted database backups kept by our
database provider roll off on the provider's own schedule, and deleted
data is not restored into the live service.
Data moves over encrypted connections (HTTPS) end to end, and our managed database provider encrypts stored data at rest. On top of that, registrant email addresses and shipping addresses are encrypted by Giftpin itself (AES-256-GCM) before they are stored, and registry passwords are stored only as salted hashes. A registry's "manage" access is protected by a private, unguessable token rather than a shared password — treat that link the way you'd treat a password, and don't share it publicly.
Test and production data are kept in separate databases. Access to production systems is limited to the developer, and Giftpin keeps an audit log of each time the app itself decrypts or exports personal data (for example, to send a registrant an email or to answer a data request). Giftpin maintains a written security incident response plan. If personal data in Giftpin's care is confirmed to have been exposed, affected merchants will be told without undue delay and no later than 72 hours after confirmation, with what happened, what data was involved, and what we are doing about it.
For personal data about a merchant's customers that Giftpin handles on the merchant's behalf, Giftpin acts as the merchant's service provider (a "processor"), and the merchant remains the controller. By installing Giftpin, the merchant and Giftpin agree that:
customers/data_request,
customers/redact and shop/redact webhooks
(Giftpin's response to a data request is prepared within the 30-day
window Shopify sets).Giftpin is not directed at children and is not knowingly used to collect information from anyone under 13.
A registrant can edit or delete registry items, or ask to have their registry removed entirely, at any time through their manage link or by contacting us below. Depending on where you live, you may have additional rights over your personal data (for example, under GDPR or CCPA/CPRA) — contact us to exercise them.
If this policy changes in a way that affects what data is collected or how it's used, the effective date at the top of this page will be updated. Material changes will be noted to merchants through the Shopify Partner Dashboard or the app itself.
Questions about this policy or your data can be sent to privacy@giftpin.app.