Privacy Policy
Last updated 10 September 2026
SendWide is an email automation app for Shopify stores. To do that job it necessarily handles personal information belonging to your customers, on your behalf. This page sets out exactly what it touches and why.
Plain summary. We collect the minimum needed to send the email you asked us to send: an address, a name, and the order or checkout that triggered it. We never sell it, never share it with advertisers, and never use it to train AI models. You can have it deleted at any time.
1. Who is responsible for what
For your customers' personal information, you are the data controller and SendWide is a data processor acting on your instructions. We process it to deliver the service you configured and for no independent purpose of our own.
2. What we collect from your store
SendWide reads a deliberately narrow slice of your Shopify data. Shopify treats customer contact details as protected customer data, and we request the minimum level that makes the feature work.
| Customer email address | The core of the service. Without it no email can be delivered. |
|---|---|
| Customer name | Personalisation in message templates. |
| Marketing consent state | To determine whether a marketing send is permitted at all. |
| Order and checkout details | To trigger flows and populate message content — items, totals, currency, timestamps. |
| Email engagement events | Delivery, bounce, complaint, open and click, used for suppression and reporting. |
We do not request phone numbers or postal addresses, because nothing in the product needs them. We use Shopify's delivery filtering so that Shopify sends us less data in the first place, rather than sending everything and discarding the remainder.
3. What we never do
- We do not sell personal information, ever.
- We do not share it with advertising networks or data brokers.
- We do not use merchant or customer data to train machine-learning or AI systems. This is both our policy and a requirement of the Shopify Partner Program Agreement.
- We do not place tracking scripts on your storefront. SendWide is not present on your public site at all.
4. Where it is stored
Data is stored in Amazon Web Services in the Asia Pacific (Sydney) region, encrypted at rest and in transit. Each store's data is partitioned so that one store's records cannot be returned by a query for another's.
5. How long it is kept
- While installed: as long as needed to run your flows and reporting.
- On uninstall: sending stops immediately, and store data is deleted after the window Shopify requires for merchants who reinstall.
- Suppression records are the deliberate exception. When a customer is erased we retain a one-way hash of their address, never the address itself, so that someone who unsubscribed or complained is never emailed again. Keeping the effect without keeping the data is the point.
6. Your customers' rights
SendWide implements Shopify's mandatory privacy webhooks, so requests made through your Shopify admin reach us automatically:
- Data request — we return the personal information we hold for that customer.
- Customer erasure — we delete it, retaining only the hashed suppression record described above.
- Shop erasure — we delete the store's data after uninstall.
Customers can also unsubscribe from any marketing email with one click, with no login and no confirmation step. That takes effect immediately and permanently.
7. Sub-processors
| Amazon Web Services | Hosting, storage and email delivery (Amazon SES), Sydney region. |
|---|---|
| Shopify | Source of store data, and the platform the app runs inside. |
We will update this list before adding any new sub-processor that handles personal information.
8. Security
Encryption in transit and at rest; least-privilege access controls scoped per function; no long-lived deployment credentials; and customer email addresses are never written to application logs in plain text.
9. Breach notification
If a data breach occurs that is likely to result in serious harm, we will notify affected merchants and, where required, the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme.
10. Contact
Privacy questions, data requests and complaints: privacy@sendwide.app. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner.
SendWide, New South Wales, Australia. A full postal address is included in every marketing email we send on your behalf, as the Spam Act 2003 requires.
11. Changes
Material changes will be notified to installed merchants before taking effect. The date at the top of this page always reflects the current version.