Privacy Policy
What Catalyst Catalogue Sync processes, why, how long it is kept, and what we deliberately do not collect.
Last updated 18 August 2026
Who this covers
Cart Catalyst provides a Shopify application that publishes catalogue data into merchant stores and reports on how products sell. This policy covers data we process on behalf of merchants who install the app, including data relating to their customers.
For that customer-related data the merchant is the data controller and we are a processor: we act on the merchant's instructions and do not use the data for our own purposes beyond what is described here.
What we process
| Data | Why | Personal data? |
|---|---|---|
| Shop domain, install date, access token | Authenticate to the Shopify API on the store's behalf | No |
| Store configuration — channels, product selection, sync rules, pricing tiers | Decide what to publish into the store | No |
| Order id, line id, product, variant, quantity, unit price, kit id, sale timestamp | Report which products sell together as kits or bundles | Yes — an order id can be linked back to a person |
| Monthly per-store, per-product totals | Long-term reporting and benchmarking | No — carries no order, line or kit id |
| Record of a data request or deletion request: the shop, the Shopify request id, and the customer and order ids it named | Evidence that a legal request was received and acted on | Yes — while the ids are held |
How long we keep it
| Data | Retention |
|---|---|
| Order-derived records (order id, line id, product, price, quantity, kit id) | 730 days (about 24 months), then permanently deleted |
| Monthly aggregate totals | Retained indefinitely. These contain no identifiers that can be linked to a person. |
| Access tokens and store configuration | Until the app is uninstalled, then deleted on request or within 30 days |
| Records of data and deletion requests | Retained as proof of compliance. The customer and order ids they name are erased after 730 days, leaving only the fact that the request was received and completed. |
Deletion of order-derived records runs automatically each night. Aggregates are computed before deletion, so reporting continues without retaining the underlying personal data.
Cross-store benchmarking
We compare aggregate product performance across the stores that subscribe to a directory, so that merchants can see how their results compare — for example, how often a part is bought as part of a kit rather than on its own.
A directory-wide figure is only shown to merchants once enough separate stores have contributed to it that it is a genuine average rather than a small number of stores' results. Below that point the figure is visible only to Cart Catalyst staff, who use it to operate the directory. We do not state the exact threshold, because knowing it would help work backwards from a published figure to the stores behind it.
Each month's figures are computed once, 5 days after the month ends, and then fixed. Opting out applies to every month not yet published; see the Merchant Terms for what that means and how to request removal from earlier months.
Security
- Data is encrypted at rest and in transit.
- Database access requires service credentials; row-level security is enabled on every table and no anonymous access policy exists.
- Access tokens are stored only for stores with the app installed and are removed when it is uninstalled.
- Scheduled jobs authenticate with a shared secret and refuse to run if it is not configured.
Requests and deletion
Shopify's customer data request, customer redaction, and shop redaction webhooks are implemented and honoured. Because we hold no customer contact details, a customer data request will usually return only the order-derived records described above. Merchants and their customers can also contact privacy@cartcatalyst.com directly.
Questions about this document: privacy@cartcatalyst.com