Privacy Policy

What Catalyst Catalogue Sync processes, why, how long it is kept, and what we deliberately do not collect.

Last updated 18 August 2026

Who this covers

Cart Catalyst provides a Shopify application that publishes catalogue data into merchant stores and reports on how products sell. This policy covers data we process on behalf of merchants who install the app, including data relating to their customers.

For that customer-related data the merchant is the data controller and we are a processor: we act on the merchant's instructions and do not use the data for our own purposes beyond what is described here.

What we process

DataWhyPersonal data?
Shop domain, install date, access tokenAuthenticate to the Shopify API on the store's behalfNo
Store configuration — channels, product selection, sync rules, pricing tiersDecide what to publish into the storeNo
Order id, line id, product, variant, quantity, unit price, kit id, sale timestampReport which products sell together as kits or bundlesYes — an order id can be linked back to a person
Monthly per-store, per-product totalsLong-term reporting and benchmarkingNo — carries no order, line or kit id
Record of a data request or deletion request: the shop, the Shopify request id, and the customer and order ids it namedEvidence that a legal request was received and acted onYes — while the ids are held
What we deliberately do not collect
We do not receive or store customer names, email addresses, phone numbers, or shipping and billing addresses. We do not request those fields from Shopify. This is a design decision, not a default: the app never contacts customers, so it has no reason to hold their contact details.

How long we keep it

DataRetention
Order-derived records (order id, line id, product, price, quantity, kit id)730 days (about 24 months), then permanently deleted
Monthly aggregate totalsRetained indefinitely. These contain no identifiers that can be linked to a person.
Access tokens and store configurationUntil the app is uninstalled, then deleted on request or within 30 days
Records of data and deletion requestsRetained as proof of compliance. The customer and order ids they name are erased after 730 days, leaving only the fact that the request was received and completed.

Deletion of order-derived records runs automatically each night. Aggregates are computed before deletion, so reporting continues without retaining the underlying personal data.

Cross-store benchmarking

We compare aggregate product performance across the stores that subscribe to a directory, so that merchants can see how their results compare — for example, how often a part is bought as part of a kit rather than on its own.

What is and is not shared
Benchmarks are computed only from the monthly aggregates described above, never from order-level records. No merchant is ever shown another merchant's identity, order counts, revenue, or customer data — only directory-wide averages. A store can be excluded from these aggregates at any time from its app settings, without affecting its own reporting.

A directory-wide figure is only shown to merchants once enough separate stores have contributed to it that it is a genuine average rather than a small number of stores' results. Below that point the figure is visible only to Cart Catalyst staff, who use it to operate the directory. We do not state the exact threshold, because knowing it would help work backwards from a published figure to the stores behind it.

Each month's figures are computed once, 5 days after the month ends, and then fixed. Opting out applies to every month not yet published; see the Merchant Terms for what that means and how to request removal from earlier months.

Who else processes it

We use the following sub-processors. We do not sell personal data, and we do not share it with third parties for their own purposes.

Sub-processorPurposeLocation
SupabaseDatabase hostingAWS, US West (Oregon)
VercelApplication hosting and scheduled jobsUnited States
ShopifySource of the data we receive, on your instructionGlobal

Security

Requests and deletion

Shopify's customer data request, customer redaction, and shop redaction webhooks are implemented and honoured. Because we hold no customer contact details, a customer data request will usually return only the order-derived records described above. Merchants and their customers can also contact privacy@cartcatalyst.com directly.


Questions about this document: privacy@cartcatalyst.com