Privacy policy

Last updated: August 6, 2026

Catalog Guardian operates Catalog Guardian. This policy explains how the app processes information when a Shopify merchant installs or uses it.

Information we process

We process the shop domain, Shopify authorization and session data, product catalog fields selected for auditing, scan findings, fix history, subscription status, and operational logs. The app does not request or store customer, order, payment, or checkout data.

Purposes and sharing

Information is used to authenticate the shop, audit and repair catalog data, enforce plan limits, prevent abuse, troubleshoot incidents, and meet legal obligations. It is shared only with Shopify and infrastructure providers required to operate the service, or when legally required. We do not sell personal information or use product data for advertising.

AI-draft generation

On the Pro plan and above, merchants can generate a search-listing draft for a product. Only when a merchant uses this feature does the app send the product title, vendor, product type, and description to a third-party AI provider to produce the draft. No other product data is transmitted, drafts are reviewed and approved by the merchant before any change is made, and the feature is never used without the merchant starting it.

The AI provider is selected by the app operator: OpenAI (OpenAI API) or DeepSeek (DeepSeek API). The selected provider processes the submitted product fields solely to generate the requested draft and does not receive Shopify account, session, customer, or payment data. We do not use the feature to train models, and we configure generation to disable reasoning-side processing where the provider exposes that control. Data submitted to the provider is subject to the provider's own terms and privacy policy, including its data-retention and (where applicable) cross-border processing practices; merchants who are subject to additional data-transfer obligations (such as GDPR or PIPL) should confirm the provider's terms before enabling the feature.

Retention and security

Catalog scans, findings, and fix history are retained for 90 days. Shop-scoped application records and sessions are deleted when the app is uninstalled or when Shopify sends a shop redaction request. Short-lived operational backups and logs may remain until their normal secure expiry. We use encrypted transport, least-privilege access, authenticated webhooks, and audited application changes.

Your choices

Store owners can uninstall the app to stop processing. For access, correction, deletion, or privacy questions, contact [email protected]. We may need to verify that the requester controls the relevant Shopify store.

Return to Catalog Guardian