Privacy Policy
Last updated: 16 July 2026
This Privacy Policy explains how Catamend (“Catamend”, “we”, “us”) collects, uses, discloses, and safeguards information when you install and use the Catamend application (the “Service”) on your Shopify store. By installing or using the Service you agree to this Policy.
1. Who we are
Catamend is a Shopify catalog health scanner and operations inbox. The data controller for the purposes of applicable data protection law is Catamend, Dubai, United Arab Emirates. For any privacy question, contact info@catamend.com.
2. Information we collect
We collect only what we need to provide the Service and process it strictly on a per-store, tenant-isolated basis.
Store & catalog data (via the Shopify Admin API)
- Store profile: shop domain, store name, primary email, plan, currency, and locations, used to configure and contact your account.
- Catalog data: products, variants, images, SKUs, pricing, SEO fields, inventory levels, and related metadata — read to run health checks and, where you explicitly authorize a fix, written back to your catalog.
We request the minimum OAuth scopes needed (read_products, write_products, write_files, read_inventory, read_locations). We do not request access to customer personal data or order data.
Account & billing data
- Subscription state (plan, status, trial and renewal dates). Payments are processed by Shopify through the Shopify Billing API; we never see or store your card details — Shopify handles payment under its own terms and privacy policy.
Usage & technical data
- Application logs, scan and fix history, and diagnostic events used to operate, secure, and improve the Service.
- A session cookie strictly necessary to keep you signed in to the embedded app inside Shopify Admin.
Website analytics
- On our public website only (catamend.com — the marketing, free-audit, guide and legal pages) we use Google Analytics 4 to measure aggregate traffic: pages viewed, approximate location derived from IP, referring source, device and browser type. We do not use it to identify you personally, and we do not run advertising or remarketing tags.
- Analytics cookies are set only after you accept them in the consent banner. If you decline, or simply ignore the banner, no analytics cookie is written and Google receives only anonymous, cookieless page counts. You can change your mind at any time by clearing this site’s data in your browser, which restores the banner.
- Google Analytics is not loaded inside the embedded app in Shopify Admin. Your catalog data, findings, and how you use the app as a merchant are never sent to Google.
3. How we use information
- Provide the Service: scan your catalog, surface findings, and apply the fixes you authorize.
- Send operational notifications you enable (scan summaries, weekly digests, and sync-failure alerts).
- Maintain a before/after audit history so changes are transparent and reversible in your records.
- Bill your subscription, prevent abuse, secure the Service, and provide support.
- Comply with legal obligations.
We do not sell your data, and we do not use your catalog data to train machine-learning models or for advertising.
4. Service providers (sub-processors)
We share data only with vetted providers who process it on our behalf to run the Service:
| Provider | Purpose |
|---|---|
| Shopify | The platform your store and catalog data originate from, and the processor for subscription billing (Shopify Billing API). |
| Vercel | Application hosting and delivery. |
| Neon | Managed PostgreSQL database storage. |
| Resend | Delivery of transactional email notifications. |
| Sentry | Application error and performance monitoring (diagnostic event data) to help us keep the Service reliable. |
| Google Analytics | Aggregate traffic measurement on the public website only, and only with your consent. Not used inside the embedded Shopify app, and never receives your catalog or customer data. |
5. Data retention & deletion
- We retain your data for as long as the app is installed and you have an account with us.
- When you uninstall the app, we stop processing and delete or anonymize your store data within 30 days, except where we are legally required to retain it.
- We honor Shopify’s mandatory GDPR webhooks —
shop/redact,customers/redact, andcustomers/data_request— to erase data or produce a data report on request.
6. Security
Data is encrypted in transit (TLS) and access is scoped per store with strict tenant isolation. We restrict internal access on a need-to-know basis. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard measures.
7. International transfers
Our providers may process data in regions including the United States and the European Union. Where data is transferred across borders, we rely on appropriate safeguards such as Standard Contractual Clauses.
8. Your rights
Depending on your location (e.g. under GDPR or the CCPA), you may have the right to access, correct, delete, or port your data, and to object to or restrict certain processing. To exercise these rights, contact info@catamend.com. You may also lodge a complaint with your local supervisory authority.
9. Children
The Service is intended for businesses and is not directed to individuals under 16. We do not knowingly collect personal data from children.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notifying you in-app or by email.
11. Contact
Questions about this Policy or your data? Email info@catamend.com or write to Catamend, Dubai, United Arab Emirates.