Privacy
Last updated 10 August 2026
Catalog Sentry compares what your Shopify store publishes against what Google and Meta actually hold. Doing that needs your catalogue. It does not need your customers, and it never asks for them.
The short version. The app requests two read-only permissions — read_products and read_publications. It cannot read customers, orders, or payment data, because it never requests access to them. It cannot change anything in your store, because it requests no write access at all.
What it reads
Product and variant identifiers, product titles, and whether each product is published to a given sales channel. From your connected channel accounts, it reads the catalogue those channels hold: item identifiers, their approval status, and the reasons a channel gives for rejecting an item.
What it stores
| Data | Why | Kept for |
|---|---|---|
| Channel settings — which publication represents a channel, your channel account id, the offer-id region | Without them the comparison cannot be made | Until you change or uninstall |
| Catalogue snapshots — item identifiers, grouping keys and status, with issue text discarded | Change detection is a comparison against yesterday. One snapshot cannot show that something changed | Rolling history |
| Open findings — what was raised, how many items, when first seen | So you are told once, not every night | Until resolved |
| A Shopify session token, and a Meta access token if you supply one | To read on your behalf | Revoked on uninstall |
What it does not store
No customer records. No orders. No payment or card data. No personal data about the people who buy from you — the app has no permission to see any of it.
Deletion
When you uninstall, your Shopify session is deleted immediately and any channel access token you gave us is erased at the same moment. Holding a live credential for a merchant who has just removed the app is indefensible, so it does not wait for anything.
Within 48 hours of uninstalling, Shopify sends a shop-redact request and everything else — settings, snapshots, findings — is deleted. You can also ask us to delete it sooner, at any time, and we will.
Shopify's two customer-data requests are implemented and answer as required. They have nothing to return or erase, because no customer data is ever collected.
Sharing
Your data is not sold, and it is not shared with anyone for advertising. It is processed only to produce your own findings. The app talks to Shopify and to the channel accounts you connect, and to nobody else on your behalf.
Who is responsible for what
For the catalogue data the app reads from your store, you are the controller and we are the processor: we process it only to produce your findings, only on your instructions, and only for as long as the app is installed. For our own records — the email address you give us, and the analytics described below — we are the controller.
Our lawful bases under the GDPR are performance of a contract (running the app you installed) and legitimate interests (keeping the service working and secure, and measuring how the site is used at an aggregate level). Where we rely on legitimate interests you may object, and we will stop unless we have compelling grounds not to.
Where it runs, and who else touches it
The app and its Postgres database run on Railway in the EU West region. The website and the free audit run on Vercel. Email to and from @catalogsentry.com is handled by Zoho Mail. If you submit your email address on this site, it is sent to a small intake service we operate on Railway. Traffic is encrypted in transit throughout.
Those are our only subprocessors. We will update this list before adding another. Where personal data leaves the EEA or the UK, it does so under the European Commission's Standard Contractual Clauses or an equivalent safeguard offered by the provider.
Analytics and cookies
This site uses Google Analytics 4 to count visits and see which pages are read. It is loaded with consent denied by default, which means it runs in a cookieless mode: no analytics cookies are written to your browser and no advertising identifiers are set unless you tell us otherwise. We collect no analytics inside the Shopify app at all.
The site sets no cookies of its own. The free audit stores nothing about you and requires no account.
Your rights
If you are in the EEA or the UK you may ask us for a copy of your personal data, ask us to correct or delete it, ask us to restrict or stop processing it, and ask for it in a portable form. Write to ohad@catalogsentry.com and we will answer within 30 days. You also have the right to complain to your local supervisory authority. Californian residents have equivalent rights of access and deletion under the CCPA, and we do not sell or share personal information as those terms are defined there.
The free audit on this site
The audit at the top of catalogsentry.com reads only what any visitor to a store can read — the public /products.json catalogue and one product page — and stores no catalogue content. If you give us an email address, it is used to tell you when the monitoring product ships, and for nothing else.
Contact
Questions, or a deletion request: ohad@catalogsentry.com.