Privacy
Last updated 10 August 2026
Catalog Sentry compares what your Shopify store publishes against what Google and Meta actually hold. Doing that needs your catalogue. It does not need your customers, and it never asks for them.
The short version. The app requests two read-only permissions — read_products and read_publications. It cannot read customers, orders, or payment data, because it never requests access to them. It cannot change anything in your store, because it requests no write access at all.
What it reads
Product and variant identifiers, product titles, and whether each product is published to a given sales channel. From your connected channel accounts, it reads the catalogue those channels hold: item identifiers, their approval status, and the reasons a channel gives for rejecting an item.
What it stores
| Data | Why | Kept for |
|---|---|---|
| Channel settings — which publication represents a channel, your channel account id, the offer-id region | Without them the comparison cannot be made | Until you change or uninstall |
| Catalogue snapshots — item identifiers, grouping keys and status, with issue text discarded | Change detection is a comparison against yesterday. One snapshot cannot show that something changed | Rolling history |
| Open findings — what was raised, how many items, when first seen | So you are told once, not every night | Until resolved |
| A Shopify session token, and a Meta access token if you supply one | To read on your behalf | Revoked on uninstall |
What it does not store
No customer records. No orders. No payment or card data. No personal data about the people who buy from you — the app has no permission to see any of it.
Deletion
When you uninstall, your Shopify session is deleted immediately and any channel access token you gave us is erased at the same moment. Holding a live credential for a merchant who has just removed the app is indefensible, so it does not wait for anything.
Within 48 hours of uninstalling, Shopify sends a shop-redact request and everything else — settings, snapshots, findings — is deleted. You can also ask us to delete it sooner, at any time, and we will.
Shopify's two customer-data requests are implemented and answer as required. They have nothing to return or erase, because no customer data is ever collected.
Sharing
Your data is not sold, and it is not shared with anyone for advertising. It is processed only to produce your own findings. The app talks to Shopify and to the channel accounts you connect, and to nobody else on your behalf.
Where it runs
On Railway, with a managed Postgres database. Traffic is encrypted in transit.
The free audit on this site
The audit at the top of catalogsentry.com reads only what any visitor to a store can read — the public /products.json catalogue and one product page — and stores no catalogue content. If you give us an email address, it is used to tell you when the monitoring product ships, and for nothing else.
Contact
Questions, or a deletion request: privacy@catalogsentry.com.