Catalogwright

Privacy

Last updated 2026-09-27

What Catalogwright does with the data of the stores you connect to it, in plain words.

What we read

From a store you connect: its catalogue and content (products, collections, pages and the like), its customers and its orders. For a customer that means their name, email, phone, addresses, marketing consent, and how many orders they placed and for how much. We never read passwords.

Why

To show a store's records to that store's own team, to compare them with another of the team's stores, and to copy them to a store the same team chooses.

What we never do

  • Sell it or share it with anyone else.
  • Use it for marketing.
  • Make automated decisions about a person. A customer's marketing consent is copied as the store recorded it and never changed.

How long we keep it

  • A connected store's current records: for as long as the store is connected.
  • Past versions of customers and orders, and the copies kept so a change can be put back: 90 days.
  • A disconnected store's customers and orders, with their past versions and the copies kept to put its changes back: 30 days after it was disconnected, however recent they are.
  • Everything about a shop: removed about 48 hours after the app is uninstalled, when Shopify asks us to.

Where it lives

In a PlanetScale Postgres database in the EU. It is encrypted when stored and when it travels. The keys that let us reach your store are encrypted a second time on top of that.

Who sees it

Only the members of the organization that connected the store. Every time someone opens a store's customers or orders, it is logged: who, when and what.

Your requests

When a customer or a shop asks Shopify to erase their data, we act on it automatically. When a customer asks what we hold about them, the request appears for the store's team, who download what we hold and pass it on. For anything else, write to mityodraganow@gmail.com.