Privacy
Last updated 2026-09-27
What Catalogwright does with the data of the stores you connect to it, in plain words.
What we read
From a store you connect: its catalogue and content (products, collections, pages and the like), its customers and its orders. For a customer that means their name, email, phone, addresses, marketing consent, and how many orders they placed and for how much. We never read passwords.
Why
To show a store's records to that store's own team, to compare them with another of the team's stores, and to copy them to a store the same team chooses.
What we never do
- Sell it or share it with anyone else.
- Use it for marketing.
- Make automated decisions about a person. A customer's marketing consent is copied as the store recorded it and never changed.
How long we keep it
- A connected store's current records: for as long as the store is connected.
- Past versions of customers and orders, and the copies kept so a change can be put back: 90 days.
- A disconnected store's customers and orders, with their past versions and the copies kept to put its changes back: 30 days after it was disconnected, however recent they are.
- Everything about a shop: removed about 48 hours after the app is uninstalled, when Shopify asks us to.
Where it lives
In a PlanetScale Postgres database in the EU. It is encrypted when stored and when it travels. The keys that let us reach your store are encrypted a second time on top of that.
Who sees it
Only the members of the organization that connected the store. Every time someone opens a store's customers or orders, it is logged: who, when and what.
Your requests
When a customer or a shop asks Shopify to erase their data, we act on it automatically. When a customer asks what we hold about them, the request appears for the store's team, who download what we hold and pass it on. For anything else, write to mityodraganow@gmail.com.