This privacy policy explains what data the Catalog Cleanup AI Shopify app ("the app", "we", "our") processes, why, and how. It applies to merchants worldwide who install the app on their Shopify store.
Where applicable under the EU General Data Protection Regulation (GDPR, if you are an EU/EEA resident), the UK Data Protection Act 2018, Moldovan Law 133/2011 on personal data protection (which applies to us as the data controller), or comparable laws in your jurisdiction, Catalog Cleanup complies with the data-protection obligations outlined below.
Shopify relationship. Catalog Cleanup is an independent third-party app provider. Shopify is not a party to this privacy policy and is not responsible for Catalog Cleanup's data practices. Shopify's own privacy policy governs the data Shopify itself processes.
Catalog Cleanup AI processes shop-level catalog metadata only — product titles, descriptions, SEO fields, and image alt text. We do not store customer personal data, order history, or any data scoped to individual shoppers. When Shopify forwards a customer-data request or redaction request to our app, we acknowledge the webhook and log it for audit purposes; there is no customer-scoped data on our side to return or scrub. When a shop uninstalls our app, all shop-scoped data is permanently deleted within Shopify's 48-hour shop-redaction window.
When you install Catalog Cleanup on your Shopify store, we access and store:
your-store.myshopify.com), Shopify session tokens, your
installed app preferences and subscription status.
Where applicable under the EU General Data Protection Regulation (GDPR) or comparable laws (Moldovan Law 133/2011 on personal data protection), we rely on the following legal bases:
Catalog Cleanup uses the following third-party services to operate. Each is a sub-processor under GDPR; data shared is limited to what's necessary for that service.
Shop-scoped data may be transferred outside Moldova and the EU/EEA in the course of using these sub-processors. Where applicable, transfers rely on Standard Contractual Clauses or equivalent safeguards.
Changes to the sub-processor list. If we add a new sub-processor, we will notify installed merchants by email at least 30 days before the change takes effect. Merchants may object to a new sub-processor by emailing support@catalogcleanup.app within that window; if a reasonable objection cannot be resolved, the merchant may terminate the service by uninstalling without penalty.
/app/export/history route. After uninstall, the export
is available during Shopify's 48-hour shop-redaction grace window;
after permanent deletion, no export is possible.
shop/redact webhook (fires 48 hours
after uninstall): we permanently delete all shop-scoped data — run
history, diffs, subscription record, usage events, email logs, and
webhook records.
Shopify forwards three privacy-related webhooks to all installed apps. Here is exactly how Catalog Cleanup handles each:
customers/data_request — Shopify
forwards a customer's request for the data you hold about them.
Because Catalog Cleanup never processes customer personal data, we
have nothing to return. We acknowledge the webhook, log it for audit
purposes, and respond 200 OK. We do not contact your
customer, do not transmit data to any third party, and do not
initiate any further action based on this webhook.
customers/redact — Shopify forwards a
request to delete a specific customer's data. Because Catalog Cleanup
never stores customer-scoped data, there is nothing to delete. We
acknowledge the webhook, log it for audit purposes, and respond
200 OK. We do not contact your customer.
shop/redact — Shopify forwards a request
to delete the shop's data 48 hours after uninstall. We delete all
shop-scoped records as described under "Retention and deletion" above.
If you are a merchant in the EU/EEA or another jurisdiction with comparable data protection laws, you have the following rights regarding the data we hold about your shop:
Catalog Cleanup is an embedded Shopify app. We use only essential cookies set by the Shopify SDK to maintain your authenticated session inside the Shopify Admin. We do not use analytics, advertising, or tracking cookies.
We follow standard practices for protecting the data we hold:
If you believe you have found a security issue, please email support@catalogcleanup.app. We aim to acknowledge reports within two business days.
Breach notification. If we become aware of a security breach affecting shop-scoped data we hold, we will notify affected merchants by email without undue delay and, where required by GDPR, no later than 72 hours after becoming aware of the breach. The notification will describe the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the measures we are taking to address it. We will also cooperate with Shopify's incident-response procedures and with the competent supervisory authority where required.
Catalog Cleanup is a B2B tool sold exclusively to Shopify merchants and is not directed at children. We rely on Shopify's age and account verification at install time and do not collect age data ourselves. If we are notified that a minor has accessed the service, we will delete any associated records on receipt of a credible report.
If we materially change how we process data, we will update this policy and notify installed merchants by email at least 30 days before the change takes effect. Minor clarifications will be reflected here with an updated "Last updated" date.
For privacy questions or to exercise your rights, email support@catalogcleanup.app.