LEGAL
Privacy Policy
Last updated: August 16, 2026. CatalogBeacon audits Shopify catalogs, prepares reviewable AI drafts, and writes back only what you approve. Here is exactly what that means for your data.
1. What this policy covers
CatalogBeacon is an embedded Shopify app that audits catalog quality, prepares reviewable AI drafts, and writes back to Shopify only the changes a merchant explicitly approves.
This policy describes what we collect, why, where it is stored, and how you can request access, correction, or deletion. It applies to the CatalogBeacon app and the catalogbeacon.com website.
2. Data we collect
Store data from Shopify. With your store's permission we read product, inventory, and — only where approved by Shopify — aggregated order information needed to prioritize catalog issues. Shopify remains the source of truth for your product and order data.
Scan records. The catalog quality rules we run produce immutable scan snapshots, detected issues, and issue-state history. These are stored in Supabase, our hosted Postgres provider.
Draft and approval records. AI-generated title, description, and alt-text drafts, your edits to them, and the record of which drafts you approved and applied.
Account and billing status. Your shop domain, plan, and Shopify Billing subscription state.
Support correspondence. Anything you send us by email or through support.
3. Data we do not collect
We do not store customer names, email addresses, phone numbers, payment card details, or raw order records. Aggregated revenue and order counts used for prioritization do not include customer identities.
We do not sell or rent merchant data to anyone, and we do not use merchant catalog content to train third-party models.
4. How we use data
To run catalog scans and show you a prioritized issue list.
To generate editable AI drafts from your product content (titles, descriptions, image context). The draft is a suggestion; nothing is written to Shopify until you approve it.
To enforce plan limits, reconcile billing, and deliver monitoring alerts you have enabled.
To improve detection accuracy and keep audit history for your review.
5. Where data is stored and processors
Supabase (hosted PostgreSQL) stores scan snapshots, issue state, drafts, approval history, sessions, and billing reconciliation records.
Vercel hosts the application and its server-side code.
Shopify stores your products, orders, and the results of any approved writes.
AI providers (currently Alibaba Cloud Model Studio and DeepSeek) receive product content only when you trigger draft generation, so they can produce the draft. No customer PII is sent.
6. Retention and deletion
Scan and approval history is kept while your store remains installed, so you can re-verify resolved issues and review what changed.
When the app is uninstalled, we honor Shopify's shop/redact webhook: the shop record and cascaded app data are deleted.
If a customer of a merchant store requests erasure, our customers/redact webhook records the request without storing the requester's identity.
7. Your rights (GDPR / CCPA)
You can request access to, correction of, or deletion of your data by emailing support@catalogbeacon.com. We respond within the period required by applicable law.
Shopify merchants can also exercise rights through Shopify's data-processing mechanisms; our privacy webhooks (customers/data_request, customers/redact, shop/redact) are wired to receive them.
8. Analytics and cookies
The website and app do not run third-party analytics until our public consent decision is complete. We may add opt-in, privacy-respecting analytics in the future and will update this policy first.
9. Changes to this policy
We may update this policy as the product evolves. Material changes will be announced through the app and this page. Continued use after changes take effect constitutes acceptance.
Last updated: August 16, 2026.
Questions? Email support@catalogbeacon.com.