CatalogLens AI
Privacy Policy
CatalogLens AI is a read-only Shopify app that helps merchants review product-catalog readiness. This policy explains what information the app processes, why it is processed, and the choices available to merchants.
Information we process
- Shop identity, granted app scopes, installation state, and Shopify authentication session data.
- Product catalog fields available through the
read_productspermission, including titles, descriptions, variants, media, tags, vendor, product type, category, status, and related readiness evidence. - Merchant-created settings, scan schedules, scan results, generated reports, subscription state, and feature-usage counters.
- Limited operational records such as webhook delivery identifiers, timestamps, and error diagnostics needed to run and secure the service.
CatalogLens AI does not request customer records and does not collect customer personal data for its catalog-audit features.
How information is used
Information is used only to authenticate the merchant, read the merchant's product catalog, calculate deterministic readiness scores, display evidence and recommended next steps, create requested reports, enforce plan limits, operate requested schedules, prevent duplicate webhook processing, and maintain service security and reliability.
The app does not automatically edit Shopify product data. If a merchant explicitly requests an AI Repair brief and that feature is configured, relevant product content and audit findings may be sent to the configured AI provider solely to generate the requested draft. Every draft remains human-review material.
Service providers and disclosure
Information may be processed by Shopify and by infrastructure providers used to host the application and database, currently DigitalOcean. An AI provider is used only when a merchant requests an enabled AI drafting feature. We do not sell merchant or catalog information, and we do not use it for third-party advertising.
Retention and deletion
Completed scan history and generated reports are retained according to the active plan's stated retention period. Operational records are retained only as long as reasonably needed for security, reliability, and legal obligations. When Shopify sends an authenticated shop-redaction request, CatalogLens AI deletes the shop record, sessions, and associated catalog-audit data from the application database.
Security
CatalogLens AI uses HTTPS, restricted application credentials, secret environment variables, database access controls, authenticated Shopify webhooks, and least-privilege Shopify scopes. No method of transmission or storage is completely risk-free, but reasonable safeguards are maintained for the information processed.
Merchant choices and requests
Merchants can stop new processing by uninstalling the app. Privacy or support requests can be sent through the support email shown on the CatalogLens AI Shopify App Store listing. Shopify's mandatory privacy webhooks are supported for customer-data requests, customer redaction, and shop redaction.
Changes to this policy
This policy may be updated when the service or its providers change. The effective date above identifies the current version.
Contact
For privacy questions, use the support email on the CatalogLens AI Shopify App Store listing or visit the CatalogLens AI support page.