Privacy Policy
Last updated: July 27, 2026
CatalogPilot helps Shopify merchants review, import, verify, and recover product catalog changes. This policy explains how information is handled when a merchant installs or uses the app.
Information we process
We process Shopify shop identity, authorized app sessions, product and inventory data required to provide the service, uploaded catalog files, import results, risk findings, and recovery snapshots. We do not request customer or order scopes.
How information is used
Information is used only to authenticate the merchant, compare proposed changes with the live catalog, execute approved updates, verify results, maintain task history, and provide recovery.
Storage and retention
App sessions, task records, and recovery snapshots are retained while needed to provide the service. Store-associated records are deleted when the app is uninstalled or when Shopify sends a mandatory shop redaction request.
Sharing and selling
We do not sell merchant data. Data is shared only with infrastructure providers required to operate the service or when required by law.
Security
CatalogPilot uses Shopify authorization, encrypted HTTPS transport, restricted production secrets, and least-privilege Shopify access scopes. No system can guarantee absolute security.
Your choices
Merchants can uninstall the app to revoke access. Requests concerning stored app data can be sent to contact@coredatalabs.net.