CatalogGuard — Privacy Policy
CatalogGuard ("the app") watches a Shopify store's product prices and costs for dangerous changes and lets the merchant put a previous value back. This policy explains what data the app processes and why.
Data we process
For every variant in the store's catalogue the app stores the product and variant IDs, the product title, the variant SKU, the price, the compare-at price, the cost per item that Shopify already records on the inventory item, and the product status. It keeps the previous value of each of these so that a restore has something to restore to. It also stores a rolling 30-day log of the price, compare-at and status changes Shopify reported, a permanent log of every write the app itself made to the catalogue, the merchant's rule settings and trusted-source list, and any private feedback the merchant chooses to send.
Where Shopify records an author for a product change in its own product event timeline, the app stores that label (an app name, or "Staff member") alongside the alert. Shopify does not record an author for every change; where it does not, the app records nothing rather than guessing.
Data we do NOT collect
CatalogGuard stores no customer personal data: no names, emails, addresses, payment details, order records, or identifiers of any kind. It does not request the read_orders, read_all_orders or read_customers scopes and has no access to them. There are no cookies and no third-party analytics or tracking of any kind.
Permissions and what they are used for
The app requests three scopes. read_products is used to take the snapshot of the catalogue and to read the product event timeline for attribution. write_products is used for exactly one thing: writing a previous price or compare-at price back through Shopify's productVariantsBulkUpdate mutation, either when the merchant clicks restore or when they have explicitly armed automatic restore for a rule. It is never used to create, delete, publish or unpublish anything, with one stated exception: the app's connection check writes a single small metafield (catalogguard.connection_check) to one product, because a change Shopify must report back is the only way to prove the webhook path is working. read_inventory is read-only and is used solely to read the cost per item so that the below-cost rule can work; the app never writes inventory and never alters stock levels.
Data retention and deletion
The change log is pruned automatically after 30 days. Uninstalling the app pauses all monitoring and disarms automatic restore immediately. All stored data for the shop is permanently deleted in response to Shopify's shop redaction webhook. Merchants can also clear resolved alerts at any time from the app's settings page.
Third parties
No data is sold, shared or sent to any third party. The app talks only to Shopify's Admin API and its own database.
Contact
Fleeta Limited — sales@fleeta.co.uk