Privacy Policy
Last updated 15 September 2026
Catalog Clinic requests a single Shopify permission: read_products. It cannot read customers, orders, payments or checkouts, and it cannot write anything to your store.
Who operates this app
Catalog Clinic is built and operated by Stefano Marra. For anything in this policy, write to catalog-clinic@stefanomarra.com.
What the app reads from your store
When you run a scan, Shopify prepares a snapshot of your catalog and the app reads it once. That snapshot contains:
- Products — title, description, vendor, product type, tags, options and status
- Variants — SKU, barcode, price, compare-at price, weight and option values
- Images — the image reference and its alt text
- Your shop profile — your myshopify domain, the store contact email, the store time zone, and the name of your active Catalog Clinic plan
The snapshot is processed in memory and discarded. It is not written to disk or kept after the scan finishes.
What the app stores
- Your settings — shop domain, language, plan, whether weekly scans are on and on which day, your time zone, the address for email reports, and a Slack webhook URL if you add one
- Scan records — when each scan ran, whether it succeeded, the health score, and counts of products, variants and issues by severity
- Findings — for each problem: which rule matched, its severity, the Shopify ID and title of the affected product or variant, when it first appeared and when it was resolved, plus a small amount of context needed to explain it — for example a duplicated SKU or barcode value, an image’s alt text, or a price
Product descriptions are measured, not stored: the app keeps the length of a description, never its text. Images themselves are never downloaded or copied.
What the app never touches
No customer records, orders, carts, checkouts, payment details or personal data of any kind are requested, received or stored. The app has no Shopify scope that would allow it, so there is nothing to delete when a customer exercises their rights — Shopify’s customers/data_request and customers/redact notifications are received and correctly return nothing.
Why the data is used
Solely to run the app: to compute your catalog health score, to list the issues found, to show what changed between scans, and to send the alerts you have switched on. Your data is never sold, rented, shared for advertising, or used to train any model.
Who else processes it
- Shopify — your store data originates there and the app is embedded in your admin
- Vercel — application hosting
- Neon — the PostgreSQL database that holds the settings, scans and findings described above
- Brevo — delivers email reports, and only receives the recipient address and the report itself, and only if you enable email reports
- Slack — receives scan summaries only if you supply a Slack webhook URL in Settings
How long it is kept
When you uninstall the app, Shopify immediately notifies us and your access session is deleted at once. Shopify then sends a shop redaction request, which it schedules up to 48 hours after uninstall; on receiving it, every setting, scan and finding belonging to your store is permanently deleted. Nothing is retained after that, and there is no backup copy kept for longer.
Your rights
You can ask for a copy of everything stored about your store, or for it to be deleted straight away rather than waiting for the uninstall flow. Email catalog-clinic@stefanomarra.com from the store’s contact address and it will be handled within 30 days.
Changes
If this policy changes, the date at the top changes with it. Material changes to what is collected or who processes it will be announced in the app before they take effect.