Catalogue Yard Privacy Policy

Effective August 22, 2026

Craft jay operates Catalogue Yard. Contact: catalogueyard@gmail.com. Postal address: Seongmisan-ro 88, Mapo-gu, Seoul, 03986, Republic of Korea.

Data we process

We process Shopify store identity, authorized staff session identifiers, product catalog content, merchant-confirmed product details, review history, merchant-requested private reference candidates, and minimal operational events. If a merchant optionally connects Google Merchant Center, we also process the Google OAuth authorization needed for that connection, encrypted access and refresh tokens, the selected Merchant Center account and supplemental data source, product identifiers used for merchant-confirmed or deterministic variant matching, merchant-approved Google product details, and Google publish status and diagnostic results. The initial launch does not collect Online Store customer events and does not request customer or order Admin API scopes. We do not collect customer names, email addresses, phone numbers, shipping addresses, or Shopify order records.

How we use data

Data is used to review product information and show product-data status, preserve merchant approvals, find merchant-requested references from approved sources, and publish only merchant-approved product data to selected destinations. For Shopify, publishing can create or update Catalogue Yard product metafields, Online Store product-detail data, an exact-match Shopify product category, and up to three merchant-approved product tags. If a merchant optionally connects Google Merchant Center, Catalogue Yard uses the merchant's authorization only to access the selected Merchant Center account, match confirmed Shopify variants to Google products, write merchant-approved product details through the selected supplemental product data source, and reconcile Google processing or diagnostic status. Catalogue Yard does not use Google authorization to alter the merchant's primary product feed, price, availability, title, description, images, shipping settings, or advertising destinations. Data is also used to secure the service, provide support, and operate billing through Shopify. Reference candidates remain store-scoped and are not automatically promoted into shared product knowledge. We also use pseudonymous lifecycle events and aggregate counts to measure install, product review, reference demand, publish, retention, and paid-conversion performance. Those analytics do not contain product copy, merchant answers, customer or order data, Shopify tokens, raw webhooks, or staff identities. We do not sell personal data or use merchant data for cross-store advertising.

Reference search runs only when a merchant selects Find reference. It may send a product barcode or GTIN, SKU as a model or part-number hint, vendor or brand, category key, and locale to Catalogue Yard's separately deployed first-party knowledge service. It does not send the product title or description, merchant answers, customer or order data, Shopify credentials, or staff identity.

Retention and deletion

Operational events are retained for up to 90 days. Delivered analytics outbox records are removed after 30 days and failed delivery records after 90 days; channel-neutral aggregate KPI records may be retained for longitudinal business reporting without store domains or catalog content. Current product snapshots and merchant-confirmed catalog facts are retained while the app remains installed; historical approval and review records are retained for up to 365 days. Encrypted backups expire after 30 days. App uninstall removes active Shopify sessions. Shopify privacy webhooks process data access and deletion requests, and shop redaction removes store data.

Security and subprocessors

Session credentials and connected-service credentials are authenticated-encrypted and staff actors are pseudonymized. Production infrastructure is hosted in North America by Vercel and Supabase; sanitized error monitoring is provided by Sentry when enabled. Shopify provides authentication, Admin API access, and app billing. Google provides optional OAuth authorization and Merchant API access when a merchant chooses to connect Google Merchant Center.

Your choices

Merchants can request access, correction, export, or deletion by emailing the privacy contact above. Google Merchant Center is optional and can be disconnected from Catalogue Yard. On disconnect, Catalogue Yard revokes the Google OAuth token when possible and stops using the connection. Published Shopify data can remain in the merchant’s store after downgrade or uninstall because it belongs to the merchant’s Shopify catalogue. This can include Catalogue Yard product metafields, Online Store product-detail data, an approved Shopify product category, and Catalogue Yard-managed product tags selected for search. Merchants can edit or remove those Shopify values using Shopify or Catalogue Yard while the app is installed. Catalogue Yard-owned supplemental Google product details can be retracted while the Google connection is available; the merchant's primary Google product feed remains under the merchant or its existing feed provider.

Terms of Service · Support

Return to Catalogue Yard