1. Who is responsible

The data controller for the CatalogLift service and this website is Testica Iga Małłek, ul. Polna 2, 87-162 Lubicz Górny, Poland (VAT ID PL8911577240) — referred to below as “CatalogLift”, “we” or “us”. Write to us at hello@cataloglift.com or through the contact page for anything in this policy.

For the catalog data you connect (section 2.2), you — the store owner or the agency acting for it — are the controller of your store's data and we process it on your instructions as a processor. The Terms of Service carry the processing terms.

2. What we collect

2.1 Account data

When you create a workspace we store your name, e-mail address, a hashed password (or passkey credential), your two-factor settings if you enable them, the time you accepted the Terms, and the sign-in and security events needed to keep the account safe.

2.2 Catalog data from connected stores

Our WordPress connector plugin exports catalog data only. For each connected store we hold a working copy of:

  • products and product variations: names, slugs, permalinks, descriptions and short descriptions, SKUs, prices and stock status, catalog visibility, and their attribute values;
  • categories, brands and global attribute definitions;
  • media metadata for product images: the image URL, alternative text, MIME type, gallery position and which image is the featured one — never the image files themselves;
  • SEO title, meta description and canonical URL fields written by your SEO plugin, when one is present;
  • store settings the catalog depends on: currency and price formatting, site language, WordPress, WooCommerce and connector versions.

The connector never exports orders, customers, customer e-mail addresses, payment details, coupons, reviews, user accounts or anything outside the product catalog. The exact fields are fixed by our connector contract and the plugin cannot be asked for more from our side.

2.3 The decisions made in your workspace

Findings, AI drafts, approvals and rejections — with the account they were made on and whether they came through the panel or a connected agent — the change history of every write to your store and the read-back that verified it, and your store's playbook (the editorial rules you give the AI). This is the record that lets you roll a change back for 150 days.

2.4 Usage and technical logs

Server logs with IP address, browser, requested URL and timestamps; job and error logs from the sync, scan and apply pipeline; and the AI usage ledger (tokens, model, cost per request) that keeps AI spend under control. Logs are kept for operations and security, not for profiling.

2.5 Billing

Paid plans are sold by Paddle as merchant of record. Paddle collects your payment details, billing address and tax information, charges you, issues the invoice and handles VAT. We receive the subscription status, the plan and quantity you bought, your billing country and Paddle's customer and transaction identifiers. We never see your card number.

2.6 Messages you send us

The name, e-mail address, company and message you enter on the contact page, what you write in the feedback form inside the application — with the page and store you were on — and any e-mail you write to us. To hold back floods of repeated submissions we also keep keyed fingerprints — one-way codes, not the values themselves — of the message text, the name and the IP address it came from, and we clear them within three days.

Before a message from either form reaches our inbox it is screened for spam by a language model (section 4). The model receives the name, company, topic and message you entered and a count of similar recent submissions — not your e-mail address and not your IP address. It only sorts: a message it is confident about goes straight to our inbox, and every other message waits for a person to read it. No message is discarded without a person seeing it.

The contact form is protected by Cloudflare Turnstile, which tells people from bots. When the form loads, Cloudflare receives your IP address, your browser's TLS fingerprint and user agent, and the address of our site, and uses them solely to detect and block bots — not to identify, profile or target anyone.

2.7 Agent connections

If you connect an AI agent of your own, we store what the client told us about itself when it registered — the name it chose and the addresses it returns to — together with the access and refresh tokens issued to it, when they were issued and when they were last renewed, and a record of any connection you cut off, so tokens issued under it stop working. We do not store what you say to your agent or what it says back: that conversation happens in the client you chose, not here.

2.8 Visits to this website

The public pages of this website — not the application — count visits with Fathom Analytics. For each page view Fathom receives the page address, the referring site, campaign parameters in the link, and — as any web request carries them — your IP address and browser user agent. It uses those values, our site identifier and a salt that changes daily at midnight UTC to create a visitor signature. Fathom stores individual page-view and click events with that signature, timestamps, page and referral details, campaign parameters, and derived browser, device and location information. Ordinary analytics records do not contain raw IP addresses or user agents; separate bot records can include IP addresses. It sets no cookie and does not create a persistent visitor identifier across days or unrelated sites. Browsers that send “Do Not Track” are not counted. We use these records for aggregate reports, including clicks on buttons such as “Scan your catalog free” and plan choices. None of this is linked to your account.

3. Why we process it, and on what legal basis

Transactional e-mail — verification links, password resets, security notices, and alerts about your own stores that you turned on — is part of the contract, not marketing. We do not send newsletters or drip campaigns.

We do not track opens or clicks in transactional e-mails. Delivery, bounce and failure events remain available for troubleshooting.

4. AI processing

CatalogLift drafts fixes with a large language model from OpenAI, reached through its API. For a single draft we send the fields of the product concerned (for example the title, descriptions, attributes, category and brand names, image alt text), the evidence the scanner collected, your store's name and playbook, and the language to write in. Store credentials and customer or order records are not part of this payload. Personal information you put in catalog fields or your playbook may be included, so keep those inputs free of personal data. Under the provider's API data-usage terms, data sent through the API is not used to train its models (provider policy).

The model only ever proposes. Nothing it writes reaches your store on its own initiative: a draft is applied only on a decision made under your workspace's authority — by a person in the panel, or by an AI agent that workspace has connected and authorised — and every draft is shown with its evidence, a confidence level and a before/after diff. AI is not used to make decisions with legal or similarly significant effects about anyone.

Some checks ask a second model a narrow question about a product — whether a description matches its title, which language it is written in, whether the category fits. For those we send the catalog fields the question is about — such as the title, brand, descriptions, attributes and category names — to a model reached through OpenRouter, which passes the request to the provider hosting that model. The answer becomes a finding for you to review; it changes nothing in your store.

Messages sent through the contact form or the feedback form inside the application are screened for spam by a model reached through OpenRouter in the same way (section 2.6). The outcome only decides whether a message goes straight to our inbox or waits for a person.

OpenRouter does not use what we send for model training (OpenRouter's privacy policy); the provider hosting a model applies its own data terms to the request.

If you connect an agent of your own, the client you connect — for example claude.ai, ChatGPT or code you run yourself — is chosen and authorised by you, not by us, and is not our sub-processor. Catalog data your agent reads through our MCP server is passed to that client on your own authority, and what it does with the data afterwards is governed by that client's terms, not ours. You can disconnect it at any time from the Agents screen.

5. Service providers and payment recipient

We do not sell data and we do not share it with advertisers or data brokers. We disclose data to authorities only when the law requires it, and we tell you when we are allowed to. If we add or replace a sub-processor that touches catalog data, we update this page first.

6. International transfers

The application and its database run with OVHcloud in Frankfurt, Germany (European Union). An EU application server does not mean that all providers store data in the EU: Resend stores message content and delivery logs in the United States even when messages are sent through its Irish region. Where a provider is outside the European Economic Area (section 5), transfers rest on the European Commission's Standard Contractual Clauses, on an adequacy decision, or on the EU–US Data Privacy Framework where the recipient is certified — with the supplementary measures the transfer needs.

7. How long we keep it

  • Catalog copy and findings — while the store is connected. When you delete a store, it stays restorable for 14 days and is then purged; a store with no decision history is purged immediately. Disconnecting the plugin stops all syncing at once.
  • Change history and rollback records — 150 days from the change, so it can be reversed, then together with the store.
  • Account data — while your account exists. Deleting your account removes it, and every store in a workspace nobody else owns, within the same grace period.
  • Billing records — as long as tax and accounting law requires (in Poland, generally five years after the end of the tax year).
  • Technical logs — a rolling window of a few weeks, longer only for a specific security investigation.
  • Website visit statistics — Fathom retains analytics history while we remain a customer, unless we delete it earlier. Rotating the daily salt does not delete stored events or their visitor signatures; historical events sharing a signature can still be grouped. After our subscription ends, Fathom queues the analytics data for deletion, which can take up to 60 days, as described in its cancellation and deletion policy.
  • Contact messages — until the conversation is closed and no longer than two years. The repetition fingerprints kept with them (section 2.6) are cleared within three days.
  • Transactional e-mail content and delivery logs — retained by Resend for 30 days on its standard plans, with provider backups retained for seven days, as described in Resend's retention policy. This is separate from correspondence in our OVHcloud mailbox.
  • VPS backups — a rolling seven daily restore points with OVHcloud. Deleted application data may remain in those backups until they expire.
  • Agent connections — while the connection stands. Disconnecting an agent revokes its tokens at once; the revoked tokens and the record of the disconnection are kept while your account exists, because they are what keeps a late-arriving token dead.

You can also ask us to delete your data at any time (section 8); we act within 30 days unless a legal duty requires us to keep a record.

8. Your rights

Under the GDPR you may ask us for access to your personal data, for a copy in a portable format, for correction, for erasure, for restriction of processing, and you may object to processing based on our legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting what happened before. Write to hello@cataloglift.com; we reply within one month.

You also have the right to lodge a complaint with a supervisory authority — in Poland the President of the Personal Data Protection Office (UODO), or the authority where you live or work.

If you are a shopper of a store that uses CatalogLift: we do not receive anything about you, so please contact the store directly.

9. Cookies

The website and the application set only the cookies they need to work: a session cookie, a CSRF token that protects forms, and — if you tick “remember me” — a sign-in cookie. There are no analytics, advertising or tracking cookies, which is why there is no cookie banner; fonts are served from our own domain. The public pages load Fathom's script for visitor statistics (section 2.8); it sets no cookie and stores nothing in your browser. The sign-in pages, the payment page and the application do not load it at all. The plan screen inside the application loads Paddle's checkout script when you open a checkout; Paddle's own privacy policy applies to it. The contact page loads Cloudflare Turnstile's script for its bot check (section 2.6); Cloudflare's Turnstile privacy addendum applies to it.

10. Security

Traffic between your browser, your store and CatalogLift is encrypted with TLS. Every request between the connector and the application is signed with a per-store secret and protected against replay. Passwords are hashed and never stored in clear text. How the connection works and what leaves your store is described in full on the Security page; report a vulnerability to security@cataloglift.com.

11. Changes to this policy

When we change this policy in a way that matters — a new sub-processor for catalog data, a new purpose, a longer retention — we e-mail workspace owners before it takes effect and update the date at the top. Smaller edits are published here.

12. Contact

Testica Iga Małłek
ul. Polna 2
87-162 Lubicz Górny
Poland
hello@cataloglift.com

See also the Terms of Service, the Refund policy and the Security page, or write to us.