Version 1.1 · Effective date: on publication of version 1.1
Privacy Policy
Catalogix ("Catalogix", "we", "us" or "our") provides software that helps retailers, wholesalers, importers and distributors compare supplier product files, clean catalogue data and export structured product information.
This Privacy Policy explains what information we collect, how we use it and what choices you have.
1. What this policy covers
This policy applies to information processed when you visit the Catalogix website, create or use a Catalogix account, upload supplier files for comparison or processing, or contact us for support or feedback.
2. Information we collect
We may collect account and organisation information such as your name, email address, password hash, organisation name, settings and preferences. We may collect supplier and catalogue information such as supplier names, metadata, uploaded CSV or XLSX files, extracted product data, field mappings, review items and export history. We may also process emails, in-app feedback, support requests, session and authentication data, browser and device information, and basic operational logs used to secure and operate the service.
3. What you should not upload
Catalogix is designed for supplier product and catalogue data. Do not upload customer, order, employee or payment data, sensitive personal data, or regulated or highly confidential personal information. You must ensure that you are allowed to use and share supplier files for your business operations.
4. How we use information
We use information to provide and operate Catalogix, process supplier files, compare catalogue versions and generate exports, maintain account access and security, respond to support requests, improve the product and comply with legal obligations.
5. Confidentiality of supplier files
We treat uploaded supplier files and derived product data as confidential business information. We use uploaded files only to operate, support and improve the service for the relevant customer account.
6. File storage and retention
The periods below are calendar days or months. Supplier uploads in their original form are kept while the organisation is active. They are deleted on an explicit user request or no later than 30 days after the organisation closes. Processed catalogue data, mappings and catalogue versions are kept while the organisation is active and for a 30-day recovery period after closure. Generated exports are kept for 30 days.
Transactional email records and related webhook events are kept for 90 days. Bounce and complaint suppression records contain only a hash and are kept until 24 months after the last relevant event. Checkout attempts and growth events are kept for 24 months. Audit logs are kept for 24 months; application and security logs for 90 days. Analytics and attribution data are kept for no more than 13 months. Sentry events are kept for 30 days only when optional Sentry monitoring is configured.
Backups are retained for no more than 35 days where the relevant infrastructure supports that limit and it has been contractually confirmed; this period is not a representation that every provider currently offers or applies it. Invoices and fiscally relevant billing records are retained for 7 years. Evidence of acceptance of the Terms and Privacy Policy is retained for 7 years after the agreement ends. Deletion-job records are retained until deletion has completed successfully and for 90 days afterwards.
A legal hold is an exception only where explicitly authorised, limited to the data and duration demonstrably necessary, and auditable. Data under a legal hold is not deleted until the hold ends; it is then subject to the otherwise applicable deletion schedule.
You may request deletion of eligible organisation data through Settings or by contacting hello@catalogix.io. These periods do not extend retention for active organisations beyond the periods stated above and do not override mandatory legal obligations.
7. Sharing information
We do not sell your information. We may share information with service providers that help operate Catalogix, including hosting, infrastructure and email providers. We may also disclose information where required by law or reasonably necessary to protect service security, rights or integrity.
8. Security
We use reasonable technical and organisational measures to protect information processed through Catalogix. No system is completely secure and we cannot guarantee absolute security. See the Security page for more information.
9. Your choices and rights
You may contact us to access your information, correct inaccurate information, request deletion of your account or organisation data, or ask how your information is used. Contact hello@catalogix.io.
10. Cookies and analytics
Catalogix uses cookies or similar technologies necessary to operate the service, maintain sessions and support security and functionality. With explicit consent, local storage may collect basic analytics such as page views and generic attribution. We do not use device fingerprinting or store raw IP addresses. See the Cookie Policy for details.
11. Third-party services
Replit provides application hosting and Replit App Storage, which uses Google Cloud Storage (GCS) for private files. Resend is used as a transactional email provider only when transactional sending is activated and configured. Zoho is used for the business mailbox and reply-to correspondence to the extent that mailbox is actually used. Stripe processes billing only when billing is enabled and used. Sentry is an optional monitoring provider and receives monitoring data only when it is configured. Providers and data flows may change; their use is limited to what is needed for the relevant service. Provider location, contract terms and transfer safeguards should be checked against the current provider arrangements; this policy does not promise a particular region or certification.
12. Changes to this policy
We may update this Privacy Policy. If we make material changes, we will update the effective date on this page.
13. Contact
Questions about this Privacy Policy may be sent to hello@catalogix.io.