Legal
Privacy notice
Effective July 29, 2026
Who operates CatalogTrail
CatalogTrail is operated by Justin Solitro, doing business as CatalogTrail, in Ohio, United States. Questions and privacy requests may be sent to privacy@catalogtrail.com.
Information we handle
We handle the following categories of information:
- Account data, including names, email addresses, Clerk user and organization identifiers, roles, and authentication metadata.
- Square connection data, including encrypted OAuth credentials, merchant and location identifiers and names, and the catalog data Square returns for the supported object types.
- CatalogTrail records, including supported Item Library values, serialized catalog object versions, saved versions, change history, alert rules, recipients, and export activity. Catalog snapshots do not contain inventory quantities.
- Billing data, including Stripe customer, checkout, subscription, invoice, payment-status, refund, and pricing-cohort identifiers. CatalogTrail does not receive complete payment-card numbers.
- Service data, including support messages, security and request logs, job and webhook metadata, email-delivery status, and limited product events such as page, setup, comparison, and reference-export activity.
- Limited attribution data, including campaign parameters, referring hostname, landing path, and a random session identifier stored in session storage. We honor the browser Do Not Track signal for CatalogTrail product events.
Where information comes from
We receive information from you and your workspace members; from Clerk, Square, Stripe, and Resend when you use those connected services; and automatically from browsers, servers, and hosting infrastructure when the service is used.
How we use information
We use information to authenticate users, manage workspaces, connect to Square with the permissions you approve, record and explain supported catalog changes, provide saved-version comparisons and reference exports, deliver alerts, manage billing, respond to support and privacy requests, secure and troubleshoot the service, prevent abuse, meet legal obligations, and understand whether core product workflows are functioning.
Where applicable law requires a legal basis, we rely on performance of our contract, our legitimate interests in operating and securing CatalogTrail, your consent when required, and compliance with legal obligations. We do not sell personal information or use it for cross-context behavioral advertising.
Providers and disclosures
We disclose information only as needed to operate CatalogTrail, at your direction, in a business transfer, or when reasonably required by law or to protect rights and safety. Our current service providers and connected platforms are:
- Vercel — website, application, serverless, and delivery infrastructure.
- Neon — managed PostgreSQL database and database recovery infrastructure.
- Clerk — authentication, sessions, and workspace membership.
- Square — the merchant-authorized source of supported catalog, merchant, and location data.
- Stripe — checkout, subscriptions, invoices, refunds, and payment processing.
- Resend — transactional and change-alert email delivery.
- Cloudflare — domain, network, security, and limited web-traffic services where enabled.
These providers may process information in the United States and other countries under their own contractual and legal safeguards. Square and Stripe also process information under the agreements you have with them.
Retention
- Successful supported-catalog snapshots, serialized object versions, current supported Item Library records, change history, alert settings, and the signed first-payment marker remain for the life of the workspace.
- Raw provider webhook payloads and successful routine job metadata are scheduled for deletion after 30 days. Failed or dead job metadata may remain for up to 90 days for incident investigation.
- Anonymous product events are scheduled for deletion after 90 days. Non-payment product events linked to a workspace are scheduled for deletion after 400 days.
- External billing and transaction records may remain with Stripe for tax, accounting, fraud-prevention, and legal requirements.
Deletion
A workspace administrator can schedule deletion in product settings. CatalogTrail immediately begins revoking Square access and canceling CatalogTrail billing, then schedules workspace data for permanent deletion seven days later. The administrator can cancel data deletion during that period, but doing so does not reconnect Square or restart billing. Database deletion removes the workspace and its linked catalog, event, and webhook records. Residual copies may remain temporarily in encrypted provider backups until those backups expire under the provider's normal recovery schedule.
Your choices and rights
You may update workspace membership and alert recipients, disconnect Square, manage or cancel billing, or schedule workspace deletion in product settings. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, or to appeal a denied request. Email privacy@catalogtrail.com to exercise a right. We may need to verify your identity and authority over the workspace before acting.
Security
CatalogTrail uses read-only Square permissions, encrypts Square OAuth tokens before database storage, scopes product access to authenticated workspaces, and verifies supported provider webhook signatures. No security measure eliminates all risk. Report a suspected issue to security@catalogtrail.com.
Children
CatalogTrail is a business service and is not directed to children under 13. We do not knowingly collect personal information from children.
Changes to this notice
We may update this notice as the service or legal requirements change. We will update the effective date and provide additional notice when a material change requires it.