CatalogEaze Privacy Policy

**Effective date:** September 20, 2026

**Operator:** YOUR LEGAL NAME / BUSINESS ENTITY

**Privacy contact:** YOUR_PRIVACY_EMAIL

This basic launch policy describes the current browser-first CatalogEaze product. It should be updated when server accounts, analytics, email, payments, cloud file storage, or direct Shopify connections are introduced.

1. What the current product does

CatalogEaze lets a user upload a supplier CSV and transform it into a Shopify-oriented CSV. In the launch build, the source file is parsed and cleaned in the user's browser. The application does not intentionally transmit the raw uploaded catalog to a CatalogEaze application server.

2. Data stored in the browser

The launch build stores limited product-state data in the browser's local storage so the tool can remember supplier profiles and local run history. This may include:

The source catalog rows are not intentionally stored in job history.

3. Data minimisation

CatalogEaze is designed to collect the minimum information necessary for the current feature set. No payment-card data, advertising profile, analytics identifier, or marketing subscriber list is required for the free launch build. No marketing email system is active in the launch build; if marketing email is introduced later, promotional messages will include a clear unsubscribe mechanism where required.

Users should not upload passwords, access tokens, payment-card numbers, government identifiers, children's personal data, or other sensitive information unless a later documented feature specifically supports it.

4. Cookies and similar technologies

The current launch build does not use analytics or advertising cookies. It uses browser local storage for essential product preferences and saved workflows. If non-essential analytics, advertising, or similar tracking technologies are added, the website will update its notices and obtain consent where required before activation.

5. Third-party services

The current build uses Papa Parse, an MIT-licensed CSV parser bundled into the browser application. It has no runtime dependencies in its current npm package. No analytics SDK is active in this build.

When public hosting is enabled, the hosting provider may process normal technical request information required to serve the website. Vendor details and applicable data-processing terms should be added here when the final hosting/provider stack is confirmed.

6. Retention and deletion

Browser-stored CatalogEaze data remains until the user deletes it or clears the browser storage. The product includes a **Delete all local data** control.

The current build does not maintain a server-side archive of source supplier files. When server accounts or cloud storage are added, the retention period, deletion process, and provider list must be updated in this policy.

7. Privacy requests

Depending on the user's jurisdiction, applicable law may provide rights such as access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Requests should be sent to the privacy contact above.

If a request concerns only the current local browser build, users can immediately use the in-app deletion control. Server-side deletion procedures will be documented before server storage is enabled.

8. Children

CatalogEaze is intended for adults and is not directed to children. Do not upload children's personal data. If a future feature knowingly processes children's personal data, the product and legal controls will be updated before that feature is enabled.

9. Security

The launch build uses browser-side processing, input-size and row limits, safe rendering of uploaded values as text, strict output validation, dependency review, and production security headers intended for static hosting. No security measure eliminates all risk.

10. International use

CatalogEaze is intended for a global audience. Privacy requirements vary by country. Before paid/global launch, the operator should review the final data flows, contracts, vendors, and user rights requirements for the jurisdictions in which the service is offered.

11. Policy changes

This policy may be updated when product features, vendors, laws, or data practices change. The effective date will be updated with material revisions.

12. Contact

**Operator:** YOUR LEGAL NAME / BUSINESS ENTITY

**Privacy email:** YOUR_PRIVACY_EMAIL

**Website:** https://YOUR-DOMAIN.example

This policy is a basic product policy and is not jurisdiction-specific legal advice.