Privacy Policy
This policy explains the main data handled by Catalat when someone creates an account, manages a catalog website, publishes content and interacts with the platform.
Account and billing data
Catalat stores the information required to create accounts, assign plans, process subscription state and keep each catalog website connected to the right tenant.
Catalog website data
Products, pages, blog posts, domain settings, media files and branding settings are stored to publish and operate the customer catalog website.
Security and operational logs
Account access attempts, payment notices, usage limits and system errors may be logged to protect and operate the service.
Retention and removal
Catalog website data may be retained while the account is active and for a limited operational period after cancellation, blocking or non-payment, according to platform policy.
Google Business Profile data
When a customer connects a Google Account in the integrations panel, Catalat requests the https://www.googleapis.com/auth/business.manage scope to access only the Google Business Profile data needed for the integration. This data may include available business accounts, selectable locations, resource name, location title, Place ID and identifiers returned by Google APIs. Catalat uses this data to list authorized locations, let the customer choose which Business Profile belongs to the catalog website, maintain the connection, display integration status and record operational errors. OAuth tokens are stored encrypted and used only for authorized API calls. The customer can disconnect the integration in the panel or revoke access from their Google Account. Catalat does not sell Google data, does not share it with third parties for advertising and does not use it to train models. Catalat’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.