← Back to Home

Catalog Sentinel privacy

Effective September 1, 2026

Data processed and stored

We store the installing Stripe account ID; encrypted OAuth access and refresh tokens; product IDs, names, descriptions, metadata, active state, and default price; price IDs, nicknames, metadata, amounts, currency, interval, type, and active state; scan timestamps, fingerprints, change findings, and risk findings; and Cazimedia billing customer, subscription, and entitlement identifiers. We do not request or store the installing account's customers, charges, payment methods, invoices, subscriptions, or card data.

Purpose

We use this data only to create durable catalog snapshots, compare changes, identify review-only risk findings, generate audit receipts, authenticate the installing account, and manage the Catalog Sentinel subscription.

Retention and deletion

Catalog history is retained while the installation remains active. Uninstall stops collection and deletes the installation, OAuth tokens, snapshots, findings, and scan history. Authenticated account controls also allow permanent deletion after any active subscription is cancelled.

Processors

Cloudflare hosts the Worker, Durable Object rate limiter, D1 database, and operational logs. Stripe provides the installed account data and processes Catalog Sentinel subscription billing. We use no analytics, advertising, tracking, or AI service.

Security

OAuth tokens are encrypted with AES-GCM. Embedded requests and webhooks require Stripe signatures, records are isolated by Stripe account ID, database queries are parameterized, public and expensive routes are rate-limited, and short-lived signed links protect billing and export actions.

Privacy requests: [email protected]