Catalog Sentinel privacy
Effective September 1, 2026
Data processed and stored
We store the installing Stripe account ID; encrypted OAuth access and refresh tokens; product IDs, names, descriptions, metadata, active state, and default price; price IDs, nicknames, metadata, amounts, currency, interval, type, and active state; scan timestamps, fingerprints, change findings, and risk findings; and Cazimedia billing customer, subscription, and entitlement identifiers. We do not request or store the installing account's customers, charges, payment methods, invoices, subscriptions, or card data.
Purpose
We use this data only to create durable catalog snapshots, compare changes, identify review-only risk findings, generate audit receipts, authenticate the installing account, and manage the Catalog Sentinel subscription.
Retention and deletion
Catalog history is retained while the installation remains active. Uninstall stops collection and deletes the installation, OAuth tokens, snapshots, findings, and scan history. Authenticated account controls also allow permanent deletion after any active subscription is cancelled.
Processors
Cloudflare hosts the Worker, Durable Object rate limiter, D1 database, and operational logs. Stripe provides the installed account data and processes Catalog Sentinel subscription billing. We use no analytics, advertising, tracking, or AI service.
Security
OAuth tokens are encrypted with AES-GCM. Embedded requests and webhooks require Stripe signatures, records are isolated by Stripe account ID, database queries are parameterized, public and expensive routes are rate-limited, and short-lived signed links protect billing and export actions.
Privacy requests: [email protected]