CatalogSignal — Privacy Policy

Effective Date: January 1, 2026

The CatalogSignal partnership (SWAT Team Partners, SuccessworksCX, and Wise Owl Collective) respects your privacy. This Privacy Policy explains how we collect, use, protect, and retain your information when you engage our CatalogSignal diagnostic services or transmit data to our platform.

Who We Are

CatalogSignal is an AI-readiness diagnostic service for e-commerce catalogs, operated by the CatalogSignal partnership. The underlying engine, Bubo AI, is developed and maintained by Wise Owl Collective, a data and analytics consultancy organized as a limited liability company (LLC) registered in the Commonwealth of Massachusetts. Our website is: https://catalogsignal.com.

Information We Collect

We collect and manage the following types of information:

Client-provided catalog data -- product catalog exports, data feeds, or URLs provided for evaluation. This data typically consists of publicly available product information (names, descriptions, prices, images, attributes) and does not contain consumer personally identifiable information (PII).

Crawled catalog data -- when a permissioned crawl is authorized, we collect publicly available product page content from your website including product descriptions, structured data markup (Schema.org, JSON-LD), images, pricing, and reviews. We only crawl pages you authorize and respect robots.txt directives.

Contact information -- submitted through business communications (e.g., name, email address, company name, phone number).

Evaluation results -- scores, evidence artifacts, and report outputs generated during the diagnostic process. These are derived from your catalog data and contain no consumer PII.

API usage metadata -- when RAG-enhanced commentary is enabled, anonymized evidence summaries (product counts, score distributions, sample product names from your catalog) are transmitted to Anthropic's Claude API for report narrative generation. No consumer PII, financial data, or credentials are included in these API calls.

How We Use Your Information

We use your information only to:

  • Perform the contracted CatalogSignal diagnostic evaluation

  • Generate executive reports, evidence artifacts, and recommendations

  • Communicate engagement progress and deliverables

  • Improve the accuracy and methodology of our diagnostic engine

  • Ensure secure, compliant handling of all data

What We Never Do

  • We never sell your data.

  • We never share your catalog data with competitors or third parties, except under written instruction or as required by law.

  • We never use your catalog data for purposes beyond the engagement you have authorized.

  • We never train AI models on your proprietary catalog data.

  • We never retain crawled content beyond the engagement retention window.

Who Has Access

Only authorized team members from the CatalogSignal partnership working directly on your engagement may access your data. Our infrastructure includes strict role-based access controls and client isolation policies. Each client's data is stored in a separate, isolated directory structure with no cross-client access.

Third-Party Services

CatalogSignal may use the following third-party services during evaluation, subject to your authorization:

Anthropic Claude API -- used for RAG-enhanced report commentary and optional LLM-based product extraction. Only anonymized evidence summaries and public product information are transmitted. Governed by Anthropic's API Terms of Service and data usage policies.

OpenAI API -- optionally used for revenue estimation web search during competitive benchmarking. Only brand names and publicly available business information are queried.

Crawl infrastructure -- permissioned crawls access only publicly available pages on your website. Crawl behavior respects robots.txt, rate limits, and any additional restrictions you specify.

No third-party service receives consumer PII, internal financial data, or credentials.

Data Retention

  • Contact and communication data is retained for up to 12 months.

  • Client catalog data and evaluation results are retained for the duration of the engagement plus 90 days, unless otherwise specified in the engagement agreement.

  • Crawled web content is retained only for the duration of the evaluation and deleted upon report delivery, unless a retention extension is agreed upon.

  • API call logs (to Anthropic, OpenAI) are subject to each provider's retention policies. We do not independently retain API request/response logs beyond the evaluation session.

  • Explicit deletion requests will be honored promptly, with certificates of destruction available upon request.

  • Retention extensions may be granted based on client requests or compliance obligations.

Cookies and Tracking

CatalogSignal is a consulting engagement, not a consumer-facing web application. We do not deploy cookies, tracking pixels, or behavioral analytics on your website or systems. Website interactions at wiseowlcollective.com are subject to Wise Owl Collective's website privacy policy.

Security Measures

Your data is protected by our enterprise-grade security framework, including:

  • Malwarebytes Premium endpoint protection on all workstations

  • AES-256 encryption at rest and TLS 1.3 for all connections in transit

  • Automatic malware scanning on all uploaded files (VirusTotal, 70+ antivirus engines)

  • Automatic PII detection on all uploaded files (Google Cloud Data Loss Prevention)

  • File quarantine for any uploads with detected malware or sensitive data

  • Client-isolated storage with strict role-based access controls

  • Object versioning to protect against accidental or malicious deletion

  • Audit logging and real-time alerting for authentication failures, permission changes, and anomalies

  • API key governance: keys logged as "present"/"absent", never by value

We follow the principle of least privilege and continuously monitor access for anomalies.

Data Breach Notification

In the event of a data breach affecting your information, the CatalogSignal partnership will:

  • Promptly investigate the incident to determine its scope and impact

  • Notify affected clients without unreasonable delay -- typically within 72 hours of discovery

  • Clearly explain what information was compromised (if known)

  • Outline the steps being taken to contain the breach and protect your data

  • Provide guidance on actions you can take to protect yourself

  • Notify relevant authorities as required by applicable law

For concerns or questions about our data breach procedures, please contact us at: legal@wiseowlcollective.com

International Users

If you are located outside the United States, including in the EU or UK, your information may be transferred to and processed in the U.S. We apply appropriate safeguards to such transfers, including Standard Contractual Clauses when required by law.

Your Rights

If you have shared identifiable information with us (e.g., as a business contact), you may:

  • Request a copy of the data we hold about you

  • Ask us to delete or restrict your data

  • Withdraw consent for future processing

  • Request early deletion of engagement data

These rights do not apply to publicly available catalog data collected during authorized crawls.

To exercise any of these rights, email us at: legal@catalogsignal.com

Changes to This Policy

We may update this Privacy Policy periodically. Any changes will be communicated to active engagement clients and reflected in the updated effective date.

Contact

If you have any questions, data concerns, or accessibility requests, contact:

Email: legal@catalogsignal.com