CatalogSignal — Privacy Policy
Effective Date: January 1, 2026
The CatalogSignal partnership (SWAT Team Partners, SuccessworksCX, and Wise Owl Collective) respects your privacy. This Privacy Policy explains how we collect, use, protect, and retain your information when you engage our CatalogSignal diagnostic services or transmit data to our platform.
Who We Are
CatalogSignal is an AI-readiness diagnostic service for e-commerce catalogs, operated by the CatalogSignal partnership. The underlying engine, Bubo AI, is developed and maintained by Wise Owl Collective, a data and analytics consultancy organized as a limited liability company (LLC) registered in the Commonwealth of Massachusetts. Our website is: https://catalogsignal.com.
Information We Collect
We collect and manage the following types of information:
Client-provided catalog data -- product catalog exports, data feeds, or URLs provided for evaluation. This data typically consists of publicly available product information (names, descriptions, prices, images, attributes) and does not contain consumer personally identifiable information (PII).
Crawled catalog data -- when a permissioned crawl is authorized, we collect publicly available product page content from your website including product descriptions, structured data markup (Schema.org, JSON-LD), images, pricing, and reviews. We only crawl pages you authorize and respect robots.txt directives.
Contact information -- submitted through business communications (e.g., name, email address, company name, phone number).
Evaluation results -- scores, evidence artifacts, and report outputs generated during the diagnostic process. These are derived from your catalog data and contain no consumer PII.
API usage metadata -- when RAG-enhanced commentary is enabled, anonymized evidence summaries (product counts, score distributions, sample product names from your catalog) are transmitted to Anthropic's Claude API for report narrative generation. No consumer PII, financial data, or credentials are included in these API calls.
How We Use Your Information
We use your information only to:
Perform the contracted CatalogSignal diagnostic evaluation
Generate executive reports, evidence artifacts, and recommendations
Communicate engagement progress and deliverables
Improve the accuracy and methodology of our diagnostic engine
Ensure secure, compliant handling of all data
What We Never Do
We never sell your data.
We never share your catalog data with competitors or third parties, except under written instruction or as required by law.
We never use your catalog data for purposes beyond the engagement you have authorized.
We never train AI models on your proprietary catalog data.
We never retain crawled content beyond the engagement retention window.
Who Has Access
Only authorized team members from the CatalogSignal partnership working directly on your engagement may access your data. Our infrastructure includes strict role-based access controls and client isolation policies. Each client's data is stored in a separate, isolated directory structure with no cross-client access.
Third-Party Services
CatalogSignal may use the following third-party services during evaluation, subject to your authorization:
Anthropic Claude API -- used for RAG-enhanced report commentary and optional LLM-based product extraction. Only anonymized evidence summaries and public product information are transmitted. Governed by Anthropic's API Terms of Service and data usage policies.
OpenAI API -- optionally used for revenue estimation web search during competitive benchmarking. Only brand names and publicly available business information are queried.
Crawl infrastructure -- permissioned crawls access only publicly available pages on your website. Crawl behavior respects robots.txt, rate limits, and any additional restrictions you specify.
No third-party service receives consumer PII, internal financial data, or credentials.
Data Retention
Contact and communication data is retained for up to 12 months.
Client catalog data and evaluation results are retained for the duration of the engagement plus 90 days, unless otherwise specified in the engagement agreement.
Crawled web content is retained only for the duration of the evaluation and deleted upon report delivery, unless a retention extension is agreed upon.
API call logs (to Anthropic, OpenAI) are subject to each provider's retention policies. We do not independently retain API request/response logs beyond the evaluation session.
Explicit deletion requests will be honored promptly, with certificates of destruction available upon request.
Retention extensions may be granted based on client requests or compliance obligations.
Cookies and Tracking
CatalogSignal is a consulting engagement, not a consumer-facing web application. We do not deploy cookies, tracking pixels, or behavioral analytics on your website or systems. Website interactions at wiseowlcollective.com are subject to Wise Owl Collective's website privacy policy.
Security Measures
Your data is protected by our enterprise-grade security framework, including:
Malwarebytes Premium endpoint protection on all workstations
AES-256 encryption at rest and TLS 1.3 for all connections in transit
Automatic malware scanning on all uploaded files (VirusTotal, 70+ antivirus engines)
Automatic PII detection on all uploaded files (Google Cloud Data Loss Prevention)
File quarantine for any uploads with detected malware or sensitive data
Client-isolated storage with strict role-based access controls
Object versioning to protect against accidental or malicious deletion
Audit logging and real-time alerting for authentication failures, permission changes, and anomalies
API key governance: keys logged as "present"/"absent", never by value
We follow the principle of least privilege and continuously monitor access for anomalies.
Data Breach Notification
In the event of a data breach affecting your information, the CatalogSignal partnership will:
Promptly investigate the incident to determine its scope and impact
Notify affected clients without unreasonable delay -- typically within 72 hours of discovery
Clearly explain what information was compromised (if known)
Outline the steps being taken to contain the breach and protect your data
Provide guidance on actions you can take to protect yourself
Notify relevant authorities as required by applicable law
For concerns or questions about our data breach procedures, please contact us at: legal@wiseowlcollective.com
International Users
If you are located outside the United States, including in the EU or UK, your information may be transferred to and processed in the U.S. We apply appropriate safeguards to such transfers, including Standard Contractual Clauses when required by law.
Your Rights
If you have shared identifiable information with us (e.g., as a business contact), you may:
Request a copy of the data we hold about you
Ask us to delete or restrict your data
Withdraw consent for future processing
Request early deletion of engagement data
These rights do not apply to publicly available catalog data collected during authorized crawls.
To exercise any of these rights, email us at: legal@catalogsignal.com
Changes to This Policy
We may update this Privacy Policy periodically. Any changes will be communicated to active engagement clients and reflected in the updated effective date.
Contact
If you have any questions, data concerns, or accessibility requests, contact:
Email: legal@catalogsignal.com