Privacy

Privacy Policy

Privacy information for CatalogSignal website visitors, prospects, clients, and authorized portal users.

Last updated: July 7, 2026. CatalogSignal respects your privacy. This policy explains how we collect, use, protect, and retain information from website visitors, prospects, clients, authorized users of CatalogSignal client portals, and client data processed while delivering CatalogSignal products and services.

Who we are. CatalogSignal provides AI catalog readiness products built around the Commerce Eligibility Index (CEI), including CEI Diagnose, CEI Activate, CEI Protect, CEI Publish, benchmark reporting, dashboards, and client portals. Our public website is https://www.catalogsignal.com. Client portals may be delivered through CatalogSignal-controlled authenticated URLs or subdomains.

Our role. For website visitors and prospects, CatalogSignal acts as the business or controller of contact and website information. For client catalog data, portal data, reports, evidence files, and client-provided materials, CatalogSignal generally acts as a service provider or processor under the applicable client agreement, except where limited operational data is used for security, auditability, billing, support, legal compliance, or service improvement.

Information you provide. We collect information you choose to send us, such as name, work email, company, role, message content, meeting requests, sales or support communications, portal account details, and any files or information submitted for an engagement.

Client and portal data. When a client authorizes a CEI assessment or portal account, CatalogSignal may process product catalog data, product page URLs, structured data, product feeds, images, descriptions, attributes, review inputs, financial profile inputs, competitor scopes, reports, remediation artifacts, evidence files, dashboard records, access roles, and portal activity needed to operate, secure, and support the service.

Public and authorized sources. CatalogSignal may collect publicly available catalog and authority data, including public webpages, sitemaps, robots.txt files, public product feeds, on-page reviews, independent review and mention sources, and live AI-assistant response data. For permissioned engagements, we may also process client-authorized private feeds, exports, owned-review files, Search Console or Merchant Center evidence, offline catalog uploads, or other materials the client chooses to provide.

How we use information. We use information to respond to inquiries, operate the website, create and manage portal access, deliver CEI Diagnose, Activate, Protect, and Publish work, generate reports and remediation artifacts, validate quality gates, provide dashboards, troubleshoot, secure the service, maintain audit evidence, improve reliability, and communicate with clients and prospects.

Client data boundaries. Client catalog data, private inputs, portal records, and individual CEI assessments are used to provide the requested service. We do not sell client catalog data or personal information. We do not knowingly share personal information for cross-context behavioral advertising through CatalogSignal-controlled systems. We do not publish a client's individual score or assessment without authorization. We do not use one client's private catalog data to produce another client's competitive assessment. Benchmark outputs may use public, aggregated, de-identified, or client-authorized patterns. We do not disclose whether a specific client is included in, excluded from, or participating in a benchmark unless that client authorizes disclosure or the benchmark is private to that client.

AI and model processing. Some CatalogSignal workflows use model providers, retrieval systems, or hosted infrastructure to classify, summarize, test, or validate catalog evidence. We limit submitted content to what is needed for the task and use outputs to produce CatalogSignal deliverables. CatalogSignal does not use client data to train general-purpose models and, where contractually available, configures model-provider processing so client data is not used to train general-purpose models by those providers.

Cookies, forms, and website measurement. Our public website is hosted on Squarespace and may use ordinary hosting, security, anti-spam, form, consent, and measurement technologies. Website consent controls, where presented, govern optional website measurement technologies. A CatalogSignal engagement does not require us to install cookies, pixels, or behavioral analytics on a client's website or systems unless that is explicitly agreed for a specific integration.

Service providers. We may use service providers for hosting, cloud storage, authentication, forms, email, analytics, security, crawling infrastructure, data processing, model processing, and business operations. We may disclose contact information, portal account information, catalog materials, usage records, support communications, and engagement records to service providers only as needed to operate, secure, support, and deliver CatalogSignal.

Privacy rights and choices. Depending on where you live and the laws that apply, you may have rights to request access to or correction, deletion, portability, or export of personal information, to opt out of sale or sharing of personal information, to limit certain uses of sensitive personal information, and to be free from discrimination for exercising privacy rights. You can also contact us to update contact information, opt out of non-transactional communications, request access changes for portal users, or ask about export, deletion, or retention of client materials. Some records may be retained where needed for security, legal, audit, or contractual reasons.

Children. CatalogSignal is intended for business users and is not directed to children. We do not knowingly collect personal information from children under 13.

International processing. Information may be processed in the United States and other locations where CatalogSignal or its service providers operate.

Retention. We retain prospect and website information for business, legal, and security purposes. We retain client portal records, reports, evidence files, and engagement data for as long as needed to provide the service, maintain auditability, satisfy contractual or legal obligations, resolve disputes, and support authorized re-measurement or monitoring. Clients may request deletion or export subject to contractual, legal, and operational limits.

Security. We use reasonable technical and organizational safeguards designed to protect information, restrict access to authorized personnel and systems, and preserve the integrity of client deliverables. No online service can guarantee absolute security.

Client agreement precedence. If a client agreement, DPA, order form, or statement of work provides stronger or more specific data handling terms, those terms control for that engagement.

Contact. For privacy questions, client data requests, or portal data requests, contact legal@catalogsignal.com.