Privacy Policy
Last updated: August 22, 2026 · Effective date: August 22, 2026
1. Introduction
Catlok ("we", "our", or "us"), operated at catlok.shop, provides an e-commerce catalog hosting, Google Sheets catalog synchronization, and WhatsApp enquiry platform for merchants and online stores. This Privacy Policy explains how we handle your personal information, merchant store details, billing and payment transactions, and Google Drive user data.
Catlok allows merchants to optionally connect their Google Account to manage their product catalog via Google Sheets. When you connect your Google Account:
- Narrow Scope: We request only the specific
https://www.googleapis.com/auth/drive.filescope. This grants Catlok permission to create, read, and edit only the single product spreadsheet that Catlok creates in your Google Drive (titledCatlok - [Store Name] - Products). Catlok cannot access, view, modify, or delete any other files or folders in your Google Drive. - Data Synchronized: Catlok reads catalog data from your product spreadsheet (product names, categories, SKUs, prices, offer prices, descriptions, and image URLs) and synchronizes it into Catlok's secure PostgreSQL database so your customers can view your store.
- Stable Product Identity: Catlok assigns and writes a unique
CATLOK_ID(UUID) back to your Google Sheet to track items stably across spreadsheet row reordering. - Encrypted Token Storage: Google OAuth refresh tokens are encrypted at rest using AES-256-GCM / Fernet encryption. Tokens are never stored in plaintext, never exposed in client-side code, and never printed in logs.
- Google Limited Use Compliance: Catlok's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- No Selling or Advertising: We never sell Google user data, share it with data brokers, or use it for targeted advertising or machine learning / AI model training.
- Revoking Access: You can disconnect Google Sheets at any time in your Catlok Dashboard Settings or via your Google Account Security Settings.
Catlok offers paid subscription plans (such as Starter and Pro) for merchant stores. We manage payment data with the following safeguards:
- PCI-DSS Compliant Payment Processor: All subscription billing transactions are processed through our payment partner Razorpay. Catlok does not store or process raw credit card numbers, debit card details, or banking PINs on its servers.
- Payment Transaction Data: We store payment transaction identifiers (Razorpay Order ID, Payment ID, payment timestamp, plan code, currency, and amount) to manage your store's active subscription period and provide invoices.
- Customer Storefront Enquiries & Orders: Storefront customers browse your catalog and send enquiries directly via WhatsApp. Customer payments for goods (if arranged between merchant and customer) take place directly between you and your customer; Catlok does not take a percentage fee on customer sales.
4. Information We Collect
In addition to Google Drive and billing metadata, we collect information you provide directly:
- Account Data: Email address, merchant display name, and Firebase authentication credentials.
- Store Details: Store public name, subdomain, logo, business type, WhatsApp contact number, and city/country.
- Catalog Data: Categories, product images, titles, pricing, and descriptions.
- Storefront Analytics: Aggregated page view counts, device types, top products, and referral sources.
5. Multi-Tenant Data Isolation & Security
Catlok utilizes a multi-tenant architecture with strict tenant isolation. Every database query, cache key, and sync operation is bound to your authenticated store tenant. Data from Tenant A can never be accessed, queried, or modified by Tenant B.
6. Third-Party Service Providers
We work with vetted service providers to deliver our platform:
- Google Firebase: User identity authentication and security tokens.
- Google Cloud: Google Sheets API and Drive API integration.
- Razorpay: Secure payment gateway for merchant subscriptions.
- AWS / Cloudflare: Secure object storage for store logos and product images.
7. Your Rights & Data Retention
You retain ownership of your catalog and customer data. You can edit, export, or delete your catalog items at any time. When you remove a row from your Google Sheet, Catlok archives the product rather than permanently deleting historic data. You may request full account and data deletion by contacting us.
8. Contact Us
If you have questions regarding this Privacy Policy, payment handling, or Google Sheets integration:
Email: support@catlok.shop
Legal Inquiries: legal@catlok.shop
Website: https://catlok.shop