Data handling and security
See which Shopify, Google, operational, and AI data Catavexa uses.
Data minimization
Catavexa is designed around catalog and feed operations. It does not require customer personal data, order data, payment card data, customer addresses, or customer email addresses for its core product-feed function.
Access and safeguards
- HTTPS for data in transit
- Tenant-scoped application queries
- Encrypted storage for Shopify and Google tokens in production
- Webhook HMAC and OAuth state validation
- Sensitive-field redaction in application logs
- Least-privilege Shopify and Google scopes
AI data use
When a merchant requests an AI suggestion, relevant product text and structured facts may be sent to the configured AI provider to generate that suggestion. AI output is reviewable, and critical commercial fields remain protected by application rules.
Still stuck? Email support@catavexa.com with your .myshopify.com domain and a short description of the issue.