Last updated: 5 October 2026
Catalog Lint reads a store's product catalogue and reports what is missing or duplicated. It has no application server and no database: everything it reads is fetched by your browser, examined in your browser, and gone when you close the tab. A single stateless function answers the compliance webhooks Shopify requires of every app and checks the session token described below, and it stores nothing it receives.
| Permission | Why |
|---|---|
read_products |
To read product and variant identifiers, product titles and handles, variant names, status, inventory totals, SEO fields, featured image alt text, and variant SKUs and barcodes — the things it checks. |
That is the only permission the app requests. It holds no write permission of any kind, so it cannot edit, delete, publish or unpublish anything, by design rather than by policy.
It requests no access to customers, orders or payments. Under Shopify's protected customer data requirements this places the app at Level 0: it handles no customer personal information.
Shopify's app permissions screen notes that an installed app can reach the store owner's name, email address, phone number and address. That comes with installing any app; it is not something Catalog Lint asks for. The app does not read those fields, does not use them, and — having nowhere to put anything — does not store them.
When the app opens, your browser sends the Shopify session token for your visit to the app's own endpoint, which checks that Shopify issued it for this app and this store. The token identifies the store and the staff account using the app. It contains no product data and no name, email address or phone number. It is checked and then discarded.
Nothing, on our side. We keep no database, no server-side log and no analytics. Product data travels directly between your browser and Shopify and is never sent anywhere else; the only thing the app's own endpoint receives is the session token above, which it checks and discards.
The CSV export is generated inside your browser and saved by your browser. It does not pass through any system belonging to the developer.
On the Pro plan, the app shows what changed since your previous scan. To do that it keeps a summary of the previous scan in your browser's local storage: product identifiers and the SKU or barcode involved, per check, with the date of the scan. No product titles, no prices, no customer data. It stays in that browser, is never sent anywhere, and is cleared when you clear the browser's site data. Which plan a store is on is read from Shopify's own record of the installation; the developer holds no copy of it.
Shopify requires every app to answer three requests: a customer's request for their data, a customer's request to erase it, and a store's request to erase its data 48 hours after uninstalling. Catalog Lint answers all three. Because it stores nothing, there is never anything to return and never anything to erase, and the acknowledgement it sends says so by holding no data.
The page loads Shopify's own App Bridge and Polaris libraries from Shopify's CDN. It is served by Cloudflare, which also runs the function described above. No other third party is involved, and no data is shared with or sold to anyone.
Adding ?debug=1 to the app's URL shows a log of what the app did:
whether its scripts loaded, whether a request succeeded, and how many products
were read. It contains counts and status messages, not product data. It is
shown to you and sent nowhere unless you choose to paste it into a support
message.
Questions about this policy, or about data handling, can be sent to the support address shown on the app's Shopify App Store listing.