Skip to content

Two ways in, both private.

Both paths are private. An upload is read in this tab. A connected catalog passes through our server and is never stored.

Effective 2026-09-19. Privacy contact: privacy@catalogroute.com.

How the processing works

When you drop a file, the browser hands the page a reference to the bytes on your disk. A Web Worker in the same tab reads those bytes, finds the columns, checks every row and builds the Square workbook. The download comes from memory in your browser.

No server sees the file. There is no copy on our side to delete, because there was never a copy. Closing the tab removes everything.

Once the tool has been opened once, it is stored in your browser and keeps working with the network switched off, which is the plainest proof that no upload is involved.

Connected Square account

Connecting is optional. Nothing happens until you press Connect Square and approve the permissions on Square.

What we read: your item library, with its prices, costs, barcodes, categories and stock. The catalog pages pass through our server in memory and are never stored.

What we write: the rows you approved, when you press Push to Square. Nothing is written on its own, and a push never deletes anything.

The access token is encrypted at rest with a key only our server holds. Next to it we keep your Square merchant id, your location ids, when you connected and when the catalog was last read.

Retention: the token is kept until you disconnect. Disconnect revokes it at Square and deletes it here. It is in Settings and in the tool.

What an account stores

Your rows
Never stored and never sent. No request carries a cell, a header or a file name.
Your email address
Stored so the sign-in link can reach you, and so we can answer a support email.
Supplier settings
The column mapping, the pricing rules and a hash of the header row. No product data.
Run counts
Numbers such as 1,240 rows and 26 price changes, with the date. No row content.
Item keys, if you switch it on
Hashed SKU and GTIN values, so next time the tool can say which products disappeared. The hash cannot be turned back into the code.
Billing ids
The Stripe customer id and subscription id. Card details stay with Stripe.

Without an account nothing is stored on our side at all. The tool then keeps your saved supplier in this browser only.

Analytics

We count how the tool is used with an analytics service. It runs cookieless: nothing is written to your disk, so there is no banner to click. If your browser sends Do Not Track, or asks for reduced data, no event is sent at all.

Every event we send, in plain words:

  • A file was dropped: the extension, a size band such as 1k to 10k rows, and how many columns it had.
  • A file was read: how long it took, in bands, and whether the backup reader was needed.
  • The mapping was confirmed: how many fields were mapped, and whether variations were on.
  • A comparison finished: size bands for matched, new, missing and cost changes.
  • A file was downloaded: create or update, a size band, and whether the row cap applied.
  • A supplier was saved, someone signed in, checkout was opened, a plan started.
  • Someone came back more than seven days after their first visit.

No cell, header, file name, supplier name or email address is ever part of an event. A signed-in visitor is counted by account id, never by address.

AI matching

AI matching is off until you switch it on. With it off, nothing on this page changes and no request leaves your browser with anything in it.

When you switch it on and press Ask AI, we send product names, option values such as Large or Red, category names, your column headers and three sample rows to an AI matching provider chosen by CatalogRoute, which runs the model that suggests the matches.

We never send prices, costs, quantities, SKUs, barcodes or email addresses. The server refuses a request that carries one, so it cannot be sent by mistake.

The provider works under a contract that does not allow training on your data. The model answers a suggestion and a confidence number. You confirm every one, and an unconfirmed suggestion never reaches the file you download.

Text features (name cleanup, SEO fields, run summaries) send product names, options, categories, headers and up to 3 sample rows to a third-party AI model provider chosen by CatalogRoute, under a contract that does not allow training on your data. Never prices, SKUs, barcodes or emails.

Error reports

When the app crashes, an error reporting service receives the error message and the line it came from, so it can be fixed. Request bodies, cookies and your IP address are removed before it is sent.

A report that carries a file name, an address, or a long run of digits that could be a barcode is dropped instead of sent.

Payments

Stripe takes the payment and holds the card details. We store the Stripe customer id and the subscription id, which is what the billing portal needs.

We never see or store a card number.

Hosting and where data sits

The site runs with our hosting provider. Account data lives in our hosting provider's database, which keeps the primary copy in one region and serves it from edge locations worldwide.

Our hosting provider also sees the usual request data a web host sees, such as your IP address, to serve the page and to block abuse.

Deleting your data

Open Settings and choose Delete account. It removes your suppliers, your run history, your billing rows and your sign-in records straight away.

Backups roll off after seven days. Write to support@catalogroute.com if you want confirmation.

Contact

Questions about this page go to support@catalogroute.com. We answer within one business day. Privacy contact: privacy@catalogroute.com.