This Privacy Policy explains what CatalogShare collects when you use the CatalogShare Android app or the website at app.catalogshare.online, why we collect it, who we share it with and what control you have over it. CatalogShare is a catalogue, storefront and estimate tool sold to businesses in India.
1. Who we are
CatalogShare (“CatalogShare”, “we”, “us”) operates the CatalogShare app (Google Play package in.catalogshare.app) and the website https://app.catalogshare.online. We are based in Gujarat, India. You can reach us at catalogshare123@gmail.com.
2. Two different roles
CatalogShare handles two kinds of data, and our responsibility differs for each.
- Your business account data. We decide how this is used, so we are the data fiduciary (controller) for it.
- Your customers’ data. When you type a customer name, phone number and address into an estimate, you are the data fiduciary for that information. We only store and process it on your instructions, as your processor. You are responsible for having a lawful basis to collect it and for telling your customers how you use it.
3. What we collect
3.1 Account and business information
Collected when you register and whenever you edit your company profile: business email address, password, phone number, company name, business address, GST number, UPI id, company logo image, UPI QR code image, and your public store slug (the address of your storefront page). Your password is hashed by Supabase Auth before storage — we never see, store or transmit it in readable form.
3.2 Customer information you enter
When you create an estimate or invoice we store the customer name, customer phone number, customer address, the line items you added, quantities, prices, tax percentages, discounts and any notes you type. This data reaches us from you, not from your customer directly.
3.3 Product catalogue
Product names, prices, categories, descriptions and the product images you upload. Your catalogue is published on a public storefront page by design — anyone with the link can see it.
3.4 Payment records
Payments are collected by Razorpay. CatalogShare never receives or stores your card number, CVV, UPI PIN, netbanking credentials or any other payment credential. What we keep is the Razorpay payment id, the Razorpay order id, the amount, the plan purchased, the payment status and the plan expiry date.
3.5 Usage and analytics
We write events to an analytics_events table so you can see how your storefront is performing. Each event records the event type (page view or product view), the page path, the company id, the product id where relevant, a hashed form of the visitor IP address (we do not store plain IP addresses), the browser user-agent string and a timestamp. The website additionally runs Google Analytics (gtag) under property G-25W133Z9E9.
3.6 Advertising identifiers
The Android app shows Google AdMob ads to users on the free tier only. For those users the AdMob SDK collects the Android Advertising ID (AAID) and related device signals. Section 5 covers this in full.
3.7 Device storage
Estimates you create are also written to IndexedDB on your own device so the app keeps working with no network, and are synced to our servers once you are online again. We also store small preferences (theme, selected skin, pending sync queue) and your login session token locally — in Android SharedPreferences in the app, in localStorage on the web.
4. Why we use it, and our legal basis
- To run the service — create your account, publish your storefront, generate estimates and PDFs, sync offline data. Basis: performance of our contract with you.
- To take payment and manage your plan — process the charge, unlock features, expire the plan after 30 days. Basis: performance of contract and legal obligation.
- To support you — answer emails and calls, investigate faults. Basis: legitimate interest and performance of contract.
- To show you storefront analytics and improve the product — aggregate view counts, error and crash patterns. Basis: legitimate interest.
- To show ads on the free tier — this funds the free plan. Basis: consent, collected through the Google-provided consent form where required and withdrawable at any time (see section 5).
- To keep records the law requires — invoices, tax and payment records. Basis: legal obligation under Indian tax and company law.
5. Advertising and the Android Advertising ID
Paid subscribers see no ads at all. While your plan is active the app makes no ad requests, so no advertising identifier is read or transmitted for you.
For free-tier users the app displays banner and occasional interstitial ads served by Google AdMob. To serve, frequency-cap and measure those ads, the Google Mobile Ads SDK collects the Android Advertising ID (a resettable identifier assigned by your device), approximate location derived from your IP address, device model, operating system version and ad interaction data. CatalogShare does not receive this identifier and does not link it to your business account.
Google’s use of this data is governed by the Google privacy and terms for partner sites and the Google business data privacy notice. A plain-language list of what AdMob collects is at support.google.com/admob/answer/6128543.
You control this in two places. In the app, open Settings and use Ad privacy options to change or withdraw your advertising consent. On the device, go to Android Settings → Privacy → Ads to reset or delete your Advertising ID. Upgrading to any paid plan removes ads entirely.
6. Who we share it with
We do not sell your personal data and we do not share it with advertisers or data brokers. We use the following sub-processors, each bound to use the data only to provide their service to us:
- Supabase — database, file storage and authentication. Holds your account, catalogue, estimates, uploaded images and analytics rows.
- Razorpay — payment processing for every plan purchase. Receives your name, email, phone and payment instrument details directly from you.
- Google AdMob — advertising, free tier only.
- Google Analytics — website traffic measurement (property G-25W133Z9E9).
- Resend — sending transactional email such as verification codes, password resets and order notifications.
- Vercel — hosting and content delivery for the website.
We will also disclose data where we are legally required to — a court order, or a valid request from a law-enforcement or tax authority — and to our professional advisers where necessary. If CatalogShare is ever sold or merged, your data may transfer to the acquirer under this same policy, and we will tell you before that happens.
7. International transfers
Our sub-processors operate global infrastructure, so your data may be stored or processed on servers outside India. Where that happens we rely on the provider’s contractual data protection commitments, including standard contractual clauses where applicable, and we do not transfer data to any territory restricted under Indian law.
8. How long we keep it
- Account, catalogue and estimate data — for as long as your account exists. Deleted immediately on account deletion, and purged from encrypted backups within 30 days.
- Payment and tax records — retained after deletion for the statutory period required by Indian tax and company law (currently up to eight years), in a reduced anonymised form: payment id, amount, plan and date, with the account identity stripped.
- Analytics events — retained for up to 24 months, then deleted.
- Support correspondence — retained for up to 24 months from the last message.
- Data stored on your device — stays there until you clear the app data, sign out, or uninstall the app.
9. How we protect it
- All traffic between the app, the website and our servers uses HTTPS/TLS.
- Data at rest is encrypted by our infrastructure provider.
- Passwords are salted and hashed by Supabase Auth. Password resets use one-time codes that expire.
- Row Level Security is enabled on our database tables, so one merchant cannot read another merchant’s account, catalogue or estimates.
- Privileged service-role keys exist only inside server-side edge functions and are never shipped in the app.
- On Android your session token is kept in app-private SharedPreferences rather than WebView storage.
No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board of India as required by law.
10. Children
CatalogShare is a business tool. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. You must be 18 or older to open an account. If you believe a child has given us personal data, email catalogshare123@gmail.com and we will delete it.
11. Your rights
Under the Digital Personal Data Protection Act, 2023 and other applicable law you may:
- ask what personal data we hold about you and obtain a copy of it;
- correct or complete anything inaccurate;
- have your data erased, by deleting your account;
- export your catalogue, estimates and analytics — the app has built-in CSV and PDF export;
- withdraw a consent you gave, such as advertising consent;
- nominate another person to exercise these rights if you die or become incapacitated;
- complain to us, and then to the Data Protection Board of India.
To exercise any of these, edit your details in the app, use the deletion flow described below, or email catalogshare123@gmail.com from your registered business email address. We respond within 30 days and may first ask you to confirm your identity.
12. Deleting your account
You can delete your CatalogShare account and everything in it at any time. In the app open Settings → Delete account, or read our account deletion page. It lists exactly what is deleted, what is retained for tax purposes and how long it takes. Deletion is permanent.
13. Cookies and local storage
The app and website use browser or device storage for strictly necessary purposes: keeping you signed in, remembering your theme and skin, and holding offline estimates and the pending sync queue. The website also sets Google Analytics cookies (names beginning _ga) to measure traffic. We do not use cookies to build advertising profiles on the website. Clearing your browser or app storage removes all of this and signs you out.
14. Changes to this policy
We may update this policy as the product or the law changes. The effective date at the top always tells you which version is current. For material changes we will notify you in the app or by email to your registered address before they take effect. Continuing to use CatalogShare after that means you accept the updated policy.
15. Grievance Officer (India)
In accordance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023, the contact details of our Grievance Officer are:
- Designation: Grievance Officer, CatalogShare
- Email: catalogshare123@gmail.com
- Address: CatalogShare, Gujarat, India (full postal address supplied on request)
- Hours: Monday to Saturday, 10:00 to 19:00 IST
We acknowledge every grievance within 24 hours of receipt and resolve it within 15 days. Please write from your registered business email and include your company name so we can locate your account.
16. Contact us
Questions about this policy, or about anything we hold on you: email catalogshare123@gmail.com.