Effective Date: May 7, 2026 · Last Updated: July 28, 2026
1. Introduction
The Double Print ("we," "our," or "us") operates the CatalogBridge application ("CatalogBridge" or "the Service"), distributed through approved app marketplace or merchant-install channels. CatalogBridge imports merchant-authorized Clover catalog and stock data into a hosted catalog workspace and synchronizes selected catalog and inventory updates with connected Shopify storefronts.
This Privacy Policy describes how we collect, use, store, and share information when a merchant ("you," "your," or "the Merchant") installs, authorizes, or uses CatalogBridge. We are committed to handling Merchant information responsibly and transparently.
Important scope note: CatalogBridge is a business-to-business (B2B) tool used by merchants to manage authorized catalog and inventory data. CatalogBridge does not collect, process, or store personal information about the end consumers who shop at the Merchant's store. The Merchant's customer data is handled by Shopify and Clover under their respective privacy policies, and CatalogBridge does not access it.
We collect only the information necessary to operate CatalogBridge. Specifically:
3.1 Information from Shopify (via OAuth)
Shop domain (e.g., your-store.myshopify.com) — used to identify your account.
OAuth access tokens or merchant-provided API tokens — used to authorize CatalogBridge to make API calls to your Shopify store on your behalf. Stored in our production database with hosting-provider encryption at rest and restricted operational access.
Granted API scopes — a record of which Shopify permissions you authorized.
3.2 Information You Provide Directly
Clover API credentials (Merchant ID and OAuth token details, or another approved credential form) — provided or authorized by you to enable connection to your Clover account. Stored in our production database with hosting-provider encryption at rest and restricted operational access.
Sync configuration settings — such as inventory-authority mode, selected Shopify stock location, location cleanup preference, category filters, email settings, conflict resolution choices, and out-of-stock behavior selections.
3.3 Operational Data Generated by Use of the Service
Sync log entries — records of when syncs ran, how many products were processed, product or variant identifiers, SKUs, inventory item and location identifiers, stock quantities processed, and any errors encountered.
Resume cache — a record of which Clover items have been successfully synced to Shopify, used to make repeat syncs efficient.
3.4 What We Do Not Collect
We expressly do not collect:
Personal information about your customers (names, email addresses, shipping addresses, payment details).
Order information or transaction histories.
Payment or financial information.
Browsing behavior or analytics data.
Marketing or advertising data.
4. How We Use Your Information
We use the information we collect solely for the following purposes:
To provide the Service — authenticating to Shopify and Clover on your behalf and synchronizing product, catalog, and stock data between them according to your settings.
To maintain the Service — diagnosing errors, improving reliability, and responding to support requests.
To meet legal obligations — including responding to GDPR data subject requests, CCPA/CPRA consumer requests, or lawful regulatory inquiries.
We do not sell your information, share it with advertisers, or use it for marketing purposes unrelated to your use of CatalogBridge.
5. Legal Bases for Processing (GDPR / UK GDPR)
If you are based in the European Economic Area, the United Kingdom, or other regions where GDPR or equivalent law applies, we rely on the following legal bases for processing your information:
Performance of a contract — processing necessary to provide CatalogBridge's functionality after you install the app.
Legitimate interests — operating, maintaining, and improving the Service in ways that do not override your rights and interests.
Compliance with legal obligations — where required by applicable law.
6. How We Share Information
CatalogBridge shares Merchant information only with the following categories of third parties, each acting in defined roles:
Shopify, Inc. — the platform from which authorized product and inventory data may be read and to which synchronized product and inventory data may be written. Governed by Shopify's privacy policy at shopify.com/legal/privacy.
Clover Network, LLC — the platform from which authorized product and inventory data may be read and to which stock quantity updates may be written when enabled. Governed by Clover's privacy policy at clover.com/privacy-policy.
Render Services, Inc. — our hosting provider. CatalogBridge's application code and database run on Render's infrastructure in the United States. Governed by Render's privacy policy at render.com/privacy.
We do not share information with advertisers, data brokers, or any third party other than those listed above. We do not sell information.
7. Data Retention and Deletion
We retain Merchant information for the period necessary to provide the Service and as required by applicable law:
While the app is installed: all information is retained to operate the Service.
Upon uninstallation: we delete the Merchant record, Shopify session records, sync logs, synced-product tracking records, and Clover webhook diagnostic records from our active database.
Upon receipt of a valid Shopify shop/redact webhook: we perform the same deletion process for any remaining Merchant information associated with that shop.
Backups: our hosting provider (Render) may retain point-in-time database backups for a limited period after active-database deletion, after which deleted data is no longer recoverable.
Sync log entries are retained only while the app remains installed and are deleted with the Merchant record.
8. Data Security
We implement reasonable and appropriate technical and organizational measures to protect Merchant information, including:
Encryption in transit — all communication with CatalogBridge uses HTTPS (TLS 1.2 or higher).
Encryption at rest — production data is stored in a Render-managed database with encryption at rest.
Access controls — production database access is restricted to authorized personnel only.
Webhook signature validation — all incoming webhooks from Shopify are HMAC-validated to prevent tampering and spoofing.
Session token authentication — every authenticated request from the embedded admin is validated using Shopify session tokens.
No system can be guaranteed 100% secure. We make commercially reasonable efforts to protect your information but cannot eliminate all risk of unauthorized access.
9. Your Rights
9.1 GDPR / UK GDPR (EU and UK Merchants)
If you are based in the EEA or UK, you have the following rights:
Right to access your information.
Right to rectification of inaccurate information.
Right to erasure ("right to be forgotten").
Right to restrict processing.
Right to data portability.
Right to object to processing.
Right to lodge a complaint with a supervisory authority.
To exercise any of these rights, email privacy@thedoubleprint.com. We will respond within 30 days. Most rights can also be exercised by uninstalling the app, which triggers deletion of your active-database app information.
9.2 CCPA / CPRA (California Merchants)
If you are a California-based business, you have the right to know what personal information we have collected, request its deletion, and to non-discrimination for exercising these rights. CatalogBridge does not sell personal information.
9.3 PIPEDA (Canadian Merchants)
If you are based in Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to access and correct your personal information.
9.4 Australian Privacy Act (Australian Merchants)
If you are based in Australia, you have rights under the Privacy Act 1988, including the right to access, correct, and request deletion of your personal information.
10. International Data Transfers
CatalogBridge's infrastructure is located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using CatalogBridge, you consent to this transfer. For Merchants in the EEA or UK, we rely on Standard Contractual Clauses (or equivalent transfer mechanisms) provided by our hosting and platform partners.
11. Cookies and Tracking Technologies
CatalogBridge may use strictly necessary session cookies or local browser storage to keep an authorized merchant session active, remember operational UI preferences, and protect the connection flow. CatalogBridge does not use third-party analytics or tracking pixels, does not share information with advertising networks, and does not use cookies for cross-site advertising.
12. Children's Privacy
CatalogBridge is not directed at, and is not intended for use by, children under the age of 16. We do not knowingly collect information from children. If you believe a child has provided information to us, please contact us at privacy@thedoubleprint.com and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or the Service itself. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify Merchants through the in-app interface or by email. Your continued use of CatalogBridge after the effective date of an updated Privacy Policy constitutes your acceptance of the changes.
14. Contact
If you have questions about this Privacy Policy or our handling of your information, contact us: