PDF Catalog is a Shopify app that turns a merchant’s own product data into PDF catalogs, price lists and spec sheets. This policy explains exactly what the app reads, what it keeps, and for how long.
The app requests three access scopes and no others:
| Scope | What it is used for |
|---|---|
read_products |
Product and collection titles, images, descriptions, SKUs, prices, variants and metafields — the content that appears in a generated PDF. |
read_customers |
One field only: customer.companyContactProfiles, to find which B2B company a signed-in buyer belongs to. |
read_companies |
Company location IDs and contract pricing, so a B2B buyer’s price list shows their negotiated prices. |
The app does not read, receive or store customer names, email addresses,
phone numbers or postal addresses. The only customer-related query it
makes returns a company location ID, which is used during rendering and never
written to storage. The app has no access to orders and does not request the
read_orders scope.
| Data | Why | Retained |
|---|---|---|
| Shopify session and access token | To call the Shopify API on the store’s behalf | Until uninstall |
| Shop settings — shop name, currency, locale, logo URL, brand colour, plan | To render documents and apply the correct plan | Until uninstall |
| Catalog designs created in the app | They are the merchant’s own work | Until deleted or uninstall |
| Generated PDF files, cached on the app server | So a repeated download is served instantly instead of re-rendering | Until the underlying product, collection or design changes, or uninstall |
| Usage events — a timestamp, document type, which design, and whether the file came from cache | Monthly usage counting and the in-app dashboard | Until uninstall |
None of these records contain personal data about a store’s customers. Product content is the merchant’s own catalog data.
fonts.googleapis.com.
Fonts already installed on the system are used without any external request.
client.crisp.chat so merchants can reach support. Crisp sets
its own cookies and receives whatever a merchant types into the chat, along
with their browser and IP address. It is not loaded in the design builder.
No store or customer data is passed to it by this app.
See Crisp’s privacy policy.
The app sends no data to analytics providers, advertising networks or data brokers. Crisp above is a support tool, used only for messages a merchant chooses to send.
Paid plans are handled entirely by Shopify’s Billing API. Payment details are never seen, handled or stored by this app. The app records only which plan a store is on and how many PDFs it has built in the current calendar month.
Uninstalling the app stops all access immediately. On Shopify’s
shop/redact request, the app permanently deletes everything it holds
for that store — settings, designs, usage events, sessions, and the cached PDF
files on disk.
Shopify’s customers/data_request and customers/redact
requests are acknowledged with nothing to return or erase, because the app stores
no customer personal data in the first place.
A merchant may also request deletion at any time through our contact form.
If this policy changes materially, the date at the top of this page is updated and merchants are notified in the app before the change takes effect.
add-ons.org — https://add-ons.org/contact/