Privacy
Privacy Policy
Last updated: 14 July 2026
This policy explains what data ChatKatalog collects, why we collect it, who we share it with, how long we keep it, and your rights over it. It applies to sellers using the admin panel and to buyers using a shop's catalog page.
On this page
- Data we collect
- Why we collect it (PDPA lawful basis)
- Cookies & analytics
- Who we share it with (subprocessors)
- Where data is stored
- How long we keep it
- Your rights (PDPA + GDPR)
- Children
- Changes to this policy
- Contact
- What we collect when you sign up
- Messages you send us (WhatsApp + contact form)
- How we keep sellers' data separate
- Trial content retention
- Shop archive
- Uniqueness enforcement
- Verification evidence
- Buyer reports
- Payment information you provide
- Payment-detail share logs and edit alerts
- Booking information
1. Data we collect
Sellers: email address, password (hashed if you sign up with email), shop details you enter (name, WhatsApp number, description, social links, address, payment-method labels), product data, uploaded images. Buyers: cart contents (stored in your browser, not on our servers), and — when you tap to send an order — the order details you confirm. We do NOT collect buyer phone numbers, names, or addresses unless you type them into the WhatsApp message yourself. Signup data we collect at /signup: see section 11. Messages you send us (WhatsApp + contact form): see section 12.
2. Why we collect it (PDPA lawful basis)
We process personal data on three lawful bases under the Sri Lankan Personal Data Protection Act (PDPA, No. 9 of 2022) and the EU General Data Protection Regulation (where applicable): (a) performance of a contract — running your shop and providing the platform; (b) legitimate interests — preventing abuse, securing the platform, basic operational analytics (never sold to third parties, never used for targeted advertising); (c) consent — where you explicitly opt in (service announcements, occasional WhatsApp follow-up). You can withdraw consent at any time by emailing legal@chatkatalog.com.
3. Cookies & analytics
We use a small number of strictly-necessary cookies: an authentication cookie (sellers only), a language preference cookie, and a bot-protection cookie on the signup and contact forms. We also use Google Analytics 4 for aggregate behaviour analytics — page views, session length, traffic sources — and a cookie-free, aggregate-only performance monitor. Neither carries personal identification or fuels advertising. A cookie notice is shown on first visit and dismissed for 90 days; you can opt out of Google Analytics tracking globally via the official Google Analytics opt-out browser add-on (https://tools.google.com/dlpage/gaoptout). We do not engage advertising or remarketing pixels.
4. Who we share it with (subprocessors)
We engage third-party services in the following categories: hosting, content delivery, bot mitigation, image storage, and performance analytics; database and authentication; aggregate behavioural analytics; application error monitoring (PII is scrubbed before send); transactional email (account confirmations, trial-state notifications, contact-form acknowledgements); and administrative email. Each operates under their own privacy terms. We do not sell personal data and do not engage marketing or advertising subprocessors.
For each vendor's specific role, jurisdiction, and link to their own privacy policy, see our full subprocessor list .
5. Where data is stored
Our primary database and image storage are hosted on infrastructure regions selected for low latency to Sri Lanka. Some subprocessors may process data outside Sri Lanka in the course of providing their service. We rely on each subprocessor's standard contractual safeguards and will align to the Data Protection Authority's formal cross-border directive when it is issued.
6. How long we keep it
- Active seller accounts: kept as long as the account is open.
- Closed seller accounts: removed from the live database immediately when you delete your account from your dashboard. Encrypted backups containing your data are rotated out within approximately 30 days.
- Operational logs and traffic metrics: 90 days.
- Audit logs (for security and dispute evidence): retained indefinitely in append-only storage.
- Backups: 30 days rolling.
- Contact-form messages: deleted 180 days after the message is archived.
- Legacy applications (the /apply form was retired on 2026-06-01 — no new applications are accepted): rejected applications were kept 90 days then deleted; pending and approved-but-expired applications followed the same 90-day clock from their state-change date. Applications already consumed into a seller account are retained for the life of that account.
For details on when inactive shops and their data may be removed, see the Account inactivity and shop removal section of our Terms.
7. Your rights (PDPA + GDPR)
- Request a copy of your data — PDPA right of access; GDPR Article 15.
- Ask for corrections — PDPA right to rectification; GDPR Article 16.
- Ask for deletion — PDPA right of erasure; GDPR Article 17.
- Restrict processing — GDPR Article 18.
- Object to processing — GDPR Article 21.
- Request portability — GDPR Article 20.
We action requests within 21 business days. Email legal@chatkatalog.com. Self-service export and account deletion are on the roadmap.
8. Children
ChatKatalog is not intended for use by anyone under 18 (our seller terms require age 18+). We do not knowingly collect data from children.
9. Changes to this policy
Material changes will be announced via email to active sellers. The "Last updated" date at the top of this page is authoritative.
10. Contact
Data requests, questions, complaints: legal@chatkatalog.com. The Privacy Contact title (Privacy Officer vs. Data Protection Officer) is pending counsel review at our pre-launch security audit.
11. What we collect when you sign up
Signing up requires only what's needed to run your shop. Via Google sign-in or email signup we collect: your name and email address (used to identify your account), your WhatsApp number (the number buyers will tap to send orders), your business or shop name, your chosen shop URL, and three legal-acceptance booleans for our Terms, Privacy Policy, and seller Guidelines. We do not ask for your home address at signup — an address field exists in the admin only if you choose to display a location on your public shop page. Signup data is retained for the life of your seller account; see section 6 for what happens when you close your account. The /apply form referenced in earlier versions of this policy was retired on 2026-06-01; legacy applications still in retention follow the windows in section 6.
12. Messages you send us (WhatsApp + contact form)
When you message ChatKatalog through WhatsApp, those messages remain on your device under WhatsApp's terms; we receive only what you send. We use WhatsApp for occasional support follow-up after you've reached out to us first. When you submit the contact form on this site we collect: your full name, your email address, the subject line you set, the message body, and the language you submitted from. Contact messages are retained for 180 days after we archive them, then deleted (section 6).
13. How we keep sellers' data separate
ChatKatalog is a multi-tenant platform. Tenant boundaries are enforced at the data layer — not at the application layer — so one seller's queries can never reach another seller's data by default. Privileged administrative access is limited to a narrow audited surface. We do not sell, share, or expose one seller's catalog or customer-message data to another seller.
14. Trial content retention
Content you create during your free 45-day Pro trial that exceeds Free-tier limits is retained for 120 days after your shop moves to the Free tier (day 53, following a short grace period at the end of the trial). After that, the excess content is permanently deleted. Your Free-tier shop and its compatible content remain until you delete your account or 365 days of inactivity pass.
15. Shop archive
If you don't log into your admin for 365 days, we email you a pre-archive warning. At day 395 the shop enters an archived state — the public URL stops resolving for buyers, but your data is preserved and you can restore the shop at any time by emailing legal@chatkatalog.com. If the shop remains un-restored we send a final notice at day 730; on day 760 the shop and all its data are permanently deleted. Shops with regular admin activity, orders, or new products are never auto-archived.
16. Uniqueness enforcement
To prevent abuse and ensure shops represent real businesses, WhatsApp numbers, primary social links, and Google Maps locations are unique per shop. For physical-store sellers, Google Maps location is collected as a real-presence signal. Multi-business owners can request a multi-shop exception via WhatsApp.
17. Verification evidence
Photos and screenshots you submit for verification are reviewed by ChatKatalog staff for fraud prevention only, never displayed publicly, and deleted 30 days after approval.
18. Buyer reports
Public catalog visitors can submit shop reports. Reports are reviewed by ChatKatalog staff. Reporter contact details are optional.
19. Payment information you provide
We collect seller payment information (bank account details, QR code images, payment link URLs) to display to buyers who place an order — and only after the seller explicitly shares them through their admin dashboard. This information is stored encrypted at rest in our database (Supabase Postgres) and object storage (Cloudflare R2, for QR images). It is never displayed on public catalog pages and never shared with third parties except where legally compelled.
20. Payment-detail share logs and edit alerts
We log every payment-detail share action (seller ID, order ID, timestamp) in a security audit log with 12-month retention, to support investigation of any disputed or fraudulent reveal. Buyers may request access logs for orders associated with their WhatsApp number by contacting legal@chatkatalog.com. Edits to seller-stored payment information (bank account changes, new QR uploads, payment link updates) trigger an email notification to the seller's account email as an account-takeover safeguard.
21. Booking information
When a shop offers services you can book, and you send a booking request, we also collect the booking details you enter at checkout: your preferred date and time, and the free-text job description you write. This booking information is part of the order and is shared with the shop you book — that sharing is the whole point of the service. Booking data is treated exactly like any other order and follows the same retention and deletion rules (see section 6). Please do not put medical or other sensitive personal details in the job-description field — discuss those directly with the seller on WhatsApp. We do not want, request, or classify such data.