Privacy Policy

Last updated: October 1, 2026

This Privacy Policy explains what information Catalog10 collects, where it comes from, what we use it for, who receives it and the choices you have. It covers the Catalog10 website (catalog10.com), web app and mobile apps; the businesses and team members who use them; and people who open catalog or listing links shared through Catalog10.

We do not sell personal information to third parties.

1. Information we collect

  • Account details you give us: your name, e-mail address, password (stored only as a one-way hash), office and mobile phone numbers, and your language and display settings.
  • Company details: company name, address, city and country, website, description, business type, logo and photos; the team members you invite (name and e-mail address); and, if you apply for a verification badge, your tax ID and the document you upload.
  • Listings and catalogs: the listings you create — titles, descriptions, categories, brands, grades, quantities, prices, photos and hashtags — and the catalogs and PDF catalogs made from them.
  • Channels: the channels you save to share to — their name, type and what you type in them, such as a WhatsApp group name, a contact’s phone number or a social network username. You enter these yourself; Catalog10 does not read your phone’s contacts or address book.
  • Text for AI listing creation: when you paste a message to create listings with AI, we send the text to our AI provider and keep the text and the results with your account.
  • Phone verification: when you verify your mobile number, we send a code by WhatsApp or SMS and store it to check the code you enter. Before an SMS code is sent, a security check (Cloudflare Turnstile) runs in your browser.
  • Messages to Catalog10 on WhatsApp: when a number linked to a Catalog10 account writes to Catalog10’s WhatsApp number, we keep the text with that account. Messages from other numbers get one automatic reply and are not stored; we keep the number for 24 hours only, so as not to reply more than once.
  • Sign-in links on WhatsApp: when a message comes from the mobile number verified on your account, Catalog10’s reply can include a link that opens Catalog10 signed in. The link works once, for 15 minutes, and we store it only as a one-way hash until it is used or expires. A session opened this way lasts up to 7 days and cannot change your profile, your company, your team or your plan, or delete your account; for that, sign in with your password.
  • Support and payments: the support requests you send us; your plan and payments, and the customer and subscription IDs Stripe gives us. Card details are handled by Stripe and never reach Catalog10.
  • Activity on shared links and listings: see section 2.
  • Technical data: the IP address and browser information sent with each request, a random identifier stored in your browser (see section 7), and server logs, which include IP addresses, kept for security and troubleshooting.

3. What the sending business sees

  • For each share and channel, businesses see counts — visits, repeat visits, responses (taps on “inquire via WhatsApp”), listings viewed and contact clicks — by day. They do not see visitors’ IP addresses or browser identifiers.
  • When a link was shared to a single person, these counts show the activity on that person’s link.
  • Forwarded links: activity is counted under the link that was opened. If a recipient forwards their link, whatever is done through it afterwards is counted under the original recipient’s link; the counts do not show that the original recipient personally did it.
  • When a signed-in user contacts a listing, the business that posted it receives the user’s name and WhatsApp number so that it can reply.

4. How we use information

  • to run Catalog10: accounts, listings, catalogs, sharing, the Trading Floor and the statistics described above;
  • to verify phone numbers and keep accounts secure: verification codes, sign-in, security checks and limits against abuse and spam;
  • to send you messages: security messages (verification codes, new sign-ins, password changes) always; notifications such as new requests on your listings, by WhatsApp or e-mail according to your settings; and news only if you turn it on;
  • to answer support requests, process payments and keep billing records;
  • to understand and improve how Catalog10 is used, including anonymous market statistics — category, brand, grade, price, quantity, country and dates of listings — that do not identify anyone;
  • to comply with the law and enforce our Terms.

5. Who receives information

  • Other users and visitors: your company profile and listings are shown on Catalog10 and to people who open your links, unless you make your company private; members of the same company account see its data; and businesses receive what section 3 describes.
  • Service providers that run parts of Catalog10 for us: DigitalOcean (servers and database), Cloudflare (photo storage and delivery, and the security check before SMS codes), Meta (WhatsApp messages from Catalog10’s number), Telnyx and Brevo (SMS codes and e-mail), Zoho (e-mail), Stripe (payments) and OpenAI (reading pasted text for AI listing creation).
  • Services your browser contacts directly while you use Catalog10, which receive your IP address and standard browser information: ipify (looks up your public IP address), Google Fonts (fonts on our website), flagcdn.com (country flags) and Cloudflare (photos and the security check).
  • Authorities and others, when the law requires it or to protect the rights and safety of our users, the public or Catalog10.
  • We do not sell personal information to third parties.

6. Connecting a WhatsApp Business account (coming soon)

This feature is not available yet. Once it launches, when a business connects its WhatsApp Business account through Meta’s Embedded Signup, Catalog10 will process:

  • the IDs of the connected WhatsApp Business account and phone numbers, and the access token Meta issues to Catalog10 for them;
  • the message templates the business creates or uses;
  • the messages the business sends through Catalog10 and the recipients’ phone numbers, which the business supplies or selects;
  • information Meta returns about those messages, such as delivery and read status and opt-out requests;
  • a separate link per recipient, with the link activity described in sections 2 and 3.

For these messages, the business decides whom to contact and why, and must have each recipient’s permission (see our Terms of Use). Catalog10 handles the recipients’ information to deliver the business’s messages and to show the business its results.

A recipient’s agreement to receive WhatsApp messages from a business is permission for those messages only — it is not consent to other kinds of tracking.

We will update this policy before launch if what we process differs from the above.

7. Cookies, browser storage and tracking

Catalog10 uses a few cookies and browser storage items, listed below. We do not use advertising cookies, third-party analytics tools (such as Google Analytics) or tracking pixels.

  • Sign-in (cookie “auth_token”, and a sign-in token and basic profile in local storage): keep you signed in.
  • Preferences (cookie “i18next” on our website; local storage in the app): remember your language, theme, number and date format, table layouts and the catalog links you opened recently.
  • Browser identifier (“d-c-b-etag” in local storage): a random value Catalog10 gives your browser. It is sent with your requests and, together with your IP address, used to tell first from repeat visits on shared links and listings (sections 2 and 3).
  • IP lookup (“agent_ip” in local storage): the app asks ipify for your public IP address and keeps it for up to 4 hours; it is sent to Catalog10 and stored with link and listing activity.
  • Security check: Cloudflare Turnstile runs only when you ask for an SMS code and uses browser and device signals to tell people from bots.

Clearing your browser’s data for catalog10.com deletes these items: you are signed out and a new identifier is created on your next visit.

8. How long we keep information

  • We keep account, company, listing, channel and link-activity information while the account exists, unless you delete it sooner.
  • When an account is deleted, it is erased 30 days later, except billing records kept for as long as the law requires (with the anonymised company and user records they refer to) and anonymous market statistics.
  • Activity recorded on a business’s links is erased together with that business’s account. Activity a person generated on other businesses’ links stays part of those businesses’ statistics.
  • Server logs are overwritten as new logs are written.

9. Your choices and rights

  • See and update your details in Settings and in your company profile.
  • Choose which notifications you receive, and how, in Settings → Notifications; security messages are always sent.
  • Reply STOP (or PARAR / BAJA) to Catalog10’s WhatsApp number to turn off WhatsApp notifications; security messages can still be sent. News e-mails have a one-click unsubscribe link.
  • Make your company private to hide it and its listings from the Trading Floor; your shared links keep working.
  • Delete your account at any time — see our Data deletion page.
  • Ask us for a copy of your information, or to correct or delete it, at [email protected]. Depending on where you live, local law may give you further rights.
  • If you opened a link a business shared with you and want your activity deleted, write to [email protected] with the link and roughly when you opened it. You can also contact the business that shared it.

10. Security

We protect information with measures such as encrypted connections (HTTPS), passwords stored only as one-way hashes, checks that the WhatsApp messages and updates sent to our servers really come from Meta, and limits and security checks against abuse. No system is completely secure.

11. International processing

Catalog10 and its service providers may store and process information in countries other than yours.

12. Changes to this policy

We may update this policy. The current version is always on this page, with the date it was last updated.

13. Contact

Privacy questions and requests: [email protected].