Trust
Trust Center
Your catalog data stays yours. Here is how we protect it, what we are certified against, and who to ask when you need more information.
Compliance
Certified and compliant
ISO/IEC 27001:2022
Certified
GDPR
Compliant, EU data residency available
How we protect your data
Your data
You stay in control
You own your data
Your catalog data is yours. We process it to do the job and nothing else.
Scoped sub-processors
A short, published list of sub-processors, each under a strict DPA.
Deleted on request
Export or delete your data at any time. We honor retention windows you set.
Questions we get asked
Do you train AI models on our catalog data?
No. Your product data is never used to train shared or third-party models. It is processed only to run the jobs you ask for.
Where is our data stored?
You can choose EU data residency. Data is encrypted at rest and in transit.
Are you certified?
Yes. CommerceClarity is ISO/IEC 27001 certified, so information security is run as an audited management system, not a set of good intentions.
How do you handle access control?
Role-based access with SSO/SAML, least-privilege internal controls, and a full audit trail.
How do we delete our data?
You can export or delete your data at any time, and set retention windows we honor.
Can you fill in our security questionnaire?
Yes. Send it over and we will complete it.
How do we report a vulnerability?
Email security@commerceclarity.com with what you found and how to reproduce it. We will confirm we have it and tell you what we do about it.