Trust & compliance
Last updated 18 August 2026
The short version for anyone doing due diligence on this shop.
Sub-processors
Named sub-processors are disclosed to data controllers under the data processing agreement, not published here. By category:
| Category | Purpose | Minimum standard |
|---|---|---|
| Payment processing | Taking payment, refunds | PCI DSS Level 1 |
| Cloud infrastructure | Hosting, database, image storage | SOC 2 Type II |
| Email delivery | Receipts, tracking notices | SOC 2 Type II |
| Shipping and labels | Postage, tracking | Carrier of record: USPS |
To receive the named list under NDA, email security@catulie.com and ask for the DPA.
Data residency
Order data is stored in the United States.
Data retention
Order records: seven years, for tax. Admin audit log: seven years. Session records: 30 days after expiry. Everything else is deleted when the purpose it was collected for ends.
Privacy requests
Access, correction and deletion requests go to hello@catulie.com and are answered within 30 days.
Vulnerability disclosure
Policy and contact are on the security page and in security.txt.
What this shop does not do
- No advertising trackers, no data brokers, no selling of customer data.
- No card numbers stored, ever.
- No marketing email without an explicit opt-in.