Data scope

Redacted product rows only.

Catalog Recall Monitor needs product fields only. Do not send customer names, order history, payment data, contracts, wholesale costs, margins, passwords, API keys, or full databases.

No customer data No payment data Product rows only
01 Send these

Product identifiers.

Title, brand, category, SKU, model number, UPC or barcode, product URL, and vendor/source.

02 Keep out

Private business data.

Customer names, emails, addresses, order IDs, payment data, credentials, contracts, costs, margins, and full exports.

03 Output

Source-backed queue.

The report returns suppress recommendation, manual review, or no visible match, with official CPSC links where relevant.

What to send · what not to send

The narrowest useful data set.

Send these

product rows
  • Product title or listing title
  • Brand or manufacturer, if known
  • Category or department
  • Internal SKU or listing ID
  • Model number, style number, serial range, UPC, or barcode if present
  • Product URL or source URL if public

Blank fields are fine. More identifiers improve recall matching quality.

Do not send these.

keep these out
  • customer names
  • emails
  • addresses
  • order IDs
  • payment data
  • passwords
  • API keys
  • contracts
  • wholesale costs
  • margins
  • full databases

If in doubt, leave it out. This workflow works on the same kind of redacted product export you would send a catalog cleanup vendor.

Boundary

Decision support, not certification.

This workflow provides source-backed decision support. It does not certify products as safe, provide legal advice, or replace human safety/compliance review.

Report language: “No visible match found in scanned official sources as of the scan time.” Never: “This product is safe.”