Privacy policy — FeedPup XML Supplier Sync

Privacy policy

FeedPup XML Supplier Sync · Last updated 2026-10-05

What this app does

FeedPup XML Supplier Sync (“the app”) reads a supplier’s XML product feed that a merchant provides, maps its fields, and creates and updates products, prices and stock in the merchant’s Shopify, Wix or Magento (Adobe Commerce) store. The app is operated by ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO.

Who is responsible for your data

Data we do NOT collect

The app does not request, access or store any customer, order, checkout, payment or marketing data. It has no customer, order or marketing permissions. The Shopify privacy webhooks (customers/data_request, customers/redact) are answered, but there is no customer data to return or erase. On Wix the app requests only product and inventory permissions, never customer or order permissions. On a Magento store the app is given one limited integration that can read and write products, categories, product attributes and stock and read the list of websites; it has no access to orders, customers, payments or store configuration.

Data we store to provide the service

AI field mapping and AI service providers

Pup can use artificial intelligence (AI) to suggest which supplier fields contain product titles, prices, stock and other product information. For this purpose, FeedPup sends OpenRouter and the model provider serving the request a small structural summary: selected field names, data types and at most four short sample records. Scheduled syncs use your confirmed mapping and do not call an AI model again.

We exclude recognisable sensitive fields and credential or contact values, truncate long values and strip URL credentials, query strings and fragments from samples. The full XML feed, your feed URL and application-held access tokens are not sent to the AI service. Filtering cannot identify every personal detail hidden in arbitrary product text. Connect product feeds only; do not include customer records, private credentials or sensitive personal information in product fields.

Production AI requests require no-training and zero-data-retention routing. If the configured service cannot meet those routing requirements, AI mapping is unavailable and you can review fields manually. Zero-data-retention is the endpoint policy defined by OpenRouter; some eligible endpoints use temporary in-memory caching. The models receive no store tools or authority to import products. Suggestions are validated, and unclear mappings require your confirmation before import.

Where data goes

These are disclosures of third-party data sharing needed to provide the service. We do not sell personal data or use supplier content for advertising. Platforms and payment providers also process information under their own terms for their billing, security and legal obligations. Requests you send to support are used to answer you and resolve service issues.

Security

Supplier feed URLs are treated as untrusted input: the app only fetches public HTTP(S) addresses, blocks internal and private network addresses, limits size and time, and parses XML with entity expansion and external entities disabled. Production connections use HTTPS. Store operations require authenticated access and tenant-scoped queries; signed webhooks are verified before processing. Stored access tokens and feed URLs are encrypted with AES-256-GCM. Deployment configuration restricts database and internal-service listeners to loopback; listener bindings, firewall rules and access permissions require operational monitoring.

Your choices and retention

Legal basis for processing (GDPR)

We act as controller for merchant account administration, support, service security and usage analytics. Where we process personal information in supplier or store content solely on a merchant’s instructions, the merchant determines the purpose and we act as processor; processor terms and any subprocessor arrangements must cover that processing.

We rely on performance of a contract where it applies to the individual merchant (Article 6(1)(b)); legitimate interests in providing a business service, communicating with business representatives, securing it and understanding pseudonymous usage, subject to your rights (Article 6(1)(f)); and applicable legal obligations, such as required financial records (Article 6(1)(c)). Feed-field suggestions do not make decisions about people with legal or similarly significant effects.

International transfers

Our hosting is in the European Union. OpenRouter and the provider serving an AI request may process a limited product-field summary outside the European Economic Area. Such summaries can still contain personal information supplied in product text. No-training or zero-data-retention routing does not itself establish a lawful international transfer. Where personal data is transferred, an applicable GDPR transfer mechanism, such as an adequacy decision or Standard Contractual Clauses with any necessary supplementary safeguards, is required. Contact support for the applicable recipient and safeguard information. Shopify and Wix are global platforms with their own data-protection arrangements.

Your rights (GDPR)

You can request access, correction, erasure, restriction or objection, and portability where applicable, subject to the conditions and exceptions in applicable law. You can withdraw consent for any processing based on consent without affecting earlier lawful processing. If we process data for a store on its instructions, we assist the merchant with the request.

To use these rights, write to contact@weareplano.gr. We respond without undue delay and ordinarily within one month. If a lawful extension is necessary because a request is complex or numerous, we explain it within the first month. We may verify your identity or authority using proportionate information.

You have the right to complain to a data protection authority. In Greece this is the Hellenic Data Protection Authority (www.dpa.gr); you may also contact the authority in your own country.

Cookies and browser preferences

The app uses authentication mechanisms required by the connected platform. Wix and Magento navigation use a short-lived signed session cookie. Your chosen app language is saved in browser local storage. These support sign-in and your settings; FeedPup does not add advertising cookies. Shopify and Wix administer their own cookies and privacy notices.

Contact

Questions or requests: contact@weareplano.gr. Last updated 2026-10-05.