Privacy policy
FeedPup XML Supplier Sync · Last updated 2026-10-05
What this app does
FeedPup XML Supplier Sync (“the app”) reads a supplier’s XML product feed that a merchant provides, maps its fields, and creates and updates products, prices and stock in the merchant’s Shopify, Wix or Magento (Adobe Commerce) store. The app is operated by ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO.
Who is responsible for your data
- Data controller: ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO
- Address: Καναδά 11, Ρόδος
- VAT / tax number (ΑΦΜ): 047290419
- Business registry number (ΓΕΜΗ): 2810543957
- Contact: contact@weareplano.gr
Data we do NOT collect
The app does not request, access or store any customer, order, checkout, payment or marketing data. It has no customer, order or marketing permissions. The Shopify privacy webhooks (customers/data_request, customers/redact) are answered, but there is no customer data to return or erase. On Wix the app requests only product and inventory permissions, never customer or order permissions. On a Magento store the app is given one limited integration that can read and write products, categories, product attributes and stock and read the list of websites; it has no access to orders, customers, payments or store configuration.
Data we store to provide the service
- Store identity: your myshopify.com domain (Shopify), your Wix site’s app-instance ID (Wix) or your Magento store’s web address (Magento), and the app’s plan.
- Access tokens issued by Shopify to the app: stored encrypted (AES-256-GCM) and deleted immediately when you uninstall. On Wix the app stores no long-lived access token; it obtains short-lived access for your site from Wix when it needs it. On Magento, the access credentials of the integration your store created for FeedPup (OAuth consumer key and secret, access token and secret) are stored encrypted (AES-256-GCM) and deleted immediately when you disconnect or uninstall the module, which also deletes that integration in your store.
- Feed settings: the supplier feed URL (stored encrypted, because such URLs often contain private tokens), the confirmed field mapping, your price/stock rules and sync preferences, and a structural summary of the feed (field names, data types, and the few distinct values of categorical fields such as stock-status words).
- Product links: supplier product/variant identifiers linked to your Shopify product/variant IDs, with content checksums, so products are updated instead of duplicated.
- Sync history: for each run, counts, timestamps, and per-item error messages (which can include supplier SKUs or product IDs). Shown for your plan’s history period (7 to 90 days) and permanently deleted after 90 days at the latest.
- Product-feed content is held only temporarily while a run is in progress and is deleted when the run ends (any leftovers are removed within 2 days). Previews are computed on demand and not stored.
- Merchant sign-in sessions may include administrator name, email, locale and account-owner flags supplied by Shopify, in addition to encrypted access tokens. These are merchant account details, not customer or order records.
- Operational logs and support correspondence may contain request addresses, store or job identifiers and error details needed to diagnose problems, answer you and protect the service. Access must be restricted to those who need it for those purposes.
- Product analytics: pseudonymous funnel events (for example “feed analyzed”). They carry a salted hash of the store domain rather than the domain, and no feed URLs or product content. A hash is not anonymous: we can match it to a known store. Associated events are erased when the store is purged.
AI field mapping and AI service providers
Pup can use artificial intelligence (AI) to suggest which supplier fields contain product titles, prices, stock and other product information. For this purpose, FeedPup sends OpenRouter and the model provider serving the request a small structural summary: selected field names, data types and at most four short sample records. Scheduled syncs use your confirmed mapping and do not call an AI model again.
We exclude recognisable sensitive fields and credential or contact values, truncate long values and strip URL credentials, query strings and fragments from samples. The full XML feed, your feed URL and application-held access tokens are not sent to the AI service. Filtering cannot identify every personal detail hidden in arbitrary product text. Connect product feeds only; do not include customer records, private credentials or sensitive personal information in product fields.
Production AI requests require no-training and zero-data-retention routing. If the configured service cannot meet those routing requirements, AI mapping is unavailable and you can review fields manually. Zero-data-retention is the endpoint policy defined by OpenRouter; some eligible endpoints use temporary in-memory caching. The models receive no store tools or authority to import products. Suggestions are validated, and unclear mappings require your confirmation before import.
Where data goes
These are disclosures of third-party data sharing needed to provide the service. We do not sell personal data or use supplier content for advertising. Platforms and payment providers also process information under their own terms for their billing, security and legal obligations. Requests you send to support are used to answer you and resolve service issues.
- Shopify or Wix: the app calls the Shopify Admin GraphQL API or the Wix Stores API on your behalf to create and update products, prices and inventory. Wix also tells the app when it is uninstalled and which paid plan the site has.
- Your Magento store: the app calls your store’s REST API with the integration you created, to create and update products, prices, categories and inventory. The FeedPup module in your admin sends the app your store’s web address and the integration credentials over HTTPS when you connect, and tells the app when you disconnect or uninstall it.
- AI routing and model providers (currently OpenRouter and the model providers it routes to): as described above, for field-mapping suggestions only.
- Our hosting provider, Hetzner Online GmbH (server located in Helsinki, Finland, in the European Union), which hosts the application and the database that store the data listed above.
Security
Supplier feed URLs are treated as untrusted input: the app only fetches public HTTP(S) addresses, blocks internal and private network addresses, limits size and time, and parses XML with entity expansion and external entities disabled. Production connections use HTTPS. Store operations require authenticated access and tenant-scoped queries; signed webhooks are verified before processing. Stored access tokens and feed URLs are encrypted with AES-256-GCM. Deployment configuration restricts database and internal-service listeners to loopback; listener bindings, firewall rules and access permissions require operational monitoring.
Your choices and retention
- Disconnect a feed at any time in the app; this removes its settings and links. Products already in your store are left untouched.
- Uninstalling the app revokes access at once. Feed settings and product links are kept for 30 days so a reinstall does not create duplicate products, then permanently deleted. On Wix, the app-removed notification starts the same 30-day period. On Magento, disconnecting or uninstalling the module starts the same 30-day period.
- When Shopify sends the shop/redact webhook, all remaining data for the store is deleted immediately. You can also ask us at any time to delete your store’s data at once (see Your rights).
- Backups: restricted nightly database backups use a 14-day production retention target. Expiry occurs during scheduled backup maintenance, so deleted data may remain in an older backup until that maintenance succeeds. Backups are not used for ordinary service access. Any restoration must reapply deletion requests before restored data returns to use.
Legal basis for processing (GDPR)
We act as controller for merchant account administration, support, service security and usage analytics. Where we process personal information in supplier or store content solely on a merchant’s instructions, the merchant determines the purpose and we act as processor; processor terms and any subprocessor arrangements must cover that processing.
We rely on performance of a contract where it applies to the individual merchant (Article 6(1)(b)); legitimate interests in providing a business service, communicating with business representatives, securing it and understanding pseudonymous usage, subject to your rights (Article 6(1)(f)); and applicable legal obligations, such as required financial records (Article 6(1)(c)). Feed-field suggestions do not make decisions about people with legal or similarly significant effects.
International transfers
Our hosting is in the European Union. OpenRouter and the provider serving an AI request may process a limited product-field summary outside the European Economic Area. Such summaries can still contain personal information supplied in product text. No-training or zero-data-retention routing does not itself establish a lawful international transfer. Where personal data is transferred, an applicable GDPR transfer mechanism, such as an adequacy decision or Standard Contractual Clauses with any necessary supplementary safeguards, is required. Contact support for the applicable recipient and safeguard information. Shopify and Wix are global platforms with their own data-protection arrangements.
Your rights (GDPR)
You can request access, correction, erasure, restriction or objection, and portability where applicable, subject to the conditions and exceptions in applicable law. You can withdraw consent for any processing based on consent without affecting earlier lawful processing. If we process data for a store on its instructions, we assist the merchant with the request.
To use these rights, write to contact@weareplano.gr. We respond without undue delay and ordinarily within one month. If a lawful extension is necessary because a request is complex or numerous, we explain it within the first month. We may verify your identity or authority using proportionate information.
You have the right to complain to a data protection authority. In Greece this is the Hellenic Data Protection Authority (www.dpa.gr); you may also contact the authority in your own country.
Cookies and browser preferences
The app uses authentication mechanisms required by the connected platform. Wix and Magento navigation use a short-lived signed session cookie. Your chosen app language is saved in browser local storage. These support sign-in and your settings; FeedPup does not add advertising cookies. Shopify and Wix administer their own cookies and privacy notices.
Contact
Questions or requests: contact@weareplano.gr. Last updated 2026-10-05.