Privacy policy
FeedPup Supplier Sync · Last updated 2026-10-02
What this app does
FeedPup Supplier Sync (“the app”) reads a supplier’s XML product feed that a merchant provides, maps its fields, and creates and updates products, prices and stock in the merchant’s Shopify store. The app is operated by ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO.
Who is responsible for your data
- Data controller: ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO
- Address: Καναδά 11, Ρόδος
- VAT / tax number (ΑΦΜ): 047290419
- Business registry number (ΓΕΜΗ): 2810543957
- Contact: contact@weareplano.gr
Data we do NOT collect
The app does not request, access or store any customer, order, checkout, payment or marketing data. It has no customer, order or marketing permissions. The Shopify privacy webhooks (customers/data_request, customers/redact) are answered, but there is no customer data to return or erase.
Data we store to provide the service
- Store identity: your myshopify.com domain and the app’s plan.
- Access tokens issued by Shopify to the app: stored encrypted (AES-256-GCM) and deleted immediately when you uninstall.
- Feed settings: the supplier feed URL (stored encrypted, because such URLs often contain private tokens), the confirmed field mapping, your price/stock rules and sync preferences, and a structural summary of the feed (field names, data types, and the few distinct values of categorical fields such as stock-status words).
- Product links: supplier product/variant identifiers linked to your Shopify product/variant IDs, with content checksums, so products are updated instead of duplicated.
- Sync history: for each run, counts, timestamps, and per-item error messages (which can include supplier SKUs or product IDs). Shown for your plan’s history period (7 to 90 days) and permanently deleted after 90 days at the latest.
- Product-feed content is held only temporarily while a run is in progress and is deleted when the run ends (any leftovers are removed within 2 days). Previews are computed on demand and not stored.
- Product analytics: anonymous funnel events (for example “feed analyzed”). They carry a salted one-way hash of the store domain, never the domain, feed URLs or product data.
AI field mapping and AI service providers
To suggest which feed field is the title, price, stock and so on, the app sends an AI routing service (currently OpenRouter) and the AI model providers it routes to a small summary of the feed’s structure: field names, data types, and at most four short sample records (long values are truncated; URL query strings and credentials are removed). The app never sends the full feed, your Shopify tokens, your feed URL, supplier credentials or any customer data. Requests require providers that neither keep nor train on the data (zero-data-retention routing); if no provider can meet that requirement the app does not use AI for that feed and you simply choose the fields yourself. The models have no tools or access to your store. The model providers used can change over time; they act only as processors for this one purpose. Every suggestion is checked by the app before it is used, you confirm every mapping that is not clear-cut before anything is imported, and scheduled syncs never call an AI model again.
Where data goes
We do not sell personal data and do not use it for advertising.
- Shopify: the app calls the Shopify Admin GraphQL API on your behalf to create and update products, prices and inventory.
- AI routing and model providers (currently OpenRouter and the model providers it routes to): as described above, for field-mapping suggestions only.
- Our hosting and database provider, which stores the data listed above.
Security
Supplier feed URLs are treated as untrusted input: the app only fetches public HTTP(S) addresses, blocks internal and private network addresses, limits size and time, and parses XML with entity expansion and external entities disabled. All traffic uses HTTPS. Tenant data is isolated per store.
Your choices and retention
- Disconnect a feed at any time in the app; this removes its settings and links. Products already in your store are left untouched.
- Uninstalling the app revokes access at once. Feed settings and product links are kept for 30 days so a reinstall does not create duplicate products, then permanently deleted.
- When Shopify sends the shop/redact webhook, all remaining data for the store is deleted immediately.
Contact
Questions or requests: contact@weareplano.gr. Last updated 2026-10-02.