Privacy policy — FeedPup Supplier Sync

Privacy policy

FeedPup Supplier Sync · Last updated 2026-10-02

What this app does

FeedPup Supplier Sync (“the app”) reads a supplier’s XML product feed that a merchant provides, maps its fields, and creates and updates products, prices and stock in the merchant’s Shopify store. The app is operated by ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO.

Who is responsible for your data

Data we do NOT collect

The app does not request, access or store any customer, order, checkout, payment or marketing data. It has no customer, order or marketing permissions. The Shopify privacy webhooks (customers/data_request, customers/redact) are answered, but there is no customer data to return or erase.

Data we store to provide the service

AI field mapping and AI service providers

To suggest which feed field is the title, price, stock and so on, the app sends an AI routing service (currently OpenRouter) and the AI model providers it routes to a small summary of the feed’s structure: field names, data types, and at most four short sample records (long values are truncated; URL query strings and credentials are removed). The app never sends the full feed, your Shopify tokens, your feed URL, supplier credentials or any customer data. Requests require providers that neither keep nor train on the data (zero-data-retention routing); if no provider can meet that requirement the app does not use AI for that feed and you simply choose the fields yourself. The models have no tools or access to your store. The model providers used can change over time; they act only as processors for this one purpose. Every suggestion is checked by the app before it is used, you confirm every mapping that is not clear-cut before anything is imported, and scheduled syncs never call an AI model again.

Where data goes

We do not sell personal data and do not use it for advertising.

Security

Supplier feed URLs are treated as untrusted input: the app only fetches public HTTP(S) addresses, blocks internal and private network addresses, limits size and time, and parses XML with entity expansion and external entities disabled. All traffic uses HTTPS. Tenant data is isolated per store.

Your choices and retention

Contact

Questions or requests: contact@weareplano.gr. Last updated 2026-10-02.