Privacy policy — FeedPup XML Supplier Sync

Privacy policy

FeedPup XML Supplier Sync · Last updated 2026-10-05

What this app does

FeedPup XML Supplier Sync (“the app”) reads a supplier’s XML product feed that a merchant provides, maps its fields, and creates and updates products, prices and stock in the merchant’s Shopify or Wix store. The app is operated by ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO.

Who is responsible for your data

Data we do NOT collect

The app does not request, access or store any customer, order, checkout, payment or marketing data. It has no customer, order or marketing permissions. The Shopify privacy webhooks (customers/data_request, customers/redact) are answered, but there is no customer data to return or erase. On Wix the app requests only product and inventory permissions, never customer or order permissions.

Data we store to provide the service

AI field mapping and AI service providers

To suggest which feed field is the title, price, stock and so on, the app sends an AI routing service (currently OpenRouter) and the AI model providers it routes to a small summary of the feed’s structure: field names, data types, and at most four short sample records (long values are truncated; URL query strings and credentials are removed). The app never sends the full feed, your Shopify tokens, your feed URL, supplier credentials or any customer data. Requests require providers that neither keep nor train on the data (zero-data-retention routing); if no provider can meet that requirement the app does not use AI for that feed and you simply choose the fields yourself. The models have no tools or access to your store. The model providers used can change over time; they act only as processors for this one purpose. Every suggestion is checked by the app before it is used, you confirm every mapping that is not clear-cut before anything is imported, and scheduled syncs never call an AI model again.

Where data goes

We do not sell personal data, do not share it with third parties for their own purposes, and do not use it for advertising. The only third parties that receive any data are the ones listed here, each for the single purpose described.

Security

Supplier feed URLs are treated as untrusted input: the app only fetches public HTTP(S) addresses, blocks internal and private network addresses, limits size and time, and parses XML with entity expansion and external entities disabled. All traffic uses HTTPS. Tenant data is isolated per store. The database and other back-end services are not reachable from the internet: they accept connections only from the server itself, and the server’s firewall allows only web (HTTPS) and administrative SSH access. Stored secrets such as access tokens and feed URLs are encrypted (AES-256-GCM) in the database.

Your choices and retention

Legal basis for processing (GDPR)

The personal data we hold is limited to business identifiers of the merchant (store domain or Wix site ID) and the information the merchant gives us to run the service. We process it to provide the service you ask for and to carry out the contract (Article 6(1)(b) GDPR); to keep the service secure, prevent abuse and measure anonymous usage (legitimate interests, Article 6(1)(f)); and to meet legal obligations such as tax records (Article 6(1)(c)).

International transfers

Our server is in the European Union. The AI routing and model providers named above may process the small feed-structure summary outside the European Economic Area. That summary is business product data, not personal data of your customers, and requests are limited to providers that do not retain or train on it. Shopify and Wix are global platforms that process your store data under their own terms.

Your rights (GDPR)

If you are in the European Economic Area, you can ask us to give you access to the personal data we hold about you, to correct it, to delete it, to restrict or object to its processing, and to provide it in a portable format. You can also withdraw any consent you gave, at any time.

To use these rights, write to contact@weareplano.gr. We answer within one month. We may need to confirm that the request comes from the store’s owner.

You have the right to complain to a data protection authority. In Greece this is the Hellenic Data Protection Authority (www.dpa.gr); you may also contact the authority in your own country.

Contact

Questions or requests: contact@weareplano.gr. Last updated 2026-10-05.