Privacy policy
FeedPup XML Supplier Sync · Last updated 2026-10-05
What this app does
FeedPup XML Supplier Sync (“the app”) reads a supplier’s XML product feed that a merchant provides, maps its fields, and creates and updates products, prices and stock in the merchant’s Shopify or Wix store. The app is operated by ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO.
Who is responsible for your data
- Data controller: ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO
- Address: Καναδά 11, Ρόδος
- VAT / tax number (ΑΦΜ): 047290419
- Business registry number (ΓΕΜΗ): 2810543957
- Contact: contact@weareplano.gr
Data we do NOT collect
The app does not request, access or store any customer, order, checkout, payment or marketing data. It has no customer, order or marketing permissions. The Shopify privacy webhooks (customers/data_request, customers/redact) are answered, but there is no customer data to return or erase. On Wix the app requests only product and inventory permissions, never customer or order permissions.
Data we store to provide the service
- Store identity: your myshopify.com domain (Shopify) or your Wix site’s app-instance ID (Wix), and the app’s plan.
- Access tokens issued by Shopify to the app: stored encrypted (AES-256-GCM) and deleted immediately when you uninstall. On Wix the app stores no long-lived access token; it obtains short-lived access for your site from Wix when it needs it.
- Feed settings: the supplier feed URL (stored encrypted, because such URLs often contain private tokens), the confirmed field mapping, your price/stock rules and sync preferences, and a structural summary of the feed (field names, data types, and the few distinct values of categorical fields such as stock-status words).
- Product links: supplier product/variant identifiers linked to your Shopify product/variant IDs, with content checksums, so products are updated instead of duplicated.
- Sync history: for each run, counts, timestamps, and per-item error messages (which can include supplier SKUs or product IDs). Shown for your plan’s history period (7 to 90 days) and permanently deleted after 90 days at the latest.
- Product-feed content is held only temporarily while a run is in progress and is deleted when the run ends (any leftovers are removed within 2 days). Previews are computed on demand and not stored.
- Product analytics: anonymous funnel events (for example “feed analyzed”). They carry a salted one-way hash of the store domain, never the domain, feed URLs or product data.
AI field mapping and AI service providers
To suggest which feed field is the title, price, stock and so on, the app sends an AI routing service (currently OpenRouter) and the AI model providers it routes to a small summary of the feed’s structure: field names, data types, and at most four short sample records (long values are truncated; URL query strings and credentials are removed). The app never sends the full feed, your Shopify tokens, your feed URL, supplier credentials or any customer data. Requests require providers that neither keep nor train on the data (zero-data-retention routing); if no provider can meet that requirement the app does not use AI for that feed and you simply choose the fields yourself. The models have no tools or access to your store. The model providers used can change over time; they act only as processors for this one purpose. Every suggestion is checked by the app before it is used, you confirm every mapping that is not clear-cut before anything is imported, and scheduled syncs never call an AI model again.
Where data goes
We do not sell personal data, do not share it with third parties for their own purposes, and do not use it for advertising. The only third parties that receive any data are the ones listed here, each for the single purpose described.
- Shopify or Wix: the app calls the Shopify Admin GraphQL API or the Wix Stores API on your behalf to create and update products, prices and inventory. Wix also tells the app when it is uninstalled and which paid plan the site has.
- AI routing and model providers (currently OpenRouter and the model providers it routes to): as described above, for field-mapping suggestions only.
- Our hosting provider, Hetzner Online GmbH (server located in Helsinki, Finland, in the European Union), which hosts the application and the database that store the data listed above.
Security
Supplier feed URLs are treated as untrusted input: the app only fetches public HTTP(S) addresses, blocks internal and private network addresses, limits size and time, and parses XML with entity expansion and external entities disabled. All traffic uses HTTPS. Tenant data is isolated per store. The database and other back-end services are not reachable from the internet: they accept connections only from the server itself, and the server’s firewall allows only web (HTTPS) and administrative SSH access. Stored secrets such as access tokens and feed URLs are encrypted (AES-256-GCM) in the database.
Your choices and retention
- Disconnect a feed at any time in the app; this removes its settings and links. Products already in your store are left untouched.
- Uninstalling the app revokes access at once. Feed settings and product links are kept for 30 days so a reinstall does not create duplicate products, then permanently deleted. On Wix, the app-removed notification starts the same 30-day period.
- When Shopify sends the shop/redact webhook, all remaining data for the store is deleted immediately. You can also ask us at any time to delete your store’s data at once (see Your rights).
- Backups: we keep nightly database backups for 14 days, in a restricted location on the same server. Data deleted from the live service therefore disappears from backups within 14 days of deletion.
Legal basis for processing (GDPR)
The personal data we hold is limited to business identifiers of the merchant (store domain or Wix site ID) and the information the merchant gives us to run the service. We process it to provide the service you ask for and to carry out the contract (Article 6(1)(b) GDPR); to keep the service secure, prevent abuse and measure anonymous usage (legitimate interests, Article 6(1)(f)); and to meet legal obligations such as tax records (Article 6(1)(c)).
International transfers
Our server is in the European Union. The AI routing and model providers named above may process the small feed-structure summary outside the European Economic Area. That summary is business product data, not personal data of your customers, and requests are limited to providers that do not retain or train on it. Shopify and Wix are global platforms that process your store data under their own terms.
Your rights (GDPR)
If you are in the European Economic Area, you can ask us to give you access to the personal data we hold about you, to correct it, to delete it, to restrict or object to its processing, and to provide it in a portable format. You can also withdraw any consent you gave, at any time.
To use these rights, write to contact@weareplano.gr. We answer within one month. We may need to confirm that the request comes from the store’s owner.
You have the right to complain to a data protection authority. In Greece this is the Hellenic Data Protection Authority (www.dpa.gr); you may also contact the authority in your own country.
Contact
Questions or requests: contact@weareplano.gr. Last updated 2026-10-05.