Data processing agreement
Last updated: 26 September 2026
These terms apply automatically to every FeedRobin account and form part of the terms of service. You do not have to ask for them, and there is nothing to sign before they apply. If your organisation needs a countersigned copy for its own records, write to contact@feedrobin.com and we will sign and return one.
You are the controller of the personal data in your catalogue and account. FeedRobin is the processor, and acts only on your instructions. Using the product is the instruction: connecting a store tells us to read it, creating a feed tells us to publish it, and deleting an account tells us to erase it.
Subject matter: generating and serving product feeds from your catalogue, checking that catalogue for defects, and running the account.
Categories of data: product catalogue data, which is generally not personal data; the account holder's email address; the email addresses of team members you invite; billing contact details. Where a catalogue happens to contain personal data — a seller name in a marketplace listing, for example — it is processed on the same terms as the rest of the file.
Data subjects: you, the people you invite to your account, and anyone whose details you choose to place in your own catalogue.
Duration: for as long as the account exists. See clause 8.
What is never processed: your customers' personal data. We do not request, receive or store orders, shoppers' names, addresses or payment details, and the platform permissions we ask for do not extend to them.
We process personal data only on your documented instructions, including for transfers, unless a law we are subject to requires otherwise — in which case we will tell you before processing, unless that law forbids it.
Everyone with access is bound by confidentiality. In practice access is held by the smallest possible number of people, because FeedRobin is run by a very small team.
We keep appropriate technical and organisational measures under Article 32. They are described, concretely and without euphemism, on the data security page. That page is part of these terms, and changes to it are changes to this agreement.
You give general authorisation for the subprocessors below. Each is bound by terms no less protective than these, for the one job named beside it.
Your catalogue and account data are stored in the European Economic Area: the database runs in Railway's EU West region in Amsterdam. The companies above are established outside the EEA, so engaging them involves a transfer out of it, and each is engaged under its own published data processing terms and the safeguards they contain.
Cloudflare provides DNS for our domain. It resolves the name and carries no traffic, so it processes none of your data and is not a subprocessor.
We will announce a new or replacement subprocessor on this page at least 30 days before it starts, and you may object in that window by writing to contact@feedrobin.com. If we cannot resolve an objection, you may terminate and receive a refund of the unused part of any prepaid term.
If someone exercises a right — access, correction, erasure, portability, objection — and we receive the request, we will pass it to you rather than answer it ourselves, because it is yours to answer. The product does most of the work without us: an account can be exported and deleted from the account page, in full, without asking anyone.
We will notify you without undue delay, and in any case within 48 hours of becoming aware, of any breach affecting personal data we process for you. The notice will say what happened, which data and roughly how many records are involved, what we have done, and what we recommend you do — and we will send it as soon as we know those things rather than waiting until we know all of them.
Deleting your account deletes your stores and every product, feed and log attached to them in the same request. There is no grace period and no archive copy, which is why the export exists and why we say to take it first. Backups roll off on their own retention cycle and are never used to restore data for anyone but you.
We will give you the information you reasonably need to verify that we are meeting these terms, and will answer a security questionnaire. We do not hold a SOC 2 report or an ISO 27001 certificate to hand you instead — if that is a requirement for your organisation, it is better to know now than after signing.
We will post a new version here and date it. Where a change materially reduces your protection we will tell account holders by email before it takes effect.
Questions about any of this reach a person at contact@feedrobin.com. See also the privacy policy, the data security page and the vulnerability disclosure policy.