Privacy policy
Last updated: 6 September 2026
What we collect. Product catalog data from the store you connect (titles, descriptions, prices, stock, images, identifiers) and the store's domain. That's what the service exists to process.
What we deliberately don't collect. No customer data from your store — no names, emails, addresses, or orders. Our Shopify app requests read access to products and inventory only.
How we use it. Solely to generate and serve your product feeds and quality reports. We don't sell data, share it with third parties for their own purposes, or use it for advertising.
Where it lives. Data is stored with our hosting provider (Railway) and served over HTTPS. Feed URLs contain an unguessable token; treat them like a password for your catalog.
Deletion. Uninstalling the Shopify app revokes our access immediately; catalog data is deleted following Shopify's redaction schedule (within 48 hours of the redaction request). For URL-connected stores, contact us and we delete everything.
The free feed check fetches the URL you submit once, computes the report in memory, and does not store your products. We keep an anonymous usage record of each check (the feed's domain name, the score, and how you found the tool) — never the products themselves.
Site analytics. We measure website traffic with Google Analytics. In the EEA, the UK and Switzerland no analytics cookies are set unless you allow them via the consent banner — declining (or ignoring it) keeps your visit cookieless, and you can change or withdraw your choice at any time via the "Cookie settings" link in the footer. Elsewhere, standard first-party analytics cookies are used. In all cases the data we see is aggregated; we never use it for advertising.
- Strictly necessary — required for the service to work, always on:
pf_session(keeps you signed in; 30 days),pf_shop(remembers which store's dashboard you're viewing; 1 year),pf_claim(links a newly installed Shopify store to the account you create; 24 hours),shopify_oauth_state(protects the Shopify connection against request forgery; 10 minutes). All first-party. - Analytics — optional; in the EEA, the UK and Switzerland these are set only with your consent:
_gaand_ga_XPYR7CG3BZ(Google Analytics; distinguish visitors and sessions; up to 2 years). - Preferences — your cookie choice itself is kept in the browser's local storage (
fr-consent), not in a cookie, and never leaves your device.
There are no advertising or cross-site tracking cookies. Payment pages run on Stripe's own domain and subscription billing for App Store installs on Shopify's — any cookies set there are governed by their respective policies.
Contact. Questions about your data: contact@feedrobin.com.