Privacy policy
Last updated 11 August 2026 · Applies to FeedParity at app.getfeedparity.com
In one paragraph
FeedParity reads your Shopify product catalogue and your Google Merchant Center product catalogue, compares them, and shows you where they disagree. It performs read operations only against those catalogues. It does not request access to customers, orders, or Google Ads, and no code path in the product writes to either catalogue. We do not sell personal information, and we do not use your catalogue data to train models.
Shopify data we access
When you connect a Shopify store, FeedParity requests a single permission scope,
read_products, and nothing else. If Shopify were ever to return a broader
grant than we asked for, the connection is refused rather than accepted.
Through that scope, FeedParity reads:
- Product titles, descriptions, product type, vendor and status
- Variants, including price, availability, SKU and barcode
- Product and variant identifiers used to match against Merchant Center
It also stores basic shop settings captured at connection time — currency, timezone and country — because a price comparison is meaningless without knowing the currency it is denominated in.
Google data we access
When you connect Google, FeedParity requests exactly one OAuth permission:
https://www.googleapis.com/auth/content. This is the only permission Google
publishes for Merchant Center access, and Google does not offer a read-only variant of it.
Through that permission, FeedParity reads:
- The list of Merchant Center accounts your Google account can access, so you can choose which one to verify
- The product listings in the account you select — title, price, availability, brand, GTIN, MPN, product identifiers and item group
- The review and issue status Google reports for those listings
Why: solely to compare that data against your connected Shopify catalogue and report the discrepancies back to you. It is used for no other purpose, in no other product, and for no other customer.
Google Limited Use
FeedParity’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide and improve the verification features described in this policy and visible to you in the product.
- We do not transfer Google user data to third parties except as necessary to provide and secure the service (see subprocessors), to comply with applicable law, or as part of a merger or acquisition with your notice.
- We do not use Google user data for advertising purposes of any kind.
- We do not sell Google user data.
- No human at FeedParity reads your Google user data except where you have given explicit consent for a specific support request, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
What we store, and for how long
| What | Why | Retention |
|---|---|---|
| Your account: email address, optional name, password hash | To sign you in and send the alerts you asked for | Until you delete your account |
| Integration credentials: Shopify and Google OAuth tokens | To read the two catalogues on your behalf | Until you disconnect. Encrypted at rest; never stored in plain text |
| Scan results and findings | To show what differs, when it was first detected, and whether it is still open | Until you delete the store or the account |
| Product snapshots | Evidence for a finding — the values each system reported at that moment | Stored only for products involved in a finding, and deleted with the store |
| Security audit log: sign-ins, connections, billing events, deletions | To investigate security incidents and to prove what happened to an account | Retained after account deletion, but unlinked from your account and containing no catalogue data |
| Billing records: Stripe customer and subscription identifiers | To operate your subscription | Payment card details are held by Stripe and never by us. Invoice records are retained as long as tax law requires |
| Password reset tokens | To let you recover access to your account | Single use, expires in 60 minutes; only a hash of the token is stored |
What we never collect
- Customer names, email addresses, shipping addresses or any other shopper personal data
- Orders, carts, checkouts or payment information from your store
- Google Ads campaigns, spend or performance data
- Card details — Stripe handles payment data and it never reaches our servers
How credentials are protected
- OAuth tokens for Shopify and Google are encrypted at rest with AES-256-GCM, using a key held outside the database, so a copy of the database alone does not yield usable credentials.
- Each encrypted token is cryptographically bound to the store it belongs to, so a row copied between accounts fails to decrypt rather than working in the wrong context.
- Passwords are hashed with scrypt using per-user salts. We cannot read your password.
- Session tokens are stored only as hashes, so a database copy yields no usable sessions.
- All traffic to the application is served over HTTPS.
Who else processes your data
FeedParity is operated with a small number of infrastructure providers. Each processes data only as needed to run the service:
- Railway — application hosting and the PostgreSQL database in which your account, findings and encrypted credentials are stored.
- Stripe — subscription billing. Stripe receives your email address and holds your payment details; we never receive card data.
- Hostinger — outbound email delivery for the alerts and account emails you receive.
- Shopify and Google — the sources we read from at your instruction, under the authorisations you grant.
We do not sell data to anyone, we do not share it with advertisers, and we do not use your catalogue data to train machine learning models.
Disconnecting an integration
You can disconnect either integration at any time from the Connections page in the app. When you disconnect Google, the stored credential is deleted immediately and FeedParity also asks Google to revoke the authorisation upstream. If Google cannot be reached at that moment, the obligation to revoke is recorded and retried until Google confirms it — the credential is not simply forgotten while the grant stays live in your Google account.
If you uninstall the FeedParity app from Shopify, Shopify notifies us and that store’s data is deleted. Other stores on your account are unaffected.
Deleting your data
Deleting your account from Settings in the app removes every store, connection, scan, finding and product snapshot associated with it. Integration credentials are destroyed and any outstanding Google authorisation is revoked as described above.
The security audit log is deliberately retained after deletion, but it is unlinked from your account and contains no catalogue data — it records that events happened, not what your products were.
To request deletion by email instead, or to ask what is held about you, contact support@getfeedparity.com from the address on the account.
Your rights and contact
Depending on where you live, you may have rights to access, correct, export or delete personal data we hold about you, and to object to certain processing. Write to support@getfeedparity.com and we will action the request. We will ask you to confirm control of the account email before acting on a request that would disclose or destroy data.
Privacy questions and requests: support@getfeedparity.com.
Changes
We may update this policy. Material changes will be communicated by email to account owners before they take effect, and the date at the top of this page will change.