Legal

Privacy Policy

Last updated 28 August 2026

FeedProof is a Shopify app that audits a store's product catalog for AI-assistant discovery, drafts reversible fixes for the gaps it finds, and reports which products earn revenue from AI referrals. This policy explains what data the app reads, why it reads it, how long it is kept, and how to have it deleted.

It covers the FeedProof Shopify app, the FeedProof agency console, and this website. It also contains our data processing terms for merchants, which take effect when you install the app. It is written to be read, not to be survived, so it is short.

The short version. FeedProof reads product data and order totals. It does not read customer names, email addresses, phone numbers, or addresses, and it does not request access to those fields. Uninstalling the app deletes everything within 48 hours.

Who we are

FeedProof is operated by Daniel Cantón, an independent developer based in Portugal. For any privacy question, including a request to access or delete your data, email privacy@getfeedproof.com. We answer within 30 days and usually within two working days.

Under the GDPR, a merchant using FeedProof is the data controller for their store's data, and FeedProof is a data processor acting on that merchant's instructions.

What the Shopify app reads

FeedProof requests the narrowest set of Shopify access scopes that make the product work. Each one maps to a specific feature:

ScopeWhat it reads or writesWhy
write_productsProduct titles, descriptions, images, variants, vendors, product types, tags, SKUs, barcodes and pricesTo score each product against the readiness rubric, and to write approved fixes back
write_metaobjects
write_metaobject_definitions
Structured product attributes in the feedproof namespaceTo store enriched attributes and the previous value of anything we change, so every edit can be undone
read_ordersOrder totals, currency, order dates, line-item products, SKUs and quantities, and the landing and referring page of the visitTo attribute orders to AI-assistant referrals and report which products earn that revenue

What we deliberately do not read

FeedProof operates at Protected Customer Data Level 1 under Shopify's classification. From an order, the app reads the value and the products. It never reads the customer object attached to that order, and it has not requested access to Shopify's protected customer fields:

These fields are not stored, not logged, and not sent to any third party. If Shopify ever returns them in an API response, they are discarded before the response is written to our database.

What this website collects

The free readiness check on this site reads a store's publicly available product feed, the same data any shopper's browser can fetch. It requires no login and no access to the store's admin.

If you submit your email address to request the full report or early access, we store that address so we can send it to you and tell you when the product opens up. We do not sell it, rent it, or add it to anyone else's list. Reply to any email to be removed.

Where the data goes

Store data is processed by a small set of subprocessors, each of which handles only what its job requires:

SubprocessorPurposeRegion
Fly.ioApplication hostingFrankfurt, Germany
SupabaseDatabaseFrankfurt, Germany
AnthropicDrafting product copy from product dataUnited States
PerplexityChecking whether AI assistants name a storeUnited States
SerpAPIFinding third-party pages that rank for a store's categoriesUnited States
ResendSending report and digest emailsUnited States

Only product data reaches the drafting and search subprocessors. No order data and no customer data is sent to any of them. Transfers to United States subprocessors rely on the European Commission's Standard Contractual Clauses.

How long we keep it

Deletion and your rights

FeedProof implements Shopify's mandatory privacy webhooks. When Shopify sends shop/redact, every record belonging to that store is deleted, across all tables, not just the obvious ones. customers/redact and customers/data_request are also implemented, and both return promptly because the app holds no customer records to redact or disclose.

You can also ask us directly. Email privacy@getfeedproof.com to access, correct, export or delete your data, to object to or restrict processing, or to withdraw consent. If you are in the EEA or the UK and you are unhappy with our response, you may complain to your local data protection authority.

Security

If we become aware of a breach affecting a merchant's data, we will notify the affected merchants and Shopify without undue delay and within 72 hours of becoming aware of it.

Consent and data sales

Customer consent. FeedProof does not set cookies or trackers on a merchant's storefront and does not identify individual shoppers. Referral attribution relies on the landing and referring page that Shopify attaches to an order, and Shopify withholds those fields when a visitor has declined analytics tracking under the store's consent settings. An order from a visitor who has not consented therefore reaches us without referral data and is never attributed. We do not attempt to reconstruct it by any other means.

Data sales and sharing. We do not sell personal data, and we do not share it for cross-context behavioural advertising, under the CCPA/CPRA or any comparable law. There is nothing to opt out of, and any opt-out signal a customer sends is satisfied by default. Our subprocessors are listed above; each is a service provider acting on our instructions, and none receives order or customer data.

Automated decision-making. FeedProof makes automated suggestions about product records, not about people. It performs no profiling and no automated decision-making that produces legal or similarly significant effects on any individual.

Data processing terms for merchants

This section is the data processing agreement between you and FeedProof. Installing the FeedProof app constitutes your acceptance of these terms. They apply for as long as the app is installed on your store.

Roles

You are the data controller for your store's data. FeedProof is your data processor and acts only on your documented instructions, which are the settings you choose in the app and the actions you take in it. If we are ever required by law to process your data otherwise, we will tell you first unless the law forbids it.

Scope of the processing

Subject matterAuditing a product catalog for AI discoverability, drafting reversible fixes, and attributing orders to AI-assistant referrals
DurationFor as long as the app is installed
Categories of dataProduct data; order value, currency, date, line-item products, SKUs and quantities; the landing and referring page of a visit. No customer identifiers.
Data subjectsStore visitors who place an order, indirectly and without being identified

Our obligations

Your obligations

You confirm you have the lawful basis and any notices or consents required to have us process your store's data as described. You are responsible for the instructions you give the app, including which fixes you approve and apply.

International transfers

The subprocessors listed above in the United States receive only product data. Those transfers rely on the European Commission's Standard Contractual Clauses, which are incorporated into these terms by reference.

Cookies

This website sets no advertising or analytics cookies. The embedded Shopify app uses a session cookie to keep you signed in, and the agency console uses a signed session cookie for the same purpose. Neither is used for tracking.

Children

FeedProof is a business tool. It is not directed at children and we do not knowingly collect data from anyone under 16.

Changes

If this policy changes in a way that affects what we collect or why, we will update the date at the top and email merchants with the app installed before the change takes effect.