Privacy Policy

Last updated: September 23, 2026

This Privacy Policy explains how AI Shopping Feeds (“we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you use our website at www.aishoppingfeeds.com and our application at app.aishoppingfeeds.com (together, the “Service”).

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and other applicable data protection laws.

By using the Service, you acknowledge that you have read and understood this Privacy Policy.


1. Data Controller

AI Shopping Feeds is the data controller responsible for your personal data.

Contact details:


2. What Personal Data We Collect

2.1 Account Data

When you create an account, we collect:

  • Full name
  • Email address
  • Password (stored in hashed form by our authentication provider)

If you choose Sign in with Google, we receive your name, email address and profile picture from your Google Account instead of a password. See Section 3 for more on the data we receive from Google.

2.2 Product Feed Data

When you use our Service, we collect and process business data that you provide, including:

  • Product feed data: Product titles, descriptions, images, prices, availability, SKUs, and other product attributes
  • Feed configurations: Export settings, channel configurations, and optimisation preferences
  • Account information: Business details, store connections, and integration credentials

Data Ownership: You retain all ownership rights to your product data, feeds, and business information. We process this data solely to provide our AI-powered feed optimisation services.

2.3 Payment Data

When you subscribe to a paid plan, payment information is collected and processed directly by Stripe. We do not store your full credit card number, CVV, or bank account details on our servers. We may receive from Stripe:

  • Last four digits of your card
  • Card brand and expiration date
  • Billing address
  • Subscription status and payment history

2.4 Contact Form Data

When you use our contact form, we collect:

  • Name
  • Email address
  • Message content

This data is sent to us via Resend (our email service provider) and is not stored in a database.

2.5 Usage Data (Automatically Collected)

When you access the Service, we automatically collect:

  • IP address
  • Browser type and version
  • Pages visited and time spent
  • Device type and operating system
  • Referring URL
  • Unique device identifiers

This data is collected via Cloudflare Web Analytics, which is a privacy-first analytics service that does not use client-side tracking or cookies.

We also use PostHog, a product analytics and error tracking tool that we host on our own server, so the data is not shared with PostHog Inc. It records which pages and screens are viewed, browser and device type, and technical details of errors, against a random identifier stored in your browser’s local storage. It is not linked to your name, email address or account, we do not store your IP address in it, and it does not record your screen or what you type. In the application, web addresses are stripped down to the page name before they are recorded, and clicks are not recorded. Our servers also record which features are used, how long requests take and any errors, against a one-way hashed code for your team rather than your name, email address or account ID, so we can see how the Service is used and fix problems. Payment events record only their type and status, never amounts, card details or customer details.

2.6 Security Verification Data

We use Cloudflare Turnstile to protect forms from automated abuse. Turnstile may collect:

  • Browser and device characteristics
  • Interaction data used to determine if you are a human

Turnstile does not use cookies and does not track you across websites.


3. Google User Data

AI Shopping Feeds is a product feed management tool for online retailers. Its Google integrations let you sign in with your Google Account, publish your product catalogue to Google Merchant Center, and see how those products perform in Merchant Center and Google Ads. This section explains exactly what we access from your Google Account, why, and what happens to it. It applies in addition to the rest of this policy.

3.1 What Google data we access

We only request access to a Google service when you choose to use the feature that needs it. Each permission is requested separately, and you can decline any of them.

Permission (OAuth scope)When we ask for itWhat we access
openid, email, profileYou click Sign in with GoogleYour name, email address and profile picture.
https://www.googleapis.com/auth/content (Merchant API)You connect a Google Merchant Center accountThe Merchant Center accounts you can access and their basic account details; your data sources and product inputs; product statuses, disapprovals and account issues; product performance and price competitiveness reports; account settings such as return policies.
https://www.googleapis.com/auth/adwords (Google Ads API)You connect a Google Ads accountThe Google Ads accounts you can access (customer IDs and names) and read-only Shopping performance metrics per product: impressions, clicks, cost, conversions and conversion value.

We do not access your Gmail, Google Drive, contacts, calendar or any other Google service.

3.2 How we use Google data

We use Google user data only to provide and improve the user-facing features of AI Shopping Feeds that you have asked for:

  • Sign-in data is used to create and log you into your account and to identify you to your teammates.
  • Merchant Center access is used to upload and update the products from your feeds in the Merchant Center account you choose, create and manage the data sources that hold them, and show you product statuses, disapprovals, account issues and performance reports inside AI Shopping Feeds so you can fix problems.
  • Google Ads access is used to read Shopping performance metrics for the products in your feeds and show them next to each product, so you can see which products earn money and which need work. We do not create, edit, pause or delete campaigns, ads, budgets or bids in your Google Ads account.

We only write to your Google accounts when you ask us to, for example when you connect a feed to Merchant Center or sync it.

3.3 How we store and protect Google data

  • OAuth access and refresh tokens are encrypted with AES-256 before they are stored, and are only decrypted on our servers when needed to make a request you have authorised.
  • Merchant Center and Google Ads data we keep (account IDs and names, product statuses, issues and performance metrics) is stored in our database hosted by Supabase, encrypted in transit and at rest, and scoped to your team so no other customer can see it.
  • Access to production systems is limited to the staff who need it to run and support the Service.

3.4 How we share Google data

We do not sell Google user data, and we do not share it with anyone except:

  • the service providers listed in Section 5 that host and run the Service on our behalf (Supabase for database hosting and Cloudflare for network delivery), under contracts that require them to protect it;
  • members of your own AI Shopping Feeds team, who can see the connected accounts and data you have shared with the team;
  • where required by law, or to protect the security of the Service or our users.

Data received from Google APIs is not sent to AI or large language model providers, and is not used to develop, improve or train any AI or machine-learning model. It is not used for advertising, is not transferred to data brokers, and is not used to decide creditworthiness or for lending.

3.5 Google API Services User Data Policy (Limited Use)

AI Shopping Feeds’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3.6 Keeping and deleting Google data

  • Disconnect at any time. You can disconnect Google Merchant Center or Google Ads from the integrations page in the app. When you do, we revoke our access token with Google, stop all syncing, and deactivate the stored credential. You can also remove our access from your Google Account at myaccount.google.com/permissions.
  • Retention. We keep Google data only while your account is active and the integration is connected, and only for as long as it is needed to show it to you. Performance metrics are refreshed on each sync, and older rows are replaced.
  • Deletion. When you delete your account, or ask us to delete your Google data by emailing [email protected], we delete your stored tokens and all data received from Google APIs within 30 days, and from backups within 90 days. Deleting your data from AI Shopping Feeds does not delete the products or data held in your own Merchant Center or Google Ads accounts.

4. How We Use Your Data

We process your personal data for the following purposes, with the corresponding legal basis under GDPR Article 6:

PurposeLegal Basis
Providing and maintaining the Service (account management, feed optimisation, exports)Performance of contract (Art. 6(1)(b))
Processing payments and managing subscriptionsPerformance of contract (Art. 6(1)(b))
Responding to your contact form enquiriesLegitimate interest (Art. 6(1)(f))
Sending transactional emails (account confirmations, password resets)Performance of contract (Art. 6(1)(b))
Protecting the Service from abuse (Turnstile CAPTCHA)Legitimate interest (Art. 6(1)(f))
Analysing Service usage to improve performanceLegitimate interest (Art. 6(1)(f))
Complying with legal obligationsLegal obligation (Art. 6(1)(c))
Sending marketing communications (only with your explicit consent)Consent (Art. 6(1)(a))
Measuring the effectiveness of our own advertising (marketing site only)Consent (Art. 6(1)(a)) where required

We do not use your product feed data to train AI models for use by other customers. Your feed data is processed solely to provide optimisation services to you. When you ask the Service to optimise product content, the product text involved is sent to an AI model provider through OpenRouter to generate the result; it is not used by us to train models. Data received from Google APIs is never sent to AI providers (see Section 3).


5. Third-Party Service Providers (Sub-Processors)

We use the following third-party service providers to operate the Service. Each acts as a data processor on our behalf:

ProviderPurposeData ProcessedPrivacy Policy
Supabase (US)Authentication and database hostingAccount data, product feed datasupabase.com/privacy
Stripe (US)Payment processingPayment and billing datastripe.com/privacy
Cloudflare (US)CDN, web analytics, Turnstile CAPTCHA, hostingIP address, usage data, security verificationcloudflare.com/privacypolicy
Resend (US)Transactional and contact form emailsEmail address, name, message contentresend.com/legal/privacy-policy
PostHog (self-hosted by us)Product analytics and error trackingRandom browser identifier, pages viewed, browser and device type, error details, feature usage keyed to a hashed team codeHosted on our own infrastructure; not shared with PostHog Inc.
Google Fonts (US)Font deliveryIP address (collected by Google when fonts load)policies.google.com/privacy
OpenRouter (US)Routing AI optimisation requests to AI model providersProduct text you ask us to optimise (never Google user data or account data)openrouter.ai/privacy

When you connect them, we also exchange data with Google (Sign in with Google, the Merchant API and the Google Ads API) on your behalf, as described in Section 3.

On our marketing website (www.aishoppingfeeds.com) only, we use the following advertising and affiliate tools to measure our own marketing. They are not loaded with any data from your product feeds or from Google APIs:

ProviderPurposeData Processed
Meta Pixel (Meta)Measuring Facebook and Instagram adsPage views, browser and device data, IP address, cookies
Google Ads tag (Google)Measuring Google Ads campaignsPage views, sign-up conversions, IP address, cookies
X Pixel (X Corp.)Measuring X (Twitter) adsPage views, contact form conversions, IP address, cookies
AffonsoTracking referrals from our affiliate programmeReferral code, page views, cookies

We do not sell your personal data to any third party.


6. Cookies and Local Storage

5.1 Cookies

We use essential cookies only for authentication and session management when you are logged into the application. These are strictly necessary for the Service to function and do not require consent under GDPR.

On our marketing website, the Meta Pixel, Google Ads tag, X Pixel and Affonso affiliate script set cookies to measure our own advertising and affiliate referrals (see Section 5). You can block or delete these cookies in your browser settings without affecting your use of the Service. We never use Google user data or your product feed data for advertising.

5.2 Local Storage

We use browser local storage to store your theme preference (light or dark mode). This data never leaves your browser and is not transmitted to our servers.

PostHog stores a random identifier in local storage so that page views from the same browser can be counted together. It is not a cookie and is not linked to your account.

5.3 Cloudflare Web Analytics

Cloudflare Web Analytics does not use cookies, does not collect personal data, and does not track users across websites. It collects aggregated, anonymised performance metrics only.


7. International Data Transfers

Your data may be transferred to and processed in the United States, where our service providers (Supabase, Stripe, Cloudflare, Resend) operate.

For transfers of personal data from the European Economic Area (EEA) or the United Kingdom to the United States, we rely on:

  • EU-U.S. Data Privacy Framework (where the provider is certified)
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable

We ensure that all transfers provide an adequate level of protection for your personal data in compliance with GDPR Article 46.


8. Data Retention

We retain your data for the following periods:

Data TypeRetention Period
Account dataDuration of your account, plus 30 days after deletion
Product feed dataDuration of your account, plus 30 days after deletion
Payment recordsAs required by tax and accounting laws (typically 7 years)
Contact form submissions12 months, unless an ongoing conversation
Usage/analytics dataAggregated and anonymised (no personal data retained). PostHog events are pseudonymous and not linked to your account
Backup copiesUp to 90 days after deletion for disaster recovery

After the retention period, data is permanently deleted from our systems and backup infrastructure.


9. Your Rights Under GDPR

If you are located in the EEA or the United Kingdom, you have the following rights under GDPR:

Right of Access (Article 15)

You can request a copy of the personal data we hold about you.

Right to Rectification (Article 16)

You can request that we correct any inaccurate or incomplete personal data.

Right to Erasure / Right to Be Forgotten (Article 17)

You can request that we delete your personal data. See Section 9 for how to do this.

Right to Restrict Processing (Article 18)

You can request that we limit how we process your data in certain circumstances.

Right to Data Portability (Article 20)

You can request to receive your personal data in a structured, commonly used, machine-readable format.

Right to Object (Article 21)

You can object to the processing of your personal data where we rely on legitimate interest as the legal basis.

Right to Withdraw Consent (Article 7)

Where we process data based on your consent, you can withdraw that consent at any time. This does not affect the lawfulness of processing carried out before withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. For the UK, this is the Information Commissioner’s Office (ICO) at ico.org.uk. For the EU, contact your local data protection authority.

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.


10. How to Delete Your Data

You have two options to delete your data:

Option 1: Self-Service Account Deletion

You can delete your account directly within the application at app.aishoppingfeeds.com. When you delete your account, all associated personal data and product feed data will be permanently removed within 30 days, with backup copies removed within 90 days.

Option 2: Email Request

You can email us at [email protected] to request deletion of your account and all associated data. We will process your request within 30 days and confirm deletion by email.

In both cases:

  • All personal data, product feed data, and feed configurations will be permanently deleted
  • Payment records may be retained as required by applicable tax and accounting laws
  • Anonymised, aggregated analytics data (which cannot identify you) may be retained

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/HTTPS)
  • Encryption of data at rest
  • Access controls and authentication
  • Regular security assessments
  • Content Security Policy (CSP) headers
  • CAPTCHA protection on forms (Cloudflare Turnstile)

While we take all reasonable precautions, no method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to [email protected].


12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33)
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to rights and freedoms (GDPR Article 34)

13. Children’s Privacy

Our Service is not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at [email protected] and we will promptly delete it.


14. Links to Other Websites

Our Service may contain links to third-party websites. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites. We encourage you to review the privacy policy of every site you visit.


15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on this page
  • Updating the “Last updated” date
  • Sending an email notification for significant changes

You are advised to review this Privacy Policy periodically. Changes are effective when posted on this page.


16. Contact Us

If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, contact us: