Privacy policy
FeedPup XML Supplier Sync · Last updated 2026-10-05
What this app does
FeedPup XML Supplier Sync (“the app”) reads a supplier’s XML product feed that a merchant provides, maps its fields, and creates and updates products, prices, stock and category assignments in the merchant’s WooCommerce store through the FeedPup WordPress plugin. The app is operated by ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO.
Who is responsible for your data
- Data controller: ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO
- Address: Καναδά 11, Ρόδος
- VAT / tax number (ΑΦΜ): 047290419
- Business registry number (ΓΕΜΗ): 2810543957
- Contact: contact@weareplano.gr
Data we do NOT collect
The app does not request, access or store WooCommerce customer, order, checkout, payment or marketing data. The WordPress plugin bridge is limited to store identity, product, stock and category operations needed for feed imports and syncs. Payment-card details are handled by Stripe and are not stored by the app.
Data we store to provide the service
- Store identity: your WordPress/WooCommerce site URL, installation ID, store name, currency, timezone, plugin version and the app’s plan.
- WordPress bridge connection secret generated by the plugin: stored encrypted (AES-256-GCM) and used only to sign server-to-plugin commerce requests. Browser login grants are one-use random tokens stored only as SHA256 hashes and expire after 60 seconds.
- Browser session data for the app dashboard: HttpOnly SameSite=Lax session cookies created only after a verified WordPress bridge grant is consumed.
- Feed settings: the supplier feed URL (stored encrypted, because such URLs often contain private tokens), the confirmed field mapping, your price/stock rules and sync preferences, and a structural summary of the feed (field names, data types, and the few distinct values of categorical fields such as stock-status words).
- Product links: supplier product/variant identifiers linked to your WooCommerce product/variation IDs, with content checksums, so products are updated instead of duplicated.
- Billing records: Stripe customer and subscription identifiers, billing period, billing currency, plan status and renewal/cancellation timestamps. The app does not store card numbers.
- Operational logs and support correspondence may contain request addresses, store or job identifiers and error details needed to diagnose problems, answer you and protect the service. Access must be restricted to those who need it for those purposes.
- Sync history: for each run, counts, timestamps, and per-item error messages (which can include supplier SKUs or product IDs). Shown for your plan’s history period (7 to 90 days) and permanently deleted after 90 days at the latest.
- Product-feed content is held only temporarily while a run is in progress and is deleted when the run ends (any leftovers are removed within 2 days). Previews are computed on demand and not stored.
- Product analytics: pseudonymous funnel events (for example “feed analyzed”). They carry a salted hash of the store domain rather than the domain, and no feed URLs or product content. A hash is not anonymous: we can match it to a known store. Associated events are erased when the store is purged.
AI field mapping and AI service providers
Pup can use artificial intelligence (AI) to suggest which supplier fields contain product titles, prices, stock and other product information. For this purpose, FeedPup sends OpenRouter and the model provider serving the request a small structural summary: selected field names, data types and at most four short sample records. Scheduled syncs use your confirmed mapping and do not call an AI model again.
We exclude recognisable sensitive fields and credential or contact values, truncate long values and strip URL credentials, query strings and fragments from samples. The full XML feed, your feed URL, application-held WordPress bridge secrets and Stripe identifiers are not sent to the AI service. Filtering cannot identify every personal detail hidden in arbitrary product text. Connect product feeds only; do not include customer records, private credentials or sensitive personal information in product fields.
Production AI requests require no-training and zero-data-retention routing. If the configured service cannot meet those routing requirements, AI mapping is unavailable and you can review fields manually. Zero-data-retention is the endpoint policy defined by OpenRouter; some eligible endpoints use temporary in-memory caching. The models receive no store tools or authority to import products. Suggestions are validated, and unclear mappings require your confirmation before import.
Where data goes
These are disclosures of third-party data sharing needed to provide the service. We do not sell personal data or use supplier content for advertising. Stripe also processes information under its own terms for billing, security and legal obligations. Requests you send to support are used to answer you and resolve service issues.
- Your WordPress/WooCommerce site: the app calls the FeedPup plugin bridge with signed HMAC requests to read store info and create or update products, prices, stock and categories.
- Stripe: the app creates and reads hosted Checkout sessions, customers and subscriptions for paid plans, and receives signed billing webhooks.
- AI routing and model providers (currently OpenRouter and the model providers it routes to): as described above, for field-mapping suggestions only.
- Our hosting and database provider, which stores the data listed above.
Security
Supplier feed URLs are treated as untrusted input: the app only fetches public HTTP(S) addresses, blocks internal and private network addresses, limits size and time, and parses XML with entity expansion and external entities disabled. WordPress bridge requests are signed with timestamp, nonce, method, path and body hash, reject replayed nonces and use constant-time signature checks. All traffic uses HTTPS in production. Tenant data is isolated per store.
Your choices and retention
- Disconnect a feed at any time in the app; this removes its settings and links. Products already in your store are left untouched.
- Disconnect the WordPress plugin at any time; this revokes app sessions and grants, cancels queued work and prevents further signed commerce calls after the plugin secret is removed locally.
- Uninstalling or disconnecting the app revokes access at once. Feed settings and product links are retained for up to 30 days to support reinstalling, then erased unless you request earlier deletion. A paid subscription does not extend retention of supplier content. Necessary billing identifiers can remain to manage an outstanding subscription and meet applicable financial obligations.
- Disconnecting or uninstalling the plugin does not cancel the separate Stripe subscription. Cancel through the subscription controls before disconnecting if you want to stop renewal; contact support if you no longer have app access.
Legal basis for processing (GDPR)
We act as controller for merchant account administration, support, service security and usage analytics. Where we process personal information in supplier or store content solely on a merchant’s instructions, the merchant determines the purpose and we act as processor; processor terms and any subprocessor arrangements must cover that processing.
We rely on performance of a contract where it applies to the individual merchant (Article 6(1)(b)); legitimate interests in providing a business service, communicating with business representatives, securing it and understanding pseudonymous usage, subject to your rights (Article 6(1)(f)); and applicable legal obligations, such as required financial records (Article 6(1)(c)). Feed-field suggestions do not make decisions about people with legal or similarly significant effects.
International transfers
The hosting region and recipients depend on the service deployment. OpenRouter and the provider serving an AI request may process a limited product-field summary outside the European Economic Area. Such summaries can still contain personal information supplied in product text. No-training or zero-data-retention routing does not itself establish a lawful international transfer. Where personal data is transferred, an applicable GDPR transfer mechanism, such as an adequacy decision or Standard Contractual Clauses with any necessary supplementary safeguards, is required. Contact support for the applicable recipient and safeguard information. Stripe processes billing information under its own data-protection arrangements.
Your rights (GDPR)
You can request access, correction, erasure, restriction or objection, and portability where applicable, subject to the conditions and exceptions in applicable law. You can withdraw consent for any processing based on consent without affecting earlier lawful processing. If we process data for a store on its instructions, we assist the merchant with the request.
To use these rights, write to contact@weareplano.gr. We respond without undue delay and ordinarily within one month. If a lawful extension is necessary because a request is complex or numerous, we explain it within the first month. We may verify your identity or authority using proportionate information.
You can complain to a data protection authority. In Greece this is the Hellenic Data Protection Authority (www.dpa.gr); you may also contact the competent authority in your own country.
Cookies and browser preferences
An essential HttpOnly session cookie keeps you signed in to the dashboard after a verified WordPress launch. It expires after eight hours and is revoked on disconnect. Your chosen app language is saved in browser local storage. FeedPup does not add advertising cookies. Your WordPress site and Stripe administer their own cookies and privacy notices.
Contact
Questions or requests: contact@weareplano.gr. Last updated 2026-10-05.