Privacy policy — FeedPup XML Supplier Sync

Privacy policy

FeedPup XML Supplier Sync · Last updated 2026-10-05

What this app does

FeedPup XML Supplier Sync (“the app”) reads a supplier’s XML product feed that a merchant provides, maps its fields, and creates and updates products, prices, stock and category assignments in the merchant’s WooCommerce store through the FeedPup WordPress plugin. The app is operated by ΑΝΔΡΕΑΣ ΓΙΩΡΓΑΡΑΣ, trading as PLANO.

Who is responsible for your data

Data we do NOT collect

The app does not request, access or store WooCommerce customer, order, checkout, payment or marketing data. The WordPress plugin bridge is limited to store identity, product, stock and category operations needed for feed imports and syncs. Payment-card details are handled by Stripe and are not stored by the app.

Data we store to provide the service

AI field mapping and AI service providers

Pup can use artificial intelligence (AI) to suggest which supplier fields contain product titles, prices, stock and other product information. For this purpose, FeedPup sends OpenRouter and the model provider serving the request a small structural summary: selected field names, data types and at most four short sample records. Scheduled syncs use your confirmed mapping and do not call an AI model again.

We exclude recognisable sensitive fields and credential or contact values, truncate long values and strip URL credentials, query strings and fragments from samples. The full XML feed, your feed URL, application-held WordPress bridge secrets and Stripe identifiers are not sent to the AI service. Filtering cannot identify every personal detail hidden in arbitrary product text. Connect product feeds only; do not include customer records, private credentials or sensitive personal information in product fields.

Production AI requests require no-training and zero-data-retention routing. If the configured service cannot meet those routing requirements, AI mapping is unavailable and you can review fields manually. Zero-data-retention is the endpoint policy defined by OpenRouter; some eligible endpoints use temporary in-memory caching. The models receive no store tools or authority to import products. Suggestions are validated, and unclear mappings require your confirmation before import.

Where data goes

These are disclosures of third-party data sharing needed to provide the service. We do not sell personal data or use supplier content for advertising. Stripe also processes information under its own terms for billing, security and legal obligations. Requests you send to support are used to answer you and resolve service issues.

Security

Supplier feed URLs are treated as untrusted input: the app only fetches public HTTP(S) addresses, blocks internal and private network addresses, limits size and time, and parses XML with entity expansion and external entities disabled. WordPress bridge requests are signed with timestamp, nonce, method, path and body hash, reject replayed nonces and use constant-time signature checks. All traffic uses HTTPS in production. Tenant data is isolated per store.

Your choices and retention

Legal basis for processing (GDPR)

We act as controller for merchant account administration, support, service security and usage analytics. Where we process personal information in supplier or store content solely on a merchant’s instructions, the merchant determines the purpose and we act as processor; processor terms and any subprocessor arrangements must cover that processing.

We rely on performance of a contract where it applies to the individual merchant (Article 6(1)(b)); legitimate interests in providing a business service, communicating with business representatives, securing it and understanding pseudonymous usage, subject to your rights (Article 6(1)(f)); and applicable legal obligations, such as required financial records (Article 6(1)(c)). Feed-field suggestions do not make decisions about people with legal or similarly significant effects.

International transfers

The hosting region and recipients depend on the service deployment. OpenRouter and the provider serving an AI request may process a limited product-field summary outside the European Economic Area. Such summaries can still contain personal information supplied in product text. No-training or zero-data-retention routing does not itself establish a lawful international transfer. Where personal data is transferred, an applicable GDPR transfer mechanism, such as an adequacy decision or Standard Contractual Clauses with any necessary supplementary safeguards, is required. Contact support for the applicable recipient and safeguard information. Stripe processes billing information under its own data-protection arrangements.

Your rights (GDPR)

You can request access, correction, erasure, restriction or objection, and portability where applicable, subject to the conditions and exceptions in applicable law. You can withdraw consent for any processing based on consent without affecting earlier lawful processing. If we process data for a store on its instructions, we assist the merchant with the request.

To use these rights, write to contact@weareplano.gr. We respond without undue delay and ordinarily within one month. If a lawful extension is necessary because a request is complex or numerous, we explain it within the first month. We may verify your identity or authority using proportionate information.

You can complain to a data protection authority. In Greece this is the Hellenic Data Protection Authority (www.dpa.gr); you may also contact the competent authority in your own country.

Cookies and browser preferences

An essential HttpOnly session cookie keeps you signed in to the dashboard after a verified WordPress launch. It expires after eight hours and is revoked on disconnect. Your chosen app language is saved in browser local storage. FeedPup does not add advertising cookies. Your WordPress site and Stripe administer their own cookies and privacy notices.

Contact

Questions or requests: contact@weareplano.gr. Last updated 2026-10-05.