Legal

Privacy Policy

How FeedGraph collects, uses, stores, and shares personal data — and what you can ask us to do with it. The people this policy is about are the people who use FeedGraph, not your store’s customers.

Last updated 2026-09-09

Who this covers

FeedGraph is a commerce data and performance platform at feedgraph.ai. This policy applies to the marketing website, early-access and contact forms, and the FeedGraph application.

FeedGraph’s data subjects are the people who use it — merchant and agency staff. The product handles a merchant’s product catalogue, not their customers’ orders. There is no orders table and no end-customer list. Advertising metrics we pull from Google and Meta are aggregate, keyed by campaign and SKU.

The one place an identifiable person who is not a FeedGraph user can appear is a product photograph. That is covered by the in-app AI rights terms, not by treating your shoppers as FeedGraph users.

Controller and processor

For accounts, sign-in, billing references, consent records, and this website, FeedGraph is the controller: we decide how that personal data is processed.

For catalogue, feed, and advertising data you connect, FeedGraph is your processor. You decide what to import, enrich, and publish. That processing is described in the Data Processing Agreement.

What we collect

We collect only what the product needs to run. Personal data falls into these categories:

What we do not collect

We do not import Shopify customer records or order PII. Product catalogue fields, inventory, and images are commercial data about goods.

We do not sell merchant data. We do not use your catalogue to train a shared model. Data is shared only with the infrastructure and AI subprocessors required for features you have switched on.

Where it comes from

You, when you create an account, invite a teammate, submit a form, or type into the assistant.

Connected platforms, when you grant OAuth access: Shopify for catalogue and inventory; Google Ads, Merchant Center, and Meta for feeds and aggregate performance.

Automatically, from running the service: sessions, audit events, job records, and hashed API keys you create.

Why we use it

Each purpose maps to a lawful basis under GDPR Article 6 and to the in-app consent register (Settings → Privacy). Absence of consent is treated as refusal. Required purposes are recorded as notice, not as a fake optional toggle.

How long we keep it

Inside the product, retention is classed in the data inventory and aged out by an automated job. A workspace can shorten a class, never extend it past the ceiling. “Keep forever” is not an option.

Data you send us through a form on this website is the exception: it arrives as email, is kept in a team inbox, and is cleared by hand. It is listed first below so the difference is not buried.

Your rights

You can ask for a copy of what we hold about you, to correct identity and contact fields, or to be erased. In the app this is Settings → Privacy → Data-subject requests. Workspace admins act on their own workspace only. The screen shows a preview — which tables will be exported, deleted, anonymised, or refused — before anything runs.

Erasure is not a blanket DELETE. Audit and approval records keep the event and clear the person (name, email, IP, user agent) so the history of what happened survives without naming who. Some rows are refused with a reason: shared workspaces, hash-chained consent, billing state, and the register of the request itself.

Rectification is a closed list: email and display name on the account, and email on linked sign-in identities. It does not rewrite the audit trail, change a role, or move credits.

If you do not have an account, use the contact form on this site. We will need enough to find you (usually the email you used).

Who else sees data

Active subprocessors — the parties this deployment actually sends data to — are listed in the Data Processing Agreement. Planned vendors that are not processing yet are not listed here, because naming a transfer that is not happening is as wrong as omitting one that is.

AI providers (Anthropic, Google Gemini/Veo, OpenAI when the image fallback is on) receive catalogue content for the job you ran, not your login. Shopify, Google, and Meta receive catalogue and feed data you chose to publish. Stripe receives billing contact and customer references. Resend receives email addresses for sign-in codes, invitations, and form replies.

International transfers

Several subprocessors process in the United States. Where GDPR requires a transfer tool, we rely on the vendor’s Standard Contractual Clauses (or an adequacy decision where one applies).

Cookies and sessions

The application uses a server-side session cookie so you stay signed in and in the right workspace. API keys you create are stored as SHA-256 hashes.

The marketing site does not run advertising pixels. Theme preference may be stored locally in your browser.

Children

FeedGraph is a business product. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.

How to reach us

Use the contact form at feedgraph.ai/contact, or the Privacy screen in your workspace. Security issues can also be sent to security@feedgraph.ai — see feedgraph.ai/.well-known/security.txt. We aim to acknowledge vulnerability reports within 48 hours.

This page describes how FeedGraph actually operates. It is written in plain language and pending external legal review. If something here conflicts with a signed order form or data processing addendum, the signed document wins.