Operator and effective date
Last updated August 14, 2026. FeedRescue AI is operated by Arya Singh, trading as FeedRescue AI, with a business and notices address at Mulund West, Mumbai, Maharashtra 400080, India. This policy explains how FeedRescue handles data for its public checker, Shopify embedded app, Google Merchant Center connection, diagnostics, monitoring, reporting, and support workflows.
Data accessed
FeedRescue may access, collect, or process the following categories of data depending on how you use it:
- Shopify store and catalog data, including shop domain, shop identifiers, product and variant identifiers, product titles, handles, status, publication state, prices, inventory and availability signals, product attributes, images, product page URLs, public storefront-visible signals, and scan/evaluation results.
- Shopify billing and app operation data, including plan status, entitlement checks, usage events, audit logs, webhook events, API call logs, job status, error state, and support context.
- Public checker data, including storefront or product URLs submitted for a scan, scan IDs, issue examples, and optional report email metadata. Public checker report emails are handled with minimization controls, including hashed report-email metadata in scan records where applicable.
- Public-site analytics data, including a one-way hash derived from the request IP address, the requested public path, page type, referrer origin, allowlisted UTM attribution values, and limited event properties such as an optional country or acquisition source.
- Newsletter and support data. A newsletter request includes the email address, source page, one-way email and IP hashes, and delivery-result metadata; the address and source page are forwarded through Resend to the FeedRescue support mailbox. A support request can include the sender email, subject, message body, source, app area, shop domain, troubleshooting environment, and reproduction details.
- Google OAuth identity data when you connect Google Merchant Center: your connected Google account email address and email verification status through the
openidandemailscopes. FeedRescue uses this only to show which Google account is connected and to support account-selection and troubleshooting workflows. - Google OAuth authorization data: granted scopes, access tokens, refresh tokens, token expiration metadata, and connection status. Tokens are stored encrypted or secrets-managed so FeedRescue can maintain the merchant-authorized Merchant Center connection.
- Google Merchant Center data through the
https://www.googleapis.com/auth/contentscope and Merchant API, including accessible Merchant Center account list, selected merchant account ID, account name, account type, developer/user access state, product and offer identifiers, product status and approval signals, pending or disapproved item state, product-level diagnostics, account-level diagnostics, policy issue details, data-source/feed information, product input metadata, aggregate approval counts, and import or publish status. - Merchant-approved repair data, including fix suggestions, write destination, supplemental feed rows, app metafield payloads, Merchant Center product input records, idempotency keys, provider responses, rollback payloads, and related audit records.
FeedRescue does not request access to Gmail, Google Drive, Google Ads, YouTube, Google Workspace documents, or unrelated Google account content.
FeedRescue is a business service and is not directed to children. Do not submit a child's personal information through the public checker, support, or merchant workflows. If you believe a child has provided personal information, contact the legal and privacy address below.
How data is used
- To authenticate Shopify shops and merchant-authorized Google Merchant Center connections.
- To sync Shopify catalog data and show real product-level issue proof before payment.
- To import Merchant Center statuses and diagnostics, compare them with Shopify catalog facts, and explain approval, pending, disapproval, account, policy, or product-level signals.
- To generate deterministic issue findings, constrained AI-assisted drafts, safe fix plans, and merchant review workflows.
- To publish or remove merchant-approved supplemental feed, Merchant Center product input, app metafield, or explicit direct catalog edits when the merchant has enabled and confirmed that workflow.
- To provide monitoring, weekly reports, alerts, support, troubleshooting, security, and abuse prevention.
- To measure minimized public-page and newsletter acquisition events, process newsletter requests, and triage merchant-submitted support messages.
- To maintain audit history, idempotency, rollback evidence, compliance records, and operational reliability.
FeedRescue does not sell Google user data, Shopify catalog data, or public checker data. FeedRescue does not use Google user data for advertising, retargeting, credit, lending, eligibility, or unrelated product profiling.
Google API limited use
FeedRescue's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve user-facing Merchant Center diagnostics, monitoring, safe repair workflows, support, security, compliance, and account-management features requested by the merchant.
- Google user data is not sold, rented, or transferred for advertising purposes.
- Google user data is not used to train, improve, or develop generalized AI or machine-learning models.
- Humans may read specific Google user data only after your affirmative agreement to that access, when necessary for security purposes including bug or abuse investigation, when required by applicable law, or when the data is aggregated and anonymized for lawful internal operations.
- Google user data is transferred only with your consent to provide or improve a prominent user-facing FeedRescue feature, for security, to comply with applicable law, or in another case expressly permitted by Google's Limited Use requirements.
Before FeedRescue accesses, uses, stores, or shares Google user data in a new or materially different way, we will notify affected users and obtain any consent required by Google policy or applicable law.
AI and merchant facts
FeedRescue treats AI as constrained enrichment only. AI may help draft explanations, category suggestions, copy improvements, or repair candidates from available product and diagnostic context, but deterministic rules and merchant-confirmed facts remain authoritative. FeedRescue does not use AI to invent GTINs, manufacturer part numbers, weights, dimensions, certifications, compliance facts, shipping facts, or other factual commerce claims.
When AI features are used, FeedRescue sends only the product and diagnostic context needed for the requested merchant-facing feature. When support triage is enabled, the submitted support source, app area, shop domain, subject, and message body can also be sent to OpenAI for classification and a draft reply. FeedRescue does not itself use Google user data or support messages to train generalized AI models. Any production processor receiving Google user data must first have applicable terms and configuration that satisfy Google's Limited Use requirements.
How data is stored and protected
- Data is transmitted over encrypted HTTPS connections.
- OAuth tokens and sensitive contact values are encrypted or stored as references to encrypted secrets.
- Operational records use hashes, fingerprints, and minimized fields where full raw values are not needed.
- Access is limited by role and need, with audit logging for scans, suggestions, external writes, and cleanup.
- External writes use idempotency and audit records so a merchant can understand what was attempted.
- Provider calls are rate-limited, timeout-bounded, and monitored to reduce abuse and operational risk.
Retention and deletion
FeedRescue retains tenant records while an installation remains active and for only as long as needed to provide the app, preserve merchant-visible audit and safety history, troubleshoot provider outcomes, prevent abuse, resolve disputes, and meet legal obligations. Paid-plan cancellation or downgrade alone does not uninstall the app or trigger deletion. The periods below are normal operational retention periods unless applicable law requires a longer period.
- Raw API-call records are retained for 90 days and then deleted after monthly aggregate records are created.
- Product snapshots older than 90 days are deleted, except for the latest snapshot retained for each product.
- Raw Google and product-issue diagnostic payloads are cleared after they have not been seen again for 180 days. A recurring issue can retain its raw payload longer. Normalized findings and audit records may remain while needed for the purposes described above.
- Hashed Resend webhook receipts and Shopify Admin performance samples are retained for 35 days. Expired authenticated acceptance challenges are deleted after a 35-day post-expiration retention window.
- Public-checker report email values are minimized and scrubbed from scan results in favor of one-way hashes during retention cleanup.
You can disconnect Google Merchant Center in the app, revoke FeedRescue access in your Google Account, or contact FeedRescue to request deletion of Google connection data. Uninstalling immediately ends app access and revokes current Shopify authority. It also queues cleanup that cancels queued work and removes stored Google authority; because that cleanup does not revoke access at Google's provider-side endpoint, you should also revoke FeedRescue in your Google Account's third-party access settings. Shopify normally sends a valid shop-redaction request about 48 hours after uninstall. FeedRescue then deletes the installation-bound tenant database records and stored artifacts through its redaction workflow within 30 days, except for data that applicable law requires us to retain and limited de-identified compliance evidence.
Provider-managed backups can retain residual copies until their then-current rotation or deletion process removes them. FeedRescue does not guarantee retrieval or export after uninstall, so preserve records you need before uninstalling.
Merchant controls
- Google Merchant Center connection is optional and happens only after merchant OAuth authorization.
- Catalog repairs are non-destructive by default through supplemental feeds or app-owned metafields.
- Direct Shopify catalog edits require an explicit merchant setting before they can be used.
- Merchant-input issues stay merchant-input issues; FeedRescue should not invent missing factual values.
- You can review suggested values, write destination, evidence, and fix method before applying a fix.
Your choices and contact
You may ask to access, correct, delete, or restrict processing of personal information associated with your use of FeedRescue, regardless of where you are located, subject only to limitations permitted by law. You may also object to processing, withdraw consent where consent is the basis for processing, or raise a privacy concern. Email the legal and privacy contact at aryasingh080202@gmail.com. For product support or Google Merchant Center disconnection help, email feedrescue.api@gmail.com. You can also revoke Google access from your Google Account's third-party access settings. Please first allow us to address a privacy grievance through the legal and privacy contact above. If applicable law then gives you a right to complain to a regulator, you may exercise that right.
You can send a consumer grievance to aryasingh080202@gmail.com or to Mulund West, Mumbai, Maharashtra 400080, India. The appointed grievance officer is Arya Singh. The customer-care and grievance phone is +91 7738976545. Where the Consumer Protection (E-Commerce) Rules apply, the officer will acknowledge a consumer complaint within 48 hours of receipt and redress it within one month of receipt.
We may update this policy to reflect service, provider, legal, or security changes. We will post the updated text and date here and, when required, provide additional notice.