Privacy Policy — Feed Heartbeat
Feed Heartbeat ("Feed Heartbeat", "we", "us", "our") is a Shopify application that monitors the health of a merchant's product feed to Google Merchant Center and alerts the merchant when that feed silently breaks, goes stale, or stops syncing. This policy explains what data the app accesses, why, how long we keep it, and the rights you have over it.
Data controller: Feed Heartbeat is operated by Pyke Limited, a company registered in the United Kingdom. Contact: privacy@feedheartbeat.com.
1. Scope
This policy covers the Feed Heartbeat Shopify app and the website at https://feedheartbeat.com. It applies to the Shopify merchants who install the app ("you") and to the data the app processes on your behalf.
Feed Heartbeat is a detect-and-advise tool. We never edit your products, your feed rules, your Merchant Center account, or move any funds. We read, we compare, we alert. That boundary is deliberate and is reflected in the minimal permissions below.
2. What we access, and why
2.1 From your Shopify store — scope: read_products only
- Product and variant data: title, price, availability/inventory state, published status, and
updated_attimestamps. - Why: this is "ground truth A" — what your store currently says. We compare it to what Google is actually serving to detect drift and drop-outs.
- We do NOT request
read_customers,read_orders, or any customer, order, payment, or financial scope. Feed Heartbeat never sees your customers' personal data.
2.2 From Google Merchant Center — scope: https://www.googleapis.com/auth/content
- Per-product status via the Merchant / Content API for Shopping: the item as Google currently holds it (offer ID, price, availability, title) plus Google's own approval/disapproval status and item-level issues.
- Account-level status: account issues and suspension-risk warnings.
- Why: this is "ground truth B" — what Google is actually serving. The gap between A and B is the product.
- We use the
contentscope read-only in effect — we call it to read status; we do not push product updates through it.
2.3 Authentication tokens
- OAuth access/refresh tokens for Shopify and for Google Merchant Center, so the app can poll on your behalf without asking you to log in each time.
2.4 Contact email
- The email address you provide (or your Shopify account email) so we can send you the alert when your feed breaks, plus billing receipts.
3. What we do NOT collect
- No customer personal data (names, emails, addresses, order history) — we never request the scopes that would expose it.
- No payment card data — billing is handled entirely by Shopify Billing; we never see or store card details.
- No browsing/behavioural tracking of your shoppers.
- No selling, renting, or sharing of any data for advertising or marketing.
4. How we use the data
Strictly to run the service you installed:
- Poll Shopify and Google Merchant Center on a schedule (hourly to daily).
- Store a snapshot of each poll so we can compare against the previous state.
- Detect silent sync-breaks, staleness, drop-outs, feed-wide stalls, and new disapprovals/warnings.
- Send you a consolidated alert (one email via Resend, plus the in-app dashboard) with plain-language fix guidance.
- Bill you through Shopify Billing.
We do not use your data to train machine-learning models, to profile you, or for any purpose beyond the monitoring service.
5. Google user data & Limited Use
Feed Heartbeat's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google Merchant Center data only to provide and improve the feed-monitoring features the merchant installed.
- We do not transfer or sell Google user data for advertising, and do not use it for any purpose unrelated to the app's core monitoring function.
- We do not allow humans to read Google user data except: (a) with your explicit consent for a specific support request, (b) where necessary for security or to comply with law, or (c) where the data is aggregated and anonymised for internal operations.
6. Storage, security, and location
- Where: encrypted managed Postgres and application servers hosted on Fly.io.
- Encryption: OAuth tokens are encrypted at rest. All data in transit uses TLS.
- Access: limited to the automated service and, exceptionally, authorised operators under the conditions in §5.
- Sub-processors: Fly.io (hosting/database), Resend (transactional email delivery), Shopify (billing, app platform), Google (the monitored API). No other third parties receive your data.
7. Data retention
- Product snapshots: retained on a rolling window (default 90 days) so we can compare state and show you history; older snapshots are automatically purged.
- OAuth tokens: retained while the app is installed; deleted on uninstall.
- On uninstall: we honour Shopify's
app/uninstalledand the mandatory compliance webhooks and delete your store's data within 30 days.
8. Shopify mandatory compliance webhooks
customers/data_request— because we hold no customer personal data, we respond confirming there is none to return.customers/redact— no customer data is held, so there is nothing to redact; we acknowledge and log the request.shop/redact— on receipt (48 hours after uninstall) we erase all stored data for that shop.
9. Your rights (UK GDPR / GDPR)
You have the right to access, rectify, erase, restrict, or port your data, and to object to processing. To exercise any of these, email privacy@feedheartbeat.com; we respond within 30 days. You may also lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk. Because the app processes no consumer PII, most requests resolve to "no personal data held."
10. International transfers
Data is processed in the region(s) our sub-processors operate. Where data leaves the UK/EEA, transfers rely on the relevant safeguards (UK IDTA / EU Standard Contractual Clauses) offered by those providers.
11. Children
Feed Heartbeat is a business-to-business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
12. Changes to this policy
We may update this policy; material changes will be announced in-app and by email, with a revised "Last updated" date. Continued use after a change constitutes acceptance.
13. Contact
Questions or requests: privacy@feedheartbeat.com
Pyke Limited, United Kingdom.