Reviewed: 2026-06-13. This policy is the published version. For questions, see the contact section at the bottom of this page.
UCP Feed

Privacy Policy

Last updated: 2026-07-16 · Effective: 2026-07-16

This Privacy Policy explains how UCP Feed (“we”, “us”, “our”) collects, uses, and protects information when you use our website at ucp-feed-landing.pages.dev and the related Shopify app. By using the service you agree to the practices described below.

1. What we collect

We collect only what is needed to run the Shopify app, serve UCP product feeds, and (optionally) notify you about the waitlist.

Information you give us

Information from Shopify (after you install)

Information collected automatically

We do not collect: customer PII, order data, payment information, device fingerprints, or advertising identifiers.

2. Why we collect it

Legal bases under the GDPR: consent (waitlist email), contract (providing the installed app), and legitimate interest (rate-limiting and security).

3. Shopify’s role

Shopify is the commerce platform. After you install UCP Feed:

  1. You authorize the app via Shopify OAuth (read-only product and inventory scopes).
  2. We store your OAuth session in Cloudflare KV so background feed refreshes work without you staying logged in.
  3. When an agent (or you) requests your feed, the Worker loads products from Shopify Admin GraphQL, transforms them to UCP JSON, and may cache the result in Cloudflare D1 for about 5 minutes.
  4. Product webhooks invalidate that cache; uninstall and shop/redact delete your token and cache.

We do not train models on your catalog. We do not sell or share product data with advertisers.

4. Data retention

5. Your GDPR rights

If you are in the EEA, the UK, or Switzerland, you have the right to:

To exercise any of these rights, email thermoye@yahoo.com with the subject line “Privacy request”. We respond within 30 days.

6. Sub-processors

We use one sub-processor: Cloudflare, Inc.

Cloudflare’s data-processing addendum and standard contractual clauses apply. Shopify receives API calls you authorize. No other third parties receive your data.

7. Cookies & tracking

The website sets no cookies. We do not use Google Analytics, Meta Pixel, or any third-party tracking script. The audit runs entirely in your browser; the only network calls leaving your device are (a) your browser fetching the merchant’s public /products.json, and (b) your browser submitting the waitlist form (if you choose to).

8. International transfers

Our infrastructure is operated by Cloudflare. Cloudflare stores data in the region where the D1 database was created (default: the region selected at Worker creation). We rely on Cloudflare’s standard contractual clauses for any cross-border transfer.

9. Changes to this policy

If we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify active waitlist subscribers by email. The previous version will be archived and available on request.

10. Contact

Email: thermoye@yahoo.com (Subject: Privacy).

Postal address: Moye Development — 2261 Market St #5035, San Francisco, CA 94114, USA.