Privacy Policy
This Privacy Policy explains how UCP Feed (“we”, “us”, “our”) collects, uses, and protects information when you use our website at ucp-feed-landing.pages.dev and the related Shopify app. By using the service you agree to the practices described below.
1. What we collect
We collect only what is needed to run the Shopify app, serve UCP product feeds, and (optionally) notify you about the waitlist.
Information you give us
- Email address — only if you submit the waitlist form on the marketing site.
- Shop domain — when you install the app or use the public audit tool (e.g.
your-store.myshopify.com).
Information from Shopify (after you install)
- OAuth access token — an offline session (access token, refresh token, and expiry) stored so we can refresh your catalog in the background.
- Product catalog — titles, descriptions, URLs, images, prices, availability, and variants for active products. We request
read_productsandread_inventoryonly. We do not access customers, orders, or payment data.
Information collected automatically
- IP address — used only for rate-limiting. We store a SHA-256 hash of the IP as the rate-limit key, not the raw IP. Counters expire within about 90 seconds.
- Aggregated, non-identifying request metadata — e.g. HTTP status, response size, and path. Retained up to 7 days for security and capacity planning.
We do not collect: customer PII, order data, payment information, device fingerprints, or advertising identifiers.
2. Why we collect it
- Email — to send a launch announcement and to honor unsubscribe requests.
- Shop domain + OAuth tokens — to authenticate to Shopify Admin GraphQL and serve your UCP feed.
- Product catalog — to transform Shopify products into the UCP feed format and serve it to AI agents and merchants.
- Hashed IP — to enforce per-IP request budgets and protect the service from abuse.
Legal bases under the GDPR: consent (waitlist email), contract (providing the installed app), and legitimate interest (rate-limiting and security).
3. Shopify’s role
Shopify is the commerce platform. After you install UCP Feed:
- You authorize the app via Shopify OAuth (read-only product and inventory scopes).
- We store your OAuth session in Cloudflare KV so background feed refreshes work without you staying logged in.
- When an agent (or you) requests your feed, the Worker loads products from Shopify Admin GraphQL, transforms them to UCP JSON, and may cache the result in Cloudflare D1 for about 5 minutes.
- Product webhooks invalidate that cache; uninstall and
shop/redactdelete your token and cache.
We do not train models on your catalog. We do not sell or share product data with advertisers.
4. Data retention
- Waitlist email — until you unsubscribe or 24 months of inactivity, whichever comes first.
- OAuth tokens (KV) — for as long as the app remains installed; deleted on uninstall and on Shopify’s
shop/redactwebhook. - Product feed cache (D1) — short-lived (about 5 minutes TTL); also deleted on product webhooks, uninstall, and
shop/redact. Edge CDN copies may remain up to about 1 hour after invalidation. - Hashed IP rate-limit keys (KV) — about 90 seconds, then auto-expire.
- Request metadata — up to 7 days in logs, then aggregated and originals dropped.
5. Your GDPR rights
If you are in the EEA, the UK, or Switzerland, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate data.
- Erasure (“right to be forgotten”).
- Restriction or objection to our processing.
- Data portability in a machine-readable format.
- Withdraw consent at any time, without affecting prior processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email thermoye@yahoo.com with the subject line “Privacy request”. We respond within 30 days.
6. Sub-processors
We use one sub-processor: Cloudflare, Inc.
- Cloudflare Workers — runs OAuth, webhooks, and feed transformation.
- Cloudflare D1 — stores waitlist emails and short-lived product feed cache rows (encrypted at rest by default, TLS in transit).
- Cloudflare KV — stores OAuth sessions and rate-limit counters (hashed IPs only).
Cloudflare’s data-processing addendum and standard contractual clauses apply. Shopify receives API calls you authorize. No other third parties receive your data.
7. Cookies & tracking
The website sets no cookies. We do not use Google Analytics, Meta Pixel, or any third-party tracking script. The audit runs entirely in your browser; the only network calls leaving your device are (a) your browser fetching the merchant’s public /products.json, and (b) your browser submitting the waitlist form (if you choose to).
8. International transfers
Our infrastructure is operated by Cloudflare. Cloudflare stores data in the region where the D1 database was created (default: the region selected at Worker creation). We rely on Cloudflare’s standard contractual clauses for any cross-border transfer.
9. Changes to this policy
If we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify active waitlist subscribers by email. The previous version will be archived and available on request.
10. Contact
Email: thermoye@yahoo.com (Subject: Privacy).
Postal address: Moye Development — 2261 Market St #5035, San Francisco, CA 94114, USA.