Privacy Policy
Last updated: August 25, 2026
This Privacy Policy explains what information Feedwyre ("we," "us," "our") collects when you use our product feed and catalog API service (the "Service"), how we use and protect it, and the choices you have.
1. Information we collect
| Category | Examples |
|---|---|
| Account information | Company name, email address, password (hashed — see §3), MFA enrollment status |
| Catalog data | Products, prices, stock levels, images, custom attributes, and any other data you upload, import, or synchronize into a feed |
| Integration credentials | API keys you generate (stored only as a one-way hash), and — if you use Database Sync — the host/credentials for your own external database (encrypted at rest) |
| Usage & activity data | API call counts, timestamps, IP addresses of requests, and a plain-English activity log of changes made to your feeds |
| Billing information | Handled directly by our payment processor, Stripe — we store a subscription/customer reference, not your card details |
2. How we use it
- To provide the Service: authenticate requests, serve your feeds, run scheduled syncs, meter usage against your plan, and enforce plan limits.
- To operate your account: send transactional email (verification codes, password resets, trial reminders, billing receipts) and respond to support requests.
- To keep the Service secure: detect abuse, enforce login lockouts after repeated failed attempts, and investigate suspicious activity.
- To improve the Service: aggregate, anonymized usage patterns only — we do not sell your Catalog Data or use it to train unrelated products.
3. How we protect it
What's actually in place
- Account passwords are hashed with a salted, industry-standard algorithm — never stored, logged, or recoverable in plain text.
- Database Sync credentials (for connecting your own external database) are encrypted at rest, not stored as plain text.
- API keys are stored only as a one-way hash; the raw key is shown once at creation and cannot be retrieved from our database afterward if lost.
- Login attempts are rate-limited with an automatic lockout after repeated failures, on both the tenant dashboard and the internal admin console.
- A scheduled database sync can only ever reach a public host you specify — it's blocked from resolving to a private or internal network address.
- Optional two-factor authentication (TOTP) is available on every account.
No method of transmission or storage is 100% secure, and we can't guarantee absolute security — but the measures above are enforced automatically, not left as optional configuration.
4. Data retention
- Your Catalog Data and account information are retained for as long as your account is active.
- Per-feed activity log entries are retained for 30 days on a rolling basis and then automatically removed.
- If a trial account is suspended without upgrading, data is retained for a further grace period before permanent deletion, giving time to reactivate by upgrading.
- Deleting your account (self-service, from the Account page, or on request through support) permanently removes every feed, product, API key, consumer, and booking associated with it. This action cannot be undone.
5. Who we share it with
- Stripe — payment processing and subscription billing.
- Google — only if you choose "Continue with Google" to sign in; we receive your basic profile (name, email) to create or match your account.
- Email delivery provider — to send transactional email (verification codes, receipts, trial notices).
We do not sell your personal information or your Catalog Data to third parties. We may disclose information if required by law, or to protect the rights, property, or safety of Feedwyre, our customers, or the public.
6. Your rights & choices
- Access & export — every product in every feed you own can be exported to CSV or XLSX at any time from the dashboard.
- Correction — update your account and Catalog Data directly at any time.
- Deletion — permanently delete your entire account and everything in it from the Account page's danger zone, with no need to contact support.
- Depending on where you're located, you may have additional rights under applicable data protection law (such as the GDPR or CCPA), including the right to object to or restrict certain processing. Contact us using the details below to exercise these rights.
7. Cookies & similar technologies
The dashboard uses only the storage strictly necessary to keep you signed in (a session token) — we don't use third-party advertising or tracking cookies.
8. Children's privacy
The Service is intended for business use and is not directed at, or knowingly used to collect information from, children.
9. International transfers
Your information may be processed in a country other than the one you're located in. Where required, we rely on appropriate safeguards for such transfers.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via the dashboard or by email before taking effect.
11. Contact us
Questions about this policy or your data can be sent to privacy@feedwyre.example.