Privacy policy
Last updated: September 19, 2026
What we process
Product Feed Scan processes a public feed URL or an uploaded XML/CSV file and the product fields needed for the audit. Uploaded files use random internal names in private temporary storage and are removed after processing or failure. Interrupted upload reservations expire after one hour. Cleanup protects queued and running scans; unreferenced crash-orphan files become eligible after 24 hours. Uploaded source files are not included in database backups. Paid delivery also uses an email address and limited Stripe confirmation identifiers. Card details are not handled by Product Feed Scan.
Optional accounts
If optional accounts are enabled and you choose one, we process your email address, hashed authentication values, session timing and scans you explicitly save. Account deletion revokes sessions, removes dashboard associations and tombstones the login address. It does not itself refund a purchase or delete independently accessible guest reports; their normal expiry and refund access rules remain in effect. Payment and audit records are retained separately. Guest scanning remains available.
Optional saved monitoring
If saved monitoring is enabled for your account and you choose to use it, we retain the saved public source URL and schedule while the monitor exists. Aggregate run snapshots and associated alert records are retained for up to 90 days. Monitoring email alerts are off until you enable them; they contain aggregate changes and a sign-in-protected dashboard link, not complete product lists. You can pause runs or turn alerts off. Account deletion removes saved sources, monitoring snapshots and alert records; protected backups follow their existing rotation.
Optional agency workspaces
If workspaces are enabled, owners can explicitly share saved scans with workspace members and group them by client. We store workspace/client names, membership and sharing grants. Invitations are bound to the invited email, use a hashed one-time token and expire after 72 hours; invitation records are removed after 30 days. Resend processes the invitation email. Workspace owners can see member email addresses and revoke membership. Deleting a workspace removes its organizational data, not the underlying personal scans or payment records. Deleting its owner account deletes the workspace. Shared reports and exports remain subject to current paid access and expiry.
Optional analytics
Analytics are off until you choose “Allow analytics.” Consented first-party events contain only approved event/page categories, time and a pseudonymous HMAC-hashed random browser-session identifier and expire after 90 days. When separately enabled by the operator, Google Analytics 4 loads only after the same consent and receives allowlisted funnel events with sanitized page templates. Advertising storage, user data and personalization remain denied. Our application event parameters exclude feed URLs, product data, report, authentication and claim tokens, private paths, email, IP addresses and raw payment identifiers. Google also receives browser/network information when its script communicates after consent; its own processing and retention settings apply. Withdrawing consent stops further events, deletes the current first-party analytics session and removes known Google Analytics cookies.
Why we process it
Data is used to perform and deliver the requested audit, secure the service, prevent duplicate processing, measure the consented funnel, meet accounting obligations and answer support requests.
Retention
Scan details, affected-product mappings, private reports and delivery addresses are retained for up to 30 days. Expiry removes access and issue/product rows, redacts the URL and removes the delivery address. Expired scan tombstones can retain technical metadata, including source domains and ownership hashes; these are not anonymous statistics. Payment references and refund audit records are retained separately from report access. Protected database backups rotate after 35 days; deletion from the active system is not immediate erasure from older backups.
Service providers
Infrastructure providers process hosted data. Stripe processes payment confirmation. Resend processes account magic links and report-delivery emails and opted-in monitoring alerts when those features are enabled. Google processes analytics events only after explicit analytics consent and only while the GA4 feature flag is enabled.
Your choices
You may request access, correction or deletion where applicable. Submit only feeds you are authorized to analyze.
Contact
Privacy requests can be sent to hello@productfeedscan.com.