PixQuality Product Feed App privacy
Privacy Policy for PixQuality Product Feed
Effective date: July 18, 2026
This policy explains how PixQuality Product Feed (the “App”) collects, uses, stores, shares, and deletes information when a Shopify merchant installs or uses the App. It supplements the general PixQuality website privacy policy.
1. Who operates the App
The App is provided by SC PIXQUALITY COMPANY SRL, CUI/CIF 42655030 (RO42655030 where applicable), registered with the Romanian Trade Register under number J2020001297221, with its registered office at Strada Veche no. 112, Romania (“PixQuality”, “we”, “us”, or “our”).
For privacy questions or requests, contact us at [email protected] or by telephone at +40 755 760 540.
2. Information the App processes
2.1 Shopify shop and installation information
We process the merchant’s myshopify.com shop domain, installation status and timestamps, approved access scopes, Shopify access-token and refresh-token records, token expiry timestamps, and a private token used to protect the generated feed URLs. Access tokens, refresh tokens, and private feed tokens are stored using authenticated encryption.
2.2 Product catalog information
Through Shopify’s APIs, the App reads the information required to create product feeds, including product and variant identifiers, titles, descriptions, status, URLs, images, vendor or brand values, prices, compare-at prices, currency, inventory and availability, publication status, collections, tags, categories, metafields, product identifiers, attributes, and shipping weight.
2.3 Information entered by the merchant
We store feed settings entered in the App, such as feed title and description, storefront URL, target country, language, currency, default brand, inclusion and exclusion rules, category mappings, metafield mappings, and custom labels.
2.4 Technical and operational information
To operate and secure the App, we process synchronization status and history, generated feed files, validation issues, error details, webhook identifiers, webhook topics, shop domain, webhook timestamps, and standard server or network logs. Infrastructure providers may also process request metadata such as IP address, browser or user-agent information, and timestamps for security and delivery purposes.
2.5 Information we do not request
The App does not request access to Shopify customer records, orders, checkouts, or payment information. It does not install tracking scripts on the merchant’s storefront and does not collect information directly from the merchant’s customers.
3. How we use information
We use the information described above only to:
- authenticate the merchant and maintain the Shopify installation;
- read and synchronize eligible catalog information;
- apply the merchant’s feed configuration;
- generate and serve separate XML feeds for Google Merchant Center and Meta Commerce Manager;
- display synchronization status and validation issues in the App dashboard;
- prevent duplicate webhook processing, diagnose failures, maintain service reliability, and protect the App from misuse;
- respond to support, privacy, security, or legal requests.
We do not sell App data, use it to build advertising profiles, or use it for advertising unrelated to providing the App.
4. Legal bases
Where the EU General Data Protection Regulation or similar law applies, we process information as necessary to provide the App and perform our agreement with the merchant, to comply with legal obligations, and for our legitimate interests in securing, maintaining, troubleshooting, and improving the service. Where consent is required by law, we rely on consent.
5. Feed URLs and disclosure to Google or Meta
The App creates unlisted Google and Meta feed URLs protected by a high-entropy private token. Anyone who has a feed URL may be able to retrieve the catalog information in that feed, so merchants must keep these URLs private and share them only with services they authorize.
The App does not automatically connect to or create accounts in Google Merchant Center or Meta Commerce Manager. Catalog information is disclosed to Google or Meta only when the merchant supplies the corresponding feed URL to that platform. Google and Meta then process the feed under their own terms and privacy practices.
6. Service providers and international transfers
We use service providers where necessary to operate the App, including Shopify for installation and API access, hosting and database infrastructure, network and security services, and Cloudflare for traffic delivery and protection. These providers process information on our behalf or as independent controllers under their own terms, depending on the service.
PixQuality is established in Romania, within the European Economic Area. Some providers may process information in countries outside the EEA. Where required, we rely on applicable safeguards such as adequacy decisions, standard contractual clauses, or other legally recognized transfer mechanisms.
7. Data retention and deletion
We retain shop-linked application data while the App is installed and as needed to provide the service. When Shopify sends a verified app/uninstalled or shop/redact webhook, the App deletes the shop record and its linked installation credentials, configuration, private feed endpoint, cached catalog items, validation issues, generated feeds, and synchronization jobs and history.
Limited webhook-receipt metadata and infrastructure logs are stored separately from shop-linked application records and may remain after uninstall for duplicate prevention, security, reliability, incident investigation, or legal compliance. Their retention depends on the applicable operational, security, and legal requirements. Merchants may request deletion of personal information by contacting us.
Because the App does not request or store customer or order data, Shopify customer data-request and customer-redaction webhooks are authenticated and acknowledged without retrieving or deleting customer records.
8. Security
We use technical and organizational safeguards designed to protect App data, including HTTPS, tenant isolation, signed webhook verification, read-only Shopify scopes, authenticated session tokens, and AES-256-GCM encryption for Shopify access tokens, refresh tokens, and private feed tokens. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Merchant choices and data-protection rights
Depending on applicable law, individuals may have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal information, and to withdraw consent where processing relies on consent. To submit a request, email [email protected]. We may need to verify the requester’s identity and authority over the relevant Shopify shop.
Merchants can also stop future App processing by uninstalling the App. Individuals in the EEA may lodge a complaint with their local supervisory authority. In Romania, the authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP).
10. Children
The App is a business service for Shopify merchants and is not directed to children. We do not knowingly collect personal information from children through the App.
11. Changes to this policy
We may update this policy when the App, our providers, or legal requirements change. The effective date at the top of this page identifies the current version. Material changes will be communicated where required by law or our agreement with the merchant.
12. Contact
Questions about this policy or the App’s data practices can be sent to [email protected].