Privacy policy
This policy explains what information Velqora Google Feed (“Velqora”, “we”, “us”) processes when a merchant uses the app, why, and what happens to it. Velqora Google Feed is a Shopify app that turns a store's products into a product feed file for Google Merchant Center.
Who we are
Velqora Google Feed is operated by Velqora Labs. You can contact us at support@velqoralabs.com.
Information we process
Store information from Shopify
When a store installs the app, Shopify gives us the store's myshopify.com address. The app then reads the store's name, currency, country, whether prices include tax, its primary web address, and whether the online store is password protected.
Product catalog from Shopify
The app has read-only access to products (the Shopify read_products permission). To build the feed it reads products, variants and product media: for example titles, descriptions, handles, status, vendor, product type, tags, category, SEO fields, publication status, online store links, SKUs, barcodes, prices and compare-at prices, availability and inventory quantities, product options, and image links and alt text.
Authentication information
Shopify issues the app an access token (and a refresh token) for the store, which we store so the app can read the catalog in the background, for example after product changes. We don't store information about individual staff accounts.
Information the app creates
- Feed settings the merchant chooses: feed name, target country, content language, and whether all products are new.
- The generated feed file, which contains product information for the products included in the feed.
- Each product variant's eligibility result and the reasons it was included or excluded.
- Records of feed refreshes (when they ran and whether they succeeded).
- A secret feed address. We store it only in hashed and encrypted form.
- Technical logs: the store's address, internal identifiers, error codes and timings. Tokens, secrets and feed addresses are removed from logs.
Subscription information
Paid plans are sold through Shopify's app pricing, and Shopify handles all payments. We never receive or store card or bank details. To know which plan a store has, the app asks Shopify's Partner API for the store's current app subscription: the plan name, whether it's billed monthly or yearly, its price, any discount, trial and billing-cycle dates, and whether a cancellation or plan change is scheduled. This is looked up when needed and kept only briefly in the app's memory (five minutes by default, never more than an hour); it isn't written to our database. If the merchant asks to cancel in the app, we send that request to Shopify through the same API.
We store the store's Shopify ID with its store record, to make these lookups. We also count how many product variants are in the feed to apply plan limits; that count comes from the feed data described above.
Notifications from Shopify
Shopify notifies the app when products are created, updated or deleted (we use only the product's ID and update time, to schedule a refresh), when the app is uninstalled, when its permissions change, and for Shopify's privacy requests.
Support requests
If you contact support, we receive what you send us, such as your name, email address, store URL and message. The support forms on this site and in the app don't send or store anything: they prepare an email that you send from your own email app to support@velqoralabs.com. Support emails are received by the email service that hosts that mailbox.
Customer data
Velqora does not access or use Shopify customer data for its core functionality. The app doesn't request access to customers or orders and doesn't read, store or share buyers' names, email addresses, addresses or order history. When Shopify sends a customer data request or customer deletion request, there is no customer data in Velqora to return or erase.
Why we process this information
- To generate and serve the store's product feed and keep it up to date.
- To show the merchant which products are included and why others are excluded.
- To authenticate the app with Shopify and keep the store's connection working.
- To check the store's plan, apply its limits and handle cancellation requests.
- To operate, secure and troubleshoot the service.
- To answer support requests.
We don't sell information and don't use it for advertising or profiling.
The feed file and Google
Velqora doesn't connect to your Google account or send data to Google itself. The merchant gives the feed address to Google Merchant Center, which fetches the file on its own schedule; Google then processes it under Google's own terms and policies. Anyone who has the feed address can read the feed file, so treat it like a password. You can replace it in the app at any time, which stops the old address working immediately.
Service providers
We use these providers to run the service:
- Shopify, the platform the app runs on, which also handles app subscriptions and billing.
- Vercel, which hosts the app (United States).
- Neon, which provides the app's database (hosted on Amazon Web Services in the United States).
- The email service that hosts our support mailbox, which receives the emails you send to support@velqoralabs.com.
The app and its public pages use no analytics, advertising or tracking services and set no tracking cookies. Inside Shopify admin, Shopify's own App Bridge is used, which is covered by Shopify's privacy policy.
Security
All connections use HTTPS. Requests from Shopify are verified: admin requests with Shopify session tokens, and notifications with Shopify's signatures. Each store can access only its own data. Access to the catalog is read-only, feed addresses are stored hashed and encrypted, and logs exclude tokens and secrets. No system is perfectly secure, but we work to protect the information we hold.
Retention and deletion
- Each catalog read replaces the previous one; only the latest catalog is kept.
- Only the current feed file (and, at most, one newer version waiting for the merchant's confirmation) is kept. Records of the 10 most recent feed versions and 25 most recent refreshes are kept for troubleshooting.
- When a store uninstalls the app, its access tokens are deleted and its feed stops being served immediately.
- About 48 hours after uninstalling, Shopify asks us to erase the store's data, and we delete the store's record and everything linked to it: catalog, feed settings, feed files, eligibility results, and refresh records. Shopify keeps its own subscription and billing records under Shopify's policies.
- Technical logs are deleted automatically after the retention period of our hosting provider's logging service.
- Deleted data may remain in our database provider's short-term recovery backups until those backups expire.
- Support emails are kept for as long as needed to handle the request.
Your choices
Merchants can uninstall the app at any time from Shopify admin, which starts the deletion described above. To ask about or request deletion of your information, including support correspondence, email support@velqoralabs.com.
Changes to this policy
If we change how Velqora handles information, we'll update this page and its effective date. For significant changes we'll also let merchants know in the app.
Contact
Questions about this policy: support@velqoralabs.com.