Privacy Policy for Jojocode Feeds

Last Updated: 17 August 2026

Jojocode (“we”, “our”, or “us”) provides the Jojocode Feeds application (the “App”) to merchants who use Shopify to power their stores. The App generates product feed files from a store’s catalogue and serves them to advertising channels such as Google, Meta and Microsoft Advertising. This Privacy Policy describes what information the App collects, how it is used, and how it is shared.

1. Information the App Collects

When you install the App, it reads the following from your Shopify store through the Shopify API, and keeps a copy so that feeds can be built without querying your store on every request:

  • Store information: your store name, domain, contact email, time zone, currency and Shopify plan.
  • Product data: products, variants, images, options, metafields and collections.
  • Inventory data: inventory items, stock levels and the locations they belong to.
  • Markets and price lists: your Shopify Markets regions, currencies and catalogues, used to produce market-specific pricing.
  • Translations: published translations of product content, used to produce translated feeds.
  • Sales channel availability: which channels each product is published to.
  • Settings you enter: the email addresses you choose to receive feed notifications at.

The App does not request access to your orders or your customers. Its access scopes are limited to reading products, inventory, locations, markets, translations and publications, so no customer names, addresses, contact details or order history are ever available to it. It never collects or processes payment details of any kind; payment processing is handled entirely by Shopify.

2. How the App Uses This Information

  • Generating feed files in the formats your marketing channels expect.
  • Serving each generated file at a stable URL that you paste into the channel once.
  • Keeping the stored copy of your catalogue current, using Shopify webhooks, so feeds reflect changes within seconds.
  • Running quality checks that tell you which products a channel is likely to reject, and why.
  • Sending you email notifications about successful or failed feed generation, to the addresses you configure.

3. Sharing Your Information

We share information only where the App cannot function without it:

  • Shopify: the App reads your store data through the Shopify API.
  • Marketing channels you choose: a generated feed file is fetched by the channel you give the feed URL to. That file contains product information — titles, descriptions, images, availability and pricing — and no personal data.
  • Service providers: the App runs on hosted infrastructure and stores generated feed files in a private object storage bucket. These providers process data on our behalf and are bound by confidentiality obligations.

We may also disclose information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request, or to otherwise protect our rights.

4. Storefront Click Tracking (Optional)

The App includes an optional feature that counts how many storefront visits arrive from each feed. It is off unless you both enable it in the App’s settings and turn on the App’s embed in your theme.

When it is on, it records:

  • the UTM source, medium and campaign values carried by the visit,
  • the date,
  • and a count of how many such visits occurred.

It sets no cookies and stores no identifiers, IP addresses, device information or browsing history. Nothing recorded can be traced back to an individual visitor: the App keeps one running total per day per campaign, not a record per visit.

5. Data Retention and Deletion (GDPR / CCPA)

For data collected through the App, we act as a Data Processor and the merchant acts as the Data Controller. The App supports Shopify’s mandatory compliance webhooks:

  • Customer data request (customers/data_request): acknowledged. Because the App holds no customer personal data, there is nothing to return.
  • Customer redaction (customers/redact): acknowledged. Because the App holds no customer personal data, there is nothing to erase.
  • Shop redaction (shop/redact): when you uninstall the App, Shopify sends this request 48 hours later. On receiving it we permanently delete every generated feed file from object storage, along with your store record and all data linked to it — the stored catalogue, feed configuration, templates, rules, settings and click counts — and the App’s stored session for your store.

6. Security

We follow industry practice to keep the data the App holds from being lost, misused, accessed without authorisation, disclosed, altered or destroyed. All communication with the App happens over encrypted HTTPS connections. Generated feed files are kept in a private bucket that is never publicly readable — the App streams them itself — and each feed is served at a URL containing an unguessable token rather than a predictable identifier. Feeds can additionally be protected with a password.

7. Changes

We may update this privacy policy from time to time to reflect changes to our practices, or for other operational, legal or regulatory reasons. The date at the top of this page shows when it last changed.

8. Contact Us

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, contact us by e-mail at hello@jojocode.dev.

© 2026 Jojocode. All rights reserved.