Last updated: 30 August 2026
Feed Doctor is operated by Grüner Baum GmbH (trading as GB-Design), Vorstädter Str. 32, 55276 Oppenheim, Germany. Questions and data requests: hello@gbdesign.art.
Feed Doctor helps a merchant review Google-reported account-health issues and find and fix supported product-data problems that cause Google Merchant Center to disapprove products. This policy explains what data the app accesses, why, how we store it, and how you can remove it.
From your Shopify store (with the permissions you grant on install): your product catalogue, that is titles, descriptions, images, prices, variants, identifiers such as SKU and barcode, inventory and shipping fields, and publication status. We use it to detect issues and, only after you approve a supported change, to write that change to the corresponding product in Shopify.
From Google Merchant Center (only if you connect it, using
Google OAuth and the https://www.googleapis.com/auth/content scope):
the disapproval status of your products, the specific item-level issue codes and
their affected countries, Google-reported account-level issue titles, details,
severity, affected destinations and regions, guidance links, and the account
identifiers needed to read that data.
Feed Doctor reads this Google data but does not create, update, or delete products
in Merchant Center. Supported approved corrections are written to Shopify. For
feed- or channel-level changes that Feed Doctor cannot write, the app provides
instructions for you to apply where that feed is managed.
We do not request or access Gmail, Google contacts, Google Drive, or any Google data unrelated to Merchant Center.
We use this data to provide the app's user-facing features: reporting account-health issues, diagnosing product problems, matching Merchant Center product findings to Shopify products, and applying the supported Shopify corrections you approve. We show the results inside the app. We do not use Google data to advertise to you or to build profiles unrelated to these features.
Feed Doctor's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely:
All data is transmitted over encrypted HTTPS/TLS connections. Your Google OAuth refresh token is encrypted at rest (authenticated encryption) before it is written to Cloudflare KV, and is only decrypted momentarily to obtain a short-lived access token from Google; it is never written to logs, URLs, or error messages. Merchant Center product, status, and account-issue data is processed in memory while the diagnosis request is running and is not saved as a persistent report or catalogue copy. Encryption keys and API secrets are held as protected platform secrets, isolated from application data, and access to production systems is restricted to authorised operators; no human reads your Merchant Center data except in the narrow cases described in section 3.
The encrypted Google refresh token, selected Merchant Center account identifier,
Shopify shop record, webhook-registration state, and trial or promotional-use markers
are retained only while the Shopify app is installed. A cached Google access token is
encrypted and expires automatically just before Google's token expiry, normally in
about one hour. Disconnecting Google deletes both Google token records immediately.
Uninstalling the app or a verified Shopify shop/redact request deletes all
of the shop-scoped records listed above.
For the separate public web scanner, a scan result may be cached for up to 10 minutes and rate-limit counters expire after one hour. Passwordless sign-in links expire after 15 minutes and web sessions after 30 days. Account and Stripe customer references for the public web subscription are retained while the account is active and as required for billing, tax, fraud prevention, and legal obligations.
You can disconnect Google Merchant Center at any time from within the app. This
deletes the encrypted refresh token, selected account identifier, and cached access
token. You can also revoke our access directly in your
Google account permissions.
Uninstalling the Shopify app or a verified shop/redact request deletes
all shop-scoped application records, including Shopify credentials, Google tokens,
webhook state, and trial or promotional-use markers. To request deletion of a public
web account or information retained for a legal obligation, email
hello@gbdesign.art.
We do not sell, rent, or share the Google Merchant Center data we access with any third party for that party's own purposes, and we never transfer it to advertisers, market researchers, credit assessors, or data brokers. The only parties that ever process it do so solely on our behalf, under contract:
Billing depends on the product surface. Subscriptions purchased inside the embedded Shopify app are offered and billed by Shopify through Shopify Managed Pricing; Stripe is not used for that billing. Stripe is used only for the separate optional subscription on the public Feed Doctor web scanner. An email provider sends passwordless sign-in and account messages for that public service. Neither Stripe nor the email provider receives your Merchant Center data. Shopify and Google are the platforms the embedded app connects to at your request.
As the data controller, Grüner Baum GmbH honours the rights granted by the GDPR, including access, correction, deletion, restriction, portability, and objection. Contact hello@gbdesign.art to exercise them. You may also complain to the data protection authority of Rhineland-Palatinate, Germany.
If we change how the app handles Google user data, we will update this policy and, where the change is material, ask for your consent again. The version published on this page is the one in force.