Security
FeedShield reads your Google Merchant Center account and crawls your storefront. Here is exactly what that access is limited to, what it runs on, and who else touches the data.
How data is protected
Encryption
Every connection runs over TLS. Data at rest in Supabase is encrypted with AES-256, including the OAuth tokens that connect Merchant Center. Google access tokens expire after an hour and are refreshed server-side.
Tenant isolation
Every table in the database has row-level security turned on. An organization's policies scope every query, so one agency's client data cannot be read through another organization's session.
Authentication
Sign in with Google OAuth or email and password. Passwords are hashed, never stored in plain text. We never see or store your Google Merchant Center password, only a scoped, revocable OAuth token.
API hardening
Rate limiting on public and authenticated endpoints, SSRF protection on the crawl and URL-input endpoints, and security headers (CSP, X-Frame-Options, X-Content-Type-Options) on every response.
Vulnerability management
Automated dependency scanning on every build (npm audit), a pinned lockfile, and code review before anything ships.
Where data lives
The primary database runs on Supabase's Frankfurt, Germany region. Application code runs on Vercel's edge network, which serves requests from the location closest to the visitor but keeps the database itself in a single EU region.
| Vendor | Role | Certification | Region |
|---|---|---|---|
| Supabase | Database (PostgreSQL), authentication, file storage | SOC 2 Type II | Frankfurt, Germany (EU) |
| Vercel | Application hosting and edge network | SOC 2 Type II, ISO 27001 | Global edge, primary compute in the EU |
| Stripe | Payment processing and billing | PCI DSS Level 1 | US, EU |
| Upstash | Rate limiting, caching (Redis) and background jobs (QStash) | Compliance details in the Upstash trust center | US for background jobs |
| PostHog | Product analytics, only after you accept the cookie banner | SOC 2 Type II | US |
| Google Analytics | Website analytics, only after you accept the cookie banner | Google's published data safeguards | US |
| Sentry | Error monitoring and crash reports | SOC 2 Type II | US |
| Resend | Transactional email (account notices, contact replies) | SOC 2 Type II | US |
| Anthropic and OpenRouter | AI fix recommendations, routed away from your account credentials | Commercial API terms | US |
Certifications belong to each vendor, verified against their own security pages, not to FeedShield itself. A full list of subprocessors is available on request at hello@feedshield.ai.
Legal frameworks we operate under
GDPR
For visitors and customers in the EU, UK, and Switzerland: data minimization, the right to erasure and portability, and breach notification to supervisory authorities within 72 hours where required by Article 33.
CCPA / CPRA
California residents can request to know, delete, or correct their data. We do not sell or share personal information.
UAE PDPL
XPAND ENTERPRISES - FZCO is registered in Dubai Silicon Oasis and operates under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
Google API User Data Policy
Merchant Center access uses the minimum OAuth scope needed, read-only, never used for advertising, and never reviewed by a human outside support you asked for.
The full legal text lives in the privacy policy and terms of service.
Report a vulnerability
Found a security issue? Email it to us before disclosing it publicly. We read every report and credit valid ones. There is no bug bounty program yet.
hello@feedshield.aiData requests
To access, correct, export, or delete your data, or to ask about a specific subprocessor, email the same address.
hello@feedshield.ai