Skip to content

Security

FeedShield reads your Google Merchant Center account and crawls your storefront. Here is exactly what that access is limited to, what it runs on, and who else touches the data.

How data is protected

Encryption

Every connection runs over TLS. Data at rest in Supabase is encrypted with AES-256, including the OAuth tokens that connect Merchant Center. Google access tokens expire after an hour and are refreshed server-side.

Tenant isolation

Every table in the database has row-level security turned on. An organization's policies scope every query, so one agency's client data cannot be read through another organization's session.

Authentication

Sign in with Google OAuth or email and password. Passwords are hashed, never stored in plain text. We never see or store your Google Merchant Center password, only a scoped, revocable OAuth token.

API hardening

Rate limiting on public and authenticated endpoints, SSRF protection on the crawl and URL-input endpoints, and security headers (CSP, X-Frame-Options, X-Content-Type-Options) on every response.

Vulnerability management

Automated dependency scanning on every build (npm audit), a pinned lockfile, and code review before anything ships.

Where data lives

The primary database runs on Supabase's Frankfurt, Germany region. Application code runs on Vercel's edge network, which serves requests from the location closest to the visitor but keeps the database itself in a single EU region.

VendorRoleCertificationRegion
SupabaseDatabase (PostgreSQL), authentication, file storageSOC 2 Type IIFrankfurt, Germany (EU)
VercelApplication hosting and edge networkSOC 2 Type II, ISO 27001Global edge, primary compute in the EU
StripePayment processing and billingPCI DSS Level 1US, EU
UpstashRate limiting, caching (Redis) and background jobs (QStash)Compliance details in the Upstash trust centerUS for background jobs
PostHogProduct analytics, only after you accept the cookie bannerSOC 2 Type IIUS
Google AnalyticsWebsite analytics, only after you accept the cookie bannerGoogle's published data safeguardsUS
SentryError monitoring and crash reportsSOC 2 Type IIUS
ResendTransactional email (account notices, contact replies)SOC 2 Type IIUS
Anthropic and OpenRouterAI fix recommendations, routed away from your account credentialsCommercial API termsUS

Certifications belong to each vendor, verified against their own security pages, not to FeedShield itself. A full list of subprocessors is available on request at hello@feedshield.ai.

Legal frameworks we operate under

GDPR

For visitors and customers in the EU, UK, and Switzerland: data minimization, the right to erasure and portability, and breach notification to supervisory authorities within 72 hours where required by Article 33.

CCPA / CPRA

California residents can request to know, delete, or correct their data. We do not sell or share personal information.

UAE PDPL

XPAND ENTERPRISES - FZCO is registered in Dubai Silicon Oasis and operates under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.

Google API User Data Policy

Merchant Center access uses the minimum OAuth scope needed, read-only, never used for advertising, and never reviewed by a human outside support you asked for.

The full legal text lives in the privacy policy and terms of service.

Report a vulnerability

Found a security issue? Email it to us before disclosing it publicly. We read every report and credit valid ones. There is no bug bounty program yet.

hello@feedshield.ai

Data requests

To access, correct, export, or delete your data, or to ask about a specific subprocessor, email the same address.

hello@feedshield.ai