1. Who we are
Arlanix ("we", "us") develops and sells extensions for Magento 2 — among them Arlanix Feed and its Google Merchant Center connector. This policy covers the data we handle as a vendor: when you visit our website, buy a product, or ask us for help. It also describes what our extensions do with data once installed, because that is what the operators who install them want to know.
We are the data controller for the vendor data in sections 2–4. For anything our extensions process inside your Magento installation, you are the controller and we are not involved at all.
2. Data we collect as a vendor
| When | What | Why |
|---|---|---|
| You buy a product or license | Name, company, email, billing address, the Magento domain the license is for, order and payment records (card details stay with the payment provider; we never see them) | To deliver the product, issue invoices, honour the license and meet tax and accounting obligations |
| You contact support | Your email, the messages you send and anything you attach — logs, screenshots, configuration | To answer your request |
| You visit our website | Server logs: IP address, browser, pages requested, time | To keep the site running and secure |
| You subscribe to product updates | Email address | To send release notes; every message has an unsubscribe link |
We do not buy data about you, do not build profiles, and do not use tracking or advertising networks. Our website sets no cookies other than those a shop or account area strictly needs to function.
3. Who we share it with
Only the providers we need to operate: a payment processor for purchases, a hosting provider for the website, and an email provider for support and release notes. Each acts on our instructions and sees only what its job requires. We do not sell or rent your data, and we disclose it beyond that only when the law requires us to.
4. Retention and your rights
Order and invoice records are kept for as long as tax law requires, typically ten years. Support conversations are kept for three years after the last message. Server logs are deleted after ninety days. A mailing-list address is deleted when you unsubscribe.
You may ask us at any time what we hold about you, ask us to correct or delete it, ask for a copy in a portable format, or object to a use you disagree with. Write to the address in section 9 and we answer within thirty days. If you are in the EU or UK, you may also complain to your data protection authority.
5. What our extensions do with data
Our extensions are software you install on your own Magento server. They run entirely there:
- they make no requests to Arlanix servers — there are none;
- they contain no analytics, telemetry, or "phone home" of any kind, and do not report installations, usage or errors to us;
- they read your catalogue, inventory and store configuration to build product feeds, and read nothing from customer, order or account tables.
Anything an extension stores lives in your Magento database and stays there until you delete the record in the admin or uninstall the extension. We have no access to it.
6. The Google Merchant Center connector
When you connect Google Merchant Center, the connector talks to the Google Merchant API (merchantapi.googleapis.com) directly from your server:
- it sends your product catalogue — titles, descriptions, prices, availability, images, links, categories, identifiers such as GTIN or MPN — to your own Merchant Center account;
- it reads back account details, data sources and product statuses to show them in your Magento admin;
- the Google credentials you provide — a service account key you upload, or an OAuth 2.0 authorization you grant by signing in with Google — are stored in your Magento database encrypted with your installation's encryption key, and short-lived access tokens are cached the same way until they expire.
7. Google user data and Limited Use
The connector requests the https://www.googleapis.com/auth/content scope, which grants management of your Merchant Center account. Its use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, it:
- uses Google data only to publish and maintain your product listings and to display their status in your Magento admin;
- does not transfer Google data to anyone other than Google and your own Magento installation — Arlanix included;
- does not use Google data for advertising, for building profiles, or for training machine-learning models;
- does not allow humans to read Google data, other than you and the administrators you authorize in your Magento admin.
Google's handling of your account and product data is governed by the Google Privacy Policy and the Merchant Center terms you agreed to.
8. Revoking Google access
You can disconnect at any time: delete the account in Arlanix → Google Merchant → Accounts (its credentials and tokens are removed with it), delete the service account key in the Google Cloud console, or revoke the connector's access from your Google account permissions. Any of these stops the connector from reaching your Merchant Center account.
9. Contact
Questions about this policy, your data, or a request under section 4:
10. Changes to this policy
If this policy changes, the new version is published at https://arlanix.com/privacy-policy with an updated effective date. A change that affects what our extensions collect always comes with a corresponding change in the extension itself.