ocuco. Product Feed for Google

Draft for review. This policy is awaiting approval by Ocuco's legal team and may change before Product Feed for Google is generally available.

Privacy policy

Product Feed for Google · Last updated 6 October 2026

Product Feed for Google is a plugin for Acuitas 3, available from the Acuitas Marketplace. It publishes an optical practice's eCommerce product catalogue to the practice's own Google Merchant Center account. This policy explains what information the plugin and its service handle, why, where it is kept, and the choices you have.

In short

  • We handle your practice's product catalogue and the account details needed to run the service. We don't access patient, appointment, prescription or clinical data.
  • From Google we request only access to Merchant Center. We don't receive your Google account's name, email address or profile.
  • We use Google data only to publish and monitor your practice's product feed. We never sell it, use it for advertising, or use it to train AI models.
  • We keep your information in Microsoft Azure in Sweden, in the EU.

1. Who we are

Product Feed for Google is provided by Ocuco Limited, a company registered in Ireland (company number 240089), referred to here as "Ocuco", "we" or "us".

Ocuco Limited, The Nexus Building, Blanchardstown Corporate Park, Blanchardstown, Dublin 15, D15 N5DX, Ireland

Questions about privacy: dataprotection@ocuco.com. Ocuco's general privacy policy is at ocuco.com/privacy-policy; this policy adds the details specific to Product Feed for Google.

2. Who is responsible for your information

Your practice's product catalogue and feed are processed on your practice's behalf, under the agreement between Ocuco and your practice. For that information, your practice decides what is published and Ocuco acts as its processor.

Ocuco is responsible (the controller) for the information we need to run, secure and bill for the service: the practice's account and agreement records, connection details, usage records and service logs.

3. What information we handle

Your practice and its account

People at your practice who use the plugin

Your product catalogue

The plugin reads your eCommerce catalogue from Acuitas: products, prices, availability, images and promotions, plus site and country lookups. It turns them into a product feed in the format Google requires. It never changes your product records. Its access to Acuitas is limited to catalogue and business information. It does not read patient, appointment, prescription, clinical, insurance, sales or diary data.

Information from Google

When your practice chooses Connect Google, Google asks you to grant one permission: management of your Merchant Center product data (the https://www.googleapis.com/auth/content scope). We don't request sign-in, email or profile permissions, so we don't receive your Google account's name, email address or picture. With that permission we:

To do this on Google's schedule, we hold an access token issued by Google (a refresh token). It is stored encrypted in Azure Key Vault, separately for each practice, and is never written to our logs.

Technical information

4. How we use Google user data

Product Feed for Google's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

5. How we use information, and why we're allowed to

We don't use your information for marketing and we don't sell it.

6. Who we share it with

Your feed is published at a private web address containing a secret token. It isn't listed or linked anywhere, and it contains only product information that your practice already publishes on its website. Anyone given that address can read the feed, which is how Google collects it, so treat it like a password.

7. Where we keep it

The service and its data are hosted in Microsoft Azure's Sweden Central region, in the European Union. Backup copies are kept in Azure's paired region in Sweden. When your feed is sent to Google, Google handles it under its own terms.

8. How long we keep it

Information How long
Plugin sign-in sessions No longer than 8 hours; expired sessions are deleted nightly.
Google refresh token Until your practice disconnects Google. It is then revoked at Google and deleted; the deleted copy is permanently erased within 90 days.
Published feed files The current feed and a few recent versions, so we can roll back; older versions are removed automatically.
Service logs 90 days.
Database backups 35 days.
Account, agreement, settings, sync history and feed-collection records While your practice uses the service. After that, until your practice asks us to delete them, except where we must keep them longer.
Billing and agreement records As long as tax and accounting law requires.

9. Disconnecting Google and removing the plugin

10. How we protect it

11. Your rights

Under data protection law (including the GDPR), people whose personal information we hold can ask to access, correct or delete it, to restrict or object to how we use it, and to receive a copy of it. To make a request, email dataprotection@ocuco.com. Where we process information on your practice's behalf, we may pass your request to the practice and help it respond.

You can also complain to the Irish Data Protection Commission at dataprotection.ie, or to the data protection authority where you live.

12. Children

Product Feed for Google is a business service for optical practices. It isn't aimed at children and doesn't knowingly collect information about them.

13. Changes to this policy

We'll update this page when the service or the law changes, and change the date at the top. If a change affects how we use Google data, we'll tell practices before it takes effect.