Draft for review. This policy is awaiting approval by Ocuco's legal team and may change before Product Feed for Google is generally available.
Privacy policy
Product Feed for Google · Last updated 6 October 2026
Product Feed for Google is a plugin for Acuitas 3, available from the Acuitas Marketplace. It publishes an optical practice's eCommerce product catalogue to the practice's own Google Merchant Center account. This policy explains what information the plugin and its service handle, why, where it is kept, and the choices you have.
In short
- We handle your practice's product catalogue and the account details needed to run the service. We don't access patient, appointment, prescription or clinical data.
- From Google we request only access to Merchant Center. We don't receive your Google account's name, email address or profile.
- We use Google data only to publish and monitor your practice's product feed. We never sell it, use it for advertising, or use it to train AI models.
- We keep your information in Microsoft Azure in Sweden, in the EU.
1. Who we are
Product Feed for Google is provided by Ocuco Limited, a company registered in Ireland (company number 240089), referred to here as "Ocuco", "we" or "us".
Ocuco Limited, The Nexus Building, Blanchardstown Corporate Park, Blanchardstown, Dublin 15, D15 N5DX, IrelandQuestions about privacy: dataprotection@ocuco.com. Ocuco's general privacy policy is at ocuco.com/privacy-policy; this policy adds the details specific to Product Feed for Google.
2. Who is responsible for your information
Your practice's product catalogue and feed are processed on your practice's behalf, under the agreement between Ocuco and your practice. For that information, your practice decides what is published and Ocuco acts as its processor.
Ocuco is responsible (the controller) for the information we need to run, secure and bill for the service: the practice's account and agreement records, connection details, usage records and service logs.
3. What information we handle
Your practice and its account
- Your practice's Acuitas Marketplace and business identifiers, name, practice number and code, location name and address, country, currency, time zone and website address.
- The plugin settings your practice chooses, such as which products to publish and the website domain your feed is checked against.
- Usage and billing records: when the plugin was installed, which locations had a live feed in each month, and the resulting charges.
People at your practice who use the plugin
- When someone accepts the plugin's terms, we record their Acuitas staff identifier, the terms version, and the date and time. We don't receive staff names or email addresses.
- When the plugin opens, Acuitas signs it in to our service. We keep a short-lived sign-in session that identifies your practice, not an individual person.
Your product catalogue
The plugin reads your eCommerce catalogue from Acuitas: products, prices, availability, images and promotions, plus site and country lookups. It turns them into a product feed in the format Google requires. It never changes your product records. Its access to Acuitas is limited to catalogue and business information. It does not read patient, appointment, prescription, clinical, insurance, sales or diary data.
Information from Google
When your practice chooses Connect Google, Google asks you to grant one
permission: management of your Merchant Center product data (the
https://www.googleapis.com/auth/content scope). We don't request sign-in,
email or profile permissions, so we don't receive your Google account's name, email
address or picture. With that permission we:
- list the Merchant Center accounts you can access, with their IDs and names, so you can choose which one to connect;
- create one data source in the account you choose, pointing Google at your practice's feed, and read back its details;
- read the status of Google's most recent fetch of your feed and the issues Google reports about your products, to show them on your dashboard;
- read your Merchant Center homepage address and whether it is claimed, because Google won't show products from an unclaimed website.
To do this on Google's schedule, we hold an access token issued by Google (a refresh token). It is stored encrypted in Azure Key Vault, separately for each practice, and is never written to our logs.
Technical information
- Service logs record each request's address (with feed tokens and sign-in codes removed), response status, timing and browser or client type (user agent). Our application doesn't log IP addresses. It uses them briefly, in memory, to limit excessive requests.
- Network security logs. The Azure Front Door service in front of our service records requests, including IP addresses, in Ocuco's network security logs.
- Feed collection records. When your feed is fetched, we record the time, outcome and client type, so your dashboard can show that Google collected it.
- Cookies and browser storage. We don't set cookies. Inside Acuitas, the plugin keeps a copy of your dashboard's latest figures in your browser's local storage, so the dashboard appears quickly. It contains no personal information, and clearing your browser's site data removes it.
4. How we use Google user data
Product Feed for Google's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We use Google data only to provide the features you see in the plugin: connecting your Merchant Center account, publishing your feed to it, and showing its status and issues on your dashboard.
- We don't sell Google data, transfer it to anyone else, or use it for advertising of any kind.
- We don't use Google data to develop, improve or train AI or machine-learning models.
- Ocuco staff don't read your Google data, except with your practice's agreement (for example, to help with a support request), where needed for security, or where the law requires it.
5. How we use information, and why we're allowed to
- To provide the service: building, checking and publishing your feed, connecting Google and showing your dashboard. We do this to perform our agreement with your practice.
- To bill for locations with a live feed, as the agreement sets out, and to keep the records the law requires.
- To keep the service secure and working: diagnosing faults, preventing abuse and investigating incidents. This is in our legitimate interest in running a reliable, secure service.
We don't use your information for marketing and we don't sell it.
6. Who we share it with
- Google, as your practice directs. Your product feed goes to your own Merchant Center account. What happens there is governed by your practice's agreement with Google and by Google's privacy policy.
- Microsoft, which hosts the service on Microsoft Azure and acts as our subprocessor.
- Authorities, where the law requires it, or a successor business, if Ocuco is involved in a merger or acquisition, under the same protections.
Your feed is published at a private web address containing a secret token. It isn't listed or linked anywhere, and it contains only product information that your practice already publishes on its website. Anyone given that address can read the feed, which is how Google collects it, so treat it like a password.
7. Where we keep it
The service and its data are hosted in Microsoft Azure's Sweden Central region, in the European Union. Backup copies are kept in Azure's paired region in Sweden. When your feed is sent to Google, Google handles it under its own terms.
8. How long we keep it
| Information | How long |
|---|---|
| Plugin sign-in sessions | No longer than 8 hours; expired sessions are deleted nightly. |
| Google refresh token | Until your practice disconnects Google. It is then revoked at Google and deleted; the deleted copy is permanently erased within 90 days. |
| Published feed files | The current feed and a few recent versions, so we can roll back; older versions are removed automatically. |
| Service logs | 90 days. |
| Database backups | 35 days. |
| Account, agreement, settings, sync history and feed-collection records | While your practice uses the service. After that, until your practice asks us to delete them, except where we must keep them longer. |
| Billing and agreement records | As long as tax and accounting law requires. |
9. Disconnecting Google and removing the plugin
- Disconnect Google in the plugin at any time. We ask Google to revoke our access straight away and delete the token. If Google can't be reached, the plugin tells you, so you can remove our access yourself. You can always do that in your Google account's security settings, under third-party connections.
- Disconnecting stops our access to your Merchant Center account. It doesn't delete the data source we created there; you can remove that in Merchant Center.
- To have your practice's information deleted after removing the plugin, email dataprotection@ocuco.com. We'll delete it except for anything the law requires us to keep, such as billing records.
10. How we protect it
- Connections to the service and to Google use HTTPS. Azure encrypts the stored data, and Google tokens are held in Azure Key Vault.
- The database, storage and Key Vault aren't open to the public internet. The service reaches them over private network connections, using managed identities rather than stored passwords, and otherwise only Ocuco's own networks can reach them.
- Every database query the service makes is limited to a single practice's records, and feed and sign-in tokens are stored only in hashed form.
- Access by Ocuco staff is limited to the people who operate and support the service.
11. Your rights
Under data protection law (including the GDPR), people whose personal information we hold can ask to access, correct or delete it, to restrict or object to how we use it, and to receive a copy of it. To make a request, email dataprotection@ocuco.com. Where we process information on your practice's behalf, we may pass your request to the practice and help it respond.
You can also complain to the Irish Data Protection Commission at dataprotection.ie, or to the data protection authority where you live.
12. Children
Product Feed for Google is a business service for optical practices. It isn't aimed at children and doesn't knowingly collect information about them.
13. Changes to this policy
We'll update this page when the service or the law changes, and change the date at the top. If a change affects how we use Google data, we'll tell practices before it takes effect.