Legal

Chrome extension privacy policy

This policy covers the StoreRadar Chrome extension. Your account, purchases and the dataset are covered by the StoreRadar privacy policy.

1. What the extension reads

The extension reads the URL of the active tab. That is the only thing it reads from your browser. It uses Chrome's tabs permission for this and for nothing else. Chrome describes that permission as "Read your browsing history".

  • No page content is read. The extension has no content script and injects nothing into any page.
  • Nothing you type, nothing you see on the page, and no other tab is read.
  • Your browsing history is not read. The extension only sees the address of the tab that is active while the side panel is open.

2. What the extension sends to StoreRadar

The host name of the active tab, for example shop.example.com, is sent to StoreRadar to look up the store record. The path, query string and page contents are not sent. Hosts on Shopify's own domains are skipped and never sent.

Each lookup is an API request on your account. It is logged like any other API request: the host looked up, your account, your IP address and a timestamp, under the retention in the main privacy policy.

3. What the extension stores in your browser

Sign-in uses OAuth. The extension stores the resulting tokens and a short-lived lookup cache in the browser and nowhere else:

  • The access token is kept in session storage. It is cleared when Chrome closes.
  • The refresh token is kept in local storage so you stay signed in across restarts. It expires after 90 days without use, and the server deletes it then.
  • The last store records you looked up are kept in session storage for 15 minutes so the panel does not repeat a lookup on the same site. They are cleared when you sign out and when Chrome closes.
  • Signing out in the panel revokes the token on the server and clears both. It does not sign you out of storeradar.io in the browser, because that is a separate session the sign-in window created.

4. Usage events

The extension sends usage events to PostHog, our product analytics provider, hosted in the EU. Events are: panel opened, sign-in started, cancelled or completed, a lookup and its outcome, a masked contact shown, an upgrade link clicked, and a site check started.

  • Each event carries your IP address, the outcome and your plan.
  • Before sign-in, events carry a random per-install id generated once when the extension is installed.
  • After sign-in, events carry your StoreRadar account identifier instead.
  • Events never carry the domain of the store you looked up.

5. Nothing else

That is the whole list. The extension reads nothing else from pages, sends nothing else to StoreRadar or to anyone, and stores nothing else in the browser than the tokens and the cache above. It does not sell or share your data. If this changes, this page changes first.

6. Contact

Questions about this policy, or a data request: jeanro@storeradar.io.

StoreRadar is not affiliated with Shopify.