Privacy Policy
Last updated 30 August 2026
1. What we collect
Account data: name, email address, and company or publisher name.
Submission data: your extension package, manifest contents, listing copy, graphic assets, permission justifications, and data usage disclosures.
Payment metadata: gateway order and payment identifiers, amounts, and status. We never receive or store raw card numbers.
Google OAuth tokens, used solely to publish to your own Chrome Web Store developer account.
2. How we protect it
Google access and refresh tokens are encrypted at rest and are never exposed to the browser.
Packages and media are stored in object storage and served through short-lived signed URLs.
Card details are entered only in the payment gateway's hosted checkout and never transit our servers.
3. How we use it
To validate, review, and publish your submissions; to bill you; to send transactional email about submission and payment status; and to maintain an audit log for compliance.
We do not sell your data and we do not use your extension source code for any purpose other than review.
4. Retention
Submission records and audit logs are retained for seven years to satisfy financial and compliance obligations. Package binaries for rejected or withdrawn submissions are deleted after 90 days.
5. Your rights
You can export or request deletion of your account data at any time from your account settings, subject to the retention obligations described above.