Privacy Policy
Last updated: July 8, 2026
This Privacy Policy applies to all products published by Extensions Market — Chrome extensions (AirPrice, STRInvest, JobPilot, CarWise, HomePilot, ReachOut), the Shopify apps EZstock, EZDrop, Quizzo, and PopBoost, and the extensionsmarket.com website. By using any of our products or this website, you agree to this policy.
PopBoost (Shopify App)
PopBoost is a Shopify app that adds 7 conversion widgets to a merchant's storefront. When a merchant installs it, we store the shop domain, OAuth session token, and widget configuration (colors, text, thresholds). The Social Proof Popup widget reads customer first names and cities from recent orders via the Shopify Admin API, caching the result in server memory for up to 5 minutes — this data is never written to a database. No customer email addresses, full names, payment data, or browsing behaviour are collected or stored. Merchant data is deleted within 48 hours of app uninstallation. See the full PopBoost Privacy Policy for complete details.
Quizzo (Shopify App)
Quizzo is a Shopify app that adds a gamified product quiz and automatic bundle discounts to any store. When a merchant installs it, we collect and store:
- Shop domain and OAuth access token — required to authenticate Shopify Admin API requests on the merchant's behalf.
- Merchant settings — quiz configuration, reward tiers, maximum discount, and product eligibility (tags and metafields).
- Anonymous quiz analytics — non-personal funnel events (opens, completions, spins, add-to-carts) tagged with a random per-visit session identifier, used for the merchant's dashboard.
We do not collect personally identifiable information from end customers (shoppers). The product quiz runs on the merchant's storefront and records only anonymous quiz events (no names, emails, or IP addresses) for the merchant's funnel dashboard. Merchant data is deleted within 48 hours of app uninstallation via the app/uninstalled webhook. All data is stored in a private PostgreSQL database hosted on Railway. See the full Quizzo Privacy Policy for complete details.
EZDrop (Shopify App)
EZDrop is a Shopify app for running product drops with referral-powered waitlists. When a merchant installs it, we collect and store the shop domain, OAuth access token, and merchant settings (email from-name, from-address, badge toggle). EZDrop also collects shopper data from people who join waitlists: email address, optional first name, referral code, and queue score. This data is used solely to assign a referral link, compute queue position, and send transactional emails (confirmation, launch notification). Transactional emails are delivered via Resend. All data is deleted within 48 hours of app uninstallation. Shoppers may request deletion by contacting us at [email protected]. See the full EZDrop Privacy Policy for complete details.
EZstock (Shopify App)
EZstock is a Shopify inventory management app. When a merchant installs it, we collect and store: the shop domain and session token (for Shopify API authentication), product and variant data (titles, SKUs, inventory levels), order history (for sales velocity calculations — we do not store customer personal data from orders), and location information. We also store data the merchant enters directly: supplier records (name, email, lead time, currency), purchase orders, and product reorder thresholds. No end-customer personal data is collected or stored. All data is deleted within 30 days of app uninstallation. See the full EZstock Privacy Policy for complete details.
1. What data we collect
Account data (all extensions)
- Email address — collected when you create an account. Used for authentication, email verification, and account management.
- Password — never stored by us. Authentication is handled entirely by Firebase Authentication (Google). We never see or store your password in plaintext.
- User ID (UID) — a unique identifier assigned by Firebase upon account creation, used internally to link your usage data to your account.
Usage and subscription data (all extensions)
- Usage counter — the number of times you have used the extension's core feature in the current billing period, used solely to enforce free plan limits. Resets monthly (or daily for JobPilot).
- Subscription plan — whether your account is on the free or a paid plan, and the reset date for your usage period.
Content data processed per extension
- AirPrice — Airbnb listing data visible on the page is sent to our server to compute pricing comparisons. Not stored after the response is returned.
- STRInvest — Airbnb listing data is sent to our server for investment analysis. Not stored after the response.
- CarWise — A VIN you enter is sent to our server and forwarded to the NHTSA public API for safety ratings and recall data. Not stored after the lookup.
- HomePilot — Property listing data visible on the page is sent to our server for closing cost and investment analysis. Not stored after the response. Saved properties are stored locally in Chrome extension storage on your device only.
- JobPilot — Your resume text and the job description of the listing you are viewing are sent to our server and forwarded to Anthropic's API to generate a cover letter. Neither your resume nor the generated cover letter is stored on our servers after the request completes. Your profile (name, contact details, work history, education, and application preferences such as work authorization or desired salary), your saved application tracker (job titles, companies, links, status, and notes), and your reusable cover-letter templates are stored locally in Chrome extension storage on your device only — never on our servers. The auto-fill feature writes these locally-stored details into application forms on the page you are viewing; that data is not transmitted to us. Optional follow-up reminders use Chrome's alarms and notifications to alert you on your device when a reminder is due, and are never sent anywhere.
- ReachOut — LinkedIn profile data visible on the page is read locally to suggest outreach messages. Contact records and your sender profile are stored locally in Chrome extension storage on your device only — never on our servers.
2. What data we do NOT collect
- We do not store the content data listed above (leads, listing details, resumes, VINs, cover letters) on our servers beyond the time needed to process your request.
- We do not collect your browsing history on any website.
- We do not use tracking pixels, ad networks, or third-party analytics SDKs inside the extensions.
- We do not sell, rent, or trade your personal information.
3. How your data is used
- To authenticate your account and maintain your session
- To enforce usage limits based on your subscription plan
- To deliver the core feature of each extension (pricing analysis, lead extraction, VIN lookup, cover letter generation, etc.)
- To process subscription payments and manage billing
- To send transactional emails (email verification, password reset)
4. Third-party services and data sharing
We share data with the following third parties solely to operate our extensions. We share no data with any other party.
| Third Party | Data Shared | Purpose | Applies To |
| Google Firebase |
Email address, UID, plan, usage counters |
Authentication (Firebase Auth) and database (Firestore) |
All extensions |
| Anthropic |
Resume text, job description text |
AI cover letter and resume parsing via Anthropic API. Anthropic does not train on API-submitted content by default. |
JobPilot only |
| Stripe |
User ID, email address |
Payment processing and subscription management |
All paid extensions |
| NHTSA (US Government) |
VIN number |
Vehicle safety ratings and open recall lookup via public API |
CarWise only |
| Shopify |
Shop domain, session token, product/inventory/order data |
Platform authentication, API access, App Block rendering, and billing for EZstock, EZDrop, Quizzo, and PopBoost |
All Shopify apps |
| Resend |
Shopper email address, first name, drop/product title; supplier email address and PO content |
Transactional email delivery for EZDrop (waitlist confirmations, launch emails) and EZstock (purchase order PDFs to suppliers) |
EZDrop and EZstock |
| Railway |
API request payloads (see §1 content data) |
Cloud infrastructure hosting our webhook servers |
All extensions & Shopify apps |
| Google Analytics |
Page views, anonymized traffic data |
Website analytics on extensionsmarket.com only — not inside extensions |
Website only |
Third-party privacy policies: Firebase · Anthropic · Stripe · NHTSA · Resend · Railway · Google
5. Extension permissions explained
- AirPrice — accesses Airbnb listing pages to read pricing data and fetch comparable listings for analysis.
- STRInvest — accesses Airbnb listing pages to perform short-term rental investment analysis.
- JobPilot — accesses job listing pages to read job details and to auto-fill application forms with your locally-stored profile. Your resume, profile, application tracker, and templates are stored locally in Chrome extension storage. Cover letter generation is processed server-side via Anthropic's API and not stored after delivery. The alarms and notifications permissions are used only to deliver optional local follow-up reminders on your device.
- CarWise — accesses car listing pages to read vehicle details. VIN lookups are forwarded to the NHTSA public API. No personal data is transmitted in these requests.
- HomePilot — accesses real estate listing pages to read property data. All analysis runs locally; saved properties are stored locally and never uploaded to our servers.
- ReachOut — accesses LinkedIn pages to read publicly visible profile data for outreach suggestions. All contact data is stored locally on your device.
6. Local browser storage
All extensions store your Firebase authentication tokens (ID token and refresh token) in chrome.storage.local on your device. This data is used to maintain your session and is cleared when you sign out. It does not leave your device except as part of authenticated API requests to our servers.
7. Data retention
- Account data (email, UID, plan, usage counters) — retained for as long as your account is active.
- Content data (listing details, resume text, VINs) — not retained. Processed in memory on our servers and discarded after the response is returned.
- Authentication tokens — stored locally in your browser and cleared on sign-out.
8. Data security
All communication between our extensions and servers uses HTTPS/TLS encryption. Firebase Authentication tokens are short-lived and automatically refreshed. We do not log resume content, cover letters, listing data, or VINs in our server logs.
9. Your rights
- Access — you may request a copy of the data we hold about you.
- Correction — you may ask us to correct inaccurate data.
- Deletion — you may ask us to delete your account and all associated data. We will do so within 7 days of a verified request.
- Portability — you may request your data in a machine-readable format.
To exercise any of these rights, email [email protected].
10. Children's privacy
Our extensions are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
11. Cookies and tracking on extensionsmarket.com
The extensionsmarket.com website uses Google Analytics (via Google Tag Manager) to collect anonymised traffic data — page views, referral source, session duration, and device type. This data is used solely to understand which pages are most useful to visitors. No personal identifiers are linked to this data.
Google Analytics sets first-party cookies (_ga, _gid, _ga_*) on your device. These cookies persist for up to 2 years. You can opt out by:
- Installing the Google Analytics Opt-out Browser Add-on
- Using your browser's built-in cookie controls to block or delete cookies for this domain
- Enabling "Do Not Track" or Global Privacy Control (GPC) in your browser
No cookies are set inside our Chrome extensions or Shopify apps.
12. Changes to this policy
We may update this policy as our extensions evolve. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the extensions or website after changes constitutes acceptance of the updated policy.
13. Contact
Questions about this Privacy Policy or data deletion requests:
[email protected]