ResaleOS – Marketplace Connector — Extension Privacy Policy
Effective Date: August 6, 2026
Last Updated: August 11, 2026
This Privacy Policy explains how the ResaleOS – Marketplace Connector browser extension (the "Extension") collects, uses, and protects your data. The Extension is published by ResaleOS and works together with your ResaleOS account (the "Service"). By installing and using the Extension, you agree to this policy.
1. Single Purpose
The Extension does one thing: it lets a ResaleOS user connect a supported resale marketplace account (for example, Poshmark) to their ResaleOS store by securely sharing their already-logged-in session for that marketplace. The captured session is used only to establish and maintain that channel connection.
Connecting is initiated in your ResaleOS account (Settings → Sales channels). The Extension's own window is read-only: it displays connection status and has no Connect action of its own.
2. What the Extension Accesses
Ongoing — cookie names only, nothing transmitted:
- Which cookies exist, by name, for the supported marketplace domains, so the
Extension can show whether you are signed in to each one. The *contents* of cookies are not read for this, and no data leaves your browser.
Only when you click Connect in ResaleOS, for the one marketplace you chose:
- Marketplace cookies for that marketplace domain (e.g. `poshmark.com`), read
via the browser's cookie API. This includes httpOnly session cookies, which carry your login.
- localStorage for that marketplace, read once at connect time via an injected
script, because some marketplaces store login state there.
- Browser compatibility details — your user-agent string, language, timezone,
and whether you are on a desktop or mobile device. These let the remote browser that manages your channel present the same characteristics your session was created under, so the marketplace is less likely to challenge it. No other device, hardware, screen, network, or location data is collected.
Your ResaleOS account identity, via a scoped device token obtained through a PKCE handshake with the ResaleOS site. The Extension never reads, copies, or stores your ResaleOS password or session cookie.
The Extension does not read your browsing history, does not read the content of any web page, and does not collect data from any site other than the supported marketplace you explicitly choose to connect. It holds no `tabs` or `activeTab` permission and therefore cannot see the addresses of other tabs you have open. Its one content script runs solely on the ResaleOS site, where it links the Extension to your account and relays Connect requests.
3. Categories of Data Collected
- Authentication information — your marketplace login cookies / session token.
- Website content — the marketplace's localStorage at connect time.
Before anything is transmitted, the Extension removes known analytics and advertising cookies (such as Google Analytics, Meta, TikTok, Reddit, Hotjar, Mixpanel, and Segment identifiers) and bulk marketing storage entries on your device, so they are never sent at all.
We do not collect personally identifiable information, health information, financial or payment information, personal communications, precise location, web history, or user-activity tracking (clicks, keystrokes, etc.).
4. How Data Is Used and Where It Goes
When you click Connect, the captured cookies, localStorage, and the browser compatibility details listed in Section 2 are transmitted over TLS (HTTPS) to the ResaleOS ingest API. They are used solely to connect and maintain that sales channel for your ResaleOS store. We do not sell or transfer your data to third parties outside this use, do not use it for any purpose unrelated to connecting your channel, and do not use it for creditworthiness or lending decisions.
The Extension contains no analytics or telemetry software. Session data is never written to any log, metric, or analytics event.
5. Retention and Security
- The raw captured session is stored encrypted (AES-256-GCM) in a short-lived
server-side entry (≤ 10 minutes) and is deleted immediately after it is used to establish the marketplace connection.
- Raw cookie values are never written to our primary database and are
redacted from logs. The durable artifacts of a successful connection are an opaque connection reference (a Browserbase context id) and, for marketplaces that require it, the marketplace's own session token stored encrypted and treated with the same lifecycle as any other integration credential.
- Your language and timezone are stored alongside that connection so the remote
browser keeps presenting consistent characteristics on later runs.
- The device token that authorizes the Extension is stored hashed at rest, is
scoped only to connecting channels, expires after 90 days, and can be revoked at any time.
- For security and abuse prevention, we keep an audit record of each connect
attempt (the account and workspace involved, IP address, user-agent, and outcome — never your cookies or session secrets) for up to 90 days.
6. Your Controls
- Connecting is always explicit and per-marketplace, initiated by you in your
ResaleOS account. Nothing connects on its own, and the Extension never re-reads a session without a new Connect action.
- Disconnecting a channel in ResaleOS deletes the stored marketplace connection.
- "Disconnect" in the Extension window revokes its device token.
- You can also list and revoke Extension tokens from your ResaleOS account settings
at any time.
- You can remove the Extension from your browser at any time; doing so deletes the
device token stored locally in the browser.
7. Permissions
- Cookies — to check which cookies exist by name (to show where you are signed
in), and to read the session of the one marketplace you choose to connect.
- Scripting — to run a single one-time script on the marketplace you are
connecting, to read that marketplace's localStorage.
- Storage — to keep your device token and in-progress connection status on your
device.
- Alarms — to check periodically whether a channel ResaleOS has flagged as
disconnected could be reconnected from a session you already have, so the Extension can mark its icon. It never reconnects on its own.
- Access to supported marketplace sites — so the Extension can show where you
are signed in and complete a connection in one click without repeated permission prompts.
- Access to the ResaleOS site — so the Extension can link to your account and
receive Connect requests from it.
Your ResaleOS session cookie is never read. Sign-in is established by the ResaleOS page itself calling our API with the cookie your browser already sends; the Extension only observes whether that call succeeded, and thereafter identifies itself with its own scoped token rather than with your login.
8. Remote Code
The Extension does not use remote code. All executable code ships inside the published package. The Extension only exchanges JSON data with the ResaleOS API over HTTPS and never downloads or executes externally hosted scripts.
9. Changes to This Policy
We may update this policy as the Extension evolves. Material changes will be reflected by updating the "Last Updated" date above.
10. Contact
Questions about this policy or your data can be directed to ResaleOS support through your ResaleOS account.