ResaleOS Channel Connector — Extension Privacy Policy
Effective Date: August 6, 2026
Last Updated: August 6, 2026
This Privacy Policy explains how the ResaleOS Channel Connector browser extension (the "Extension") collects, uses, and protects your data. The Extension is published by ResaleOS and works together with your ResaleOS account (the "Service"). By installing and using the Extension, you agree to this policy.
1. Single Purpose
The Extension does one thing: it lets a ResaleOS user connect a supported resale marketplace account (for example, Poshmark) to their ResaleOS store by securely sharing their already-logged-in session for that marketplace. The captured session is used only to establish that channel connection.
2. What the Extension Accesses
- Marketplace cookies for a supported marketplace domain (e.g.
`poshmark.com`), read via the browser's cookie API only when you explicitly click "Connect this channel." This includes httpOnly session cookies, which carry your login.
- localStorage of the active marketplace tab, read once at connect time via
an injected script, because some marketplaces store login state there.
- Your ResaleOS account identity, via a scoped device token obtained through
the hosted ResaleOS sign-in page.
The Extension does not read your browsing history, does not run background content scripts, and does not collect data from any site other than the supported marketplace tab you explicitly choose to connect.
3. Categories of Data Collected
- Authentication information — your marketplace login cookies / session
token.
- Website content — the marketplace tab's localStorage at connect time.
We do not collect personally identifiable information, health information, financial or payment information, personal communications, precise location, web history, or user-activity tracking (clicks, keystrokes, etc.).
4. How Data Is Used and Where It Goes
When you click Connect, the captured cookies, localStorage, and your browser's user-agent string are transmitted over TLS (HTTPS) to the ResaleOS ingest API. They are used solely to connect that sales channel to your ResaleOS store. We do not sell or transfer your data to third parties outside this use, do not use it for any purpose unrelated to connecting your channel, and do not use it for creditworthiness or lending decisions.
5. Retention and Security
- The raw captured session is stored encrypted (AES-256-GCM) in a
short-lived server-side entry (≤ 10 minutes) and is deleted immediately after it is used to establish the marketplace connection.
- Raw cookie values are never written to our primary database and are
redacted from logs. The only durable artifact of a successful connection is an opaque connection reference (a Browserbase context id).
- The device token that authorizes the Extension is stored hashed at rest, is
scoped only to connecting channels, expires after 90 days, and can be revoked at any time.
- For security and abuse prevention, we keep an audit record of each connect
attempt (the account and workspace involved, IP address, user-agent, and outcome — never your cookies or session secrets) for up to 90 days.
6. Your Controls
- Connecting is always explicit and per-channel, behind a consent screen in
the Extension.
- "Disconnect" in the Extension revokes the device token and removes the stored
marketplace connection.
- You can also list and revoke Extension tokens from your ResaleOS account
settings at any time.
- You can remove the Extension from your browser at any time; doing so deletes
the device token stored locally in the browser.
7. Remote Code
The Extension does not use remote code. All executable code ships inside the published package. The Extension only exchanges JSON data with the ResaleOS API over HTTPS and never downloads or executes externally hosted scripts.
8. Changes to This Policy
We may update this policy as the Extension evolves. Material changes will be reflected by updating the "Last Updated" date above.
9. Contact
Questions about this policy or your data can be directed to ResaleOS support through your ResaleOS account.