Extension data is used only to provide and secure its disclosed purpose.
This public statement applies to PayHQ's pre-release inbox-protection browser extension. Publishing it does not mean the extension is available for production use or has completed Chrome Web Store review.
Affirmative statement
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. This statement is published for the pre-release extension; production release and Chrome Web Store review are not complete.
Single-purpose use
We use extension user data only to provide or improve the disclosed single purpose: advisory protection for selected AP/finance users against suspicious supplier, payment and link indicators in supported business webmail. Related operational use is limited to maintaining, securing and measuring the reliability of that feature.
The extension uses a local, bounded transmit-on-trigger design. The exact categories and exclusions are published in the Browser Extension Privacy Policy.
Transfers
We transfer extension user data only where necessary to provide or secure the single purpose, comply with applicable law, or protect against malware, spam, phishing, fraud or abuse. PayHQ processes triggered indicators for the customer workspace. If explicitly enabled by the customer, a sanitized URL for a link already flagged locally may be sent to licensed Google Web Risk for malware/phishing reputation; PayHQ retains a digest and bounded result, not the URL path/query.
Providers and locations are disclosed in our Sub-processor register. We do not sell extension user data or transfer it to advertising platforms, data brokers or information resellers.
Human access
Humans may read individual extension user data only when:
- the user explicitly asks us to access specific data;
- access is necessary for a documented fraud/abuse or security investigation;
- access is required to comply with applicable law; or
- the data is aggregated and anonymized and used for permitted internal operations under applicable privacy law.
A customer's scan-event audit view and report triage are limited to fraud/abuse protection and security investigation. They are not an employee productivity or performance-monitoring feature.
Prohibited uses
We do not use or transfer extension user data:
- for personalized or other advertising;
- for sale to data brokers or other information resellers;
- to determine creditworthiness or for lending;
- for unrelated profiling or a second product purpose; or
- for employee productivity, performance or disciplinary monitoring.
User choice, retention and security
Before first collection, the extension must provide a prominent disclosure and obtain an affirmative user action. It must provide an in-extension setting that immediately stops new collection, including for managed installations. The proposed pilot scan-event default is 90 days and is customer-configurable; production collection remains off until that retention/deletion and stop behavior are implemented and tested.
Data is transmitted over TLS and scoped to the bound workspace, mailbox and device. A separate, explicit action is required to upload a selected invoice attachment; ordinary scan permission cannot upload message content.
Contact and changes
Privacy questions: [email protected]. Security reports: [email protected]. Material changes to purpose, collection, transfer, human access or retention require an updated disclosure and policy review before release.