ShopifyShopifyKlaviyoKanalInflateTrendtrackTrendtrackInfinite FulfillmentInfinite FulfillmentAddingwellBoostEcom AgencyBoostEcom AgencyThe DeployerStork MarketingTheme Copilot AITheme Copilot AIPandectesPandectesTheme FullStackTheme FullStackCookiebotTriple WhaleTriple WhaleRechargeIntelligemsHotjarHotjarDatafastDatafastTrustMRRTrustMRRPageBuilder.storePageBuilder.storeTaap.itShopifyShopifyKlaviyoKanalInflateTrendtrackTrendtrackInfinite FulfillmentInfinite FulfillmentAddingwellBoostEcom AgencyBoostEcom AgencyThe DeployerStork MarketingTheme Copilot AITheme Copilot AIPandectesPandectesTheme FullStackTheme FullStackCookiebotTriple WhaleTriple WhaleRechargeIntelligemsHotjarHotjarDatafastDatafastTrustMRRTrustMRRPageBuilder.storePageBuilder.storeTaap.it
ShopifyShopifyKlaviyoKanalInflateTrendtrackTrendtrackInfinite FulfillmentInfinite FulfillmentAddingwellBoostEcom AgencyBoostEcom AgencyThe DeployerStork MarketingTheme Copilot AITheme Copilot AIPandectesPandectesTheme FullStackTheme FullStackCookiebotTriple WhaleTriple WhaleRechargeIntelligemsHotjarHotjarDatafastDatafastTrustMRRTrustMRRPageBuilder.storePageBuilder.storeTaap.itShopifyShopifyKlaviyoKanalInflateTrendtrackTrendtrackInfinite FulfillmentInfinite FulfillmentAddingwellBoostEcom AgencyBoostEcom AgencyThe DeployerStork MarketingTheme Copilot AITheme Copilot AIPandectesPandectesTheme FullStackTheme FullStackCookiebotTriple WhaleTriple WhaleRechargeIntelligemsHotjarHotjarDatafastDatafastTrustMRRTrustMRRPageBuilder.storePageBuilder.storeTaap.it
Legal

Chrome extension privacy policy

This page describes the BoostEcom Spy extension for Google Chrome, version 1.0.5. It is part of the BoostEcom privacy policy, which covers boostecom.app and everything not described here. For the extension itself, this page is the more specific text.

The data controller, the legal basis and the sub-processors are those of the privacy policy. Questions go to contact@boostecom.app.

In short

  • The extension reads the page you are on, on your device, to tell whether it is a Shopify storefront and to fill its diagnostics. That reading is not uploaded.
  • When you open the panel, it sends the domain of that page (for example store.example) to boostecom.app to load the store's record. Never the full address, the title or the content.
  • Everything else that leaves your browser starts with a click of yours. The few automatic requests are marked as such below.
  • No browsing history, no keystrokes, no cookies of other sites, no advertising, no analytics library, no sale of data.

What the extension does not collect

These are statements about version 1.0.5, checked against its code:

  • Your browsing history: the extension keeps no list of the pages you visit and sends none to BoostEcom. The only domains it sends are the one of the page where you open the panel (or where Auto-open opens it) and the stores you ask it to scan or track.
  • Page content, except for the Shopify store you choose to analyze. Picking an element, capturing a page or saving an observation works on the page you are on, when you ask, and stays in your browser unless you then save it to your account or attach it to a conversation.
  • Keystrokes: it records none of your typing, clicks or mouse movements. While the element picker is active it follows the pointer to highlight the element you choose, and listens to the keyboard so that you can cancel.
  • Cookies of other sites: the extension has no cookies permission and never reads cookies. Your BoostEcom session cookie is attached by the browser to requests to boostecom.app only. When the extension reads another site, it asks the browser to send no cookies.
  • Passwords and payment details: signing in happens on boostecom.app. The extension stores the access tokens it receives, not your password, and it never sees a card number.
  • Your location: it uses no geolocation. Like any web request, a request to boostecom.app shows your IP address to the server.
  • No advertising and no analytics library: the extension contains neither. It detects the trackers present on a page you inspect, locally, to show them to you.

What stays on your device

Nothing in this list is uploaded.

  • Page diagnostics: storefront detection, theme, load time, third-party script hosts, trackers and on-page SEO are read in the page you are on. This is the Page tab.
  • Automatic detection: on the sites it may access, the extension checks each page you load for Shopify signals, to show its icon badge. By default that means boostecom.app, the Shopify hosts listed under permissions below, and the tabs where you click the toolbar icon. If you grant the optional all-sites access, it checks every page you load. The result is kept in memory only, and no history of it is kept.
  • Robots header: the SEO audit makes one request to the page you are on (HEAD, or GET if HEAD is refused), without cookies, to read its X-Robots-Tag header.
  • Public product catalog in the panel: to list a store's new, promotional and preorder products, its price range and its collections, the extension reads that store's public /products.json and /collections.json from the store page itself, without cookies, at most once per store per browser session. The result stays in the panel and is never sent to BoostEcom.
  • Catalog CSV: only when you click, and only on Shopify pages, the extension requests /products.json?limit=250&page=N from the origin of the store you are on, with N up to 10 and without credentials. The CSV file is built and saved on your device.
  • Page media download: only when you click (the button that appears over a picture or video, a button in the media list, or the ZIP button), the extension fetches that file from the page itself. It sends no credentials to another site: the site's own cookies accompany only a file with the same origin as the page. It accepts only http(s) addresses and image or video data and blob types, never HTML. Limits: 200 MB for a single file, 50 MB per file in a ZIP, 150 MB per ZIP, and 300 media listed. The file is saved through your browser's downloads, and nothing is sent to BoostEcom or to a third party. If a host blocks the read, the extension opens the file in a new tab instead, and that host then receives the request of the tab, as for any link.
  • Screenshots: the Page tab shows a screenshot of the visible tab, and the capture tools save full-page screenshots. The browser makes them, and they stay on your device unless you hand them over (see the list below).
  • Your library: saved websites and ad links, folders, page observations, research briefs, recent colors and the ads-spend rate you set (the cost per thousand used for the estimate).
  • Theme editor structure: in the Shopify theme editor, the panel reads the names of the sections and folders it shows, and keeps that snapshot.

What is sent to BoostEcom, and when

Requests go to www.boostecom.app. When you are signed in, your browser attaches your session cookie so that the server can apply your plan. This list is complete for version 1.0.5.

The store's record: the domain of the page is sent to load the store's lookup, ownership graph, SEO record, forecast, supplier and similar stores. Never the full address, the title, the content or anything you typed.When you open the panel
Auto-open: off by default. If you turn it on and are signed in, the panel opens by itself on pages recognized as Shopify storefronts, so that domain is sent without a click. Turn it off in the extension options.No click, Auto-open on
Automatic collection and analysis: when you are signed in and open a store that is already indexed but has no traffic figures, or a Shopify storefront the index does not know yet, the extension asks the platform to collect or analyze it without a click, at most once per store and per day (a daily slot, a cooldown and a rate limit apply). The request holds the domain only, and nothing read on the page is sent. BoostEcom then reads the store's public storefront and may add it to the Intelligence index (see Scan this store). Signed out, nothing is requested and nothing is sent.Automatic
Scan this store: for a store that is not in the index yet, you can ask for a scan. The request holds the domain. BoostEcom then reads the store's public storefront and may add it to the Intelligence index (see the section on storefronts that are not yours in the privacy policy).When you click
Sign-in check: at browser start, when you open the panel and when a boostecom.app tab finishes loading, the extension asks boostecom.app for your usage summary and your account (plan, credits, first name, organizations and stores). It keeps your first name, a connected flag, your plan and credits, and an index of your stores' names and domains on your device.Automatic
Platform status: opening the Help tab asks for the public status summary, without cookies.When you click
Connecting a store: sign-in runs on boostecom.app. The extension registers as an OAuth client, receives access tokens and keeps them on your device. Disconnecting revokes the token on the server.When you click
Cloud library, briefs and alerts: "Save browser copy to this account" sends your whole library to your account, including the full addresses, titles and observed fields of the pages you saved. "Send brief" saves a brief in the notes of the store you chose. The alert buttons read competitor events and priorities for a store. These requests run through a boostecom.app tab you have open, with your session.When you click
Tracking a store: sends the store's domain and the id of the destination store to add it to, or remove it from, your tracked competitors.When you click
Picked elements and page captures: when you pick an element (its selector, HTML, text, attributes and a screenshot of it) or capture a full page (screenshot, the page's address, title, headings, up to 12,000 characters of its visible text, and its main colors and fonts), the result is handed to a boostecom.app tab you have open, where it can be attached to a conversation with the assistant. It leaves your browser only if you send that conversation. With no boostecom.app tab open, nothing is relayed.When you click
Uninstalling: Chrome opens a BoostEcom page whose address carries the extension version and your browser language, for example ?v=1.0.5&lang=en. See "If you uninstall".When you click

Like every request to boostecom.app, these appear in server logs (IP address, time, requested path, and the path of a lookup contains the domain), covered by the browsing data described in the privacy policy. BoostEcom stores no list of the domains you open next to your account: the lookup routes read the index and do not record who asked. A scan adds one to an anonymous weekly count for that store, which is not linked to you.

What is sent to other companies

These requests are made by your browser, not by BoostEcom, and each company applies its own policy.

  • Google Search, when you click: "Find this text on this site" and "across the web" open a Google Search tab. The query holds the text you selected (up to 30 words) and, for the search on this site, the host of the current page (site:store.example). Nothing is sent before you click the menu item.
  • Google Lens, when you click: "Find similar products" and "Find the supplier" open Google Lens with the public address of the image you chose. Lens downloads the image itself and the extension uploads nothing. The supplier search adds the word aliexpress to the query.
  • Meta Ads Library, optional: the live ad count needs the optional facebook.com permission, which Chrome asks you for after a click. Once you have granted it, the extension reads the public Ads Library on its own when you open a store whose record has no ad count: in a background tab that closes by itself, with your browser's own session, using the store's domain (and its Facebook page) as the query. Meta receives these requests as if you had opened the Ads Library yourself. The result is not sent to BoostEcom. Decline or revoke the permission to stop it.
  • Brand icons: for apps and pixels without a bundled brand mark, the panel shows an icon from Google's favicon service (www.google.com/s2/favicons) for the vendor's domain, taken from a fixed table in the extension, never the domain of the page you are on. An app missing from the table gets a neutral icon and no request. Icons of similar stores come from the same service with that store's domain, and the icon of the site you are on is read from the page, not from Google. These images are requested with no referrer. Google sees your IP address and the domain of the icon requested. Bundled brand marks make no request. The extension adds no cookie or account data, and your browser sends what it would for any image on a web page, minus the referrer.
  • Internet Archive, when you click: the Site history tool opens the Wayback Machine for the site's hostname (https://web.archive.org/web/*/ followed by the hostname) in a new tab. The extension itself sends no request to archive.org; the Internet Archive receives the request of the tab your browser opens.
  • Product and ad images: the pictures in the panel are loaded from the addresses the store records list (usually the store's own image host or an ad network's), like any image on a web page. Those hosts see your IP address.

Country flags are bundled with the extension and load nothing from a third party.

Permissions in plain language

Chrome shows these when you install. The required hosts are granted at install. The optional ones are asked for later, from a click of yours.

  • storage: keeps your preferences, your library, your sign-in state and short caches in your browser.
  • scripting: injects the panel into the tab you open it on and runs the storefront check in the page.
  • identity: opens the BoostEcom sign-in window when you connect a store (OAuth).
  • contextMenus: adds the BoostEcom right-click menu: open the panel, pick an element, capture a page, copy items, search on Google.
  • clipboardWrite: copies briefs, reports, colors and diagnostics, only when you press copy.
  • activeTab: temporary access to the tab where you click the toolbar icon, so the panel works on any domain without broad access at install.
  • sidePanel: shows the same interface in Chrome's side panel.
  • Required hosts: boostecom.app (sign-in state and store records) and the Shopify hosts admin.shopify.com, *.myshopify.com and online-store-web.shopifyapps.com (the panel in the Shopify admin and the theme editor).
  • Optional hosts (all websites): asked for only when you turn on Auto-open or the live ad count. They let the extension work on a custom-domain storefront (detection, robots header) without a click. The public catalog read happens in the page itself, on its own origin, and needs no host permission. If you do not grant them, the extension works on demand, from the toolbar click.
  • The version published on the Chrome Web Store has no access to localhost. A developer build can reach a local BoostEcom server and is not distributed.

What is stored in your browser

Uninstalling the extension deletes all of it.

  • Chrome sync storage (synchronized by Google across your Chrome profile): your first name, a connected flag, and your preferences (language, Auto-open, context menu choices, link capture choices, display mode, launcher).
  • Local extension storage: OAuth tokens, your library, the index of your stores, your plan and credits, the ads-spend rate, recent colors, the launcher position, the theme editor snapshot, and your choice to show or hide the download buttons on media. Picked elements and page captures are not stored.
  • Session storage (cleared when the browser closes): the records of up to 50 stores for ten minutes, the collection and scan limits, the ad count cache, and the public catalog read of up to 20 stores for six hours. This is a cache, not a history.

How long data is kept

  • On your device: until you remove the item, disconnect, clear the extension's data or uninstall it.
  • The domains you open: BoostEcom does not keep them against your account (see above). Server logs follow the privacy policy.
  • Cloud library and briefs: the library is stored on your account until you replace it or delete the account. A brief is a note in the store you chose, kept as long as that store.
  • Uninstall answer: it carries no account and no email. Your IP address is used only for a rate limit that expires after one hour.

The periods that apply to your account data are in the retention table of the privacy policy.

If you uninstall

Chrome opens a BoostEcom page whose address carries only the extension version and your browser language. The page offers an optional, anonymous survey: one reason and a comment of up to 500 characters. It asks for no email and reads no session, so the answer is not linked to an account. Your IP address is used only to limit answers to five per hour and is not stored with the answer. BoostEcom staff read the answers, and each one sends an email to an administrator. Please do not write personal data in the comment.

Disconnect a store from the extension to revoke its access token on the server. Deleting your account erases your cloud library with it.

Your choices and rights

You can limit the extension without losing the rest of BoostEcom:

  • Auto-open: leave it off, or turn it off in the extension options, and no domain is sent without a click.
  • Optional site access: do not grant it, or remove it in chrome://extensions. The extension then works on demand only.
  • Right-click menu: turn it off in the extension options.
  • Download buttons on media: turn them off in the Tools tab. Media downloads, the catalog CSV and the site history happen only when you click them.
  • Your library: export it, remove any item, observation or brief, or replace the cloud copy.
  • The extension: remove it from Chrome to delete its data from your device.

Your rights under the GDPR (access, portability, erasure, objection, rectification, restriction) are exercised as described in the privacy policy. The owner of a storefront can remove it from the Intelligence index without an account.

Remove a storefront →

Providers behind the extension

The extension adds no provider of its own. Requests to boostecom.app run on Vercel Inc., Neon Inc., and Upstash Inc.. A scan of a store that is not yet in the index reads its public storefront through Browserbase Inc., Firecrawl (Sideguide Technologies), Apify Technologies s.r.o., and Bright Data Ltd., which receive the store's public domain and not your account. Google and Meta are not our providers in this flow: they receive requests from your browser when you click.

See the full list →

Chrome Web Store Limited Use

The Chrome Web Store requires this statement, in these words:

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

  • We use the data the extension handles only to provide and improve its single purpose: analyzing the Shopify store you are viewing.
  • We transfer it to third parties only when necessary to provide or improve that purpose, to comply with the law, to protect against fraud, abuse or malware, or in a merger or sale after your explicit consent.
  • We do not let people read it, except with your consent, for security or abuse investigations, to comply with the law, or when it is aggregated and anonymized for internal operations.
  • We do not sell it. We do not use or transfer it for personalized advertising, to advertising platforms, data brokers or resellers, or to assess credit-worthiness or for lending.
  • Web browsing activity is used only for the feature described in the store listing and in the panel: the domain of the page you open is looked up to show that store's record.

Changes

This page describes version 1.0.5. A new request, host or permission is added here before the version that introduces it is published. The date below is the last substantive revision.

Contact

For any question about the extension or this page, write to contact@boostecom.app. You may also lodge a complaint with the CNIL, the French data protection authority.

Last updated October 2, 2026