🔐 Extension Specific

Extension Privacy Policy

Last Updated: May 2026 · Applies to the Parash browser extension for Microsoft Edge and Google Chrome

1. Overview

This privacy policy applies specifically to the Parash browser extension available for Microsoft Edge and Google Chrome. For our main website privacy policy, see parash.in/privacy.

The extension is built on the principle that we need to know as little about you as possible to provide the cashback and price comparison service.

2. What the Extension Accesses

The extension requests only the following browser permissions, each with a specific purpose:

storage

Stores your card preferences and cached product data locally on your device. This data never leaves your browser.

activeTab

Reads the URL of the current tab only when you are on a supported shopping site (Amazon, Flipkart, Myntra). It does not access content on any other tab or website.

scripting

Injects the Parash widget overlay onto supported product pages. The script only reads the product URL and title — not payment details, login sessions, or personal data on the page.

host_permissions

The extension is allowed to contact parash.in (our API) and the three supported shopping sites. It cannot contact any other domain.

3. What We Send to Our Servers

When you visit a product page on a supported site, the extension sends the following to parash.in/api:

  • The product page URL (so we can scrape the live price)
  • Your saved card IDs (anonymous integer IDs — never card numbers or CVVs)
  • A random instance fingerprint (a device-specific random string generated on install, used only for rate-limiting abuse)

We do not receive or store: your name, email address, IP address (beyond rate-limit buckets that expire hourly), browsing history, or any payment credentials.

4. Data Stored Locally on Your Device

The extension stores the following in your browser's local storage:

  • Card preferences — the IDs of cards you have added to your wallet
  • Product cache — scraped product data cached for up to 6 hours to reduce API calls
  • JWT token — a short-lived (30-minute) authentication token to talk to our API securely
  • Instance ID — a random identifier generated on install, used for rate-limiting only
  • Price alerts — product IDs and target prices you have set

You can clear all of this data at any time by uninstalling the extension or using Edge's "Clear site data" settings.

5. Authentication & Security

The extension uses a short-lived JWT token (expires every 30 minutes) to authenticate API requests. No static password or API key is embedded in the extension package. Tokens are issued fresh by our servers and cannot be used beyond their expiry window.

All communication between the extension and our servers uses HTTPS encryption.

6. Third Parties

The extension does not load any third-party analytics, tracking scripts, or advertising SDKs. The only external connections made by the extension are:

  • parash.in — our own API for price and cashback data
  • Google Fonts — only to load the Inter font for the widget UI

7. Children's Privacy

The Parash extension is not directed at children under 13. We do not knowingly collect any information from children.

8. Changes to This Policy

If we introduce any new data collection, we will update this page and note the change date above. Significant changes will also be communicated via an extension update notification.

9. Contact

Questions about this privacy policy? Email us at [email protected] or visit our Contact page.