Politique de confidentialité pour PorterBase Cart Sync
PorterBase Cart Sync par PorterBase
PorterBase Cart Sync Privacy Policy
Last updated: September 2, 2026
PorterBase Cart Sync reads a supported supplier cart only when the user clicks “Read cart” and transmits cart lines to PorterBase only when the user explicitly clicks “Add cart” or “Update cart.”
DATA HANDLED BY THE EXTENSION
Authentication information:
The user enters their PorterBase email address and password on the extension-owned sign-in page. These credentials are transmitted over HTTPS to the PorterBase login endpoint. The password is not stored or logged by the extension.
After successful authentication, the session token, expiration date, user profile, accessible businesses and selected business are held in browser session storage.
Personally identifying information:
The login response may contain the user’s PorterBase name, email address and user ID. These values are used only to identify the signed-in account and are not provided to supplier websites.
Browsing activity:
The extension runs only on the supported supplier domains listed in its manifest. It uses the current supported supplier URL to identify the vendor and verify that the user is on a recognized cart page. It does not collect general browsing history and is inactive on unsupported websites.
Website and cart content:
When the user clicks “Read cart,” the extension may read part numbers, product descriptions, quantities, unit prices and job or work-order references from visible supplier cart rows. Reading the cart happens locally and transmits nothing.
Financial information:
Unit prices displayed in the supplier cart may be transmitted as part of a cart line. The extension does not access credit-card numbers, bank details, payment credentials or other payment instruments.
WHEN DATA IS TRANSMITTED
Signing in sends the email address and password to:
POST https://porterbase.com/api/login
After consent and authentication, opening the panel sends the vendor identifier and selected business ID to check whether a cart already exists:
GET https://porterbase.com/api/extension/vendor-carts/<vendor>
Clicking “Read cart” sends nothing.
Clicking “Add cart” or “Update cart” sends the cart lines displayed in the panel:
PUT https://porterbase.com/api/extension/vendor-carts/<vendor>
The selected PorterBase business ID is included in cart requests so the cart is stored under the business selected by the user.
STORAGE AND RETENTION
The active session token, expiration, user profile, accessible businesses and selected business are stored in browser session storage. They are deleted when the user signs out, PorterBase rejects the session, the user revokes consent, or the browser restarts.
The extension stores only the accepted privacy-disclosure version and acceptance date in local extension storage.
Passwords and supplier cart lines are not stored by the extension. Cart information synchronized to PorterBase becomes part of the user’s PorterBase account.
DATA SHARING AND USE
Data is transmitted only to PorterBase to provide authentication and user-requested cart synchronization.
The extension does not sell data, use data for advertising, contain analytics or tracking, transfer data to data brokers, determine creditworthiness, train machine-learning models, or execute remote code.
USER CONTROLS
Users can sign out, change the selected PorterBase business, revoke consent and clear extension data, or uninstall the extension. Cart information already synchronized to PorterBase can be managed through the user’s PorterBase account.
CONTACT
Privacy and support enquiries:
porterbaseinfo@gmail.com