Политика приватности для «ONOXSOFT Hosting Control Panel»
ONOXSOFT Hosting Control Panel от ONOXSOFT
Политика приватности для «ONOXSOFT Hosting Control Panel»
Last updated: August 13, 2026
ONOXSOFT Hosting Control Panel is a Firefox extension that allows users to connect to and manage their own ONOXSOFT Panel servers.
This Privacy Policy explains what information the extension handles, why it is needed, where it is transmitted, and how it is protected.
Depending on the features used, the extension may handle:
- ONOXSOFT customer name and email address
- Authentication credentials submitted by the user
- Short-lived Google OAuth credentials
- ONOXSOFT account access and refresh tokens
- Panel API keys and device-bound sessions
- A locally generated extension device identifier
- Connected panel addresses and server names
- Server health, resource usage, services and alerts
- Hosting account, DNS, SSL, backup, log and WordPress information
- Extension settings, notification preferences and safe navigation state
The extension does not collect financial information, payment card details, health information, precise location information, personal communications or browsing history.
Information is processed only to provide features explicitly requested by the user, including:
- Authenticating an ONOXSOFT customer account
- Connecting to user-selected hosting panels
- Monitoring server health and resource usage
- Displaying services, alerts and backups
- Managing supported hosting accounts, DNS records and SSL certificates
- Managing supported WordPress installations
- Sending user-enabled server notifications
- Restoring the last extension screen
- Protecting local extension access with an optional PIN
Information is not used for advertising, behavioral profiling, credit scoring or purposes unrelated to hosting management.
Email addresses and passwords entered into the extension are transmitted directly to the ONOXSOFT account service over HTTPS for authentication. Passwords are not stored by the extension.
Google authentication is initiated only when the user selects “Continue with Google.” A short-lived Google identity credential is sent to the ONOXSOFT account service for server-side verification. Google credentials are not permanently stored by the extension.
Panel API keys and ONOXSOFT account sessions are encrypted with AES-GCM before being stored in the extension’s local device storage.
The extension requests access only to hosting panel origins that the user explicitly connects, imports or authorizes.
Information received from connected panels may include server metrics, health results, service states, alerts, backups, DNS records, SSL certificates, hosting accounts, logs and WordPress installation information.
This information is used to display and operate the extension’s management features. It is not sold or transferred for advertising purposes.
Information may be transmitted only to the following parties when required for a requested feature:
- Google authentication services, when Google sign-in is selected
- The ONOXSOFT account and license service at license.onox.com.tr
- ONOXSOFT services at onox.com.tr
- Hosting panel origins explicitly connected by the user
Connected hosting panels may be hosted on customer-controlled domains and ports.
The extension does not sell, rent or disclose user information to data brokers, advertising networks or unrelated third parties.
The extension uses browser permissions for these purposes:
- Alarms: periodically refresh connected server information
- Active tab: detect an authenticated ONOXSOFT Panel selected by the user
- Identity: provide interactive Google authentication
- Notifications: display user-enabled server and authentication notifications
- Scripting: detect panel information and request short-lived pairing credentials from the active panel
- Storage: keep settings, encrypted credentials and extension state locally
- Optional website access: communicate with panel origins explicitly approved by the user
The extension does not download or execute remote JavaScript or WebAssembly.
Extension settings and connected server information remain in local Firefox extension storage until the user removes them, signs out, resets the extension or uninstalls the add-on.
Temporary authentication state and PIN unlock state are kept only for the current browser session.
The extension does not use Firefox Sync to transfer panel keys, account sessions or server data between devices.
Information stored by ONOXSOFT account services or connected hosting panels is subject to the retention policies of those services.
The extension uses HTTPS for supported remote connections.
Sensitive locally stored credentials are protected using AES-GCM encryption. The optional extension PIN is verified using PBKDF2-HMAC-SHA256 with a random salt. The raw PIN is not stored.
No method of electronic storage or transmission can guarantee absolute security. Users should protect access to their Firefox profile and connected hosting accounts.
Users can:
- Disconnect individual servers
- Sign out of their ONOXSOFT account
- Disable notifications
- Remove locally stored sessions through the extension
- Reset the extension’s local security state
- Uninstall the add-on to remove its local data
Requests concerning information stored by ONOXSOFT services can be submitted through the contact details below.
The extension is intended for hosting administrators, developers and authorized server operators. It is not directed to children, and ONOXSOFT does not knowingly collect information from children through the extension.
This Privacy Policy may be updated when extension functionality, legal requirements or data-handling practices change. The updated policy will include a revised “Last updated” date.
For privacy questions, support requests or data-related requests, contact:
ONOXSOFT
Website: https://onox.com.tr
Email: onoxyazilim@gmail.com