← Gleamz Privacy Policy

Gleamz Extension Privacy Policy

Last updated: August 2026

This policy describes how the Gleamz browser extension(the “Extension”) accesses, uses, and shares information. It applies only to the Extension. For the Gleamz website, app, and account services, see the main Gleamz Privacy Policy. Where the two overlap, this policy governs the Extension's behaviour.

Questions about the Extension can be sent to support@gleamz.ai.

1. What the Extension Does

Gleamz is an AI assistant for resellers. The Extension lets Gleamz carry out actions you have asked for — such as creating or removing a listing — on marketplaces that have no usable public API, by making requests from your own browser in your own logged-in session. Gleamz's servers decide which action to run and send the Extension a named operation with its details; the Extension performs that request and reports whether it succeeded. It does not open tabs, read the pages you browse, or run code delivered from a remote server.

2. Information the Extension Accesses

Your Gleamz Sign-In (Authentication Information)

When you first connect a device, the Extension reads your existing Gleamz sign-in session from an open Gleamz tab in order to prove the device is yours. It uses that session once to register the device and receive a credential of its own, and relies on that device credential from then on. The Extension does not store your password, and reading your sign-in never happens on any non-Gleamz page.

Your Marketplace Session (Authentication Information)

For each marketplace you explicitly connect, the Extension reads that marketplace's own session cookies and access token from your browser. This is the same session your browser already holds because you are signed in to that marketplace. The Extension uses it in two ways:

  • On your device: to send the marketplace the requests needed to carry out the action you asked for, exactly as your browser would.
  • To Gleamz's servers, as a fallback: a copy of that session is transmitted to Gleamz over an encrypted connection and stored so that Gleamz can complete time-criticalactions on your behalf when your device is offline — most importantly, removing a listing after an item sells elsewhere so it is not sold twice. This copy is used only to act on marketplaces you have connected, on your behalf.

Operational Telemetry

The Extension reports whether the actions it performed succeeded, so Gleamz can detect a marketplace breaking before it affects your listings. These reports contain only the shapeof an outcome — the operation name, the marketplace, success or failure, an HTTP status code, which step failed, a classified error code, and how long it took. They never include message or listing text, request or response bodies, or personal data.

What the Extension Does Not Access

  • It does not collect your browsing history or the content of pages you visit.
  • It does not read cookies or data from sites other than Gleamz and the marketplaces you connect.
  • It does not record keystrokes, form input, or screen contents.

3. Permissions the Extension Requests

Each permission maps to one of the functions above:

  • Cookies: to read your Gleamz sign-in (once, to register the device) and your connected-marketplace sessions (to act in them on your behalf).
  • Host access to Gleamz:to communicate with Gleamz's servers to receive the actions you have asked for and report their outcomes.
  • Host access to marketplaces (optional): requested only for the marketplaces you choose to connect, so the Extension can send requests to them.
  • Network-request header rules:to make the Extension's requests match what the marketplace expects from its own website, so your authorised actions are accepted.
  • Alarms: to check for pending work on a periodic timer.
  • Storage & scripting:to keep the device's own credential and settings, and to run the bundled action handlers.

4. How the Information Is Used

The Extension uses the information above solely to provide the Gleamz service you signed up for: registering your device, carrying out listing and sale actions you have asked for on the marketplaces you connect, keeping a fallback session so time-critical actions still happen when your device is offline, and monitoring whether those actions succeed. We do not sell this information, use it for advertising, or use it to train AI or machine-learning models.

5. How the Information Is Shared

  • Gleamz servers:the Extension sends data to Gleamz's own backend as described above. That backend's handling of your data, and the service providers it relies on, are covered in the main Privacy Policy.
  • The marketplaces you connect: the Extension sends requests to those marketplaces in your session to carry out your actions. Each marketplace is a separate data controller for the data it holds about you.
  • We do not share the Extension's data with anyone else, except where required by law.

6. Storage & Retention

The device credential and settings are stored locally in your browser. The fallback copy of a marketplace session is kept on Gleamz's servers only while that marketplace is connected and is refreshed as your session changes; it is deleted when you disconnect the marketplace, remove the device, or delete your Gleamz account, subject to the retention rules in the main Privacy Policy.

7. Your Controls

  • Disconnect a marketplace to stop the Extension acting on it and to remove the stored fallback session.
  • Remove the device from your Gleamz settings to revoke its credential.
  • Revoke marketplace host accessfrom Chrome's extension settings at any time.
  • Uninstall the Extension to stop all of the above and clear its local storage.

8. Changes to This Policy

We may update this policy as the Extension changes. Material changes will be reflected in the “Last updated” date above and, where appropriate, notified through the Service.

9. Contact Us

For questions about the Extension's privacy practices, email support@gleamz.ai.