SiteHandoff Privacy Policy

Effective 21 September 2026 ยท SiteHandoff 0.2.1

SiteHandoff audits websites locally in your browser. Page HTML, audited URLs, findings, scores and reports are not uploaded to the SiteHandoff licensing service or to Stripe.

Free plan

The Free plan requires no account. A Free-only installation that has never started a Pro upgrade does not create a licensing identifier and does not contact the SiteHandoff licensing service.

Local data

SiteHandoff can store the latest page audit, latest whole-site scan and optional reporter name/contact in chrome.storage.local. After an upgrade is started it also stores a random installation identifier, a separate high-entropy license credential and a cached Free/Pro entitlement.

Passwords, form values and credential-shaped attributes are redacted before they can reach stored findings or exported reports.

Website access

Single-page audits normally use Chrome activeTab access after you invoke SiteHandoff from its toolbar icon. On Chrome 133 and later, if the side panel was opened without that temporary grant, Chrome can surface a native site-access request for the current tab. Accepting it grants access to that site until you revoke it in Chrome site-access controls.

When you explicitly start a whole-site scan, SiteHandoff requests optional access to the selected site and fetches pages with credentials: omit so browser cookies are not sent. It respects robots.txt. The crawler queues and audits only URLs on the selected origin; a response redirected to another origin is discarded and no links from it are followed. Fetched content is analysed locally.

Pro licensing and Stripe

If you start a Pro upgrade, SiteHandoff creates a random installation identifier and separate license credential. Before Stripe opens, the licensing service returns a signed reference derived from the installation ID and a one-way hash of that credential. Stripe receives only that signed reference. After a verified paid checkout, the licensing backend stores the installation ID, token hash and the Stripe customer/subscription identifiers, subscription status, selected price, current period end and webhook-event identifiers needed to provide or revoke Pro access.

Stripe hosts checkout and subscription management. SiteHandoff does not receive or store raw payment-card or bank-account credentials. A successfully verified Pro entitlement is cached locally for up to 72 hours for temporary outages.

What is not sent to SiteHandoff

Page HTML, page text, audited or crawled URLs, audit findings, evidence, Ready Scores, exported reports, cookies, passwords and form values are not sent to the SiteHandoff licensing backend.

Chrome Web Store Limited Use

SiteHandoff uses handled data only to provide or improve the disclosed website-QA, report and subscription-entitlement functionality. It does not sell user data, use it for personalized advertising or creditworthiness, or transfer audit/client data to advertising platforms, data brokers or information resellers.

Service providers

Neon hosts the minimal licensing database/function and Stripe processes subscription billing. Those providers process the limited information needed for those roles under their own terms and privacy notices.

Retention and deletion

Local extension data is removed when the extension is removed. Removing the extension does not cancel a Stripe subscription; billing must be managed through the Stripe-hosted customer portal. Server-side subscription records are retained as needed to provide billing entitlement and meet applicable accounting, dispute, security or legal requirements.

Your choices

You can use Free without an account, decline a Pro upgrade, revoke optional crawl access to a site after a scan, and manage or cancel a Pro subscription through Stripe. Privacy requests can be sent to the contact address below.

Contact: jasoncurro31399@gmail.com