Legal · Chrome Extension

Chrome Extension Privacy Policy

Last updated: 25 September 2026 (version 2.18.1)

This policy covers the Easify — MCA Underwriting Chrome extension. Your use of the Easify platform itself is covered by our main Privacy Policy.

This extension uploads the bank statements and financing applications that you choose to Easify (https://easify.net), shows you the underwriting result, and — only when you ask — runs background checks on the merchant and sends the deal to your own lenders. This policy describes exactly what it handles.

What the extension sends

Data When Where it goes
The PDF files you select, drop, or pick with an Easify tag on a page Only when you click Analyze https://easify.net
Your email and password Only when you sign in with them https://easify.net, to obtain an API token
A Google access token (email and basic profile scopes) Only when you click Continue with Google https://easify.net, once, to match your Google account to an existing Easify account and obtain an API token
A merchant/deal label you type With the upload, as group_name / mid https://easify.net
A merchant name read from the page you are on With the upload, when you open the Easify panel on a CRM record (see below). You can edit or clear it first https://easify.net
A financing application you tag as Application Only when you click Analyze https://easify.net, which reads the merchant's details from it
A request to run a paid background check on that application (DataMerch, consumer credit, business credit, PACER court records) Only when you press that check's Run button and then Confirm https://easify.net — see Background checks below
Your API token With every request https://easify.net
A Google access token with permission to send mail as you Only when you click Connect Gmail and accept Google's consent screen https://easify.net, which verifies it with Google and stores it to send your submissions
A deal you choose to submit: the statements you uploaded and a summary of them Only when you pick lenders and press Send https://easify.net, which emails them to the lender addresses on your organization's own panel

Submissions and background checks are the only things that leave Easify. When you send a deal, the statements and summary are emailed to the funders your organization put on its lender panel — nobody else, and never without you selecting them and pressing Send. The extension itself only asks Easify to send; it never emails anyone directly. Every submission is recorded, with what was sent and to whom.

Background checks. When you tag a file as an application, its summary can offer checks on the merchant: DataMerch, a consumer credit report and a business credit score (through StitchCredit, which uses Experian), and PACER federal court records. Each is its own button with its price on it and needs a confirmation; nothing runs on its own and there is no "run everything". When you confirm, Easify — not the extension — sends that provider the details it needs (for example the business name and EIN, or the owner's name, address and SSN for a consumer credit report), and shows you the answer.

Apart from that, nothing is sent to any other destination. The extension has no analytics, no telemetry, no advertising identifiers, and no third-party SDKs. Everything it sends goes to one host, https://easify.net, over HTTPS only; that address is fixed and cannot be changed. The only other requests it makes are downloads of the PDFs you pick with an Easify tag, from the site that hosts them (see below).

Connect Gmail is separate from signing in, and asks for more. Google shows its own consent screen for permission to send email as you (gmail.send — send only: the extension cannot read, search or delete your mail). Chrome hands the extension a short-lived access token, which is passed to Easify; Easify checks with Google that the token is genuine and carries that permission before storing it, and uses it only to send the submissions you choose. No refresh token is issued, so the permission lapses about an hour after each use until the extension mints another. Disconnect at any time from the Easify web app, or revoke it at myaccount.google.com/permissions.

Continue with Google uses Chrome's built-in sign-in (chrome.identity): Google shows its own consent screen, and Chrome hands the extension an access token limited to your email address and basic profile. The extension passes that token to Easify once and does not store it; Chrome itself caches it as it does for any extension using Google sign-in. Easify uses it only to find the Easify account with the same email. It never creates an account, and the extension never sees your Google password.

What the extension stores on your computer

Held in chrome.storage.local, readable only by this extension (plus, in chrome.storage.session, a random one-time code per open tab that lets the tags hand files to the panel; it is never written to disk and is deleted when the tab closes):

PDF file contents are never written to extension storage. Files are held in memory only for the duration of the upload and released afterwards. Analysis results are fetched from Easify when you open them and are not stored by the extension. Download JSON on the result page saves a copy only when you ask.

Signing out deletes the stored token and batch list, and revokes the token on the server. Your password is never stored.

What the extension does on web pages — and what it does not

Permissions and why each is needed

Handling of financial information

Bank statements are sensitive financial records. Handle them accordingly:

Retention and deletion

Uploaded statements and their analyses are retained by Easify under its own policy and your contract — not by this extension. To delete an analysis, use the Easify web application or contact Easify. Removing the extension deletes everything it stored locally but does not delete anything already uploaded.

Contact

Questions about this extension: privacy@easify.net. Easify is the data controller for statements and applications you upload.