This policy covers the Easify — MCA Underwriting Chrome extension. Your use of the Easify platform itself is covered by our main Privacy Policy.
This extension uploads the bank statements and financing applications that
you choose to Easify (https://easify.net), shows you the underwriting
result, and — only when you ask — runs background checks on the merchant and
sends the deal to your own lenders. This policy describes exactly what it handles.
What the extension sends
| Data | When | Where it goes |
|---|---|---|
| The PDF files you select, drop, or pick with an Easify tag on a page | Only when you click Analyze | https://easify.net |
| Your email and password | Only when you sign in with them | https://easify.net, to obtain an API token |
| A Google access token (email and basic profile scopes) | Only when you click Continue with Google | https://easify.net, once, to match your Google account to an existing Easify account and obtain an API token |
| A merchant/deal label you type | With the upload, as group_name / mid |
https://easify.net |
| A merchant name read from the page you are on | With the upload, when you open the Easify panel on a CRM record (see below). You can edit or clear it first | https://easify.net |
| A financing application you tag as Application | Only when you click Analyze | https://easify.net, which reads the merchant's details from it |
| A request to run a paid background check on that application (DataMerch, consumer credit, business credit, PACER court records) | Only when you press that check's Run button and then Confirm | https://easify.net — see Background checks below |
| Your API token | With every request | https://easify.net |
| A Google access token with permission to send mail as you | Only when you click Connect Gmail and accept Google's consent screen | https://easify.net, which verifies it with Google and stores it to send your submissions |
| A deal you choose to submit: the statements you uploaded and a summary of them | Only when you pick lenders and press Send | https://easify.net, which emails them to the lender addresses on your organization's own panel |
Submissions and background checks are the only things that leave Easify. When you send a deal, the statements and summary are emailed to the funders your organization put on its lender panel — nobody else, and never without you selecting them and pressing Send. The extension itself only asks Easify to send; it never emails anyone directly. Every submission is recorded, with what was sent and to whom.
Background checks. When you tag a file as an application, its summary can offer checks on the merchant: DataMerch, a consumer credit report and a business credit score (through StitchCredit, which uses Experian), and PACER federal court records. Each is its own button with its price on it and needs a confirmation; nothing runs on its own and there is no "run everything". When you confirm, Easify — not the extension — sends that provider the details it needs (for example the business name and EIN, or the owner's name, address and SSN for a consumer credit report), and shows you the answer.
Apart from that, nothing is sent to any other destination. The extension has no analytics, no
telemetry, no advertising identifiers, and no third-party SDKs. Everything it
sends goes to one host, https://easify.net, over HTTPS only; that address is
fixed and cannot be changed. The only other requests it makes are downloads of
the PDFs you pick with an Easify tag, from the site that hosts them (see
below).
Connect Gmail is separate from signing in, and asks for more. Google shows
its own consent screen for permission to send email as you
(gmail.send — send only: the extension cannot read, search or delete your
mail). Chrome hands the extension a short-lived access token, which is passed to
Easify; Easify checks with Google that the token is genuine and carries that
permission before storing it, and uses it only to send the submissions you
choose. No refresh token is issued, so the permission lapses about an hour after
each use until the extension mints another. Disconnect at any time from the
Easify web app, or revoke it at myaccount.google.com/permissions.
Continue with Google uses Chrome's built-in sign-in (chrome.identity):
Google shows its own consent screen, and Chrome hands the extension an access
token limited to your email address and basic profile. The extension passes
that token to Easify once and does not store it; Chrome itself caches it as it
does for any extension using Google sign-in. Easify uses it only to find the
Easify account with the same email. It never creates an account, and the
extension never sees your Google password.
What the extension stores on your computer
Held in chrome.storage.local, readable only by this extension (plus, in
chrome.storage.session, a random one-time code per open tab that lets the
tags hand files to the panel; it is never written to disk and is deleted when
the tab closes):
- Your API token, its expiry time, and your account email and name.
- A short list of your recent upload batches — filenames, per-file status, bank name, masked account label, statement period, transaction count and true revenue — so progress survives the popup being closed. Entries are removed when you sign out.
- Where you dragged the Easify button on a CRM page, so it stays out of your way.
- Your organization's CRM profiles — the site addresses your admin set up and which element on those pages holds the merchant name. No page content is stored with them.
PDF file contents are never written to extension storage. Files are held in memory only for the duration of the upload and released afterwards. Analysis results are fetched from Easify when you open them and are not stored by the extension. Download JSON on the result page saves a copy only when you ask.
Signing out deletes the stored token and batch list, and revokes the token on the server. Your password is never stored.
What the extension does on web pages — and what it does not
- Easify tags on web pages. On the pages you visit, the extension looks for PDFs — links to PDF files, links whose text is a PDF file name, PDF attachments in an email you have open in Gmail, and embedded PDF viewers — (including PDF attachments in an email you have open in Outlook on the web) and adds a small Easify tag next to each. To do that it reads only link addresses, link text and embed sources, on your computer. Apart from the merchant name on a CRM record (below), it does not read the rest of the page (text, forms, what you type), never adds tags inside something you are editing, and sends nothing from the page anywhere on its own.
- Checking that a link really is a PDF. A name ending in ".pdf" is only a
guess. For links to the same website you are on, once they are visible
on screen, the extension asks that website for the file's headers only (an
HTTP
HEADrequest — the file itself is not downloaded) and removes the tag if the website says it is not a PDF. At most 60 such checks per page. It never does this for links to other websites, or on Gmail. - When you click a tag, the extension downloads the PDFs you chose from the site, the same way your browser would if you clicked the link (using your existing login on that site), and puts them in the Easify panel on the page. Each file is checked first: anything that is not really a PDF is marked Not a PDF on its tag and never reaches the panel. They are sent to Easify only when you press Analyze there. If you close the panel instead, nothing is sent.
- Sites whose Download button works only in script. Some web apps show the file name as text and fetch the file only when you press their own Download button. On such a row, clicking the Easify tag presses that Download button for you, and the file the site produces is handed to the Easify panel instead of being saved to your Downloads folder. To do that, the extension briefly adds a small catcher to that page, only at the moment you click the tag; it takes the one file the button produces and switches itself off (after one file or 30 seconds). It only ever presses a site's Download, Preview, View or Open control, or (in Outlook on the web) the attachment itself — never Edit, Delete, Share, Send, Add to Drive or similar.
- The panel is the extension's own uploader: the web page cannot read what happens in it, including your token or the files you staged.
- On a CRM it also adds an Easify — Bank Statement tab on the right edge that opens the same panel. It recognises Salesforce, Zoho CRM, GoHighLevel, LendSaaS and Phonify, plus any site your organization's administrator has set up. To recognise a CRM it looks only at the address and, for GoHighLevel, a few fixed markers in the page's code.
- The merchant name on a CRM. When you open the panel on a CRM record, the extension looks for the business name on that record: the element your administrator pointed it at, or otherwise a value printed next to a label such as "Business Name" or "Doing Business As". It reads it again every time you open the panel, so it follows the record you are on. It only pre-fills the merchant field — you can edit or clear it, and it is sent only with an upload.
- It reads the title of your current tab when you open the popup, to pre-fill the merchant name field. You can edit or clear it. The title is only transmitted if you leave it in that field and upload.
- It does not sell, share, or transfer your data to third parties.
- It does not use your data for advertising, credit scoring, or any purpose other than performing the analysis you requested.
Permissions and why each is needed
- storage — to keep you signed in and to remember in-progress uploads.
- alarms — to check on your uploads while the popup is closed.
- notifications — to tell you when an analysis is finished.
- scripting — only when you click an Easify tag on a row whose Download button works purely in script: to catch the file that button produces for the Easify panel (see above).
- identity — for Continue with Google only: to ask Chrome for a Google access token (email and basic profile) when you click that button.
- host access to
https://easify.net— the one server the extension uploads statements to and reads results from. - access to all websites (
http://*/*,https://*/*) — to show the Easify tags next to PDFs on the pages you visit, and to download a PDF you chose when the site would not let the page itself hand it over. Chrome describes this as "read and change all your data on all websites"; the extension only recognises PDFs, recognises CRMs and reads the merchant name on them, and adds its tags and panel, as described above. It does not run onhttps://easify.net.
Handling of financial information
Bank statements are sensitive financial records. Handle them accordingly:
- Only upload statements you are authorised to process.
- On a shared computer, sign out when you finish. Your token otherwise remains on that machine until it expires.
- Transport is HTTPS only.
Retention and deletion
Uploaded statements and their analyses are retained by Easify under its own policy and your contract — not by this extension. To delete an analysis, use the Easify web application or contact Easify. Removing the extension deletes everything it stored locally but does not delete anything already uploaded.
Contact
Questions about this extension: privacy@easify.net. Easify is the data controller for statements and applications you upload.