Privacy Policy — Vendor Status Dashboard

Effective date: 2026-08-17
Contact: support@vendorstatus.dev

Vendor Status Dashboard is a browser extension for on-call engineers. It shows vendor status in a toolbar popup and persistent Side Panel, and alerts you when a selected scope changes. The extension has no backend, user accounts or analytics — it runs entirely in your browser. The public website uses small first-party endpoints for anonymous aggregate conversion measurement and uninstall feedback, plus a read-only monitor of vendors’ public status feeds. This policy explains them separately.

What we store (locally, on your device)

Everything the extension saves lives in your browser’s chrome.storage.local and never leaves your machine except as described in “Network calls” below:

We do not collect your name, email, browsing history, or the contents of any page you visit. The extension requests no access to your tabs or browsing.

Browser extension network calls

The extension makes network requests in exactly three cases, all of which you control:

  1. Vendor status pages you chose. It fetches each enabled vendor’s official public machine-readable status and incident feeds: Statuspage summary.json, or the official AWS RSS, Google Cloud incidents JSON and Microsoft Azure RSS feeds. Nothing about you is sent; it’s a plain read of public information.
  2. Your own Slack webhook (Pro, optional). If you add a Slack incoming webhook, the extension posts a short status message to that URL — and only to hooks.slack.com — when a tracked vendor changes state. Your webhook URL is stored locally, sent only to Slack, and is never logged.
  3. Payment provider (Polar, our merchant of record). To unlock and periodically verify Pro, the extension sends the key you paste, Vendor Status Dashboard’s public organization and benefit identifiers, and a random browser activation label/ID to api.polar.sh. Store policies classify the user-supplied key as authentication information; it is sent only after you paste it and click Activate. No administrative token is included. Checkout and payment happen entirely on Polar’s site — we never see or store your card details. See Polar’s privacy policy for its payment processing.

That’s the complete list for the browser extension. There are no other servers involved in extension operation.

What we never do

Website measurement

The website’s editorial status pages may read a cached, read-only snapshot from signals.vendorstatus.dev. That monitor polls the same public vendor status feeds listed above, stores status history and source timestamps, and receives no extension configuration, license key, account data or browser identifier. Its snapshot is informational and each page links to the vendor’s official status page for confirmation.

Fixed outbound labels and visitor-derived attribution are separate. Chrome Web Store links include fixed utm_source, utm_medium, utm_campaign and placement labels that identify our source page and link position. Those original labels are not derived from a visitor and do not depend on analytics consent. Visitor-derived campaign attribution is off by default: only after you choose Allow analytics, and only while your browser is not sending Do Not Track: 1, may valid utm_source, utm_medium and utm_campaign values from the landing URL, plus optional utm_content and utm_term, replace the corresponding fixed labels on the exact Chrome Web Store link. Only those five names are accepted; each value is limited to 80 letters, numbers, dots, underscores, tildes or hyphens. They are kept in sessionStorage for that tab and never added to our first-party event payload. Choosing Decline or changing your choice later erases the visitor-derived session copy and restores the original fixed-label store links; otherwise, the copy disappears when the tab session ends.

The website at vendorstatus.dev offers optional measurement so we can compare hero copy and understand whether visitors choose an extension store or Pro. All optional website measurement is denied by default and begins only after you choose Allow analytics. If allowed, the browser sends only:

Anonymous feedback after removal

After the extension has already been removed, Chrome or Edge may open /uninstall with only the store name and extension version. The page records one aggregate page view for that tab in our Cloudflare Analytics Engine dataset and, only if you submit the form, one optional closed-choice reason. The feedback request contains only the event, closed-choice reason (or none), store and version. It contains no extension configuration, account, email address, free text, license data, cookie, persistent identifier or user/device identifier. A sessionStorage flag used to avoid repeating the view in the same tab is not sent. Cloudflare processes standard network metadata to deliver the page under its privacy terms, but that metadata is not written to the feedback dataset.

We do not write IP addresses, email addresses, user-agent strings, referrers, cookies, persistent identifiers or fingerprints to that first-party dataset. Cloudflare processes the request at its edge and stores the four allowlisted fields above in Workers Analytics Engine for three months, its fixed retention window. Results are queried only as aggregate counts.

The feedback request is not Google Analytics 4 and sends no cookie. The current feedback page does not load Google Analytics or set a measurement cookie. On pages where optional Google Analytics 4 is loaded, it begins and may set a first-party measurement cookie only after you explicitly choose Allow analytics; it does not run while your browser sends Do Not Track: 1. If allowed, it records page views plus install_click, pricing_view and checkout_click events. Advertising storage, ad-user data, ad personalization and Google Signals remain disabled. Google Analytics does not receive extension data, account data, payment details or the contents of your local Vendor Status Dashboard configuration.

You can change the choice at any time with the Privacy choices control. Optional Google Analytics and consent-gated conversion measurement are disabled when your browser sends Do Not Track: 1; the separate, cookie-free aggregate uninstall view and closed-choice reason remain as described above. Measurement failures are ignored and never block navigation or product use.

Permissions

The extension requests only what these features need: local storage, scheduled alarms, desktop notifications and the browser’s Side Panel permission to display the local Command Center. The Side Panel does not grant access to tabs or page contents. Access to a vendor’s domain is limited to preset status pages; catalog/custom additions and imports request only the specific optional origins the user approves.

Data retention and removal

Extension data is local. Removing any vendor deletes its active monitoring configuration, snapshots, history, observed component catalog, triage state, group/profile membership, vendor-specific notification timing, and scheduled snooze, reminder and recovery alarms. Source-level retry and next-poll bookkeeping is also deleted when no other configured vendor uses the same feed source. Removing a custom vendor additionally deletes its local note and vendor-linked runbooks. Removing a bundled catalog vendor preserves the note text and vendor-linked runbooks you authored because the bundled vendor remains a valid offline context target, so that context is available if you add it again or use an export/import that explicitly includes local notes and runbooks.

To erase preserved context without uninstalling, open the extension’s Options → Runbooks, select the vendor under Runbooks & local context, erase the note text and move focus out of the field, and choose Remove for each saved runbook. Uninstalling the extension clears its chrome.storage.local data. Website data is separate: Privacy choices disables future optional measurement, and your browser’s site-data controls clear the consent value, tab-session attribution and any Google Analytics measurement cookies.

First-party Analytics Engine rows expire automatically after three months. Because they contain no user or device identifier, they cannot be isolated as belonging to a particular visitor.

Changes

If this policy changes, we’ll update the effective date above and post the new version at the same URL.

Contact

Questions? Email support@vendorstatus.dev.