Sponsor.krd Extension
Privacy Policy
This policy explains how Sponsor.krd Extension for Chrome and its authorization service access, use, store, and protect information.
1. Scope and operator
This Privacy Policy applies to Sponsor.krd Extension for Chrome, the related authorization API, and the administrator tools used to control access. The service is operated by Sponsor.krd (“we,” “us,” or “our”).
Sponsor.krd Extension helps authorized users activate supported manual campaign settings in TikTok Ads Manager and limits use to advertiser accounts approved by the administrator.
2. Information we process
Google account information
When you choose “Continue with Google,” we request only the standard openid, email, and profile scopes. We receive and store your Google account identifier, verified email address, display name, and profile image URL. We do not receive or store your Google password. Google access and refresh tokens are not retained by the extension or our database.
Authentication and access information
We process a random extension session token, its expiration time, login and last-activity times, account status, administrator assignments, and security records needed to authenticate requests. The extension keeps the session token and basic Google profile information only in Chrome session storage, which is cleared when the browser session ends. Our server stores only a cryptographic hash of the extension session token.
TikTok advertiser information
We process the numeric TikTok advertiser account ID visible in the active TikTok Ads Manager context. The advertiser ID is sent to our authorization server together with your extension session so we can determine whether that account is assigned to your email. When you request campaign activation, the extension also sends the limited campaign category needed to select the correct operation plan, such as Lead Generation or Sales. We store assigned advertiser IDs and may store the most recent authorization result and activity timestamps.
Campaign, page, and request data processed locally
To perform the feature you request, the extension temporarily reads the active TikTok Ads Manager URL, campaign and draft identifiers, campaign draft request content, and a limited set of TikTok request headers needed to save the updated draft. This may include an authentication or CSRF header already present in your TikTok session.
The complete campaign content, TikTok cookies, and TikTok authentication headers are processed in extension memory or short-lived Chrome or page session storage. They are not sent to our authorization server. They are sent only to TikTok when the extension performs the user-requested campaign operation.
Technical and security information
Our server, reverse proxy, hosting provider, and security controls may process standard connection information such as IP address, request time, user agent, response status, and rate-limit events. The extension also keeps short-lived workflow states and error messages in Chrome session storage.
3. How we use information
- Authenticate users through Google and maintain secure sessions.
- Show the signed-in account and provide the requested extension functionality.
- Check whether a TikTok advertiser account is assigned to the signed-in email.
- Process and save supported campaign changes requested by the user.
- Prevent unauthorized access, abuse, fraud, and security incidents.
- Operate, troubleshoot, maintain, and improve reliability.
- Comply with legal obligations and enforce our Terms of Use.
We do not sell personal information, use it for personalized advertising, or use Google user data for creditworthiness or lending decisions.
4. Google API Limited Use disclosure
Sponsor.krd Extension’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. When information is shared
We disclose information only as needed to operate the service:
- Google: to complete the sign-in flow and verify identity.
- TikTok: campaign and request data is sent to TikTok only to carry out the action initiated by the user in TikTok Ads Manager.
- Infrastructure providers: hosting, database, networking, security, and backup providers may process data on our behalf under appropriate confidentiality and security obligations.
- Legal and safety: when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or enforce agreements.
- Business transfer: as part of a merger, acquisition, financing, or asset transfer, subject to continued protection and applicable notice requirements.
We do not permit service providers to use extension data for their own advertising purposes.
6. Storage and retention
- OAuth state and one-time login codes are short-lived and expire automatically.
- Server-side extension sessions expire no later than one day after sign-in and can be revoked earlier when you sign out or an administrator disables your access. The browser removes its local copy when the browser session ends.
- Temporary campaign workflow data in Chrome session storage is removed as workflows finish, tabs close, or the browser session ends.
- Google profile data, advertiser-account assignments, and access history are retained while needed to provide and secure authorized access, or until the account is deleted, subject to legal and legitimate security retention requirements.
- Infrastructure backups and security logs may remain for a limited additional period before scheduled deletion.
7. Security
We use HTTPS in production, access controls, hashed session tokens, parameterized database queries, rate limiting, restrictive browser security headers, administrator authentication, CSRF protection, and limited OAuth scopes. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
8. Your choices and deletion requests
You can stop local collection by signing out and uninstalling the extension. Signing out revokes the active extension session and removes the locally stored authentication record.
You may request access, correction, or deletion of your stored Google profile and extension authorization records by contacting us at [email protected]. We may need to verify the requesting email before fulfilling a request. Some limited security or legal records may be retained where required or permitted by law.
9. International processing and children
Information may be processed in countries where we or our infrastructure providers operate. We take reasonable steps to protect data in accordance with this policy and applicable law. The extension is intended for business users who are legally capable of managing advertising accounts and is not directed to children.
10. Third-party services
Google and TikTok process information under their own terms and privacy policies. Sponsor.krd Extension is not affiliated with or endorsed by Google, TikTok, or the Chrome Web Store. You should review the policies that apply to those services.
11. Changes and contact
We may update this policy when the extension, legal requirements, or data practices change. The effective date and version at the top identify the current policy. Material changes will be communicated through an appropriate product or listing notice.
Privacy questions and requests: [email protected]
Website: https://sponsor.krd/
Sponsor.krd Extension