Privacy Policy

Transparency and data handling disclosure for the ZESTRA TOOLKIT browser extension.
Extension: ZESTRA TOOLKIT Effective Date: August 27, 2026 Last Updated: August 27, 2026
🔒 100% Local Execution
All automation scripts run inside your browser. No data is ever sent to developer servers.
🚫 Zero Data Selling
We never sell, rent, monetize, or transfer your personal or business records to third parties.
âš¡ Zero Remote Code
All scripts are packaged locally within the extension archive. No external code loading.

1. Introduction

This Privacy Policy describes how ZESTRA TOOLKIT ("the Extension", "we", "us", or "our"), developed by Joseph Peters Wafula (Website: https://www.josephpetersw.com), handles, processes, and protects information when you install and use the ZESTRA TOOLKIT Chrome extension.

ZESTRA TOOLKIT is a specialized productivity and workflow automation tool built specifically for authorized personnel operating the Hire Purchase Sales desk on the Zestra administrative and agent-manager web portals (zestra.co.ke).

We are committed to user privacy and data security. The Extension operates entirely within your local browser environment and does not transmit, collect, or store personal or business data on any external servers operated by the developer.

2. Single Purpose

The single purpose of ZESTRA TOOLKIT is to automate routine Hire Purchase Sales desk operations on the authorized Zestra portal (https://zestra.co.ke) and cross-verify records with external partner portals (including https://portal.onfonmobile.co.ke and https://partners.mogo.co.ke).

Its specific features include:

  • Verifying hire-purchase sales against user-provided CSV or Excel spreadsheets.
  • Cross-referencing customer records and payment status directly against provider portals.
  • Un-flagging resolved sales records in bulk across multiple providers.
  • Bulk-approving pending agent commissions.
  • Generating locally rendered audit-trail run reports.

3. Information Accessed and Processed

In order to fulfill its single purpose, ZESTRA TOOLKIT accesses and processes the following categories of data strictly within your local browser runtime:

Personally Identifiable Information (PII) Read / Match
  • Customer full names, mobile phone numbers, and national identification (ID) numbers.
  • Front-officer and sales agent names.
Purpose: Cross-referencing and matching sales records between Zestra tables, partner portals, and imported spreadsheets.
Financial and Payment Information Reconciliation
  • Transaction reference codes (e.g., M-Pesa codes), amounts paid, deposit payments, retail device prices, and agent commission calculations.
Purpose: Reconciling payment records, auto-populating verification forms, and approving eligible commissions.
Website Content and Form Data DOM Automation
  • Document Object Model (DOM) elements, table rows, input fields, modal dialogs, and verification/flag action buttons on supported web portals.
Purpose: Reading table entries, populating verification forms, and triggering the same button clicks a staff member performs manually.
User-Uploaded Files Local Memory
  • CSV and Excel (.xlsx) spreadsheet files uploaded directly by the user into the extension popup.
Purpose: Extracting IMEI, phone number, and payment codes for local batch comparison. Files are parsed entirely in memory and never uploaded to remote servers.
Application State and Preferences Local Storage
  • Pace and delay settings, dry-run toggles, live run progress counters (verified, flagged, skipped, failed counts), live run logs, and recent run audit reports.

4. Data Storage and Retention

Local Storage Only: All persistent data is stored strictly on your local computer using Chrome's built-in chrome.storage.local API. This data is never synchronized to Chrome Sync or any cloud service.

No External Database: The developer does not maintain, operate, or communicate with any external backend database, cloud storage, telemetry service, or tracking server.

Retention: Locally stored configurations and recent run reports remain on your computer until manually cleared by the user or until the extension is uninstalled.

5. Data Sharing and Disclosure

No Sale or Commercial Transfer: We do not sell, rent, lease, trade, monetize, or transfer any user data, customer records, or financial information to third parties.

No Advertising or Tracking: Data is never used for advertising, behavioral analytics, user profiling, or commercial marketing.

No Credit Decisions: The extension does not make automated creditworthiness or lending decisions; it solely performs operational reconciliation of pre-existing records.

Authorized Portal Communication: Network requests occur strictly between your browser and the specific authorized portals required to conduct the workflow:

Primary https://zestra.co.ke/* — Zestra Hire Purchase Sales Admin & Manager Portal
Partner https://portal.onfonmobile.co.ke/* — Onfon Mobile Verification Portal
Partner https://partners.mogo.co.ke/* — Mogo Partner Sales Portal

These communications execute entirely within your existing authenticated browser sessions.

6. Browser Permissions Used

The Extension requests the following browser permissions solely to execute its core functionality:

Permission Justification / Functional Purpose
activeTab Targets the active Zestra tab currently open when the user launches an automation run from the popup.
tabs Tracks, reloads, and coordinates multi-tab automation workflows (e.g., cross-checking Onfon records) and opens the generated Full Report page in a new tab.
scripting Injects local runner scripts into authorized pages to read table records, fill out verification forms, and simulate user clicks.
storage Stores run configurations, pace preferences, live progress, and audit history locally on the user's device via chrome.storage.local.
host_permissions Restricts extension execution strictly to declared host origins (zestra.co.ke, portal.onfonmobile.co.ke, and partners.mogo.co.ke).

7. Remote Code Policy

ZESTRA TOOLKIT strictly adheres to Google Chrome Web Store policies regarding remote code:

  • No Remote Code: No code is loaded or executed from external network locations or CDNs.
  • Self-Contained Package: Every script, runner, style, and asset is bundled directly inside the local extension archive.
  • No Unsafe Evaluations: The Extension does not utilize eval(), remote script tags, or dynamic execution of third-party strings.

8. Security

All data processing takes place entirely within the secure sandboxed runtime of your web browser. Your information is protected by Google Chrome's process isolation and security architecture.

The Extension does not access, handle, log, or transmit user credentials, passwords, or authentication cookies.

9. User Control and Data Deletion

You have full control over your data stored locally by the Extension:

  • Clear Storage: You can clear extension data at any time via Chrome Settings (chrome://extensions → ZESTRA TOOLKIT → Storage).
  • Uninstall: Removing ZESTRA TOOLKIT from Chrome permanently deletes all locally stored preferences, run history, and cache from your system.

10. Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect updates to the extension's features or changes in applicable regulatory requirements. Any updates will be published with a revised "Last Updated" date at the top of this document.

11. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or the data handling practices of ZESTRA TOOLKIT, please reach out via the official channels below:

Developer
Joseph Peters Wafula
Extension
ZESTRA TOOLKIT
Source Code