Privacy Policy
1. Introduction
This Privacy Policy describes how ZESTRA TOOLKIT ("the Extension", "we", "us", or "our"), developed by Joseph Peters Wafula (Website: https://www.josephpetersw.com), handles, processes, and protects information when you install and use the ZESTRA TOOLKIT Chrome extension.
ZESTRA TOOLKIT is a specialized productivity and workflow automation tool built specifically for authorized personnel operating the Hire Purchase Sales desk on the Zestra administrative and agent-manager web portals (zestra.co.ke).
We are committed to user privacy and data security. The Extension operates entirely within your local browser environment and does not transmit, collect, or store personal or business data on any external servers operated by the developer.
2. Single Purpose
The single purpose of ZESTRA TOOLKIT is to automate routine Hire Purchase Sales desk operations on the authorized Zestra portal (https://zestra.co.ke) and cross-verify records with external partner portals (including https://portal.onfonmobile.co.ke and https://partners.mogo.co.ke).
Its specific features include:
- Verifying hire-purchase sales against user-provided CSV or Excel spreadsheets.
- Cross-referencing customer records and payment status directly against provider portals.
- Un-flagging resolved sales records in bulk across multiple providers.
- Bulk-approving pending agent commissions.
- Generating locally rendered audit-trail run reports.
3. Information Accessed and Processed
In order to fulfill its single purpose, ZESTRA TOOLKIT accesses and processes the following categories of data strictly within your local browser runtime:
- Customer full names, mobile phone numbers, and national identification (ID) numbers.
- Front-officer and sales agent names.
- Transaction reference codes (e.g., M-Pesa codes), amounts paid, deposit payments, retail device prices, and agent commission calculations.
- Document Object Model (DOM) elements, table rows, input fields, modal dialogs, and verification/flag action buttons on supported web portals.
- CSV and Excel (
.xlsx) spreadsheet files uploaded directly by the user into the extension popup.
- Pace and delay settings, dry-run toggles, live run progress counters (verified, flagged, skipped, failed counts), live run logs, and recent run audit reports.
4. Data Storage and Retention
Local Storage Only: All persistent data is stored strictly on your local computer using Chrome's built-in chrome.storage.local API. This data is never synchronized to Chrome Sync or any cloud service.
No External Database: The developer does not maintain, operate, or communicate with any external backend database, cloud storage, telemetry service, or tracking server.
Retention: Locally stored configurations and recent run reports remain on your computer until manually cleared by the user or until the extension is uninstalled.
5. Data Sharing and Disclosure
No Sale or Commercial Transfer: We do not sell, rent, lease, trade, monetize, or transfer any user data, customer records, or financial information to third parties.
No Advertising or Tracking: Data is never used for advertising, behavioral analytics, user profiling, or commercial marketing.
No Credit Decisions: The extension does not make automated creditworthiness or lending decisions; it solely performs operational reconciliation of pre-existing records.
Authorized Portal Communication: Network requests occur strictly between your browser and the specific authorized portals required to conduct the workflow:
https://zestra.co.ke/* — Zestra Hire Purchase Sales Admin & Manager Portal
https://portal.onfonmobile.co.ke/* — Onfon Mobile Verification Portal
https://partners.mogo.co.ke/* — Mogo Partner Sales Portal
These communications execute entirely within your existing authenticated browser sessions.
6. Browser Permissions Used
The Extension requests the following browser permissions solely to execute its core functionality:
| Permission | Justification / Functional Purpose |
|---|---|
activeTab |
Targets the active Zestra tab currently open when the user launches an automation run from the popup. |
tabs |
Tracks, reloads, and coordinates multi-tab automation workflows (e.g., cross-checking Onfon records) and opens the generated Full Report page in a new tab. |
scripting |
Injects local runner scripts into authorized pages to read table records, fill out verification forms, and simulate user clicks. |
storage |
Stores run configurations, pace preferences, live progress, and audit history locally on the user's device via chrome.storage.local. |
host_permissions |
Restricts extension execution strictly to declared host origins (zestra.co.ke, portal.onfonmobile.co.ke, and partners.mogo.co.ke). |
7. Remote Code Policy
ZESTRA TOOLKIT strictly adheres to Google Chrome Web Store policies regarding remote code:
- No Remote Code: No code is loaded or executed from external network locations or CDNs.
- Self-Contained Package: Every script, runner, style, and asset is bundled directly inside the local extension archive.
- No Unsafe Evaluations: The Extension does not utilize
eval(), remote script tags, or dynamic execution of third-party strings.
8. Security
All data processing takes place entirely within the secure sandboxed runtime of your web browser. Your information is protected by Google Chrome's process isolation and security architecture.
The Extension does not access, handle, log, or transmit user credentials, passwords, or authentication cookies.
9. User Control and Data Deletion
You have full control over your data stored locally by the Extension:
- Clear Storage: You can clear extension data at any time via Chrome Settings (
chrome://extensions→ ZESTRA TOOLKIT → Storage). - Uninstall: Removing ZESTRA TOOLKIT from Chrome permanently deletes all locally stored preferences, run history, and cache from your system.
10. Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect updates to the extension's features or changes in applicable regulatory requirements. Any updates will be published with a revised "Last Updated" date at the top of this document.
11. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or the data handling practices of ZESTRA TOOLKIT, please reach out via the official channels below: