BWA Horizon Connector — Privacy Policy

Last updated: 2026-07-27

The BWA Horizon Connector is a browser extension for existing BWA Horizon customers (restaurants and food businesses). It lets you authorize this browser once and connect your own PC Express grocery account to BWA Horizon so the platform can check live grocery prices for your business, and — when you ask it to — prepare a proposed grocery cart for you to review, using your own logged-in session.

This policy explains exactly what the extension collects, why, where it goes, who can access it, how long it is kept, and how to delete it.

What the extension collects

For the PC Express banner sites you are signed in to (loblaws.ca, nofrills.ca, realcanadiansuperstore.ca), the extension reads:

  1. Product and price data your store page already shows (primary). As you browse or search your PC Express store while signed in, the extension reads the product rows the page itself rendered — product name, price, package size, unit, and an in-stock flag — together with your selected store and a timestamp. This is read from the page's own data and carries no session tokens. When the data the page embedded is stale or incomplete, the extension may request the current page's own data file from the same PC Express origin (the route data the site itself loads when you navigate); it makes no requests to any other site.
  2. Your grocery-session cookies for those sites (supporting). These are the cookies the grocery site itself set in your browser when you logged in (for example the session/access tokens). They are read with the browser cookies API, including HttpOnly cookies that page scripts cannot see, only on the optional session-connect path.
  3. The site build identifier (__NEXT_DATA__.buildId) and your selected store, read from the page markup, so BWA queries the correct store.
  4. A capture timestamp and a random, non-secret install id the extension generates so you can see which browser is connected. If you type an optional label for the browser when authorizing it (for example "back office laptop"), that label is stored with the installation and shown in your BWA Horizon account. The install id is a persistent identifier tied to your BWA Horizon tenant.
  5. A connector-specific BWA device credential. After you explicitly choose Authorize this browser in BWA Horizon, the extension stores a rotating connector refresh credential and a short-lived access credential. These are limited to connector price/session/supervised-order APIs. The extension does not receive or store your BWA password, normal BWA login session, or Supabase key.
  6. Supervised grocery-order data (only when you start an order in BWA). See the next section.

Supervised order preparation and cart staging

This is a feature of the extension, not a background activity: it runs only for an order you create in BWA Horizon and only after you act. When it runs, the extension:

The extension never completes checkout for you. It does not select or enter payment information, does not submit or place the order, and does not automate sign-in or multi-factor authentication. Reviewing the cart and checking out are always your actions.

What the extension does not collect

The extension does not collect your browsing history, your activity on non-grocery sites, your payment or card details, your contacts, your personal communications, your keystrokes, or your PC Express order history beyond the orders you asked BWA Horizon to prepare.

It does not access your device location: it requests no geolocation permission and reads no GPS, IP-derived, or Wi-Fi location data. It does record which store you selected on the PC Express site (a store identifier you chose, needed to price the correct store), and — during a supervised order — the fact that your tab reached the order-confirmation route described above.

The extension has no analytics, no advertising, no tracking pixels, and no telemetry. It does not build a profile of you and does not follow you across sites: it runs only on the three PC Express banner sites and only for your own account.

Why it collects this

BWA Horizon checks live grocery prices to power procurement decisions. PC Express only serves prices to a real, signed-in session and blocks automated/data-center traffic, so prices must be read from a real logged-in session — yours. The in-browser read sends the prices your account already sees to your BWA Horizon tenant; the optional session connect lets BWA keep that pricing current between your visits. Supervised order preparation exists so you do not have to retype a BWA-generated purchase list into the grocery site by hand.

Where it is sent, and who processes it

Human access

Google/Chrome Limited Use disclosure

Our use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:

  1. We use the data only to provide and improve the single purpose described in this policy — checking your grocery prices and preparing supervised orders for your BWA Horizon account.
  2. We do not sell this data, and we do not transfer it to third parties except to the infrastructure providers named above who process it on our behalf to run the product, or when required by law.
  3. We do not use or transfer this data for advertising, ad targeting, ad personalization, or any other purpose unrelated to the single purpose.
  4. We do not use or transfer this data to determine creditworthiness or for lending purposes.
  5. We do not allow humans to read this data, except: with your affirmative consent for a specific case (for example a support request you raise); as necessary for security purposes such as investigating abuse or an incident; to comply with applicable law; or where the data is aggregated and de-identified for internal operations.

Retention and deletion

Data the extension stores locally

In chrome.storage.local: the rotating connector refresh credential, the random install id and its optional label, bounded connection/recovery status, and per-banner status — which includes the store you selected and the site build identifier, so captures resume correctly. Product rows, prices, cookies, and cart contents are not retained in extension storage. A legacy link code is present only if you use the temporary support flow. Credential storage is restricted to trusted extension contexts, so PC Express page scripts and extension content scripts cannot read it.

In chrome.storage.session: the short-lived connector access credential, the bounded identifier of an in-progress order intent (a UUID plus the banner and the tab/origin it was staged in — never the order's contents), and, for at most about 100 seconds during explicit authorization, the PKCE verifier and random state. Session storage is cleared when the browser session ends. No credential is placed in the BWA page DOM, website storage, or console logs.

Permissions

The extension uses the minimum set: cookies, storage, alarms, and host access to the three PC Express banner sites plus the BWA Horizon backend API origin — four hosts in total. It does not request the tabs permission, so it cannot see the URLs or titles of your other open tabs.

No remote code

The extension contains no remotely-hosted or dynamically-evaluated code. All logic ships in the package and is auditable.

Changes to this policy

If we materially change what the extension collects or how it is used, we will update this policy and its "last updated" date before the change ships in a released version.

Contact

Questions or deletion requests: your BWA Horizon account contact, or support@bwa-horizon.com.