BWA Horizon Connector — Privacy Policy
Last updated: 2026-07-27
The BWA Horizon Connector is a browser extension for existing BWA
Horizon customers (restaurants and food businesses). It lets you
authorize this browser once and connect your own PC Express grocery account
to BWA Horizon so the platform can check live grocery prices for your
business, and — when you ask it to — prepare a proposed grocery cart for you
to review, using your own logged-in session.
This policy explains exactly what the extension collects, why, where it
goes, who can access it, how long it is kept, and how to delete it.
What the extension collects
For the PC Express banner sites you are signed in to (loblaws.ca,
nofrills.ca, realcanadiansuperstore.ca), the
extension reads:
-
Product and price data your store page already shows
(primary). As you browse or search your PC Express store while
signed in, the extension reads the product rows the page itself rendered —
product name, price, package size, unit, and an in-stock flag — together
with your selected store and a timestamp. This is read from the page's own
data and carries no session tokens. When the data the page embedded is
stale or incomplete, the extension may request the current page's own data
file from the same PC Express origin (the route data the
site itself loads when you navigate); it makes no requests to any other
site.
-
Your grocery-session cookies for those sites (supporting).
These are the cookies the grocery site itself set in your browser when you
logged in (for example the session/access tokens). They are read with the
browser
cookies API, including HttpOnly cookies
that page scripts cannot see, only on the optional session-connect path.
-
The site build identifier
(
__NEXT_DATA__.buildId) and your selected store,
read from the page markup, so BWA queries the correct store.
-
A capture timestamp and a random, non-secret
install id the extension generates so you can see which
browser is connected. If you type an optional label for
the browser when authorizing it (for example "back office laptop"), that
label is stored with the installation and shown in your BWA Horizon
account. The install id is a persistent identifier tied to your BWA Horizon
tenant.
-
A connector-specific BWA device credential. After you
explicitly choose Authorize this browser in BWA Horizon,
the extension stores a rotating connector refresh credential and a
short-lived access credential. These are limited to connector
price/session/supervised-order APIs. The extension does not receive or
store your BWA password, normal BWA login session, or Supabase key.
-
Supervised grocery-order data (only when you start an order in
BWA). See the next section.
Supervised order preparation and cart staging
This is a feature of the extension, not a background activity: it runs only
for an order you create in BWA Horizon and only after you
act. When it runs, the extension:
-
Fetches your own pending order intents from BWA Horizon —
the proposed purchase lines BWA already holds for your business (product
identifiers, product names, and quantities that BWA itself generated).
-
Stages a proposed cart in your own signed-in PC Express
tab, adding the proposed items at the proposed quantities.
-
Navigates that tab to the PC Express cart-review page so
you can inspect, change, or abandon the cart.
-
Reports line-level results back to BWA Horizon — for each
proposed line, the product identifier, product name, quantity, and a
bounded status (
staged, already_present,
needs_review, rejected, failed,
reconcile_failed) with a short reason code, plus counts of how
many lines reached each status. These identifiers and names are the ones
BWA supplied in the order intent; no cart id, seller id, price, or free
text is sent.
-
Observes whether the order was placed. If, in that same
tab and on that same store origin, you complete checkout yourself and the
browser lands on the proven PC Express order-confirmation route
(
/en/checkout/thank-you), the extension reports a single
boolean placement outcome to BWA Horizon so your order
record stops showing as pending. It reads no payment details, no order
total, no confirmation number, and no page content from that route — only
the fact that the route was reached in the tab that received the staged
cart.
The extension never completes checkout for you. It does not
select or enter payment information, does not submit or place the order, and
does not automate sign-in or multi-factor authentication. Reviewing the cart
and checking out are always your actions.
What the extension does not collect
The extension does not collect your browsing history, your
activity on non-grocery sites, your payment or card details, your contacts,
your personal communications, your keystrokes, or your PC Express order
history beyond the orders you asked BWA Horizon to prepare.
It does not access your device location: it requests no
geolocation permission and reads no GPS, IP-derived, or Wi-Fi location data.
It does record which store you selected on the PC Express
site (a store identifier you chose, needed to price the correct store), and —
during a supervised order — the fact that your tab reached the
order-confirmation route described above.
The extension has no analytics, no advertising, no tracking pixels,
and no telemetry. It does not build a profile of you and does not
follow you across sites: it runs only on the three PC Express banner sites
and only for your own account.
Why it collects this
BWA Horizon checks live grocery prices to power procurement decisions. PC
Express only serves prices to a real, signed-in session and blocks
automated/data-center traffic, so prices must be read from a real logged-in
session — yours. The in-browser read sends the prices your account already
sees to your BWA Horizon tenant; the optional session connect lets BWA keep
that pricing current between your visits. Supervised order preparation
exists so you do not have to retype a BWA-generated purchase list into the
grocery site by hand.
Where it is sent, and who processes it
-
All data is sent only to the BWA Horizon backend, over
HTTPS. The extension refuses to send to any other host:
the destination is fixed at build time and enforced in code
(
lib/origins.js → assertAllowedBase). Nothing is
sent to advertisers, analytics providers, or data brokers, and no
data is ever sold.
-
BWA Horizon runs on infrastructure providers who process this data
solely on our instructions, as service providers, in order
to run the product: Railway (hosts the BWA Horizon backend
that receives the data), Supabase (hosts the PostgreSQL
database that stores it), and Vercel (hosts the BWA
Horizon web application you sign in to). These providers do not receive the
data for their own purposes and are not permitted to use it for anything
other than providing hosting to BWA Horizon.
-
Price data is stored as your tenant's own private price
history, isolated per customer by row-level security. Only your BWA Horizon
tenant can read it.
-
Session cookies (session-connect path only) are
encrypted at rest (Fernet symmetric encryption) in a
per-tenant secrets vault, also isolated per customer by row-level security.
Human access
-
You and your tenant. Data is isolated per customer by
database row-level security, so users of other BWA Horizon tenants can
never read it.
-
BWA Horizon staff. A small number of authorized BWA
Horizon operations personnel can access production infrastructure, and
therefore stored data, for legitimate operational reasons only:
investigating a fault you reported, preventing or responding to a security
incident, or complying with a legal obligation. Stored grocery-session
cookies are encrypted at rest and are not routinely viewed. We do not read
customer data for product analytics, marketing, or model training.
-
No one else. We do not share this data with any other
third party except the infrastructure providers named above, or where
required by law.
Google/Chrome Limited Use disclosure
Our use of information received from the extension adheres to the
Chrome
Web Store User Data Policy, including the Limited Use
requirements. Specifically:
-
We use the data only to provide and improve the single
purpose described in this policy — checking your grocery prices and
preparing supervised orders for your BWA Horizon account.
-
We do not sell this data, and we do not
transfer it to third parties except to the infrastructure providers named
above who process it on our behalf to run the product, or when required by
law.
-
We do not use or transfer this data for advertising, ad
targeting, ad personalization, or any other purpose unrelated to the
single purpose.
-
We do not use or transfer this data to determine
creditworthiness or for lending purposes.
-
We do not allow humans to read this data, except: with
your affirmative consent for a specific case (for example a support request
you raise); as necessary for security purposes such as investigating abuse
or an incident; to comply with applicable law; or where the data is
aggregated and de-identified for internal operations.
Retention and deletion
-
Each refresh overwrites the previous capture for that
store — old cookies are not accumulated.
-
A grocery session is short-lived by design; the stored bundle carries a TTL
(default 45 minutes) after which it is treated as stale.
-
BWA connector access credentials last 60 minutes and renew automatically
whenever the browser is open. The rotating refresh family expires after 30
idle days or 90 days absolute, and can be revoked for one browser at any
time.
-
Supervised-order line results and the placement outcome are retained with
that order in your tenant's own order records, as the audit trail for a
purchase your business made.
-
The connection is gated by a link code that you generate
in BWA Horizon and that expires (default 1 hour to bind,
revocable at any time) only when the temporary legacy support flow is used.
-
To stop sharing and delete locally: click
Disconnect in the extension popup, or remove the
extension. This clears local connector credentials and status from your
browser.
-
To revoke server-side: revoke that browser installation in
BWA Horizon (or revoke the connector link for the legacy flow). Revocation
immediately prevents new connector API calls. You can also ask BWA Horizon
support to purge any stored session for your tenant.
Data the extension stores locally
In chrome.storage.local: the rotating connector refresh
credential, the random install id and its optional label, bounded
connection/recovery status, and per-banner status — which includes the
store you selected and the site build identifier, so
captures resume correctly. Product rows, prices, cookies, and cart contents
are not retained in extension storage. A legacy link code is
present only if you use the temporary support flow. Credential storage is
restricted to trusted extension contexts, so PC Express page scripts and
extension content scripts cannot read it.
In chrome.storage.session: the short-lived connector access
credential, the bounded identifier of an in-progress order intent (a UUID
plus the banner and the tab/origin it was staged in — never the order's
contents), and, for at most about 100 seconds during explicit authorization,
the PKCE verifier and random state. Session storage is cleared when the
browser session ends. No credential is placed in the BWA page DOM, website
storage, or console logs.
Permissions
The extension uses the minimum set: cookies,
storage, alarms, and host access to the three PC
Express banner sites plus the BWA Horizon backend API origin — four hosts in
total. It does not request the tabs permission, so it cannot see
the URLs or titles of your other open tabs.
No remote code
The extension contains no remotely-hosted or dynamically-evaluated code.
All logic ships in the package and is auditable.
Changes to this policy
If we materially change what the extension collects or how it is used, we
will update this policy and its "last updated" date before the change ships
in a released version.
Contact
Questions or deletion requests: your BWA Horizon account contact, or
support@bwa-horizon.com.