CPR Activity Monitor Privacy Policy

Last updated October 9, 2026. Publisher: repairqtools. This policy describes the CPR Activity Monitor extension and its associated store-owner-operated notification receiver.

Purpose and operation

CPR Activity Monitor lets authorized store users observe saved RepairQ ticket views in their Chrome profile for new refunds and cancelled or rejected claims. Local test mode saves detected events on that computer. When a user pairs the extension to a receiver, detected events are sent to that receiver to notify the store owner through Pushover. The extension observes supported ticket pages that are opened in that browser; it does not provide complete monitoring of activity on other computers or unopened tickets.

Information handled

The extension processes content rendered on supported RepairQ ticket pages. It extracts store and ticket identifiers, the ticket URL, event time and time zone, the recorded employee name and identifier when available, and the event or closure reason. Refund records include the refund and original transaction identifiers and amounts. Claim records include the claim number, status, cancellation or rejection event, client program, and service program.

It also stores setup and delivery information: selected store, activation time, receiver address, a receiver-issued device credential, queued events, identifiers used to prevent duplicate alerts, delivery errors and timestamps, and the last observed ticket information. A connection setup draft, including a pairing code, may be kept temporarily in Chrome session storage. Pairing codes expire on the receiver after 15 minutes and can be used once.

The extension does not collect RepairQ passwords or session cookies, payment-card numbers, or general browsing history. It does not deliberately extract customer names, addresses, phone numbers, or email addresses. However, information entered into a recorded event reason or another extracted field may contain personal information; those field values can be included in event records and alerts. Complete page HTML and complete ticket histories are not sent to the receiver.

How information is used and shared

Information is used to identify supported events, show test results and monitoring status, deliver alerts, retry pending deliveries, and prevent duplicate notifications. Local test mode does not send its saved test events to the receiver or Pushover. A user can download test results to a file on that computer.

In connected mode, the extension sends event records to the receiver address selected during setup. In this pilot the receiver runs on the store owner's Mac. The public HTTPS connection uses ngrok, which handles the connection traffic and associated network metadata. The receiver sends notification text and a ticket link to Pushover for delivery to the configured recipient devices. Notification text can include the store, ticket, event time, recorded employee, reason, claim information, and refund information described above. The owner and people with access to the receiving devices may see those notifications.

The receiver keeps a store-bound device registration, a hash of its credential, event records, receipt timestamps, and delivery status and errors. Service providers may handle network metadata, including IP addresses, under their applicable agreements and privacy terms: ngrok privacy policy, ngrok data processing agreement, and Pushover privacy policy. Provider storage and retention are governed by those providers.

This implementation has no advertising, analytics tracker, sale of user data, or use of user data for advertising or creditworthiness decisions. The extension limits its use of RepairQ page data to the monitoring, test results, and notification features described here. It transfers that data only to the configured receiver and service providers needed to deliver these features. It does not use or transfer that data for advertising or unrelated purposes. Access to business event records is intended for the authorized store operator and alert recipient as part of the monitoring feature.

Storage, security, and retention

Browser settings, credentials, queues, and local test records are stored in this Chrome profile using local storage and are not synchronized by the extension across computers. Setup drafts are stored in Chrome session storage; they are discarded on extension reload or browser restart and are restored by the setup screen only within its 15-minute draft window. Local test records remain after stopping a test. The test record and pending-delivery queues are each limited to 2,000 events. The extension keeps up to 10,000 recently delivered event identifiers for duplicate suppression.

Connections to receivers on other computers require HTTPS. An HTTP loopback connection is allowed only for a receiver on the same computer. The Mac receiver uses private filesystem permissions for its database and stores Pushover credentials in macOS Keychain. The SQLite event database and Chrome local storage are not separately encrypted by this application; protection also depends on the computer's operating-system and disk-security settings.

Receiver event records and device registrations have no automatic retention deadline in this pilot. They remain until the receiver operator removes them. The extension does not erase previously downloaded test-result files, receiver records, or Pushover notifications when monitoring is stopped or disconnected. Users and the receiver operator must manage those copies separately.

Choices, access, and deletion

A user can stop local testing or disconnect central alerts from the extension. Pending central deliveries must finish before disconnection. Removing the extension removes its browser-local data, but does not remove exported files, receiver records, or provider-held notifications. The store owner can arrange access to or deletion of receiver-held records and revoke device registrations. Contact the publisher to request help with the data held by this pilot; provider-held copies may also require a request to the relevant provider.

This policy website

This policy page is hosted on Vercel. Vercel may process connection information, such as IP addresses and request metadata, to serve and secure the page under its privacy policy. This page contains no analytics script, advertising, tracking pixel, or form that collects information.

Contact and changes

For support, questions about this policy, or requests concerning information held by the publisher, email repairqtools@gmail.com. The publisher may need to verify your identity and authorization before providing access to or removing business records.

The publisher will update this policy when the extension's data practices change and display the updated date on this page.