Skip to main content

Last updated 4 July 2026

Pack privacy notice

This notice explains what Pack handles in the browser extension, on this website, and when you contact us.

Scope

Pack browser extension

Pack runs in the user's browser, uses Chrome extension storage inside the current browser profile, and writes selected downloads to the user's machine.

  • No extension analytics or telemetry.
  • The local-download workflow does not upload GST files or document contents to ComplyEaze.
  • Local storage may contain pack:install with local extension version, install timestamp, and local-only metadata, plus pack:active-filed-returns-run, pack:full-fiscal-year-ledger, pack:filed-returns-target-review, and pack:last-manifest.
  • Session storage may contain pack:last-context, pack:last-filed-returns-observation, and pack:last-filed-returns-flow-summary.
  • Clear local Pack data removes Pack local/session extension state after active or unresolved recovery state is resolved.

GST Portal interaction

The user opens and authenticates to the GST Portal directly. Pack acts only on exact GST Portal hosts from the active browser session and does not ask for or store GST Portal credentials, OTPs, CAPTCHA responses, cookies, or session tokens.

  • https://www.gst.gov.in/*
  • https://services.gst.gov.in/*
  • https://return.gst.gov.in/*

Pack website diagnostics

The Pack website is separate from the browser extension. GST credentials, session tokens, and downloaded GST files are not sent to ComplyEaze by the extension workflow. Pack does not collect or transmit extension analytics or telemetry.

  • Website page analytics are disabled.
  • Pack pages use Sentry error diagnostics in the Pack telemetry profile with replay, tracing, logs, request bodies, cookies, and default PII disabled; full query strings are stripped from request URLs before Pack website diagnostics leave the app.
  • Pack pages do not initialize or use the ComplyEaze app session.

Support and security reports

Email support, GitHub issues when available, pull requests, and private security reports receive only what a visitor or reporter chooses to send. Reports must use synthetic or redacted material.

  • Do not send real GST Portal credentials, OTPs, CAPTCHA responses, session cookies, taxpayer files, portal HTML, raw network captures, or unredacted screenshots.
  • Security reports go to [email protected]; general questions go to [email protected].
  • Public issues, pull requests, screenshots, and support messages must not include taxpayer identifiers, credentials, portal captures, or downloaded GST files.

Pack browser extension

The extension processes supported GST Portal page state locally in your browser to find and trigger filed GSTR‑3B PDF, filed GSTR‑1 summary PDF, and optional GSTR‑1 e-invoice details Excel downloads.
Rendered GST page text and controls
Read transiently in the browser to classify and operate supported GST Portal pages; raw page text is not transmitted to ComplyEaze.
GST origin and page kind
Reduced to allowlisted context labels and stored temporarily in extension session storage.
Selected financial year and period
Processed locally to identify requested filed GSTR‑3B and GSTR‑1 downloads; local run, full-year ledger, and unresolved target-review state may remain in extension local storage until cleared or the extension is removed.
Download metadata
Examined transiently to correlate the requested GST-origin PDF or Excel file and verify completion; raw filenames, local paths, referrers, and URLs are not transmitted or persisted.
Installation metadata
Stored in extension local storage as pack:install with local extension version, install timestamp, and local-only metadata until cleared or the extension is removed.
Local demo manifest
Stored in extension local storage as pack:last-manifest for the synthetic demo until clear-data runs or the extension is removed.
GST PDF or Excel file
Saved by Chrome to the user's configured download location; Pack does not upload downloaded GST files to ComplyEaze.

GST Portal interaction

You open and authenticate to the GST Portal directly. Pack acts only on exact GST Portal hosts from the active browser session.
  • Pack does not ask for or store GST Portal credentials, OTPs, CAPTCHA responses, cookies, or session tokens.
  • Pack does not automate OTP, CAPTCHA, login, or consent challenges.
  • https://www.gst.gov.in/*
  • https://services.gst.gov.in/*
  • https://return.gst.gov.in/*

Pack website

The Pack website is separate from the browser extension. GST credentials, session tokens, and downloaded GST files are not sent to ComplyEaze by the extension workflow. Pack does not collect or transmit extension analytics or telemetry.
Website analytics
disabled
Error diagnostics
Pack pages use Sentry error diagnostics in the Pack telemetry profile with replay, tracing, logs, request bodies, cookies, and default PII disabled; full query strings are stripped from request URLs before Pack website diagnostics leave the app.
Infrastructure logs
Standard hosting logs may include ordinary request metadata such as IP address, user agent, timestamp, path, status, and referrer.
ComplyEaze app session
not initialized or used by Pack pages

Your privacy choices and requests

Use this route for website, support, and security-report data that ComplyEaze can access. Extension-local state that never leaves your browser profile must be cleared locally.
  • Contact [email protected] to request access, correction, deletion, or grievance review for Pack website/support data ComplyEaze can access.
  • Send private security reports to [email protected], not public issues.
  • ComplyEaze cannot retrieve downloaded GST files, GST Portal credentials, cookies, OTPs, CAPTCHA responses, or extension-local data that never leaves your browser profile.
  • Clear local Pack data removes Pack local/session extension state after active or unresolved recovery state is resolved; removing the extension or browser profile also removes extension-local state.

DPDP 2026 readiness workstream

Engineering readiness target for DPDP 2026 obligations; this is not a legal certification or compliance guarantee.
Data-principal request handling (active)
ComplyEaze Pack maintainer: Maintain a dated response log for Pack website/support access, correction, deletion, and grievance requests.
Support and security intake minimisation (active)
Support maintainer: Keep public support templates and private security-report guidance aligned with the prohibited sensitive attachment list.
Processor and recipient review (active)
Privacy maintainer: Review hosting logs, Sentry diagnostics, GitHub, and email inbox handling before broad public distribution.
Security incident and breach workflow (todo)
Security maintainer: Document intake, triage, user-notification, authority-notification, containment, and post-incident review steps before claiming DPDP compliance.
External legal review (todo)
Legal reviewer: Record legal sign-off against applicable DPDP Act and Rules obligations before any compliance badge or certification wording.

Who receives data

Pack separates browser-local extension processing from website diagnostics, support, and public-source collaboration.
Chrome browser profile
Stores extension-local Pack state and writes selected downloads to the user's configured download location.
Hosting provider logs
May process ordinary Pack website request metadata such as IP address, user agent, timestamp, path, status, and referrer.
Sentry diagnostics
Receives sanitized Pack website error diagnostics under the Pack telemetry profile.
GitHub issues and pull requests
Receives public reports a visitor chooses to submit, using synthetic or redacted material only.
Email support inboxes
Receives support, privacy, and security-report messages a visitor chooses to send.

Support and security reports

Public issues, pull requests, email support, and private security reports receive only what a visitor or reporter chooses to send.
  • Do not send real GST Portal credentials, OTPs, CAPTCHA responses, session cookies, taxpayer files, portal HTML, raw network captures, or unredacted screenshots.
  • GSTIN, PAN, Aadhaar, taxpayer names, client names, or trade names.
  • Passwords, OTPs, CAPTCHA responses, cookies, session tokens, or credentials.
  • ARNs, return values, tax amounts, downloaded GST files, real filenames, portal HTML, headers, cookies, raw network captures, or unredacted screenshots.
  • Support and security submissions are retained only as needed to respond, investigate, and maintain an audit trail.

Chrome Limited Use

Pack's extension data use is limited to providing or improving the user-facing supported download workflow. Extension data is not used for advertising, lending, creditworthiness, unrelated profiling, or sold to third parties.
  • No extension analytics or telemetry.
  • No advertising or session-replay SDK in the extension.
  • The extension workflow does not upload GST files or GST document contents to ComplyEaze.
  • Local extension data can be cleared through Clear local Pack data after active or unresolved recovery state is resolved, browser extension removal, or browser profile cleanup.