Effective date: August 16, 2026
Supra Operations Session Helper is a companion browser extension for the local Tool hỗ trợ vận hành application. Its single purpose is to let an authorized user explicitly capture the current Supra API session and the request payload used to create the supported STO report so the user's local operational tool can perform authorized exports.
After the user explicitly enables capture, the extension may process authentication/session information contained in request headers sent to api-supra.winmart.vn, including session or authorization tokens, user/warehouse identifiers, and request-signature headers. It may also process the URL of a Supra API request and the request body for the specific STO report creation endpoint.
The data is used only to provide the user-facing session capture and local export functionality described above. It is not used for advertising, profiling, creditworthiness, lending, analytics unrelated to the extension's purpose, or any other secondary purpose.
Sensitive captured session data is held in Chrome session storage and is not intentionally persisted by the extension across browser sessions. The user can clear it at any time by disabling capture or pressing the clear-session control. The extension stores only the user's capture-enabled preference persistently.
If the user explicitly chooses to export a session JSON file, that file is saved locally under the user's control. The extension does not control the retention of files after export.
The extension does not automatically transmit captured authentication/session data or STO request payloads to the developer, advertising networks, data brokers, or other third parties. It does not sell user data. Any later use of a JSON file explicitly exported by the user occurs outside the extension and under the user's authorized local operational workflow.
Capture is disabled by default. Before any relevant data is captured, the extension presents an in-product disclosure and requires the user to take the explicit action "Bật capture và đồng ý". The user can disable capture or clear the currently held session from the extension popup.
The extension limits host access to https://api-supra.winmart.vn/*, requests only the browser permissions needed for its stated purpose, does not execute remote code, and does not contain hardcoded Supra authentication credentials.
The use of information received through Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. User data is used only as necessary to provide or improve the extension's disclosed single purpose and is not transferred for advertising or other prohibited purposes.
If the extension's data practices materially change, this policy and the Chrome Web Store disclosures will be updated before the changed behavior is released.
Use the developer contact information shown on the Chrome Web Store listing for privacy questions or data-handling requests.