Chrome Extension Privacy Policy
AlphaLoops Carrier Intelligence browser extension · Effective July 20, 2026
The AlphaLoops Carrier Intelligence extension overlays motor-carrier records (FMCSA authority, safety, insurance, fleet, and contacts) on LinkedIn, Gmail, and carrier websites. This policy describes exactly what the extension sends off your device, when, and what it never touches. It supplements the general AlphaLoops Privacy Policy, which governs data handled by AlphaLoops services generally.
The short version
Signed out (no AlphaLoops account): nothing leaves your browser. The extension runs entirely on bundled, clearly-labeled sample data. No page URLs, no domains, no telemetry.
Signed in: the extension sends the minimum identifier needed to match a carrier — a website domain or a LinkedIn company identifier — to AlphaLoops servers, plus anonymized product telemetry. It never sends page content, page titles, email bodies, or your browsing history.
Where the extension runs
By default, the extension only runs automatically on linkedin.com and mail.google.com. On any other site it runs only when you click the toolbar icon and choose “Scan this page,” or if you explicitly enable the optional “Scan every website automatically” setting — which triggers a standard Chrome permission prompt you can revoke at any time. A default installation sends nothing about your general browsing.
What leaves the browser (signed in only)
- Website domain (e.g.
schneider.com) — sent to AlphaLoops only for pages where the extension runs (see above), to match the site to a carrier. Only the registrable domain — never the URL path, query string, page title, or page content. A built-in skip list excludes consumer and government sites before any request. - Gmail sender domain — when you open an email conversation, the sender's email domain is used to match a carrier. Freemail providers and your own company's domain are filtered out locally and never sent. Email bodies are never read off-device; only addresses visible in the open conversation are used, locally, to pick the sender.
- LinkedIn company identifier — the company page URL/slug and the company name shown on the page, used as the carrier search key.
- DOT/MC numbers you type into the extension's lookup.
- Contact unlock and CRM push requests — recorded against your account because they consume plan quota and write to your connected CRM.
- Product telemetry — batched event names with coarse properties (e.g. “a match succeeded via domain lookup”). Never URLs, domains, emails, or carrier identity.
- Map coordinates — a carrier's public FMCSA headquarters latitude/longitude is sent to Mapbox to render a static map image. This is the carrier's location, not yours.
What is stored on your device
Your API key, account email, and an authentication-status flag (cleared on sign-out); UI preferences; and a short-lived carrier-resolution cache that is wiped when your browser closes. No cookies, no fingerprinting, no third-party analytics SDKs.
What we deliberately do not do
- No data collection of any kind while signed out.
- No page content, page titles, or browsing-history collection.
- No reading of email bodies.
- No selling, renting, or trading of personal information.
- No third-party processors beyond AlphaLoops infrastructure and Mapbox (map images).
Retention and control
Carrier match queries and telemetry follow the AlphaLoops account data-retention policy. Signing out of the extension revokes its credential server-side and clears everything it stored locally. To request deletion of account data, contact your AlphaLoops representative or use the contact options in the AlphaLoops Privacy Policy.
Changes
Updates to this policy will be posted on this page before taking effect. Use of the extension after an update represents agreement with the revised policy.