Privacy Policy · WhoHeld Extension
Last updated: September 30, 2026
The WhoHeld Extension is a browser extension for customers of the WhoHeld service. It shows, directly on Amazon product pages, the Buy Box and market data already available in your workspace, and lets you add a product to your tracked catalog in one click. It is designed to process as little data as possible.
Who is responsible
The extension is published by WhoHeld SASU, 49 cours Mirabeau, 13100 Aix-en-Provence, France, registered in Aix-en-Provence (RCS 130 164 783). For the data of your workspace account, the controller is the company that subscribed to WhoHeld, usually your employer; WhoHeld processes that data on its behalf, as its processor. The full privacy policy, the list of sub-processors and the transfers outside the European Union are published at whoheld.com/trust/privacy and whoheld.com/trust#subprocessors.
Data the extension processes
- Account and session data. You sign in with the email and password of your existing workspace account. The session token is stored locally in your browser (
browser.storage.local) and sent only to our API to authenticate your requests. We never see your password in the extension: authentication is handled by our identity provider. - Product identifiers. The extension works on the Amazon marketplaces it is installed for (amazon.fr, amazon.de, amazon.co.uk, amazon.es, amazon.it, amazon.com, amazon.ca, amazon.com.mx, amazon.co.jp, amazon.in, amazon.com.br), and only while you are signed in. It reads product identifiers (ASINs) in two places. On a product page, it reads the ASIN and the marketplace from the page URL, and sends these two values to our API, to fetch the data your workspace already tracks for that product and, if you click “Track”, to add it to your catalog. On search and category result pages, it reads the ASINs of the product tiles shown on the page (a standard attribute of each tile) and sends them to our API in batches of up to 60, so it can mark the products your workspace already tracks. In both cases, only product identifiers and the marketplace are transmitted. The extension never reads or sends product titles, prices, reviews, your search terms, or any other page content.
Data the extension does not process
- No browsing history: pages outside the Amazon marketplaces listed above are never read.
- No page content beyond the product identifiers described above: no product titles, prices, reviews or search terms. No keystrokes, form data or cookies are collected.
- No analytics, advertising or tracking of any kind is embedded.
- No data is ever sold or shared with third parties for their own purposes.
How data is used and kept
Requests are used solely to operate the service you subscribed to: displaying your tracked data and enrolling products at your request. API requests are subject to per-workspace rate limits and minimal operational logging (request counts and status codes) used for reliability and abuse prevention. Your session remains on your device until you sign out from the extension popup.
Where data is processed
The service database is hosted in France. Requests from the extension reach our web application, run by Vercel Inc., a company established in the United States, in its Frankfurt region, under the EU standard contractual clauses. Other sub-processors, some established outside the European Union, are listed with their safeguards on whoheld.com/trust. Data is encrypted in transit (TLS). Access to workspace data is isolated per customer (row-level security).
Your rights
Under the GDPR you may request access, rectification or deletion of your personal data, or object to its processing. Contact us at privacy@whoheld.com. You can stop all processing at any time by signing out of the extension and removing it from your browser.
Changes
We will update this page if the extension's data practices change, and the “Last updated” date above will reflect it.