Legal
Browser extension privacy policy
Last updated: August 2026
This Browser Extension Privacy Policy explains how BULLWHIP LTD ("Bullwhip", "we", "us", "our") collects, uses, and protects information when you use the BullWhip browser extension for Chrome or Microsoft Edge.
This policy supplements our general privacy policy. If there is a conflict between this policy and the general policy for browser-extension activity, this browser-extension policy applies to that activity.
BULLWHIP LTD
24 Sandiway, Irlam, Manchester, England, M44 6EF
Email: info@bull-whip.com
Phone: +44 7432 623451
What the extension does
The BullWhip browser extension helps signed-in BullWhip users use saved BullWhip company information while working on supported websites. It can identify Companies House company pages, show BullWhip company context, show recent BullWhip favourite companies, and help create a company in HubSpot from an already-open HubSpot company form.
Information the extension processes
The extension may process the following information:
- Active tab URL on supported pages - used to recognise Companies House and HubSpot pages after you open the extension or while the extension is active on an allowlisted HubSpot page.
- Companies House company number - derived from the active Companies House URL and sent to BullWhip so we can return matching company context.
- BullWhip account session status - used to confirm whether you are signed in to BullWhip. The extension uses your existing BullWhip browser session cookie when making requests to BullWhip APIs.
- BullWhip company data - including company name, domain, company number, SIC labels, size score, and recent favourite companies returned by BullWhip APIs for your account.
- HubSpot form fields you choose to populate - when you click a recent BullWhip favourite in the extension popup, the extension can fill the company name and domain into the supported HubSpot create-company form and click the HubSpot create button.
- Technical diagnostics - browser and extension runtime errors may be visible in your local browser developer tools. The current extension does not send those console logs to BullWhip automatically.
Information the extension does not collect
The extension does not intentionally collect or store:
- passwords or sign-in credentials;
- BullWhip session cookies;
- HubSpot cookies;
- CRM OAuth access or refresh tokens;
- payment card details;
- personal messages, email inbox contents, or unrelated website content;
- browsing history outside the specific supported BullWhip, Companies House, and HubSpot pages required for the extension workflow.
How we use information
We use extension-related information to:
- identify whether the active page is a supported Companies House or HubSpot page;
- look up BullWhip company context for the Companies House company number shown in the active tab URL;
- show recent BullWhip favourites for the signed-in user;
- fill and create a HubSpot company record after the user clicks a recent BullWhip favourite;
- maintain account security, access control, and auditability in BullWhip APIs;
- debug and improve the extension.
Browser permissions
The extension requests limited permissions for its stated purpose:
- activeTab - allows the extension to work with the current tab after you interact with the extension.
- https://bull-whip.app/* - allows authenticated requests to BullWhip APIs.
- https://find-and-update.company-information.service.gov.uk/* - allows the extension to recognise Companies House company pages and derive company numbers from their URLs.
- https://*.hubspot.com/* - allows the extension to detect the supported HubSpot create-company form and populate company fields after your action in the extension popup.
Cookies and authentication
The extension does not ask you for your BullWhip password. When it calls BullWhip APIs, it uses standard browser requests with credentials included, so your browser may attach your existing BullWhip session cookie. The extension does not read, copy, or store that cookie itself.
The extension does not read, copy, or store HubSpot cookies. Browser-assisted HubSpot actions happen in the HubSpot page you already have open in your browser.
Sharing and disclosure
We do not sell extension data. We do not share extension data for advertising. Information processed through the extension may be sent to BullWhip APIs to provide the extension service to the signed-in user. HubSpot form values are entered into HubSpot only after the user selects a company in the extension popup.
Data retention
The extension itself is not designed to maintain a separate long-term database of your data. BullWhip API requests and any server-side records associated with your BullWhip account are handled under BullWhip's general data retention and security practices. HubSpot records created through the browser remain in the user's HubSpot account and are governed by the user's HubSpot configuration and policies.
Security
We design the extension to use narrow host permissions, packaged extension code, and authenticated HTTPS requests to BullWhip. No method of transmission or storage is completely secure, but we take reasonable technical and organisational measures to protect the information processed through BullWhip services.
Your choices
You can stop using the extension at any time by disabling or uninstalling it in your browser. You can sign out of BullWhip to prevent authenticated BullWhip API requests from succeeding. You can manage or delete HubSpot records created through the extension in your HubSpot account, subject to your HubSpot permissions.
Changes to this policy
We may update this Browser Extension Privacy Policy from time to time. Updates will be posted on this page with an updated "Last updated" date.