Privacy

Privacy Policy

This policy explains how RepayIQ handles information when authorized partner users use the RepayIQ Partner Chrome Extension and the RepayIQ services that support it.

Last updated:

1. Scope and purpose

This policy is scoped to the RepayIQ Partner Chrome Extension, related partner-account administration, and the RepayIQ API endpoints used by the extension. Other RepayIQ products may provide additional privacy notices for their separate features.

This policy is issued by the publisher of the RepayIQ Partner Chrome Extension, which operates the service under the RepayIQ name. In this policy, “RepayIQ,” “we,” and “us” refer to that publisher.

The extension's single purpose is to let authorized partner users sign in and generate preliminary federal student-loan repayment estimates from borrower-related information the user enters in a Chrome side panel.

The extension is not a lending product. It does not originate, underwrite, approve, or offer credit, and its estimates concern repayment options for existing federal student loans. RepayIQ does not use or transfer extension user data to determine creditworthiness or for lending purposes.

2. Information we handle

Account and authentication information

An authorized administrator may provide a user's full name, work email address, sponsoring organization and account identifiers, role, permission scopes, and account status when creating or managing extension access. A user provides an email address and password to sign in. RepayIQ does not retain the plaintext password; the server stores a salted, one-way password hash.

Quick-quote information

To request an estimate, a user enters an analysis date, annual income, estimated student-loan balance, family size, state of residence, loan category, and loan timing. RepayIQ uses these fields to calculate and return preliminary repayment estimates, assumptions, qualification notes, and warnings.

The extension does not save quick-quote inputs or results in Chrome storage, and the RepayIQ application does not persist a quote record containing the raw quick-quote fields. RepayIQ does persist a cryptographic request hash linked to operational audit metadata. Because that hash is derived deterministically from the request and linked to account activity, RepayIQ does not treat it as anonymous data.

Information stored by the extension

Chrome's local extension storage holds the fixed RepayIQ API origin and, after sign-in, the opaque session token, expiration time, name, email, sponsoring partner and account identifiers, role, permission scopes, account status, and account and last-login timestamps. This allows the session to continue between side-panel openings. Where Chrome supports it, access is limited to trusted extension contexts.

Operational and security information

RepayIQ processes the extension version, login and session timestamps, last-session activity, partner and user identifiers, request path and method, response status, operation outcome, and a request hash. During authentication, RepayIQ processes the request IP address to enforce short-lived rate limits; the application stores a hashed limiter key rather than the raw IP address. Network and hosting providers may process the IP address, user-agent or browser metadata, request time, host and path, and response status on extension requests to deliver and protect the service.

Support communications

If a user contacts RepayIQ by email or phone, RepayIQ processes the user's contact details and the information included in the request to respond and provide support. Email and telephone service providers may process those communications on RepayIQ's behalf.

For Chrome Web Store disclosure purposes, annual income and estimated student-loan balance are financial information, and state of residence and IP address are location information. The extension does not read content from visited webpages and does not collect health information, personal communications, web-browsing history, or activity across websites. It does not monitor clicks, keystrokes, mouse movement, or scrolling, and it does not collect payment-card, bank-account, or transaction data.

3. How we use information

RepayIQ uses extension information only as necessary to:

  • create and administer authorized partner-user accounts;
  • authenticate users, maintain sessions, and enforce account permissions;
  • calculate and display requested preliminary repayment estimates;
  • prevent abuse, enforce rate limits, and investigate security incidents;
  • audit operations and maintain the service's reliability and performance;
  • respond to support requests and communications initiated or authorized by the user; and
  • comply with applicable law and enforce our agreements.

4. Chrome permissions and network access

  • sidePanel: provides the extension's sign-in and quick-quote interface beside the current browser tab.
  • storage: maintains the limited session and account information described above between side-panel openings.
  • https://repayiq.org/*: permits the production extension to call RepayIQ's authentication and quick-quote API endpoints. The production build is configured to communicate only with this RepayIQ application origin.

The extension does not use content scripts or browser APIs to read or modify content in open tabs, and it does not request tabs or browsing-history permissions. All executable extension code is included in the installed package. Server responses contain data and are not executed as remote JavaScript or WebAssembly.

5. Sharing and service providers

RepayIQ does not sell or rent extension user data. We share extension user data only when necessary to provide or improve the extension through the parties identified below, to comply with applicable law, when necessary to protect against malware, spam, phishing, fraud, or abuse, or as part of a merger, acquisition, or sale of assets after obtaining the user's explicit prior consent. We do not otherwise transfer or sell extension user data.

The service providers that process extension information on our behalf are:

  • Cloudflare processes extension request traffic and related network and security metadata for network delivery and security;
  • DigitalOcean processes extension requests and application data for application hosting;
  • MongoDB Atlas stores partner-account, password-hash, session, and operational-audit records for managed database infrastructure; and
  • Brevo receives an invitee's email address, sponsoring partner name, invitation content, and one-time setup link to send transactional partner-account invitation email.

These providers receive only the information needed to perform their assigned services for RepayIQ. Authorized RepayIQ system administrators can view and manage account-directory information needed to provision, suspend, and support extension access, including a user's name, work email, sponsoring partner, role, permission scopes, account status, and last sign-in. The extension does not provide administrators a history of raw quick-quote inputs or results.

6. Chrome Web Store Limited Use commitments

RepayIQ's use of user data obtained through the RepayIQ Partner Chrome Extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

  • We collect, use, and transmit extension user data only when reasonably necessary to provide the extension's disclosed single purpose or to maintain, secure, or measure the performance and reliability of functionality directly related to that purpose.
  • We do not use or transfer extension user data for personalized, retargeted, or interest-based advertising.
  • We do not transfer or sell extension user data to advertising platforms, data brokers, or information resellers.
  • We do not use, transfer, or sell extension user data to determine creditworthiness or for lending purposes.
  • We permit human access to specific user data only with explicit consent for support, when necessary for security or abuse prevention, to comply with law, or in aggregated and anonymized form for lawful internal operations.

Review the Chrome Web Store User Data Policy.

7. Retention and deletion

Extension authentication sessions are valid for 12 hours. The extension removes local session state on sign-out, when it detects an expired session, or when the server rejects the stored session as unauthorized. Removing the extension removes its Chrome-managed local storage. Server session records are configured to expire automatically, and password or account-status changes revoke active sessions.

Single-use account-invitation records are configured to expire after 72 hours. Raw quick-quote fields are processed to return the requested estimate and are not persisted as a quote record. Rate-limit counters are configured to expire after their security windows.

The application does not currently assign automatic expiration periods to partner-user account records or operational audit records. RepayIQ retains those records according to its account-administration, service-security, fraud-and-abuse prevention, and legal-compliance requirements. Users may contact support to request access, correction, or deletion, subject to those requirements.

8. Security

RepayIQ uses HTTPS for extension network traffic, allowlists production extension identifiers, limits access based on account status and permission scope, and applies rate limits and security headers. Passwords are protected with salted, one-way scrypt hashes and a server-side pepper, and server-side session records contain only cryptographic token hashes. Chrome's local extension storage is not encrypted by the extension; where Chrome supports it, access is restricted to trusted extension contexts. No security measure can eliminate every risk, but RepayIQ reviews and maintains safeguards appropriate to the information handled.

9. Your choices and requests

Users choose whether to sign in and submit quick-quote information. Declining to provide required information prevents the corresponding extension feature from working. Users can sign out to revoke the current session or remove the extension to clear its local Chrome storage.

The sponsoring partner organization may ask RepayIQ to change or suspend a user's access, and authorized RepayIQ administrators manage the account. To request access to, correction of, or deletion of RepayIQ-held extension information, contact RepayIQ support. RepayIQ evaluates requests under applicable law, contractual obligations, security requirements, and authorized account administration.

10. Children

The RepayIQ Partner Chrome Extension is intended solely for authorized professional users and is not directed to children under 13.

11. Changes to this policy

RepayIQ may update this policy as the extension, service providers, or legal requirements change. We will update the date above. Before introducing any new or different extension data practice, we will prominently disclose the change to affected users and obtain any required consent.

12. Contact us

Questions or privacy requests can be directed to:

Email: [email protected]

Phone: 855-301-5550

Support page: repayiq.org/support