This disclosure describes what the Kwashly browser extension does on your device, which permissions it requests and why, and what leaves the device. It is written to satisfy the Chrome Web Store user data policy, including the Limited Use requirements, and the equivalent review policies for Microsoft Edge Add-ons, Firefox Add-ons and Safari extensions. It supplements our Privacy Policy; on extension specifics, this page governs.
1. What the extension does
Kwashly is a travel laundry finder. While you are booking a stay or a flight on a supported site, the extension reads the destination and the trip dates from the page and shows a small panel with laundry options for that trip — for example “7-night stay: hotel laundry from $8/kg, pickup laundry nearby from $3/kg” or “Pack lighter: book mid-trip laundry instead of a second bag”. Nothing is booked from the panel automatically; opening a booking takes you to kwashly.com, where you sign in and confirm.
2. Permission-by-permission justification
| Permission | Why it is requested | What it does not allow |
|---|---|---|
| activeTab | Lets the extension read the destination and dates from the page you are looking at when you open the Kwashly panel or when a supported booking page is detected in that tab | No access to other tabs, no background scanning of tabs you are not using, no browsing history |
| storage | Saves your trips, your currency and unit preferences, whether the pack-lighter prompt is shown, and a short-lived wallet token so your loyalty balance can be displayed | Not readable by the websites you visit; not synced to any third party; no advertising identifiers |
| Host permissions: booking.com, agoda.com, airbnb.com, expedia.com, hotels.com, ryanair.com, easyjet.com, kayak.com, skyscanner.net | The content script must run on these specific booking and airline domains to find the destination, the locality and the check-in and check-out dates in the page markup, which differs from site to site | No wildcard access to all sites, no banking, email, government or corporate domains, no injection of content into pages outside this list |
We do not request tabs, history, cookies, webRequest, bookmarks, downloads, clipboardRead, geolocation or nativeMessaging. If a future version needs a new permission, the browser will ask you to approve it and we will publish the reason here before the release.
3. Exactly what is read from the page
On a supported page, the content script extracts at most four values:
- Destination city — for example “Lisbon” or “Bangkok”.
- Property or airport locality — the neighborhood or airport code shown for the stay or flight, used to find nearby partner laundries and estimate pickup distance.
- Check-in and check-out dates, or outbound and return dates, used to calculate trip length and the laundry slots that fit inside it.
- Baggage add-on price, only when the page displays one, used to compare the cost of a second bag with the cost of a mid-trip wash.
4. What is transmitted, and what never leaves your device
The four values above are sent over TLS to Kwashly’s API (hosted in the EU, Frankfurt) to price laundry options. Extension requests are not tied to your account unless you are signed in; when you are, the trip is saved to your account.
The following never leaves your device: your name, address and contact details as typed on the booking site; payment card or bank details; booking references; loyalty or frequent-flyer numbers; passenger or guest names; search queries; page screenshots or HTML; and your browsing history. The extension cannot read a page outside the supported domain list, so data from such pages cannot be collected even in error.
5. Commitments
- We do not sell or rent personal data, and we never transfer it to data brokers, advertising networks or credit scoring services.
- The extension shows no advertisements and injects no sponsored content into the pages you visit.
- The extension contains no third-party tracking pixels, advertising SDKs, session-replay libraries or fingerprinting code.
- Extension analytics are limited to anonymous, aggregated counts of panel opens and errors, and are off unless you opt in from the extension settings.
- We do not modify, redirect or rewrite any booking, price or affiliate link on the page you are viewing.
- All extension code is first-party and bundled with the release; no code is fetched and executed at runtime.
6. Limited Use compliance statement
Kwashly’s use of information received from the extension complies with the Chrome Web Store Limited Use requirements. Specifically: (a) data is used only to provide and improve the trip laundry features that are user-facing and described in this disclosure; (b) data is not transferred to third parties except to subprocessors acting on our instructions, where required by law, or as necessary to complete a laundry booking you request; (c) data is not used or transferred for advertising, including retargeting or personalized advertising; (d) data is not used to determine creditworthiness or for lending purposes; and (e) no human reads the data, except with your explicit consent for a support request you have raised, where it is necessary for security or to comply with law, or on aggregated, de-identified data for operational reporting.
7. Storage, retention and deletion
Trip data read from a booking page is kept for the request and, if you save the trip, stored with your account. Unsaved trip lookups are discarded from our systems within 24 hours. Saved trips are kept for 24 months after the trip end date, or until you delete them.
How to uninstall and delete your data
- Chrome and Edge: right-click the Kwashly icon in the toolbar and choose “Remove from Chrome” or “Remove from Microsoft Edge”.
- Firefox: open the add-ons manager, find Kwashly and choose “Remove”.
- Safari: Settings → Extensions, deselect Kwashly, then delete the containing app.
Uninstalling deletes the extension’s local storage, including saved trips held on the device and the wallet token. To delete data held in your Kwashly account as well, sign in and use Settings → Privacy → Delete account, or email [email protected]; we complete deletion within 30 days. Signing out of the extension clears the wallet token immediately.
8. Enterprise and managed deployment
Kwashly Teams customers can deploy the extension by policy through Chrome Enterprise, Microsoft Intune or Jamf. Managed installations support three administrator settings, independent of any user setting: a domain allowlist that can be narrowed below our default list; a switch that disables the wallet token so no credential is stored on managed devices; and a switch that turns extension analytics off permanently. The extension makes no outbound connection other than to api.kwashly.com, so it can be allowlisted at the network boundary. A data processing agreement and our security overview are available to Teams administrators from [email protected].
9. Children
The extension is not directed at children and is intended for travelers aged 16 and over.
10. Changes and contact
We update this disclosure whenever the extension’s permissions, the supported domain list or the data it transmits changes, and we raise the version number at the top of the page. Questions, security reports and data requests: [email protected], or our Data Protection Officer at [email protected] (Marta Vieira). Postal address: Kwashly Labs, Lda., Rua da Prata 12, 2.º andar, 1100-052 Lisbon, Portugal. See also our Cookie Policy, Terms of Service and contact page.