1. Overview and Scope
This Privacy Policy describes how Gorilla Software Sp. z o.o. ("Gorilla Software", "we", "us", "our") collects, uses, stores, and protects data when you use the GP Connect Chrome Extension (the "Extension") and related Gorilla Panel Connect services. We are committed to transparency and complying with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Google Chrome Web Store Developer Program Policies.
2. Single Purpose & Functionality
The single purpose of the GP Connect extension is to enable website administrators and clients to report requested changes, defect fixes, and development tasks directly from their browser while viewing their website, receive instant automated estimates, and order development work from Gorilla Software. The extension operates only when explicitly invoked by the user.
3. Chrome Extension Permissions & Justification
GP Connect requests only the minimum permissions required to provide its core functionality. This list corresponds exactly to the contents of manifest.json in this version of the Extension — we request no other permissions, and no optional permissions:
- storage: Saving draft task reports, local user settings and session state in your browser’s local storage.
- scripting: Injecting the visual element selector and annotation interface into the active page at the moment you choose to report an issue.
- tabs: Reading the URL and title of the active tab on which you create a report.
- notifications: Notifying you when a quote is ready or a ticket changes status.
- alarms: Periodically synchronising ticket statuses in the background without continuously consuming CPU.
- Host permissions (<all_urls>): The Extension is available on the websites you visit, because its purpose is to report changes on any client site and it cannot know in advance at which address a given site is located. It is not injected on the
clickup.com,stripe.comorsslip.iodomains. Apart from those exceptions we do not maintain a list of excluded domains — no data is collected until you open the Extension yourself and submit a report.
This version of the Extension does not record the screen or audio of a browser tab, does not use the microphone, and does not request any optional permissions — the list above is complete. If a recording feature is made available in future it will require a separate permission and separate consent, and this Policy will be updated beforehand.
4. Technical Diagnostics & Context Collected
To enable developers to replicate and resolve reported issues, submitting a Ticket bundles the following technical context:
- Screenshot and optional tab video recording of the selected area.
- URL, screen resolution, viewport size, browser version, and operating system.
- DOM element snippet corresponding to the annotated page area.
- Count of JavaScript console errors (count only; no stack traces or private log content).
- User-provided task descriptions and annotations.
5. Chrome Web Store User Data Policy Compliance
In strict adherence to Google Chrome Web Store Developer Policies:
- No Sale of Data: We never sell, rent, monetize, or trade your personal data or extension data to third parties.
- No Unrelated Data Transfers: Data is transferred solely to process change requests and provide technical services ordered by you.
- No Advertising or Credit Assessment: Data is never used for personalized ads, behavioral tracking, retargeting, or credit assessment.
- No Passive Browsing Tracking: The Extension does not track, collect, or record your browsing history. Data capture occurs strictly upon manual submission.
6. Legal Basis for Processing (GDPR)
We process personal data in accordance with Article 6(1) of the GDPR:
- Art. 6(1)(b) GDPR: Necessary for the performance of a contract or to take steps at the user's request prior to entering into a contract (estimating quotes, delivering technical fixes).
- Art. 6(1)(c) GDPR: Compliance with legal and tax obligations (invoicing, accounting retention).
- Art. 6(1)(f) GDPR: Legitimate interests of the controller (system security, abuse prevention, assertion of legal claims).
7. Data Recipients & Processors
Data may be processed by trusted subcontractors bound by GDPR Data Processing Agreements:
- Hosting and server infrastructure providers within the European Economic Area (EEA).
- Authorized payment operators (Tpay / Krajowy Integrator Płatności S.A., Wise) for payment processing.
- Invoicing and accounting systems (e.g., Fakturownia.pl).
- Internal project task management (ClickUp) under strict confidentiality.
8. Data Retention & Deletion
Draft tickets in local browser storage remain until cleared by the user or submitted. Technical context attached to orders is retained for the duration of the service plus 3 years for warranty and dispute handling. Invoices and tax records are retained for 5 years following the relevant tax year. Account data is retained until account termination or verified deletion request.
9. Security Measures
All communication between the Extension and Gorilla Panel servers is encrypted with TLS 1.2/1.3. Access to customer code, screenshots, and server logs is restricted to authorized personnel under strict non-disclosure obligations. Regular vulnerability assessments and backups are maintained.
10. Your GDPR Rights
Under the GDPR, you have the right to request access to, rectification of, or erasure of your personal data, restriction of processing, data portability, and the right to object to processing. You also have the right to lodge a complaint with a supervisory authority (in Poland: Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl).
11. Controller & Contact Information
The data controller is Gorilla Software Sp. z o.o., ul. Jana i Jędrzeja Śniadeckich 20D/7, 35-006 Rzeszów, Poland, KRS 0000890717, REGON 388472110, NIP 8133856997.
Contact email: [email protected] | Phone: +48 789 022 921.