Privacy Policy — DispatchTrack Order Assist
How the DispatchTrack Order Assist browser extension handles your information: what it sends, where it sends it, what is kept on your device, and what it never does.
- Effective date
- September 24, 2026
- Publisher
- DispatchTrack LLC, 900 E Hamilton Ave, Suite 201, Campbell, CA 95008
- Contact
- support@dispatchtrack.com
What the extension does
DispatchTrack Order Assist (“the Extension”) recognises an order number on a page you are viewing — or one you select yourself — and shows that order’s delivery status from your own DispatchTrack account. It runs in your Chrome browser.
There is no Order Assist server. The Extension talks to the DispatchTrack instance you sign in to, and — only if you switch on AI-assisted detection — to DispatchTrack’s order-extraction service, which passes that page text to OpenAI to read. Apart from OpenAI in that one case, there is no other destination.
Information the Extension handles
Your sign-in details
Your DispatchTrack instance URL, activation code, email address and password. The password is sent to your own DispatchTrack instance to obtain a session token.
It is kept on your device only if you leave Stay signed in ticked when signing in from the side panel, or enter a password in the Extension’s Settings — so it can sign you back in when your session expires without prompting you again. Where it is kept, it is stored encrypted (AES-GCM, with a key held only in that browser profile), is still sent only to your own DispatchTrack instance, is never displayed back to you, and is removed by Forget password in Settings or by clearing the sign-in there.
DispatchTrack sign-ins you have used on this browser
The instance URL, activation code, email address and business name of recent sign-ins, kept on your device so the Extension can offer them back instead of asking you to type them again. No password is ever part of this list. Clearing the sign-in details in Settings removes it.
Your session token
The short-lived token your DispatchTrack instance returns, held on your device so the Extension can make lookups on your behalf. If you already have a DispatchTrack tab open and signed in, the Extension uses that session and no separate sign-in is needed.
Order numbers, and the delivery details returned for them
The order number the Extension recognises, or that you select, is sent to your DispatchTrack instance to perform the lookup. What comes back may include the recipient’s name, delivery address, phone number and email address; the delivery window, current status and scheduled date; the items on the order; a record of the notifications sent to that recipient — that a text message, email or call was made, what kind it was and when, and for an email its subject line; and any delivery notes recorded against the order. It is displayed in the side panel for you to read and is not stored by the Extension.
A random identifier for this installation
A value with no meaning outside the Extension, created when you install it. It is used only to attribute a recognition rule you choose to record to the browser it came from, so DispatchTrack can tell one contributor’s rules from another’s. It says nothing about you: who recorded a rule is taken from the DispatchTrack account you are signed in to, not from this value.
Settings
Which response fields the panel displays, and the order-recognition rules the Extension loads from your DispatchTrack instance.
Recording how a page shows its orders
Only when you ask
The Extension recognises order numbers using rules DispatchTrack maintains centrally. When it meets a page those rules do not cover, you can teach it: the side panel offers “Remember how this page shows orders”, and the Settings page lets you add a rule by hand.
Only those two actions send anything. Nothing is recorded as you browse.
When you do use them, the Extension sends to your own DispatchTrack instance:
- the address of the page, with its query string removed — so …/orders/list?customer=Acme&id=91 is recorded as …/orders/list, because that is the part describing the page’s shape and the rest is usually about one specific record or person;
- one example of the order number on it, which is what makes the rule checkable;
- how the number was found — the label text beside it, or the position it sat in;
- the random installation identifier described above.
Your DispatchTrack instance records who sent it, from the account you are signed in to. DispatchTrack support staff can see these entries, in order to build better recognition rules for everyone. They are not published, sold, or shared outside DispatchTrack.
If a page’s address is itself sensitive in your organisation — an internal system whose URL you would not paste into a support ticket — do not use “Remember how this page shows orders” on it. Everything else the Extension does works without it.
AI-assisted detection
Off until you switch it on
When the Extension cannot recognise an order number on a page from its existing rules — and only if you have turned this on yourself — the visible text of that page is sent to DispatchTrack’s order-extraction service, which asks OpenAI (a third-party large-language-model provider) to identify the order number in it. The result is used to look the order up, and to improve the recognition rules so the same page shape is handled without a model call next time.
It is off until you turn it on. The setting lives in the Extension’s own Settings page and starts off. While it is off — the state the Extension ships in — no page content leaves your browser.
Where it goes. Unlike an order lookup, which goes only to your own DispatchTrack instance, this request goes from your browser directly to DispatchTrack’s extraction service over HTTPS. It is authorised with your DispatchTrack session, so it is only ever made on behalf of a signed-in user, and it carries the page text and the page address — nothing else.
Who processes it. DispatchTrack’s extraction service passes the page text to OpenAI, which runs the model that identifies the order number. OpenAI acts as a subprocessor for this feature and for no other part of the Extension.
What is kept. The page text is used to answer that one request and is not retained by DispatchTrack. OpenAI processes it as a subprocessor under its own API terms, which govern how long it is held and whether it may be used to improve its models.
How that information is used
- Sign-in details are used only to authenticate to your own DispatchTrack instance.
- Order numbers and delivery details are used only to show you the status of the order you asked about. Delivery details are not stored by the Extension beyond the lookup you are looking at.
- Settings and rules are used to recognise order numbers and decide what the panel shows.
- Recorded page shapes are used to improve order recognition for DispatchTrack customers generally.
Where information is stored
Settings, cached recognition rules, saved sign-in details, the session token and — if you chose to save one — your encrypted password are stored in your browser profile on your device, using Chrome’s extension storage. Clearing the Extension’s data, or removing the Extension, removes them.
What the Extension does not do
- It sends your data to one third party, and only in one case: if you switch on AI-assisted detection, the page text goes to DispatchTrack’s order-extraction service and on to OpenAI to be read. Otherwise it talks only to your own DispatchTrack instance.
- It does not track your browsing, collect analytics, or record which pages you visit.
- It does not read pages in the background for any purpose other than recognising an order number on the page you have open.
- It does not sell or share personal information, and does not use it for advertising, credit, or lending decisions.
Permissions, and why each is needed
- Access to the pages you visit (http://*/*, https://*/*) — an order number can appear in any system you work in, so the Extension must be able to recognise one on the page you are viewing. It reads the current page only to find an order-number-shaped value.
- Storage — to keep the settings, recognition rules, saved sign-in details, session token and encrypted password described above on your device.
- Side panel — the Extension’s user interface.
- Notifications — for one message: that the Extension has found the DispatchTrack sign-in already open in your browser and needs your password to finish setting up. It carries no order or customer information, and nothing else raises a notification.
Data retention and deletion
The Extension keeps nothing on a server of its own. To avoid repeating identical work, your own DispatchTrack instance may hold the assembled result of a lookup briefly (up to 30 minutes) so that asking for the same order twice does not rebuild it; that copy lives inside your own DispatchTrack account and is replaced whenever the order changes. Data held in your browser profile is removed when you clear the Extension’s storage or uninstall it. Data held in your DispatchTrack account — including recorded page shapes — is governed by DispatchTrack’s own privacy policy and your organisation’s agreement with DispatchTrack.
Children
The Extension is a business tool and is not directed at children.
Changes to this policy
Material changes will be reflected here with a new effective date, and — where a change affects what data leaves your browser — in the Extension’s own disclosure before the change takes effect.
Contact
support@dispatchtrack.com · DispatchTrack LLC, 900 E Hamilton Ave, Suite 201, Campbell, CA 95008