Scope and single purpose
This Privacy Policy applies to AuditFlow Runner, the AuditFlow browser extension published by Inovotech Jamaica, and the AuditFlow controller with which a user deliberately pairs the extension.
AuditFlow Runner has one purpose: to guide authorized users through predefined browser-based acceptance tests, record structured test outcomes and user-authorized evidence, and send those results to the paired AuditFlow controller for audit trails and standardized reports.
The extension is not an advertising, analytics, browsing-history or general monitoring product.
Data we handle
Depending on the test configured by your organization, AuditFlow may handle the following categories:
Identifiers
A randomly generated extension identifier, tester name, workspace, project name, project code or other record reference entered for the test.
Authentication data
The controller address, pairing code, temporary run token and, when expressly configured by an authorized workspace administrator, login username and password used to access the application under test.
Website and navigation data
The allowed target URL, page title, route, visible headings and landmarks, and metadata describing the page controls used during the test.
Test activity and evidence
Authorized clicks or form-change descriptions, expected and actual results, status, tester notes, defect references, timestamps and visible-page screenshots captured as evidence.
Local preferences
The AuditFlow controller URL and the on-screen position of the movable AuditFlow panel.
AuditFlow does not intentionally collect payment-card information, health information, precise location, advertising identifiers or unrelated browsing history. Password-field values are redacted from recorded events and screenshots are captured with the AuditFlow controller hidden.
How data is collected
- The user enters an AuditFlow controller URL and pairing code to connect a specific authorized run.
- The paired controller supplies the test definition, permitted target origins, expected results and any authorized target configuration.
- The extension content script is packaged for HTTP and HTTPS pages, but it remains inactive unless a run is paired and the current page origin matches an origin authorized for that run.
- Test outcomes, notes and defect information are entered by the tester.
- Visible-page screenshots are captured when the tester records an assessment or requests evidence capture as part of the active test.
How data is used
AuditFlow uses the data solely to:
- pair the extension with the test selected by the user;
- display guided instructions and identify configured controls on the authorized application;
- record test results, evidence and audit timestamps;
- maintain execution progress and prevent results from being recorded against an unrelated site;
- generate authorized Word, Excel and on-screen testing reports; and
- maintain, secure and troubleshoot AuditFlow's testing functionality.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Storage, retention and deletion
The controller URL, extension identifier and panel position remain in Chrome local storage until the user clears extension data or removes the extension. Pairing tokens, run details and progress are held in Chrome session storage and are cleared when the user disconnects the run, clears extension data or the applicable browser session ends.
Evidence and reports sent to the controller are retained according to the customer's testing, audit and records-management requirements. Users may request correction or deletion through their AuditFlow workspace administrator or by contacting Inovotech. Some records may be retained where required for security, legal or contractual audit obligations.
Security safeguards
Production controller communications use HTTPS. AuditFlow uses workspace isolation, scoped run tokens and allowed-origin checks. Credentials stored by the controller are encrypted at rest, password values are excluded from recorded events, and the extension panel is hidden while evidence screenshots are taken.
Users should pause or disconnect AuditFlow before entering information unrelated to the authorized test. No method of transmission or storage is completely secure, but Inovotech applies safeguards designed to reduce unauthorized access, disclosure and misuse.
User choices and controls
- AuditFlow does not start a test until the user pairs a specific run.
- The tester can pause the extension, decline an assessment, disconnect a run or uninstall the extension.
- Users can clear locally stored extension information through Chrome's extension settings.
- Test evidence can be reviewed through the paired AuditFlow workspace.
- Requests concerning access, correction, deletion or retention should be sent to the workspace administrator or Inovotech.
Children's privacy
AuditFlow is a business testing tool and is not directed to children. Inovotech does not knowingly use AuditFlow to collect personal information from children.
Changes to this policy
We may update this policy when AuditFlow's features, data practices or legal obligations change. The revised effective date will appear at the top of this page. Material changes to extension data practices will also be disclosed through the product or its Chrome Web Store listing as required.
Contact us
Questions, privacy requests or concerns about AuditFlow can be directed to:
Inovotech JamaicaEmail: info@inovotechjm.com
Website: www.inovotechjm.com