Auto-Postback — Privacy Policy
Last updated: 28 August 2026
Auto-Postback (“the extension”) is published by Aff Labs. This policy describes every piece of data the extension touches, why it touches it, and where it goes.
The short version: the extension has no server. Nothing it reads is transmitted to us, to an analytics service, or to any third party. Everything happens between two tabs in the partner’s own browser.
What the extension handles
1. Website content
The extension reads the page on a tab in exactly two situations, both begun by the partner.
In the affiliate cabinet (pocketpartners.com,
gamechange.partners, and their subdomains) it reads the postback creation form: the
form’s address, its CSRF token, the list of campaigns on the account, and the campaign link
shown in the page’s link preview. These are the fields a person would otherwise fill in and
submit by hand on that same screen.
On a tracker tab it reads two things, and only after the partner has told the wizard which tracker they use: the address in the browser’s address bar, and the tracker’s postback key. The key is taken from the page’s own configuration object; if it is not there, the visible text of the page is searched for a postback receiver address already displayed on it. Before the partner has named their tracker, no page is inspected at all.
Nothing is read on any tab the partner has not clicked the extension’s icon on.
2. Authentication information
The tracker’s postback key — the secret segment of the tracker’s receiver address — is stored in the browser’s local extension storage so the wizard can compose postback URLs from it. It is written into the postback URLs created in the partner’s own affiliate cabinet, which is its purpose. It is sent nowhere else.
Where the tracker keeps an API key alongside the postback key in the same configuration object, the extension does not read it. The postback key is matched specifically and the API key is excluded.
3. Configuration the partner enters
The tracker choice, a receiver address typed by hand, Postback Bot links pasted into the wizard, the selected conversion events, and the campaign selection. Held in local extension storage so that moving between the tracker tab and the cabinet tab does not lose the partner’s place.
4. The cabinet session
Requests the extension sends to the affiliate cabinet carry the browser’s existing cookies for that site, exactly as the cabinet’s own form does when the SAVE button is pressed. The extension does not read, copy, store or transmit the cookie itself; the browser attaches it.
Where the data goes
Nowhere outside the partner’s browser, with one exception: the affiliate cabinet the partner is already logged into. The two requests the extension makes go to that cabinet, on the same origin as the tab the partner has open, and they are the requests the cabinet’s own form already makes.
The extension contacts no server operated by us. It contains no analytics, no telemetry, no crash reporting, no advertising code and no third-party SDK of any kind. It loads no remotely hosted code: every line it runs ships inside the package.
Setup marker
Every postback URL the extension composes carries a fixed parameter,
pp_ref=ext-kt-v1. It is a constant. It contains no information about the partner,
their account, their browser or their traffic, and its only use is to count how many postback
setups were made with the extension rather than by hand. Every URL is shown in full on the
review screen before anything is created, this parameter included.
Retention and deletion
Everything named above lives in the browser’s local extension storage, on the partner’s own device. It is erased when the partner presses the restart control (↺) in the wizard, when they close the panel, or when the extension is uninstalled. We hold no copy, because we never receive one.
What we do not do
- We do not sell or transfer this data to third parties.
- We do not use it for advertising, retargeting, or interest-based profiling.
- We do not use it to determine creditworthiness or for lending purposes.
- We do not use it for any purpose other than setting up postbacks, which is the extension’s single purpose.
- No person at Aff Labs reads this data. We have no mechanism by which we could.
Changes
If the extension’s data handling ever changes, this policy is updated before the change ships and the change is described in the extension’s store listing.