CoreTax Console — Privacy Policy
Your Smart Assistance for CoreTax
Effective: May 10, 2026
This Privacy Policy describes how the "CoreTax Console" Chrome extension ("Extension") collects, uses, and shares user data. By installing and using the Extension, you agree to the practices described herein.
1. Data We Collect
1.1 Session Data from CoreTax Website
The Extension reads the following data from your active CoreTax (coretax.pajak.go.id) browser session to enable its automation features:
- Access Token — extracted from your active session to authenticate API download requests on your behalf.
- Cookie — captured from the active tab to maintain session continuity during automated downloads.
- Taxpayer ID — read from the CoreTax page's own localStorage to identify your tax profile for API requests.
- X-DGT-Code — captured from intercepted HTTP headers to include in API download requests as required by CoreTax.
Important: This data is held in memory only during active jobs and is NEVER persisted to chrome.storage or transmitted to any external server. When the job completes or the Extension is closed, this data is discarded.
1.2 API Response Data
The Extension intercepts JSON API responses from CoreTax's list endpoints to enable its capture and download features. This data includes invoice numbers, document numbers, and taxpayer document details. This data is stored locally in chrome.storage.local and is never transmitted to any external server.
1.3 Extension Configuration
The following data is stored locally in chrome.storage.local or localStorage for Extension functionality:
- Settings (concurrency, retries, delay) — stored in
chrome.storage.local
- Job State (download progress, logs) — stored in
chrome.storage.local
- UI Preferences (selected method, source, technique) — stored in
localStorage
- Subscription Data (active status, token, expiry) — stored in
chrome.storage.local
- Device ID (random UUID, generated at install) — stored in
chrome.storage.local
2. Data We Transmit
2.1 To Our Payment Server
When you subscribe or donate, the following data is sent to fecttral.com/api/payment/extension:
- Device ID — a random UUID generated at install to identify your installation for payment verification.
- Subscription Token — sent only during verification to confirm your subscription is active.
- Payment Type & Amount — "subscription" or "donation" and the requested amount.
We do NOT send any CoreTax data (invoices, documents, taxpayer information, access tokens, or cookies) to our payment server or any other third party.
2.2 To CoreTax APIs
The Extension makes API requests to coretax.pajak.go.id using your own session credentials (access token, cookie) to download documents on your behalf. These are the same requests you would make manually — the Extension automates the process.
3. Data We Do NOT Collect
- We do NOT collect browsing history.
- We do NOT collect data from websites other than coretax.pajak.go.id.
- We do NOT collect personal information beyond what is needed for CoreTax automation and payment processing.
- We do NOT use your data for advertising.
- We do NOT sell, rent, or share your data with third parties for marketing purposes.
4. Passive Skills — Filter & Overlay Restoration
The Extension includes a passive checkpoint system that saves your current filter settings (year, period, invoice number) and visual overlay state (selected/processed rows, scroll position, pagination) into sessionStorage on the CoreTax page. When you navigate away and return to a list page (e.g., after editing a faktur), these checkpoints are automatically restored so you resume exactly where you left off — without losing your selection or having to re-apply filters.
This data exists only in sessionStorage (cleared when the tab closes) and is never transmitted externally.
5. Interstitial Ads
Free (non-subscribed) users will see a short video advertisement before starting download jobs. These ads are served from local video files bundled with the Extension — they do not contact any ad network, tracker, or external server. No personal data is collected or transmitted during ad playback.
6. Data Retention
- Session data (access token, cookie) — held in memory only, discarded when job ends or Extension closes.
- Job state & settings — stored locally until you clear Extension data or uninstall.
- Subscription data — stored locally until subscription expires or you clear Extension data.
- SessionStorage checkpoints — cleared automatically when the browser tab is closed.
- Payment records — retained on our server for payment verification; device ID is the only identifier.
7. Third-Party Services
- WebQRIS (webqris.com) — Payment gateway for QRIS transactions. Communication is server-to-server only; the Extension never contacts WebQRIS directly. WebQRIS's own privacy policy applies to data they process.
- Google Fonts — The Extension loads fonts from fonts.googleapis.com for UI rendering. Google's privacy policy applies to font loading requests.
8. Data Security
We implement reasonable security measures to protect your data:
- CoreTax session data is held in memory only, not persisted to disk.
- Payment server communication uses HTTPS encryption.
- Webhook signatures are verified using HMAC-SHA256.
- Spreadsheet cell values are sanitized to prevent formula injection attacks.
9. Your Rights
- You may clear all locally stored data at any time by uninstalling the Extension or clearing Extension data in Chrome settings.
- You may request deletion of your payment records by contacting us with your Device ID.
- Subscription can be cancelled at any time; no further charges will be made after the current period expires.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected on this page with an updated effective date. Continued use of the Extension after changes constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions or concerns, please contact the developer through the Chrome Web Store listing support channel.
Last updated: May 8, 2026