MurmSpy — Privacy Policy
Last updated: 2 August 2026
MurmSpy is a browser extension for ecommerce store and product research, published by MurmTools. This policy explains what MurmSpy does and does not do with data.
The short version
- MurmSpy reads only public store data on pages you visit (or explicitly scan) — the same product listings, scripts and metadata any visitor's browser already loads.
- MurmSpy does not collect, transmit or sell your personal data. There is no MurmSpy account, no tracking SDK, and no analytics beacon. The one exception is buying Pro, which happens on ExtensionPay's own page — see Payments.
- Everything MurmSpy stores (saved shops, settings, local usage counters) lives in your browser's extension storage and never leaves your machine.
What MurmSpy processes
| Data | Where it goes | Why |
|---|---|---|
| Public storefront data (products.json, collection pages, sitemaps, page markup) of the store you're viewing | Fetched by the extension, cached briefly in extension session storage | To show store intel, best sellers and product lists |
| Your saved shops, UI preferences and daily export counter | chrome.storage on your device only |
Core functionality |
| Local feature-usage counters (e.g. "csv_export: 3") | chrome.storage on your device only; never transmitted |
To let us debug locally; no PII, no identifiers |
| An ordinary page request to murmtools.com when you install or remove MurmSpy | Installing opens a welcome page; removing opens a short feedback page, with the version number in the URL. Our web host sees these like any other visit to the site — an IP address and a browser user-agent. | Getting started, and finding out why people leave |
What MurmSpy never does
- MurmSpy never reads your browser history, and stores only the shops you chose to keep.
- No collection of names, emails, or any personal identifiers — except on the paid tier, where your email goes to ExtensionPay on their own page. See Payments below.
- No login-gated scraping, no automation of any website.
- No selling or sharing of data with third parties — there is nothing to sell.
- No lookups about the store you are viewing against any third-party service. Everything in the panel is computed on your machine from that store's own public pages. (Up to v0.6.0 one figure — a traffic rank — was fetched from a Google API; that feature was removed in v0.6.1 precisely because it did not match this page.)
Payments (Pro)
Pro subscriptions are processed by ExtensionPay (extensionpay.com) and Stripe. When you purchase Pro, you give your email address to ExtensionPay on ExtensionPay's own checkout page and your card details go to Stripe; both handle that data under their own privacy policies. MurmSpy only learns whether the current browser has an active license, and stores the anonymous licence key ExtensionPay issues for it. On the free tier you never provide an email. The licence check is the one request MurmSpy makes that is not to the store you are looking at. See extensionpay.com/privacy and stripe.com/privacy.
Permissions, explained
storage— save your shops, preferences and local counters.activeTab— when a Shopify store runs on its own domain rather than a myshopify.com address, clicking the MurmSpy toolbar icon grants access to that one tab for that one click. This is why MurmSpy does not ask for access to every site.scripting— injected into the tab you are viewing: automatically on a Shopify storefront, and on your click for custom-domain stores. It is used to put the panel on the page, and to read the page's own Shopify globals — the shop name, theme and currency the storefront itself defines — because a content script cannot otherwise see the page's own variables. It reads those values; it writes nothing to the page and injects no code from outside the extension package.- Host access to
*.myshopify.com— read that store's public pages, and show the overlay automatically where MurmSpy is designed to work. - Host access to
www.tiktok.comandshop.tiktok.com— TikTok Shop pages are navigated in-page and served from several URL shapes, so the grant cannot be narrowed to a path. The script classifies the URL itself: on anything that is not a TikTok Shop product or shop page it renders nothing and reads nothing. - Host access to
extensionpay.com— license checks and checkout.
Changes & contact
We'll update this page when anything changes and bump the date above. Questions: murm.marketing@gmail.com.