Privacy Policy
1. Purpose
iFlow Transport Assistant helps an authorized SAP Cloud Integration user create or update a renamed iFlow copy within the tenant where the user is already signed in.
2. Data handled
The extension processes only the information required to perform the transport workflow selected by the user:
- Website content: SAP tenant package and artifact metadata, source and target technical IDs, versions, internal identifiers, the source iFlow ZIP in browser memory, response status and diagnostic request references.
- Web history: the currently open supported SAP tenant URL is inspected to identify the active package and iFlow context. General browsing history is not collected or retained.
- Authentication information: the browser uses the user's existing SAP session and the extension temporarily handles CPI CSRF tokens for user-confirmed requests. Passwords and session-cookie values are not read or stored.
3. Local browser storage
Chrome local storage is used for up to ten recent non-sensitive operation summaries, launcher and popup positions, theme preference, suffix preference and dry-run/execute preference. Operation history contains result, action, technical IDs, target package ID and timestamp.
Local storage does not contain passwords, session cookies, OAuth secrets, service keys, CSRF tokens or iFlow ZIP content. Users can remove operation summaries with Clear history.
4. Data transmission
The extension sends HTTPS requests only to the SAP tenant origin currently selected by the user and only to provide the visible transport workflow. It does not send tenant data to the publisher, analytics providers, advertising networks or other external services.
5. Retention
- CPI metadata, CSRF tokens and ZIP content are processed transiently and are not retained after the active operation.
- Local preferences and operation summaries remain until the user clears them or removes the extension.
- SAP may retain requests and content according to the tenant owner's SAP configuration and policies.
6. Sharing, sale and advertising
The publisher does not sell, rent or share data processed by the extension. Data is not used for advertising, credit decisions, profiling or purposes unrelated to the extension's transport-assistance function.
7. Security
- Manifest V3 with no remotely executed code.
- Same-tenant HTTPS requests using the active browser session.
- No password, session-cookie or service-key storage.
- Short-lived CSRF tokens used only for the current operation.
- Dry-run validation and explicit confirmation before changes.
- Diagnostic output excludes cookies and CSRF tokens.
8. User control
Users control when the assistant opens, which source and target values are used, whether an operation is a dry run or execution, and whether a prepared execution is confirmed. The extension performs no background transport activity.
9. Limited-use statement
Information received from Chrome APIs and the SAP tenant is used only to provide or improve the extension's disclosed single purpose. The publisher does not transfer this information except when necessary to provide the user-requested function, comply with applicable law or address security abuse. Information is not used for personalized advertising, and humans do not read it except with the user's explicit consent for support or when required for security or legal reasons.
10. Changes
Material changes to data handling will be reflected in this policy and the Chrome Web Store privacy disclosures before the corresponding extension update is published.
11. Contact
For privacy, security or support questions, contact umesh8019@gmail.com.
12. Trademark notice
iFlow Transport Assistant is an independent utility and is not affiliated with or endorsed by SAP SE. SAP, SAP Integration Suite and SAP Cloud Integration are trademarks or registered trademarks of SAP SE or its affiliates.