Clear by default
A short, human privacy summary.
Coupon checking handles checkout context locally in your browser and returns quote fields only to the regional SHEIN site you are already using. Aggregate usage analytics, per-code reliability reporting, and email updates are separate and optional.
On-device coupon checking
Checkout context stays with your browser and SHEIN
After you start a coupon check, the extension temporarily reads the current SHEIN checkout page and in-page checkout state. That local state can include coupon controls, applied-code state, checkout and cart context, payable totals, country, postcode, and quote, mall, shipping, payment-method, or product identifiers already held by SHEIN.
The extension validates and uses only the fields needed to build coupon quote requests. Those quote fields are sent only to a same-origin SHEIN coupon endpoint on the regional domain open in your browser. The checkout snapshot, quote fields, coupon text, totals, cart or product details, addresses, and payment details are not sent to api.gilcoupons.com, retained by GilCoupons, or included in analytics or optional reliability reports.
After you start a coupon check, the extension also asks api.gilcoupons.com for ranked coupon candidates. That core request contains only the coarse SHEIN market and requested candidate limit. It contains no analytics identifier or checkout details.
Optional aggregate analytics
Off until you choose to share
Before you enable aggregate analytics in extension settings, the extension does not generate an analytics installation ID or create, queue, or send an aggregate event. If you opt in, GilCoupons may receive:
- Pseudonymous analytics ID The random ID stays in Chrome storage; only its one-way SHA-256 hash is sent.
- Lifecycle events Install, update, heartbeat, coupon run, and coupon success.
- Basic environment Interface language, platform category, and SHEIN market.
- Aggregate coupon activity Run and success events without a coupon ID, code text, cart value, or checkout total.
Exact fields in each optional aggregate event
A random event ID; event type; one-way installation hash; event time; extension version; coarse language and platform; and, when available, the two-letter or GLOBAL SHEIN market.
These events support reported opt-in install counts, active-install estimates, and performance and reliability measurement for the coupon-testing feature.
You can turn aggregate analytics off again at any time. Turning it off deletes the local analytics identifier and queued aggregate events. This choice is separate from per-code reliability reporting.
Separate and optional
Per-code reliability reporting is off by default
If you separately enable “Share per-code reliability results” in extension settings, a report helps identify working and dead coupon records. You may enable either optional choice, both, or neither.
It contains coupon ID, market, success/failure/error result, extension version, selector version, observed time, and a random idempotency key. It does not contain the installation hash, coupon text, cart, products, account, or checkout total.
Retention and network privacy
Raw events expire; a minimal aggregate remains
Raw optional aggregate analytics event rows are retained for up to 365 days. Raw optional per-code outcome events and ranking-signal buckets are retained for up to 30 days under the current service configuration.
For shoppers who opt in, a minimal installation aggregate is retained for historical reported-install and active-install counts. It contains the installation hash, first installation and activity times, last activity time, and the latest coarse version, language, platform, and market. Turning analytics off stops future events but does not retroactively delete server aggregates.
Access logging is disabled for the optional analytics and per-code outcome routes; the analytics route also strips forwarded client-address headers. The outcome service can use an IP address transiently in memory for abuse control. Core ranked-candidate requests and the first-install welcome page can create standard HTTPS access logs containing network metadata such as IP address, time, request path/query, response status, and user agent. Those logs are used only for service delivery, security, and abuse prevention and are retained for up to 14 days. No IP address is stored in the analytics database or per-code outcome database.
Optional uninstall feedback
Feedback is saved only when you submit it
The uninstall form stores the reason you select, the message you write, your chosen site language, and the submission time for up to 180 days. It does not ask for an email address. An IP address may be used transiently in memory to limit abuse, but it is not stored with the feedback. Do not include checkout, order, address, password, or payment information.
Optional email updates
Your email is used only after you ask to subscribe
After a coupon check ends with verified savings applied, the extension may show an optional invitation to receive occasional SHEIN coupon updates from GilCoupons. If you enter an email address and select “Email me coupon updates,” the extension sends only that address, your base interface language, the fixed source “extension-first-success,” and the consent-notice version to api.gilcoupons.com. Coupon checking works without subscribing, and dismissing the invitation does not send an email address.
Signup uses single opt-in. Selecting “Email me coupon updates” activates the subscription immediately. GilCoupons sends a subscribed welcome email with an unsubscribe link; you do not need to click a confirmation link. The extension does not read a Chrome or SHEIN account email and does not store the address locally.
Newsletter requests use HTTPS. api.gilcoupons.com acts only as a stateless gateway for the extension request. The subscriber record is stored in the access-controlled GilCoupons Cloudflare D1 subscriber database used by gilcoupons.com/admin. Resend processes the address to deliver the subscribed welcome notice and the coupon newsletters you requested.
An active email address is retained while the subscription remains active. Every newsletter includes an unsubscribe link. After unsubscribe, GilCoupons retains the address and minimal consent, source, language, status, and timestamp records only as needed to suppress future sends and document consent, unless you request deletion. Contact support to request deletion of the associated newsletter record.
The email address is not linked to an analytics installation ID, coupon result, SHEIN market, cart, products, page URL, checkout total, savings, address, account, or payment information. It is not sold, used for personalized advertising, or used for credit or lending decisions.
Not sent to GilCoupons
Checkout details do not go to GilCoupons
The extension's coupon and analytics APIs do not receive or retain:
- Names, phone numbers, or account credentials. An email address is received only through the separate, voluntary newsletter signup described above.
- Shipping addresses, payment-card details, or bank-account information.
- Cart contents, product names, coupon text, payable totals, or savings amounts.
- SHEIN page URLs, general browsing history, or activity outside supported SHEIN pages.
Your control
Simple boundaries
Coupon checks run only after you select the extension action at checkout. Aggregate usage analytics and per-code reliability reporting have separate, default-off controls. Before aggregate opt-in, no analytics identifier or aggregate event is created. You can turn either choice off, disable the extension, or remove it at any time.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Questions
Ask us directly
For privacy questions or a request concerning optional analytics or newsletter data, contact support. For extension questions, include the version shown on Chrome’s Details page; for a newsletter request, contact us from the subscribed address so we can locate the correct record.