MSM Core

Browser Extension Privacy Policy

MSM Distribution
Last updated: August 11, 2026

1. Scope of This Policy

This Browser Extension Privacy Policy explains how MSM Distribution accesses, uses, stores, protects, and discloses information in connection with browser extensions developed, maintained, distributed, or operated by MSM Distribution.

This policy supplements our Privacy Policy and Terms of Use.

This policy applies to browser extensions published or distributed by MSM Distribution, including the MSM Cin7 POS Toolkit and MSM Cin7 UI. It also applies to future updates, maintenance releases, replacement versions, and related internal browser-extension functionality unless a separate policy expressly applies.

These extensions are intended solely for authorized employees, contractors, administrators, and other personnel approved by MSM Distribution. They are designed for internal business use with authorized Cin7 POS and MSM Distribution systems and are not intended for general consumer use.

2. Purpose of the Extensions

MSM Distribution browser extensions are designed to enhance approved business workflows within Cin7 POS and related internal systems. Depending on the extension and supported page, functionality may include:

  • Displaying product intelligence and product metadata
  • Displaying cost, price, margin, and pricing context
  • Displaying customer purchase and sales history
  • Supporting controlled product-data refresh operations
  • Improving navigation between Cin7 POS workflows
  • Assisting with check-payment attachment workflows
  • Highlighting the applicable order or transaction within supported Cin7 pages
  • Connecting authorized users to secure MSM Distribution API services

The extensions are intended to improve internal accuracy, efficiency, operational visibility, and workflow consistency. They do not independently authorize business transactions, modify Cin7 permissions, replace Cin7 controls, or provide access beyond that granted through the user's authorized business accounts and MSM Distribution systems.

3. Information the Extensions May Access

When an authorized user accesses supported Cin7 POS pages, the extensions may read limited information already displayed or made available within those pages. Depending on the extension and workflow, this may include:

  • Product names, identifiers, item numbers, SKUs, and barcodes
  • Product pricing, cost, average cost, and margin information
  • Inventory and product metadata
  • Customer identifiers and customer-related sales history
  • Receipt numbers, sale identifiers, order numbers, and payment information displayed within Cin7 POS
  • Payment type, payment amount, and payment date when needed for an authorized workflow
  • Page state, selected records, and interface information needed to render or operate extension features

The extensions access this information only when necessary to perform their stated internal business functions. Access is limited to supported Cin7 POS pages and approved MSM Distribution services.

4. Information the Extensions Do Not Collect

MSM Distribution browser extensions are not designed to collect or monitor general browser activity. The extensions do not intentionally collect, record, sell, or use the following for advertising, profiling, or unrelated purposes:

  • General browsing history
  • Browsing activity outside supported Cin7 POS and MSM Distribution pages
  • Search history
  • Passwords or credentials entered into unrelated websites
  • Keystrokes outside extension-specific configuration fields
  • Private messages, email content, or unrelated communications
  • Advertising identifiers or behavioral advertising data
  • Cross-site tracking data
  • Location, biometric, or health information
  • Consumer payment-card information
  • Analytics data used for advertising or marketing

The extensions do not inject advertising, display sponsored content, or participate in advertising networks.

5. Browser Storage

The extensions may use browser-provided storage to retain operational settings required for authorized use. Stored values may include:

  • Selected environment or API endpoint
  • Authentication token used to connect to authorized MSM Distribution services
  • Connection settings and user preferences
  • Temporary workflow state needed to continue an authorized action between supported Cin7 POS pages

Browser storage is used only for extension functionality. Business records retrieved from MSM Distribution systems are not intended to be permanently stored in the browser. Authorized users must not share extension configuration values, authentication tokens, or browser profiles with unauthorized persons.

6. Network Communication

Depending on the extension, network communication may occur with authorized Cin7 POS pages and services and with MSM Distribution services hosted through MSM Core.

The MSM Cin7 POS Toolkit communicates with authenticated MSM Distribution API endpoints to retrieve approved product and sales information and to perform controlled product-data refresh actions. The MSM Cin7 UI extension primarily operates within supported Cin7 POS pages to provide workflow and interface enhancements.

MSM Distribution does not use third-party advertising networks, unrelated analytics services, or data brokers within these extensions.

7. Browser Permissions

The extensions request only the browser permissions reasonably necessary to perform their intended internal functions. Depending on the extension, requested permissions may include:

  • Storage: Used to retain extension configuration, authentication tokens, connection settings, and limited workflow state.
  • Host Access: Restricted to supported Cin7 POS pages, MSM Distribution services, and local development environments when explicitly enabled by an authorized administrator.
  • Content Script Access: Used to read supported page state and render approved user-interface enhancements within Cin7 POS.
  • Background Processing: Used to route extension messages, perform authenticated API requests, and coordinate approved extension functions.

Permissions are not used to monitor unrelated websites, collect general browsing activity, or access information outside the stated business purpose.

8. Authentication and Access Controls

Access to protected MSM Distribution API services requires valid authentication. Authentication tokens may be stored within browser extension storage and transmitted only to approved MSM Distribution endpoints.

Server-side controls may restrict requests based on authentication status, approved extension origin, supported request method, request format, or other security criteria. Possession of an extension installation does not independently guarantee access to protected business information.

Authorized users are responsible for protecting browser profiles, devices, authentication tokens, and account credentials from unauthorized access.

9. How Information Is Used

Information accessed or transmitted through the extensions may be used solely for legitimate MSM Distribution business purposes, including:

  • Displaying accurate product information to authorized personnel
  • Supporting product pricing, cost, margin, and purchasing decisions
  • Displaying relevant customer purchase and sales history
  • Improving transaction and check-processing workflows
  • Maintaining internal system reliability and security
  • Diagnosing operational errors and connection failures
  • Protecting MSM Distribution systems from unauthorized access or misuse
  • Complying with legal, regulatory, contractual, or audit obligations

10. Data Sharing and Disclosure

MSM Distribution does not sell, rent, license, or trade information accessed through the extensions for advertising, marketing, or unrelated commercial purposes.

Information may be disclosed only when reasonably necessary:

  • To authorized MSM Distribution personnel
  • To service providers supporting approved business operations
  • To Cin7 or related authorized providers as part of normal system operation
  • To investigate security incidents, misuse, fraud, or violations of law
  • To comply with a legal obligation, court order, subpoena, or governmental request
  • To protect the rights, property, systems, personnel, customers, or business operations of MSM Distribution

11. Data Retention

The extensions are not designed to maintain independent long-term copies of business records. Product, sales, customer, and other operational information remains within Cin7 and authorized MSM Distribution systems in accordance with applicable internal retention practices.

Configuration values stored within the browser may remain until the extension is removed, browser storage is cleared, a value is replaced, or an administrator resets the configuration.

12. Security Practices

MSM Distribution uses reasonable administrative, technical, and organizational safeguards designed to protect information associated with the extensions. These safeguards may include:

  • Encrypted HTTPS communication
  • Authenticated API access
  • Approved-origin restrictions
  • Request validation
  • Server-side access controls
  • Rate limiting and operational safeguards
  • Controlled internal distribution
  • Least-privilege browser permissions
  • Logging and monitoring of application errors and synchronization activity

No security method is guaranteed to prevent every possible incident. Authorized users must promptly report suspected unauthorized access, token exposure, device loss, or other security concerns to MSM Distribution.

13. Third-Party Services

The extensions are designed to work with third-party business software, including Cin7 POS. Third-party services are governed by their own agreements, privacy policies, security practices, and terms of use.

MSM Distribution is not responsible for the independent privacy or security practices of third-party providers. Use of Cin7 and related services remains subject to the applicable agreements between MSM Distribution and those providers.

14. Artificial Intelligence and Automated Processing

Certain MSM Distribution backend services may use automated processing or artificial-intelligence-assisted tools to support internal product classification, enrichment, matching, review, or data-quality workflows.

The browser extensions do not independently perform artificial-intelligence processing within the browser. Any automated or AI-assisted functionality is performed through authorized MSM Distribution systems and remains subject to internal review, validation, and access controls.

15. Authorized User Responsibilities

Authorized users must:

  • Use the extensions only for approved MSM Distribution business purposes
  • Protect access tokens and configuration settings
  • Avoid installing the extensions on unauthorized or shared devices
  • Not copy, distribute, reverse engineer, or disclose internal extension functionality without authorization
  • Comply with MSM Distribution policies and applicable Cin7 requirements
  • Report suspected misuse, unauthorized access, or security incidents promptly

MSM Distribution may suspend or revoke access to the extensions or related services at any time when necessary to protect company systems, data, personnel, customers, or business operations.

16. Children's Privacy

The extensions are internal business tools and are not directed to children. MSM Distribution does not knowingly use the extensions to collect personal information from children.

17. Geographic Scope

The extensions are intended for authorized MSM Distribution business operations in the United States. Information may be processed through service providers or systems located in the United States or other locations where approved providers operate.

18. Changes to This Policy

MSM Distribution may revise this policy to reflect changes in extension functionality, legal requirements, security practices, business operations, browser-store requirements, or third-party services.

Updated versions will be posted on this page with a revised effective date. Continued use of the extensions after an update may be treated as acknowledgment of the revised policy to the extent permitted by law and applicable company policy.

19. Contact

Questions, concerns, security reports, or requests related to this policy or the MSM Distribution browser extensions may be directed to: support@msmcore.com.

General MSM Core privacy practices are described in our Privacy Policy, and use of MSM Core and its browser extensions is subject to our Terms of Use.

This policy describes MSM Distribution's current browser-extension privacy practices and is intended to provide clear notice to authorized users, browser-store reviewers, and other applicable parties. It does not create contractual rights beyond those required by applicable law, written agreement, or official MSM Distribution policy.