Privacy Policy — Align Buddy for IFS Cloud


Align Buddy for IFS Cloud

Privacy policy · Last updated August 10, 2026 · Extension version 26.8.10

In short: The Extension collects anonymous usage analytics (feature clicks, session duration, IFS Cloud hostnames, projection/entity names, error codes, browser language, derived country code, organization name from hostname) via Google Analytics 4. In the EU/EEA, Switzerland and the UK this is off until you opt in; elsewhere it is on and you can opt out. An anonymous usage profile (role classification, feature adoption, known tenants, churn risk score) is maintained locally and included in analytics. No personal information, IFS business data, credentials, or record-level data is ever collected — and from version 26.8.10 session tokens and cookies are not even stored on your own disk. All settings and cached data stay in your browser. One feature writes to IFS Cloud: Record Transfer creates a record you copied in the environment you choose, only when you press Paste — see Writing Data to IFS Cloud below. Optional Page Translation: when you explicitly enable translation and the browser’s built-in on-device AI translator is unavailable, visible IFS Cloud page text is sent to Google’s public translation endpoint to be translated. If your organization deployed the Extension, an administrator can switch off analytics, translation and the rest centrally.

Overview

Align Buddy for IFS Cloud (”the Extension”) is a browser extension that provides developer and consultant productivity tools for IFS Cloud (Aurena) applications. This policy explains what data the Extension accesses, collects, and how it is handled.

Data Collection — What We Collect

The Extension collects anonymous usage analytics via the Google Analytics 4 Measurement Protocol. This data is sent directly from the extension’s background service worker to Google Analytics servers.

Anonymous Identifiers

Client ID — A randomly generated UUID stored locally. Not linked to your Google account, email, name, or any personal identity.

Session ID — A temporary identifier for grouping events within a single browser session.

Extension and Environment

Extension version — The installed version number (e.g. ”26.8.10”). On an update, the previous version number is also sent.

Browser language — Your browser’s language setting (e.g. ”en-US”, ”sv-SE”).

Country code — A two-letter country code (e.g. ”SE”, ”US”) derived from your system timezone. No IP-based geolocation is used.

Platform and screen resolution — Your operating system name and screen dimensions (e.g. ”Windows”, ”1920×1080”).

User-Agent header — Included in analytics requests so GA4 can auto-detect device category, browser, and operating system.

IFS Cloud Host Information

Hostname — The IFS Cloud hostname you visit (e.g. ”customer-uat.ifs.cloud”). Helps us understand how many organizations and environments use the extension.

Organization name — An identifier extracted from the IFS Cloud hostname (e.g. ”customer” from ”customer-uat.ifs.cloud”).

IFS module detection — Which IFS product areas are used (e.g. ”manufacturing”, ”finance”), inferred from projection names. Only the category is sent, not actual data.

IFS Cloud version — The major version number (e.g. ”25.1.9”), detected from the server. Only the version is collected.

Usage Analytics

Category What is tracked Example
Lifecycle Extension install and update events, and the install source ”ext_install”, ”chrome_web_store”
Sessions Session start, duration, frequency ”45 min, 12th session”
Features Which tools are used and how they were discovered ”query_execute”, ”annotate”
Queries That a query was run, which projection/entity set (no data values) ”query on CustomerOrder/OrderSet”
Errors Error codes encountered (ORA codes, HTTP status codes) ”ORA-01403”, ”HTTP 500”
Exports That an export was performed and its step or item count — BPA workflow, Postman collection, JMeter test plan, or evidence pack ”postman export, 5 steps”
Record transfer outcome How many records were pasted into the target environment, how many failed, how many values IFS changed, and the HTTP status of the first failure. Never the record content. ”3 pasted, 1 failed, 409”
Adoption Feature adoption milestones and time to first feature use ”user adopted 10 features”
Premium interest Clicks on premium/upgrade feature prompts and a running count of such clicks (no payment or identity data) ”optimizer, 3rd inquiry”
Team sharing That a config was exported/imported (not the config content) ”team config exported”
Onboarding Whether the welcome walkthrough was completed ”onboarding completed”
Search terms Command palette and side panel Inspector filter searches (truncated to 50 chars) ”ShopOrder”
Command palette The label of the command you ran ”Open Side Panel”
Environment labels The name or id you gave an environment in Settings, sent when a custom-CSS environment banner is applied or an environment is edited ”UAT”, ”customer-prod”
Settings changes Which setting key you changed, and the character length of any custom CSS (never the CSS itself) ”bannerEnabled”, ”css_length: 240”
Configuration counts How many environments and bookmarks you have saved, and how many distinct IFS tenants have been seen ”6 environments, 12 bookmarks”
Request volume Total and failed OData request counts observed by the network monitor, plus the HTTP method — counts only, never URLs, payloads, or responses ”412 total, 3 failed, GET”
Tenant grouping The first 8 characters of your anonymous Client ID, used only to estimate how many users share one IFS tenant ”a1b2c3d4”
Side panel usage Which side panel tab was opened and how long it was viewed ”Page, 30s”
Page scanning That a page scan or annotation pass ran, and which scan type ”annotate_page, cpi”
Translation That a translation was triggered and the target language code. The text being translated is never sent to analytics. ”target language: sv”
User role Automatically classified role based on usage patterns ”developer”, ”consultant”
Peak usage Hour of day when sessions start ”hour: 14”
Churn risk Behavioral score from engagement patterns ”churn_risk: low”
Session depth Count of actions per session ”24 actions”
User properties Persistent attributes: platform, resolution, first seen, active days, feature count, org count, version ”Windows, 42 days, 14 features”

A field-by-field inventory of every parameter transmitted is available on request — see For Organizations.

Data We Do NOT Collect

The Extension does not collect, transmit, or store externally:

No personal information — No names, email addresses, usernames, or account details are ever read from IFS Cloud or from your browser profile. Note that free text you type into the command palette or the Inspector filter is sent as a search term (truncated to 50 characters), so avoid typing personal data into those two boxes.

No IFS business data — No record values, field contents, order numbers, customer names, or financial amounts.

No credentials — No passwords, tokens, API keys, session cookies, or authentication data is ever transmitted anywhere. From version 26.8.10 they are not stored on your disk either; see Credentials and Session Tokens below.

No request/response bodies — No OData payloads or response data. Only projection and entity set names are tracked.

No full URLs or paths — No IFS Cloud URL paths, query parameters, or record keys are collected. The hostname is collected; see Data Collection — What We Collect above for the full list of identifiers that are sent.

Exception: When you explicitly enable the optional Page Translation feature and the browser’s on-device translator is unavailable, the visible text of the current IFS Cloud page is sent to Google’s public translation endpoint solely to obtain translations. See Third-Party Services below. This does not include OData payloads, credentials, or analytics identifiers.

Data Accessed Locally

The Extension accesses the following data solely within your browser to provide its features. This data is never sent externally:

Website content — Reads IFS Cloud page structure (field names, labels, entity mappings) to power the Page Scanner, Page Annotator and Element Inspector. Only accessed on IFS Cloud URLs.

Network requests — Monitors OData API requests for the Inspector and Performance Dashboard. Projection and entity set names from observed requests are included in analytics. No request content is sent externally.

Clipboard — The Extension writes to your clipboard when you use copy actions. It does not read your system clipboard. It does read the record IFS itself stores when you use IFS’s own Copy command, so that record can be shown to you and transferred to another environment.

Writing Data to IFS Cloud

One feature writes to IFS Cloud: Record Transfer, in the Copy / Paste tab. When you copy a record in IFS and press Paste, the Extension creates that record in the environment you choose, using IFS’s own projection API and the session of the tab you are pasting into. Every other feature only reads.

Only when you ask — nothing is written until you select records, choose a target environment, and press Paste. There is no automatic or background writing.

Your own permissions apply — the write runs as the signed-in IFS user in that tab, so IFS enforces exactly the access that user already has.

Shown before it happens — the fields to be sent are listed and can be excluded before you paste, and afterwards the Extension reports what IFS actually stored, including any value IFS changed.

Not sent to us — the record goes only to your own IFS Cloud environment. No record content is transmitted to Align Consulting or to Google Analytics. Only the counts described under Record transfer outcome above are included in analytics.

Data Storage

All user settings, bookmarks, environment configurations, query templates, recorded sequences, and cached data are stored locally in your browser using chrome.storage.

Never leaves your browser — Except via Chrome Sync for small settings, which is a built-in Chrome feature under your control.

Not accessible externally — No external service can access your extension data.

Fully clearable — Remove the extension or clear its storage at any time to delete all data.

Permissions

Each permission is used solely for its stated purpose:

Permission Purpose
storage Save settings, bookmarks, query templates, and request history locally. Also how the Extension reads any policies your administrator has set.
activeTab Access the current tab to read IFS Cloud page content and inject UI elements.
sidePanel Display the developer tools side panel.
webRequest Monitor OData API traffic on IFS Cloud pages for the Inspector. Does not modify or block requests.
tabs Detect IFS Cloud environments, send messages, and enable environment switching.
scripting Inject content scripts for page scanning and annotation on IFS Cloud pages.
*://*/main/ifsapplications/* (host access) Limits every content script and network observation to IFS Cloud (Aurena) application paths. The Extension cannot read any other site.

That is the complete list — six permissions and one host pattern. Version 26.8.10 removed two optional permissions (contextMenus and alarms) that earlier versions declared but never actually used.

Deliberately not requested: cookies, history, downloads, nativeMessaging, debugger, management, windows, and <all_urls>. The webRequest permission is used for observation only — the Extension does not declare the blocking capabilities that would let it modify, redirect or block any request.

Analytics and Your Choices

Whether analytics start automatically depends on where you are, because the law differs:

Where you are Default How you are asked
EU / EEA, Switzerland, United Kingdom Off — opt-in Nothing is sent until you actively choose. You are asked during the welcome walkthrough, and again by a prompt in the extension popup.
Everywhere else On — opt-out Disclosed during the welcome walkthrough with a one-click decline, and switchable in Settings > Privacy at any time.

Your region is worked out from your browser’s timezone setting. No IP-based location lookup is performed and no request is made to determine where you are.

Change your mind anytime — Go to Settings > Privacy and toggle ”Share anonymous usage data”. The change takes effect immediately.

When off — All analytics events are silently discarded. No data is sent to any external service. The extension continues to function normally.

Consent state — Stored locally in chrome.storage.local under the key ifs_analytics_consent, alongside a marker recording whether the value came from your own choice or from the regional default. A default is never treated as your consent.

If you were already a user — Versions before 26.8.10 switched analytics on automatically for everyone. If you are in a region where opt-in applies, that automatic setting was not valid consent, so it has been cleared: analytics are off for you until you choose otherwise. If you had made an explicit choice, it has been kept.

Administrator controls

If your organization deployed the Extension for you, your administrator can switch these capabilities off centrally, and their choice overrides yours:

Policy Effect
AnalyticsEnabled No analytics event is ever sent, regardless of your own setting.
PageTranslationEnabled Page Translation is unavailable.
TranslationCloudFallbackEnabled Translation runs on your device only; no page text is sent to Google.
CredentialHeaderCaptureEnabled Authorization and Cookie headers are always discarded.
UninstallSurveyEnabled No feedback page opens when the Extension is removed.

A setting your administrator has switched off appears in Settings as off, greyed out, and labelled as managed by your organization. An administrator can only ever restrict — no policy can switch data collection on for you.

Credentials and Session Tokens

The Extension observes the IFS Cloud API calls your browser makes, so that the API Inspector can show them to you. Those calls carry your IFS session — an Authorization header and cookies.

Never transmitted — No credential, token or cookie is sent to Align Consulting or to any third party, in any version.

Not stored, from version 26.8.10Authorization, Cookie, Set-Cookie and XSRF/CSRF headers are discarded the moment a request is observed, before anything is written to your browser storage. Earlier versions kept them in the saved request history on disk; that history is cleaned up automatically the first time you run 26.8.10.

Optional for developers — Settings > Privacy has a ”Capture credential headers” toggle, off by default, for developers who need copy-as-cURL to carry real authentication. Your administrator can prevent it being switched on.

CSRF token — The Record Transfer feature reads the XSRF-TOKEN cookie in the page’s own context, because IFS requires it to be echoed back on any write. It is used for that one request and never stored or transmitted.

No cookie access — The Extension does not request the cookies permission and cannot read cookies for any other website.

Third-Party Services

The Extension sends anonymous usage analytics to Google Analytics 4 (operated by Google LLC) via the GA4 Measurement Protocol. The data sent is limited to the categories described above. No personal information or IFS business data is included.

Google’s privacy policy: policies.google.com/privacy

Page Translation Service (opt-in)

The Extension includes an optional Page Translation feature that translates visible IFS Cloud text into a target language you select. Translation is off by default and only activates when you explicitly enable it from the popup.

Preferred path — on-device AI: When your browser supports its built-in on-device translator API, translation runs entirely on your device. No text leaves the browser.

Fallback path — Google Translate: When the on-device translator is unavailable or does not support the requested language pair, the Extension falls back to Google’s public translation endpoint https://translate.googleapis.com/translate_a/single. The visible text of the current IFS Cloud page is sent to this endpoint to obtain translations.

What is sent: The visible text of the current page and the target language code. No OData payloads, credentials, URLs, hostnames, or analytics identifiers are sent to the translation endpoint, and the request carries nothing that identifies you or your organization.

Be aware of the scope: The translator works through the visible text on the page. It skips scripts, styles and code blocks, and ignores purely numeric strings, but it cannot tell a column heading apart from a business value shown in a grid cell. If personal or commercial data is on screen when you translate, that text is included in the request. This is the only place in the Extension where business content can leave your browser, which is why it is off by default and why administrators can block it.

What is logged: Google’s public translation endpoint may log requests per its standard service practices. The Extension does not control this endpoint.

How to stop it: Disable Page Translation from the popup at any time. When disabled, no further requests are made to the translation endpoint. An administrator can also restrict translation to on-device only, or switch the feature off entirely.

Google’s privacy policy applies to data received by Google’s translation endpoint: policies.google.com/privacy

Uninstall Survey (Microsoft Forms)

When you uninstall the Extension, your browser opens an optional feedback survey hosted on Microsoft Forms (forms.cloud.microsoft, operated by Microsoft). The survey link is static — the Extension does not include any identifiers, analytics data, or usage data in the URL. Microsoft receives only the standard web request your browser makes when opening the page (such as IP address and user agent), plus whatever you choose to submit in the survey. Answering is entirely optional; you can simply close the tab.

Microsoft’s privacy statement: privacy.microsoft.com/privacystatement

No other third-party services receive data from the Extension. (The optional team configuration sync feature fetches a config file from a URL you provide yourself; data is only sent to a server if you configure one.)

Data Retention

Local data — Stored until you uninstall the Extension or clear its storage. You are in full control.

Analytics data — Retained by Google Analytics per the retention setting configured on the property. No personal identifiers are collected, and Align Consulting keeps no copy outside Google Analytics: no data warehouse, no export pipeline, no CRM ingestion.

Your Choices

Uninstall anytime — Remove from chrome://extensions (or edge://extensions in Microsoft Edge). All locally stored data is deleted.

Disable analytics — Toggle off in Settings > Privacy at any time. Takes effect immediately.

Changes to This Policy

If this privacy policy is updated, the changes will be reflected on this page with an updated date. Significant changes will be noted in the Extension’s changelog.

International Data Transfers

Align Consulting AB is established in Sweden (European Union) and operates no servers that receive your data. Where data reaches Google or Microsoft as described above, those transfers rely on the EU–US Data Privacy Framework (both are self-certified), its Swiss–US extension, and the EU Standard Contractual Clauses incorporated in their standard data-processing terms. The UK Addendum covers UK transfers.

If your organization’s transfer assessment does not accept these safeguards, an administrator can disable analytics and the translation fallback by policy. With those switched off, the Extension makes no request to any third party at all.

For Organizations

A complete vendor assessment pack is available on request: a signature-ready Data Processing Agreement, the full sub-processor list with transfer mechanisms, a field-by-field data inventory, the enterprise policy configuration guide, and a security overview covering permissions, credential handling and the release process. Request it from post@alignconsulting.se.

Questions about this policy?

Write to post@alignconsulting.se — procurement and security teams can request the full vendor assessment pack at the same address.

© 2026 Align Consulting AB. All rights reserved. · post@alignconsulting.se