Privacy Policy for IraniCard Shared Accounts
Last Updated: July 26, 2026
Effective Date: July 26, 2026
This Privacy Policy explains how IraniCard Shared Accounts, operating under the brand IraniCard(“we,” “us,” or “our”), collects, accesses, uses, stores, transmits, and protects information when authorized users use the IraniCard Shared Accounts Chrome extension.
The Extension is intended solely for authorized employees and administrators of Iranicard / registered customers with an active subscription. It is designed to authorized customer/admin logins to IraniCard Services.
By installing or using the Extension, you acknowledge the practices described in this Privacy Policy.
1. Extension’s Single Purpose
The Extension has one narrow and clearly defined purpose:
“To enable authorized users to securely access and use approved web services through controlled sessions provided by IraniCard.”
The Extension accesses and processes information only when necessary to provide, secure, maintain, or improve this stated functionality.
The Extension is not intended to monitor users’ general browsing activity, create advertising profiles, or collect information unrelated to its stated purpose.
2. Scope of This Privacy Policy
This Privacy Policy applies only to information processed through:
– the IraniCard Shared Accounts Chrome extension;
– the Extension’s communication with api.iranicard.ir;
– authentication and session-management services connected to the Extension;
– approved websites that the Extension must access to provide its functionality.
This Privacy Policy does not govern unrelated websites, applications, or services operated by third parties.
Third-party websites may have their own privacy policies and terms.
3. Categories of Information Processed
Depending on how the Extension is configured and used, it may process the following categories of information.
3.1 Account and Authentication Information
The Extension may process:
– user account identifier;
– authentication token;
– session identifier;
– access status;
– subscription or authorization status;
– role or permission level;
– login and logout timestamps.
The Extension does not intentionally collect or store a user’s Iranicard account password unless password processing is explicitly required by the authentication flow and clearly disclosed to the user.
Authentication tokens and session information are treated as confidential information.
3.2 Technical and Device Information
The Extension may process limited technical information necessary for security and operation, such as:
– browser type and version;
– Extension version;
– operating system type;
– IP address;
– date and time of requests;
– session expiration time;
– error and diagnostic information;
– security-related events;
– supported domain or active-tab URL when required for an Extension feature.
We do not use this information to build advertising profiles or monitor general browsing behavior.
3.3 Browser and Tab Information
Where required by the Extension’s functionality, the Extension may detect:
– whether the current tab belongs to an approved domain;
– the URL or hostname of the active supported page;
– whether a supported page is ready for the Extension to operate;
– the status of an authorized Extension session.
The Extension does not collect complete browsing history or continuously track browsing across unrelated websites.
Any access to website activity is limited to what is necessary for the user-facing functionality described in the Extension’s Chrome Web Store listing and user interface.
3.4 Cookie and Session Information
The Extension may access, set, modify, or remove cookies on approved domains when necessary to:
– establish an authorized session;
– maintain authenticated access;
– prevent concurrent or unauthorized sessions;
– clear session data after logout or expiration;
– restore an approved session;
– enforce access restrictions.
The Extension does not use cookies for advertising or cross-site behavioral tracking.
3.5 Website Content and Form Data
On supported websites, the Extension may read or modify limited page content when necessary to provide its disclosed functionality.
This may include:
– detecting page status;
– inserting or updating approved session information;
– completing authorized login or access steps;
– displaying Extension controls or status messages;
– preventing unauthorized copying or disclosure of protected credentials;
– enforcing restrictions required by the service.
The Extension does not collect passwords, payment card information, private messages, or unrelated form entries from third-party websites unless such processing is strictly necessary for a clearly disclosed feature and legally permitted.
3.6 Usage, Security, and Diagnostic Data
To maintain security and reliability, we may process:
– successful and unsuccessful session-start events;
– logout and session-expiration events;
– failed authentication attempts;
– policy violations;
– unauthorized access attempts;
– Extension errors;
– API response status;
– limited performance and reliability metrics.
These records are used only for security, troubleshooting, fraud prevention, service reliability, and support.
4. Information We Do Not Collect for Unrelated Purposes
The Extension is not designed to collect or use the following for advertising, resale, or unrelated profiling:
– complete browsing history;
– personal communications;
– emails or message contents;
– payment card numbers;
– banking credentials;
– biometric information;
– precise GPS location;
– health information;
– advertising identifiers;
– contacts;
– files stored on the device;
– microphone or camera recordings.
Where an approved website itself processes such information, that processing is governed by that website’s own privacy policy unless the Extension directly accesses the information.
5. How We Use Information
We use processed information only to:
– verify that a user is authorized;
– provide access to the Extension’s features;
– create, maintain, and terminate secure sessions;
– enforce subscription, account, and usage limitations;
– prevent simultaneous, unauthorized, or abusive access;
– communicate with approved backend services;
– operate the Extension on supported domains;
– protect credentials and confidential session information;
– investigate technical errors and security incidents;
– respond to support requests;
– improve the Extension’s security, performance, and reliability;
– comply with legal obligations and enforce applicable terms.
We do not use Extension data for personalized advertising, credit decisions, insurance eligibility, or sale to data brokers.
6. Chrome Web Store Limited Use Disclosure
The use of information received from Google Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Specifically:
– we limit the use of user data to providing or improving the Extension’s single stated purpose;
– we do not transfer user data for personalized advertising;
– we do not sell user data;
– we do not use user data to determine creditworthiness or for lending purposes;
– humans do not read user data except where necessary for security, support, legal compliance, or with the user’s explicit consent;
– we do not use or transfer user data for purposes unrelated to the Extension’s prominently disclosed functionality.
This disclosure applies to raw information and to information that is aggregated, anonymized, de-identified, or derived from it.
7. Chrome Permissions
The Extension may request some or all of the following Chrome permissions, depending on the published version.
7.1 Storage
The storage permission is used to store limited Extension settings and temporary session-related information, such as:
– authentication state;
– session expiration time;
– Extension preferences;
– supported-domain configuration;
– security and session flags.
Storage is not used to create advertising profiles.
7.2 Cookies
The cookies permission is used only on approved domains to establish, maintain, synchronize, or remove authorized sessions required for the Extension’s functionality.
7.3 Alarms
The alarms permission is used to schedule operational tasks, such as:
– checking session expiration;
– clearing expired information;
– refreshing approved configuration;
– ending inactive sessions;
– performing security-related checks.
It is not used for advertising or unrelated background monitoring.
7.4 Tabs or ActiveTab
The tabs or activeTab permission is used to identify whether the user is viewing a supported website and to operate the Extension only on relevant pages.
The Extension does not use this permission to create a history of unrelated browsing activity.
7.5 Scripting
The scripting permission is used to execute packaged JavaScript or CSS on approved websites to provide the Extension’s user-facing functionality.
It may be used to:
– display controls;
– detect page state;
– support authorized sessions;
– insert required data;
– apply security restrictions.
The Extension does not download or execute remote code through this permission.
7.6 Declarative Net Request
The declarativeNetRequest permission is used to apply predefined network-request rules necessary for the Extension’s operation and security.
Depending on the Extension configuration, these rules may:
– modify permitted request headers;
– restrict unauthorized requests;
– support approved session handling;
– block disallowed requests;
– enforce supported-domain policies.
It is not used to intercept unrelated browsing traffic for advertising or profiling.
7.7 Host Permissions
Host permissions allow the Extension to operate only on domains required for its stated functionality.
The current approved domains are:
– https://api.iranicard.ir/*
– https://iranicard.ir/*
– https://panel.iranicard.ir/*
The Extension does not use host access to monitor unrelated websites.
7.8 Notifications
If requested, the notifications permission is used to display important service, session, security, expiration, or access-status messages.
7.9 Identity
If requested, the identity permission is used to authenticate the authorized user through an approved identity provider.
7.10 Web Navigation
If requested, webNavigation is used only to detect navigation within supported domains when required to activate or deactivate Extension functionality.
8. Legal Bases for Processing
Where applicable data-protection laws require a legal basis, information may be processed based on:
– performance of a contract or provision of the requested service;
– the user’s consent;
– our legitimate interest in securing and operating the Extension;
– compliance with legal obligations;
– protection of users, our systems, and third parties from fraud or misuse.
Where processing is based on consent, the user may withdraw consent where legally applicable. Withdrawal may make some Extension functionality unavailable.
9. Data Storage
Extension-related information may be stored:
– locally in Chrome Extension storage;
– temporarily in browser memory;
– on secure servers operated by or on behalf of IraniCard;
– in security and diagnostic logs;
– in authentication or session-management systems.
Sensitive information is stored only where necessary and is subject to access controls.
Local information may be removed after logout, session expiration, Extension removal, or another configured cleanup event.
10. Data Transmission and Security
Data transmitted between the Extension and our servers is sent using encrypted HTTPS/TLS connections.
We use reasonable technical and organizational measures, including where applicable:
– encrypted transmission;
– authentication and authorization controls;
– limited employee access;
– session expiration;
– single-session or concurrent-session restrictions;
– server-side validation;
– audit and security logging;
– rate limiting;
– secure credential handling;
– periodic dependency and security updates.
No internet-based service can guarantee absolute security. Users must also protect their devices and account access.
11. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Indicative retention periods are:
– local session data: until logout, expiration, cleanup, or Extension removal;
– authentication session records: for the duration of the session and the necessary security period afterward;
– security and access logs: up to 14 days;
– support communications: up to 1 year;
– financial or subscription records: for the period required by applicable law;
– incident records: for as long as required to investigate and protect against repeated abuse.
Retention periods may be extended when required by law, dispute resolution, fraud prevention, or security investigations.
After the retention period, information is deleted, anonymized, or securely isolated unless continued retention is legally required.
12. Sharing and Disclosure
We do not sell or rent Extension user data.
Information may be disclosed only to:
12.1 Service Providers
Trusted providers may process limited information on our behalf for:
– cloud hosting;
– API infrastructure;
– security monitoring;
– authentication;
– error reporting;
– customer support.
They may use information only under our instructions and for the contracted purpose.
12.2 Legal and Security Requirements
Information may be disclosed where reasonably necessary to:
– comply with applicable law or a lawful request;
– protect the rights and security of users or the company;
– investigate fraud, abuse, or security incidents;
– enforce our terms;
– respond to emergencies involving safety or security.
12.3 Business Transfers
If our business or the Extension is reorganized, merged, acquired, or transferred, relevant information may be transferred subject to appropriate confidentiality and legal protections.
13. Human Access to Information
Authorized personnel may access limited information only when necessary to:
– investigate a security incident;
– resolve a support request;
– prevent fraud or misuse;
– comply with legal obligations;
– protect the Extension and its users;
– perform internal operations with the user’s consent where required.
Access is restricted according to role and operational need.
14. International Data Transfers
Our servers or service providers may operate in countries different from the user’s location.
Where legally required, we use appropriate contractual, organizational, or technical safeguards for international data transfers.
15. User Choices and Rights
Depending on applicable law, users may have the right to:
– request access to their personal information;
– request correction of inaccurate information;
– request deletion of eligible information;
– object to or restrict certain processing;
– withdraw consent;
– request information about data sharing;
– file a complaint with a competent authority.
Some information may be retained where required for security, legal compliance, fraud prevention, or the establishment or defense of legal claims.
Requests may be submitted through the contact details below.
16. Deleting Extension Data
Users may clear certain local information by:
– signing out of the Extension;
– ending the active session;
– clearing the Extension’s stored data through Chrome;
– uninstalling the Extension.
To request deletion of server-side personal information, contact:
info@iranicard.ir
Requests should include enough information to verify the requester’s identity and locate the relevant account, without sending passwords or sensitive credentials.
17. Children’s Privacy
The Extension is not intended for children under the minimum legal age applicable in their jurisdiction.
We do not knowingly collect children’s personal information through the Extension.
If such information is identified, we will take reasonable steps to delete it where required.
18. Third-Party Websites and Services
The Extension may operate on or interact with third-party websites.
Those services are controlled by their respective operators and may independently collect or process information.
We are not responsible for third-party privacy practices, availability, content, or policies.
Users should review the privacy policies and terms of each third-party service they access.
19. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
– changes to the Extension;
– changes to permissions;
– security improvements;
– legal or regulatory requirements;
– changes to service providers.
The latest version will remain available at this URL.
Where required, we will provide additional notice of material changes.
The “Last Updated” date at the top indicates the latest revision.
20. Contact Information
Data Controller / Extension Publisher:
Legal Name: IraniCard.ir
Brand Name: IraniCard.ir
Address: Tehran, Beheshti St., between Mir Emad St. and Mofteh St., 14th Kaj Building, No. 14, 2nd Floor, Unit 30, 16th Alley
Country: Iran
Privacy Email: info@iranicard.ir
Support Email: support@iranicard.ir
Website: https://iranicard.com
Extension Name: IraniCard Shared Accounts
Responding 24 hours a day, 7 days a week
021-91091000
03131117