MurmSpy — Privacy Policy

Last updated: 2 August 2026

MurmSpy is a browser extension for ecommerce store and product research, published by MurmTools. This policy explains what MurmSpy does and does not do with data.

The short version

  • MurmSpy reads only public store data on pages you visit (or explicitly scan) — the same product listings, scripts and metadata any visitor's browser already loads.
  • MurmSpy does not collect, transmit or sell your personal data. There is no MurmSpy account, no tracking SDK, and no analytics beacon. The one exception is buying Pro, which happens on ExtensionPay's own page — see Payments.
  • Everything MurmSpy stores (saved shops, settings, local usage counters) lives in your browser's extension storage and never leaves your machine.

What MurmSpy processes

DataWhere it goesWhy
Public storefront data (products.json, collection pages, sitemaps, page markup) of the store you're viewing Fetched by the extension, cached briefly in extension session storage To show store intel, best sellers and product lists
Your saved shops, UI preferences and daily export counter chrome.storage on your device only Core functionality
Local feature-usage counters (e.g. "csv_export: 3") chrome.storage on your device only; never transmitted To let us debug locally; no PII, no identifiers
An ordinary page request to murmtools.com when you install or remove MurmSpy Installing opens a welcome page; removing opens a short feedback page, with the version number in the URL. Our web host sees these like any other visit to the site — an IP address and a browser user-agent. Getting started, and finding out why people leave

What MurmSpy never does

  • MurmSpy never reads your browser history, and stores only the shops you chose to keep.
  • No collection of names, emails, or any personal identifiers — except on the paid tier, where your email goes to ExtensionPay on their own page. See Payments below.
  • No login-gated scraping, no automation of any website.
  • No selling or sharing of data with third parties — there is nothing to sell.
  • No lookups about the store you are viewing against any third-party service. Everything in the panel is computed on your machine from that store's own public pages. (Up to v0.6.0 one figure — a traffic rank — was fetched from a Google API; that feature was removed in v0.6.1 precisely because it did not match this page.)

Payments (Pro)

Pro subscriptions are processed by ExtensionPay (extensionpay.com) and Stripe. When you purchase Pro, you give your email address to ExtensionPay on ExtensionPay's own checkout page and your card details go to Stripe; both handle that data under their own privacy policies. MurmSpy only learns whether the current browser has an active license, and stores the anonymous licence key ExtensionPay issues for it. On the free tier you never provide an email. The licence check is the one request MurmSpy makes that is not to the store you are looking at. See extensionpay.com/privacy and stripe.com/privacy.

Permissions, explained

  • storage — save your shops, preferences and local counters.
  • activeTab — when a Shopify store runs on its own domain rather than a myshopify.com address, clicking the MurmSpy toolbar icon grants access to that one tab for that one click. This is why MurmSpy does not ask for access to every site.
  • scripting — injected into the tab you are viewing: automatically on a Shopify storefront, and on your click for custom-domain stores. It is used to put the panel on the page, and to read the page's own Shopify globals — the shop name, theme and currency the storefront itself defines — because a content script cannot otherwise see the page's own variables. It reads those values; it writes nothing to the page and injects no code from outside the extension package.
  • Host access to *.myshopify.com — read that store's public pages, and show the overlay automatically where MurmSpy is designed to work.
  • Host access to www.tiktok.com and shop.tiktok.com — TikTok Shop pages are navigated in-page and served from several URL shapes, so the grant cannot be narrowed to a path. The script classifies the URL itself: on anything that is not a TikTok Shop product or shop page it renders nothing and reads nothing.
  • Host access to extensionpay.com — license checks and checkout.

Changes & contact

We'll update this page when anything changes and bump the date above. Questions: [email protected].

MurmSpy is not affiliated with Shopify or TikTok. It reads the same public pages your browser already loads — no logins, no automation, no private APIs.