Product privacy notice

InfoCar – Uspacy Status Checker

Effective date
6 September 2026
Last updated
14 September 2026

This notice explains how the browser extension handles personal information when it checks the production status of a Polish driving licence through InfoCar.

01

Operator and Scope

Halerka Digital operates this extension. For the extension data described here, contact:

ФОП Грогуль Юрій Васильович Україна, 35604, м. Дубно, вул. Івана Мазепи буд. 15 Email: contact@halerka.digital

The extension processes personal information even when it is processed only in the browser. It is an independent integration and is not operated by, affiliated with, or endorsed by InfoCar, PWPW, or Uspacy.

02

Data We Handle and Why

  • Verification fields: first name, surname, and full 11-digit PESEL entered manually, selected through the context menu, or detected on a supported Uspacy CRM page. They identify the person whose document status is requested.
  • CRM page content: after the user opens the popup or in-page form, or requests a rescan, the extension reads form labels and values, deal/contact titles, IDs, and table rows to map fields and select a client. This can include other personal information in CRM fields, including contact details or notes, and records for multiple clients shown in a table.
  • Results and context: the document status, timeline, and dates returned by InfoCar; plus active-tab URL, page title, and CRM deal IDs used to identify supported pages and the current deal.
  • Settings: field names, mapping priorities, transformation rules, widget visibility, optional automatic status copying, preferences for saving status to CRM deals (including the chosen CRM target field and optional automatic record update), and the history preference.

CRM scanning remains in the browser. Only the three verification fields are sent to InfoCar. Password, hidden, file, and fields marked as payment or authentication inputs are excluded from form scanning. Do not enter client records or credentials into custom mapping settings.

03

Transmission and Recipients

Opening the popup or form reads CRM data locally; it does not submit a check. Clicking Check or Run test request sends the normalized first name, surname, and PESEL directly by HTTPS POST to https://info-car.pl/api/ssi/status/driver/driver-licence. The request omits browser credentials, disables HTTP caching, and rejects redirects. Halerka Digital does not use a proxy server for these requests.

When the user chooses Save to CRM or enables optional automatic CRM updates, the extension transmits the retrieved document status directly to the user's active Uspacy CRM workspace via its local deal update API endpoint, using the user's existing authenticated session. This CRM update occurs directly between the browser and the user's CRM instance; no client data or status updates pass through Halerka Digital servers.

InfoCar is operated by Polska Wytwórnia Papierów Wartościowych S.A. (PWPW). It receives the request and normal connection metadata such as the public IP address and HTTP headers. Its independent processing, retention, and rights information are governed by InfoCar’s terms and personal-data provisions. The legacy InfoCar privacy-policy link redirects to that page.

The extension contains no Halerka Digital analytics, advertising trackers, or telemetry. It does not send client records to Halerka Digital, does not sell user data, and does not use it for advertising, creditworthiness, or lending. Its use of user data is limited to document-status checks and related field-selection, history, and CRM update features.

04

Storage and Retention

  • Optional local history: saving new entries is off by default. If enabled, successful checks store normalized name, surname, full PESEL, status, date, and query time in chrome.storage.local. The extension keeps up to 50 entries, replaces a matching PESEL-and-surname entry, and has no time-based expiry. PESEL masking is a display feature only; the stored number is not masked or encrypted by the extension.
  • Existing records: earlier versions saved history automatically. Disabling history or resetting settings stops new entries but does not delete existing history. Users can delete individual records or clear all history in the extension. Uninstalling removes extension storage from that browser profile but not external copies or backups.
  • Settings: settings, field mappings, and CRM target field selection use chrome.storage.sync, with a local fallback. Depending on browser settings, the browser provider may synchronize them between devices. Query history is not written to sync storage by the extension.
  • Widget position: coordinates use the Uspacy site’s localStorage under infocar_btn_pos. Site scripts can access those coordinates; clearing the site’s data removes them.

Scanned data and results also exist temporarily in memory and the interface. Closing the in-page form clears its inputs and removes its DOM and event handlers; closing the popup destroys its document. An already-sent request can still finish and, if history is enabled, save a result. Browser memory, operating-system memory, developer tools, and backups are outside the extension’s control.

Copy controls write a status, PESEL, or formatted result to the system clipboard. Clipboard history, sync, and other applications can retain that text; deleting extension history does not clear it. The in-page form is part of the Uspacy document, so page scripts can access its displayed values. The popup is outside the page DOM.

05

Browser Permissions

  • storage supports settings, target CRM field preferences, and optional local history.
  • activeTab and scripting support user-requested CRM access and fallback script/CSS injection, restricted in code to supported HTTPS Uspacy hosts.
  • Declared content scripts add the widget on supported Uspacy hosts; extraction and status updates follow a user action.
  • contextMenus adds a selected-PESEL action on supported CRM pages.
  • Host access covers HTTPS info-car.pl for the API and HTTPS *.uspacy.com, *.uspacy.ua, and *.uspacy.pl for reading client fields and saving status updates to CRM deals upon user action.
  • declarativeNetRequest sets request headers only for the extension’s POST requests to the document-status endpoint. It does not grant authorization from PWPW to use the service.
06

Controls, Authorized Use, and Rights

Users can review, correct, or remove detected verification fields before submitting a check. Use the extension only for people whose data you are authorized to process. The organization using the CRM is responsible for the lawful basis and notices required for client data; a click on Check does not itself establish consent or another legal basis.

Halerka Digital has no extension backend holding query records to retrieve or erase. Use the extension’s history controls for locally saved records, contact the CRM organization for CRM records, and consult PWPW’s information for data received by InfoCar. Depending on the responsible organization and applicable law, people may have rights to access, correction, erasure, restriction, objection, and complaint.

For extension questions or privacy requests, use the contact details below. Do not include a client PESEL number or an unredacted CRM screenshot in email.

Halerka Digital ФОП Грогуль Юрій Васильович Україна, 35604, м. Дубно, вул. Івана Мазепи буд. 15
07

Changes to This Notice

We will update this notice if the extension’s data practices change. The Last updated date identifies the current version.

Ask a privacy question