CAO Connect — Privacy Policy

Chrome Extension

CAO Connect — Privacy Policy

Effective: 01/07/2026  ·  Last updated: 10/07/2026

CAO Connect is an internal productivity extension built for the JJRE property-management team. It adds workflow shortcuts, form auto-fill, and contextual links to the web platforms the team already uses. This policy explains, in full, what data the extension handles and how.

CAO Connect is distributed privately to jeffjones.com.au Google Workspace users only. It is not offered to the general public. The extension does not sell user data, does not use it for advertising, and does not share it with any third party outside the JJRE organisation.

1. Data we collect

CAO Connect accesses the following categories of data, strictly to operate its features on the pages where they run:

CategoryWhat it is
Authentication informationSession cookies from Queensland RTA domains (digital.rta.qld.gov.au), read only to authenticate bond-search requests the user initiates.
Personally identifiable informationTenant, owner, and property details (such as names, addresses, and contact details) present on the pages the extension auto-fills, read only to populate the corresponding form fields.
Financial informationBill, invoice, disbursement, and transaction details on Xero and related pages, read only to auto-fill fields and link records. Payment card numbers are never accessed.
Web browsing activity and website contentThe URLs, page titles, and on-page content of the specific platforms the extension supports (Reapit, Console Cloud, Xero, Freshdesk, SimpleRent, Tanda, RTA), read to inject links, auto-fill forms, detect the record a user is working on, and identify the active support-ticket tab.
User-provided settingsFeature toggles and preferences that the user configures in the extension's options.

The extension only reads data on the specific domains listed in its permissions. It does not monitor general browsing, and it does not collect data from any site outside those platforms.

2. How we use the data

Data is used solely to provide the extension's user-facing features:

  • Auto-filling forms in Xero, Reapit, Tanda, and RTA bond uploads to reduce manual entry.
  • Adding contextual links and cleaning up sidebars on supported platforms.
  • Linking Freshdesk tickets to the corresponding Xero records, which includes detecting which open tab is the active support ticket.
  • Authenticating RTA bond-search lookups on the user's behalf.

We do not use any collected data for any purpose beyond these features. We do not profile users, build advertising audiences, or assess creditworthiness.

3. How we store the data

Settings and operational state (feature toggles and the reference to the currently active Freshdesk ticket) are stored locally on the user's device using Chrome's storage.local API. This data stays on the device and is not uploaded to us except where a specific feature requires it (see Sharing, below). Authentication cookies are read at the moment of a request and are not retained by the extension.

4. How we share the data

CAO Connect shares data with exactly one party, and only for one feature:

  • JJRE internal automation server (n8n.jjre.com.au). When a user triggers the Freshdesk ↔ Xero sync, the extension transmits the relevant Freshdesk and Xero record URLs to JJRE's own internal n8n server over HTTPS, so the two records can be linked. This server is operated by JJRE and is not a third party.

We do not share, sell, rent, or transfer user data to any third party, advertising network, data broker, or analytics provider. Transmissions to the internal server are made over a secure (HTTPS) connection.

5. Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

6. Data retention and deletion

Locally stored settings persist until the user clears them from the extension's options or uninstalls the extension, which removes all locally stored data. Record URLs sent to the internal automation server are retained only as needed to maintain the ticket-to-invoice links within JJRE's systems.

7. Changes to this policy

If our data practices change, we will update this policy and revise the "Last updated" date above, and disclose material changes to users where required.

8. Contact

Questions about this policy or the data CAO Connect handles can be directed to privacy@jeffjones.com.au.