Knockout / Privacy

Privacy policy

Last updated: 2026-10-10

Publisher: mjumartin Contact: chrome-dev@mju.se

Knockout is a tool for testing OCI, cXML and PEPPOL punchout sessions. It has no analytics, advertising or developer-operated data collection server.

Information handled

Knockout handles the information you enter: supplier endpoint URLs, usernames, passwords, buyer identifiers, names, custom XML templates and password preferences. It stores saved entries in your local Chrome profile, not Chrome sync. Stored-mode passwords are unencrypted. Ask on execute does not persist the password in an entry; 1Password mode stores a secret reference instead of the resolved password. Custom templates and supplier responses can independently contain sensitive data.

Session history stores session names, supplier URLs, timestamps, status/errors, returned form fields and raw/decoded content. Returned carts can contain names, addresses, product descriptions, quantities and prices. Knockout reads tab URLs for active punchout sessions to request access to redirected storefronts. It does not collect a general browsing history.

Transfers and services

When you choose Execute, credentials and setup fields are sent directly to the supplier you select. Supplier pages control their own cookies, authentication and shopping workflows, subject to the supplier's privacy policy. Remote setup URLs require HTTPS. Loopback HTTP is available for local testing with dummy data. The postback address is https://localhost:13371; a fallback network request may attempt to reach that address. Knockout does not operate a callback server.

Optional 1Password integration uses a locally installed helper and your signed-in 1Password desktop app to resolve a secret reference. The helper stores the account name and permitted extension ID locally and does not store retrieved passwords. 1Password's service practices are described at 1Password privacy policy. The bundled helper supports macOS Apple Silicon. Stored and Ask on execute modes do not require it. Downloaded exports remain wherever you save them.

No session data is sent to the Knockout publisher. Data is not sold or used for advertising, creditworthiness, lending or unrelated purposes. Knockout's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Retention and control

Saved entries and history remain locally until deleted or the extension is removed. Delete an entry to remove its stored fields/password. Changing from Stored to another password mode and saving removes that entry's stored password; it does not alter custom templates or previously captured responses. Delete individual history records or use Clear history to erase captured results. Remove the extension to clear its Chrome storage, including configured endpoints. Chrome's extension settings let you revoke site access.

Exports, supplier-side records and helper installation/configuration are not removed by uninstalling the extension. Remove downloaded files yourself. Remove ~/Library/Application Support/Knockout/onepassword/ and ~/Library/Application Support/Google/Chrome/NativeMessagingHosts/com.knockout.onepassword.json to uninstall the macOS helper. Manage supplier and 1Password data with those services.

Changes and questions

This policy will be updated when data practices change; material changes will also be disclosed in the extension. Contact the publisher at the address above for privacy questions.

This website

This static website uses no analytics, cookies, forms or third-party scripts. The hosting provider, Microsoft Azure, may process technical request information such as IP addresses to deliver and secure the site. Emailing support shares the information you choose to include with the publisher; do not include passwords or private supplier payloads.