OnboardMe

Terms & policies

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Electronic records & signature disclosure
  • Chrome extension privacy
  • Google user data

Trust & security

  • Information security & business continuity
  • Subprocessors
  • Data storage & backups
Contact usLog in

© 2026 OnboardMe Pty Ltd

OnboardMe Assist Chrome extension

Last updated August 2026

Summary

This notice explains what the OnboardMe Assist Chrome extension handles, and that it only fills empty fields in Xero Practice Manager using information already held in OnboardMe. It supplements our Privacy Policy, Data Processing Agreement, Terms of Service, and Security Policy.

About this extension

OnboardMe Assist is a Chrome extension operated by OnboardMe Pty Ltd. Its single purpose is to help practice users look up bank details and identity verification outcomes already held in OnboardMe, and fill only empty fields on Xero Practice Manager client tax pages.

This notice supplements our Privacy Policy, Data Processing Agreement, Terms of Service, and Security Policy. Use this URL for Chrome Web Store privacy disclosures for the extension.

What data the extension handles

  • Session API credentials — route key, client ID, and client secret used to call the OnboardMe Extension API. These are stored only in Chrome storage.session for the current browser session and are cleared when the session ends or the user disconnects.
  • Client lookup results — display name / identifiers, bank account fields, and identity verification status fields returned by the OnboardMe API for the client the user selects or that matches the open Xero Practice Manager page.
  • Page context on Xero Practice Manager — the extension reads the client URL / UUID and which bank or ID fields on the open tax page are empty, so it can fill only empty fields.

The extension does not sell data, show ads, track browsing outside OnboardMe and Xero Practice Manager, or send data to unrelated third parties.

How data is used (Limited Use)

Data accessed by the extension is used only to:

  1. Authenticate the practice user's Extension API session
  2. Retrieve the bank / ID fields needed for the open or selected client
  3. Write those values into empty fields on the matching Xero Practice Manager page at the user's request (including automatic fill of empty fields when connected)

Financial and personal identifier fields are used solely to provide this assist feature. They are not used for advertising, unrelated analytics, or sale / transfer for other commercial purposes.

Sites the extension can access

  • https://*.onboardme.app and https://onboardme.app — detect installation, receive session credentials from the signed-in OnboardMe app, and call regional OnboardMe APIs
  • https://practicemanager.xero.com and https://app.practicemanager.xero.com — read empty field state and fill empty bank / ID fields

Localhost hosts are used only in development builds and are not included in the Chrome Web Store package.

Storage and retention

  • Credentials are session-scoped in the browser and are not written to long-lived extension storage.
  • Looking up or filling fields does not create a separate OnboardMe database of extension activity beyond normal API audit / application logging that already applies to authenticated API use.
  • Users can disconnect from the extension side panel or remove Extension API access from OnboardMe Profile → Chrome extension.

Permissions (summary)

  • storage — session credentials and connection state
  • sidePanel — the Assist UI
  • tabs — find the open Xero Practice Manager client tab
  • scripting — reinject the XPM content script when needed after updates or navigation
  • Host permissions — limited to OnboardMe and Xero Practice Manager hosts listed above

Contact

Privacy questions about OnboardMe Assist:

  • Email: [email protected]
  • Security: [email protected]
  • Website: onboardme.app