PointsYeah Extension — Privacy Policy

Effective date: October 2, 2026
This policy describes what the PointsYeah browser extension does with information. It covers the extension and the match request the extension sends to PointsYeah. It does not cover the PointsYeah website beyond the sign-in the extension uses.
What the extension does
PointsYeah adds award prices — in points and miles — to flight results on travel sites you already use. To do that, it sends the flight you are looking at to PointsYeah and shows the answer next to that result. It does not book flights.
Information the extension handles
Account email. When you sign in, the extension reads the email address on your PointsYeah account and stores it on your device, so the popup can show who is signed in. The extension does not send your email with match requests.
Sign-in token. The extension reads your PointsYeah website session to obtain a sign-in token, and stores that token on your device along with its expiry and whether the account is a premium account. Each match request sends this token in the Authorization header. Because the token identifies your account, PointsYeah can associate a match request with your account. The premium flag is stored on your device for display and is not sent with match requests.
Flight search details. For a result the extension can price, it sends PointsYeah: the cabin, the departure and arrival airports, the date, the flight numbers, and, when the travel site shows them, the cash price and its currency. It does not send passenger names.
Filter preferences. The programs you choose to show, and any maximum points price or maximum taxes you set, are stored on your device. They are not sent to PointsYeah or to anyone else.
Information the extension does not collect
  • Your password, cookies, or session token for any travel site, including Chase Travel, Amex Travel, Capital One Travel, Citi Travel, Kayak, and Expedia. Match requests are sent with credentials omitted, so no cookie from the travel site is attached to them.
  • Payment card numbers, bank account numbers, or passport details.
  • Your name, address, or contact details beyond the account email above.
  • Browsing history outside the supported flight-search pages.
  • The extension contains no advertising and no third-party analytics.
Two requests carry cookies, and neither sends a travel site's cookies to PointsYeah. The sign-in request to the PointsYeah website uses your existing PointsYeah session to obtain the token; those cookies go only to PointsYeah. On Chase Travel, the extension also asks Chase Travel for the details of the search you are viewing (see below); that request goes only to Chase Travel, with the Chase Travel cookies your browser already sends to that site.
How information is used
Flight search details and the sign-in token are sent to PointsYeah for one purpose: to return award matches and show them on the result. The email and the premium flag are used only to show your sign-in state in the extension.
PointsYeah does not sell this information. It does not use it for advertising, and it does not use it to assess creditworthiness. It does not transfer it to data brokers, advertising networks, or credit-reporting agencies.
Where information goes
Match requests are sent to PointsYeah's API at api.pointsyeah.com, as an HTTPS POST, with the sign-in token in the Authorization header and with no cookies attached. The sign-in token is obtained from the PointsYeah website you are signed in to.
On Chase Travel, the extension sends one request to Chase Travel itself to read the details of the search on the page (airports, dates, cabin), the same way the page loads them. On the other supported sites, the extension sends nothing to the travel site. On every site, the extension reads flight results the site has already loaded; it does not modify the site's requests or responses.
Where information is stored
On your device, the sign-in token, its expiry, your email, your premium status, and your filter preferences are stored in the extension's local storage (chrome.storage.local). They stay on your device.
Signing out of PointsYeah deletes the token, email, and premium status from the device. An expired token is also deleted. Uninstalling the extension removes everything the extension stored locally. Filter preferences stay on the device until you change or clear them, or until you uninstall the extension. Signing out does not clear them.
On PointsYeah's servers, a match request arrives together with your sign-in token, so it can be associated with your account. This policy does not state how long PointsYeah keeps those requests, because the extension does not control that. To ask what is held or to ask for it to be deleted, use the contact below.
Your choices
  • Sign out to delete the token and account details stored on your device.
  • Use the filters to limit which results are marked.
  • Uninstall the extension to remove everything it stored locally.
  • Write to the contact below to ask about the match requests associated with your account, or to ask for them to be deleted.
Changes
If the extension starts sending anything this policy does not describe, this policy will be updated first, and the date above will change. The Chrome Web Store privacy disclosure is written from this policy and has to match it.
Contact