Overview
Cardpad is a browser extension that gives developers keyboard-shortcut access to Stripe test cards, with autofill on checkout forms and clipboard fallback. We are committed to protecting your privacy.
Data Collection
Cardpad does NOT collect, store, or transmit any personal data.
The extension makes zero network requests. All test card data is bundled with the extension and runs locally in your browser.
What we access locally (never transmitted):
- Active tab : When you invoke the keyboard shortcut, the extension injects the command palette overlay on the current tab. It also fills detected card-number, expiry, and CVC input fields when you press Enter on a card.
- Clipboard (write only) : When autofill is not possible (for example, on cross-origin Stripe Elements iframes), the extension writes the card number to your clipboard so you can paste it manually. The extension never reads your clipboard.
What we do NOT collect:
- Personal information
- Browsing history
- Form data or passwords
- Analytics or usage data
- Cookies from websites you visit
- The contents of any input field, including pre-existing values
Permissions Explained
| Permission | Why it's needed |
|---|---|
activeTab |
Granted only on the tab where you press the keyboard shortcut. Lets the extension inject the command palette overlay on that tab. The extension does not request any host permissions and does not run on tabs you have not activated it on. |
scripting |
To run the injected palette and autofill helper on the active tab |
clipboardWrite |
To copy card numbers and PaymentMethod ids to your clipboard |
Data Storage
The extension stores no data. If a future release adds preferences
(such as custom shortcuts or remembered last-used cards), those will
be stored only in your browser using Chrome’s
storage.local API, and we will request the
storage permission and update this policy at that time.
No data is ever transmitted off your device.
Test Card Data
The card numbers, PaymentMethod ids, and metadata bundled with this extension are sourced from the public Stripe testing documentation at https://docs.stripe.com/testing. They are test values only and are not real payment instruments. The extension is not affiliated with Stripe; “Stripe” is a trademark of Stripe, Inc.
Third Parties
Cardpad does not share any data with third parties. There are no analytics, tracking, or advertising components. The extension does not communicate with Stripe, Zorrotheo Technologies, or any other service.
Changes to This Policy
If we make changes to this privacy policy, we will update the “Last updated” date above.
Contact Us
If you have questions about this Privacy Policy, please contact us:
Reach us anytime at
support@zorrotheo.com