AwardChecker privacy policy
Effective October 1, 2026.
AwardChecker reads the awards in a Hyatt account that is already signed in through Chrome. The user signs in directly on Hyatt; AwardChecker does not ask the user to enter a Hyatt password.
Ordinary checks
After the user grants optional access to hyatt.com, the extension makes fixed profile and award requests in the selected Hyatt tab. It filters Hyatt's responses to the account identity and award fields needed for the checker. The current masked identity and grouped inventory are kept in Chrome session storage. Ordinary checks do not send the Hyatt session or inventory to AwardChecker's verifier.
Hyatt session expiry
The companion uses Chrome's cookies API to read Hyatt's HttpOnly oscar sign-in cookie locally, after the user grants Hyatt access. It stops requests 60 seconds before the token's declared expiry or, if earlier, Chrome's cookie expiry. It reads the current cookie before each direct profile or award request. Page-driven checks and automated gift actions use the deadline captured at the start; the verifier also checks token expiry before each Hyatt read. This applies to sign-in watching as well as ordinary checks and marketplace features. It does not assume a fixed login duration or extend an old token's deadline when it is read again. If expiry cannot be determined or the deadline is reached, the member opens Hyatt normally to refresh their sign-in before retrying. Normal Hyatt navigation may refresh a token while the member remains signed in.
The expiry guard processes cookie and token contents temporarily. It adds no stored cookie values or authentication data transmission beyond the temporary session headers described below.
Temporary live sharing
When the user selects Create 10-minute code, and during subsequent refreshes while that panel stays open, the extension sends an allowlisted set of temporary Hyatt session headers and the expected account identifier over HTTPS to the AwardChecker verifier hosted through Vercel and Modal. These authentication headers can grant broader Hyatt account access. The verifier uses them only for fixed, read-only Hyatt profile and award requests.
Session headers and full Hyatt responses are processed temporarily in memory. The application does not deliberately write them to extension storage, verifier records, analytics, or application logs. JavaScript cannot promise immediate erasure of every in-memory copy. Vercel, Modal, Hyatt, and their infrastructure providers process requests and ordinary connection metadata as part of delivering the feature.
Shared data and retention
For each active code, the verifier stores an encrypted record containing first name and last initial, the last four account characters, grouped award titles and counts, expiry dates, transferability or received indicators, and the latest verification time. Full membership numbers, certificate numbers, Hyatt session headers, and the bearer code are excluded from the encrypted record. The code is represented in storage only by a one-way-derived opaque identifier; the owner control key and account identifier are also stored only as hashes.
Codes expire ten minutes after creation. The owner can stop sharing earlier. Expired records are deleted during service cleanup. Infrastructure backups may follow provider retention schedules, so immediate physical removal from every underlying backup is not promised.
Anyone who receives a valid code can view and forward the minimized status until it expires or the owner stops it. A recipient can save a screenshot or copy. “Live” means the verifier successfully checked Hyatt within the previous 90 seconds; older results are labeled “Last checked.” A status does not reserve or transfer an award.
Use of data
AwardChecker does not sell personal data, use it for advertising, or use it for lending or credit decisions. The extension includes no advertising or analytics SDK. Data is used only to provide the disclosed award checking, temporary sharing and marketplace features.
Marketplace
The marketplace website at award-marketplace.vercel.app lets members list awards, make offers, and coordinate an exchange in a private conversation. Browsing public listings does not require an account. The local marketplace preview contains synthetic data only; it displays test sign-in codes and sends no email.
Signing in
Members sign in with a one-time code sent to their email address, or with Google. There are no AwardChecker passwords. Supabase Auth, operated by Supabase Inc., confirms the email address: it stores the account's email address, the sign-in methods used and sign-in timestamps, and sends sign-in code emails through the configured email provider. With Google sign-in, Google authenticates the user and shares the account's verified email address and basic profile (name and picture) with Supabase; AwardChecker uses only the email address and first name. When the first name fits AwardChecker's display-name rules, it becomes the display name other members see; otherwise, and for sign-ins by email code, the member chooses a display name after the email address is confirmed.
Once the email address is confirmed, AwardChecker issues its own sign-in session in an HttpOnly cookie and immediately ends the Supabase session. The browser does not receive Supabase or Google tokens. Signing out removes the AwardChecker session.
Your name and setup answers. After you confirm your email, you choose the display name other members see on your listings, offers and messages; new display names are never taken from your email address, members whose earlier name was made from their email are asked to choose one when they next sign in, and you can change your name once every 30 days. During setup we may ask where you first heard about AwardChecker. The answer is optional, is stored with your membership, is visible only to AwardChecker moderators, and is used only to understand where members come from. The sign-in page remembers on your device which sign-in method you used last, and the tab you signed in from keeps a pending code step for up to 10 minutes; neither is sent to AwardChecker.
Marketplace records
Member profiles, listings, offers, conversations, recipient details, agreed instructions, participant statements, check results, reports and moderation records are encrypted by the AwardChecker service (AES-256-GCM) before they are stored in a Supabase-hosted Postgres database in the United States. The database stores only ciphertext with opaque record identifiers; the encryption key is held by the AwardChecker service, not by Supabase. Vercel, Modal and Supabase process requests and ordinary connection metadata as part of delivering the service.
Marketplace checks require a one-time consent in the Chrome companion, given in a small AwardChecker window before Chrome's own Hyatt permission prompt. The consent record (the marketplace address, the disclosure version and the time) stays in Chrome's extension storage until the member disconnects on the marketplace or removes the extension's Hyatt access; it survives browser restarts and extension updates. While a member uses the marketplace (opening My awards, publishing or relisting an award, or choosing a check), the website may ask the companion for a check. Each check temporarily sends the same limited set of Hyatt session headers described above to the verifier. Only fixed profile and award requests are made; the website does not receive those headers. If no Hyatt tab is open, the companion opens Hyatt in a background tab for that read and closes it afterwards; if Hyatt needs the member to sign in, it opens Hyatt's own sign-in page in a new tab and, while the member signs in (for example through Hyatt's emailed link), reads only the Hyatt profile in open Hyatt tabs to notice when the sign-in is complete. To show whether Hyatt is still signed in, the companion may read only the Hyatt profile in an open Hyatt tab, and it keeps the resulting state and the masked account (last four characters) in Chrome session storage; the website learns only that state and the masked account. When a member asks the website to fill in their own gift recipient details (a buyer making a buy request or trade offer, or a seller accepting a trade), the companion reads the Hyatt profile in an open Hyatt tab (or in a background tab it then closes) and gives that marketplace page the member's first name, last name and full member number for that request only; the companion does not store them. Disconnecting does not delete earlier check evidence or an exchange history.
Public listings contain a display name, membership date, award type, expiry, asking price, listing note and check time. They do not reveal email, full Hyatt membership numbers or certificate numbers. Account bindings and certificate references are stored as keyed hashes. The seller may see a short certificate suffix to distinguish their own awards. Buyer recipient details are shared only within an accepted exchange after the buyer consents. Do not submit passwords, card details or bank credentials in conversations or instructions.
Marketplace payment is arranged directly between members. AwardChecker does not receive payment credentials, hold funds, process refunds or infer payment success from a member's confirmation. Member confirmations and independently checked facts are kept separate. Reports and necessary moderation details are available to the operator, but moderator status does not by itself grant participant access to a private conversation. Recipient details go only to the other member of that exchange: a buyer's name and member number to the seller who sends the award, and in a trade, the seller's name and member number to the buyer, who sends their award first. When an exchange needs a member's attention (for example a new buy request or offer, an accepted offer, the seller's commitment to send, a confirmation from the other member, or a delivery), AwardChecker emails them a short notice through its email provider, Resend. The notice names the award and price and links to the exchange; it never includes member numbers, payment instructions or conversation messages. No marketing emails are sent.
Assisted gifting
For a trade a member sets up in an AwardChecker trade room, and only after that member explicitly confirms it, the Chrome companion completes the Hyatt side of the gift for them. It fills in Hyatt's own “Gift Your Award” form — the recipient's membership number and last name, taken from that trade's own signed record on AwardChecker's server, never typed by the member and never read from a marketplace web page — and submits it in the member's own, already-open Hyatt tab. The gift request travels directly from the member's browser to Hyatt: the AwardChecker service never sends it and never holds the certificate code being gifted. Hyatt's own step-up check (a code emailed to the member) still requires the member's own action; the companion does not see or enter it. Assisted gifting stores nothing beyond the trade record already described above, and it never acts except on a trade the member set up and confirmed themselves.
Support chat
The marketplace website has a chat button for questions and feedback, provided by Crisp (crisp.chat). Crisp's chat loads only after you select the button, or in the background on a device that has used the chat before, so that replies can reach you. Crisp stores the messages and files you send and the details of your visit its chat needs (such as your IP address, browser and the page you're on), and sets a cookie on this website so a conversation continues across visits. When you're signed in, AwardChecker also gives Crisp your email address, display name and member identifier, so we know who we're talking to. Signing out starts a new conversation on that device. Don't send passwords, card details, bank credentials or Hyatt member numbers in the chat.
Retention and deletion
Marketplace records are kept while the member's account is active and while an exchange or report they are part of remains open, because the other participant relies on the shared exchange history. Automatic deletion is not yet in place. A member can ask for their account and personal details to be deleted by emailing williezhou@gmail.com; where another member's exchange record depends on it, personal details are removed or replaced and the minimal record needed for that exchange is kept. Sign-in sessions expire after seven days and unused sign-in requests after ten minutes. Infrastructure backups follow the providers' retention schedules.
The early-access waitlist has closed; sign-up is open on the marketplace website.
AwardChecker is independent from Hyatt. Questions and deletion requests can be sent to williezhou@gmail.com.