Privacy policy for Library Seats SG - for NLB
Library Seats SG - for NLB by Triple Tweaks Lab
Privacy policy for Library Seats SG - for NLB
Effective date: 24 August 2026
Library Seats SG - for NLB ("Library Seats SG", "the extension") is a free,
independent Chrome and Firefox extension maintained by the Library Seats SG project. It
works only on the National Library Board Singapore (NLB) Seat Booking website.
Library Seats SG is not affiliated with, endorsed by, sponsored by, or supported
by NLB. "NLB" is used only to identify the service with which the extension
works.
This policy explains the information the extension handles, why it is needed,
where it goes, and how users can delete it. In this policy, "handle" includes
information processed only on the user's device; it does not mean that the
developer receives that information.
- Library Seats SG has no developer-operated server, advertising, analytics, or
tracking. - The developer does not receive users' NLB account information, bookings,
favourites, browsing activity, or extension usage data. - The extension does not ask for an NLB password, request browser cookie
permission, or read browser cookies directly. - The extension uses the NLB session already active in the Seat Booking tab.
The browser attaches that session to same-origin NLB requests. - Favourite seats, saved areas, and pseudonymous profile preferences are kept
in the browser's extension-local storage on the user's device. - Account, booking, quota, catalog, and availability information is processed
in memory and is not persistently stored by the extension. - Booking and cancellation requests are sent only to NLB after the user
reviews and confirms them.
When the NLB Seat Booking page is open, the extension may retrieve and process:
- the current NLB account identifier and signed-in state;
- account quota and current or upcoming booking details;
- library, area, seat, operating-hour, holiday, and booking-rule information;
- seat and time-slot availability; and
- seat-plan image URLs and images supplied by NLB.
This information is used only to show the extension interface, associate the
current session with the correct local profile, display availability and
bookings, validate requested actions, and reconcile results from NLB.
The complete NLB account identifier is used transiently in memory. It is
combined with a random installation-local secret to derive a pseudonymous
profile identifier. The complete identifier is not written to extension storage
or rendered in the page by the extension. The interface may show a masked
version that preserves the first and last character and replaces the middle
characters with asterisks.
The extension handles choices made in its interface, including:
- favourite seats;
- the last selected library and area;
- dates, seats, and time slots selected for review;
- booking and cancellation confirmations and an NLB cancellation reason;
- Guest-favourite copy preferences; and
- acknowledgement of the first-use privacy and session disclosure.
Dates, time slots, booking confirmations, cancellation choices, and
cancellation reasons are kept in memory only, except when sent to NLB to carry
out an action the user confirmed.
Library Seats SG does not collect an NLB password or authentication token and does
not read cookies directly. Requests to NLB use
credentials: "include", whichallows the browser to attach the existing same-origin NLB session automatically.
When the user starts sign-in, the extension stores a timestamp-only pending
sign-in marker in the NLB page's
sessionStorage. It contains no accountidentifier or credential, expires after five minutes, and is removed after
sign-in completes, on sign-out, when all extension data is cleared, or when
the page session ends.
Library Seats SG uses the WebExtensions
storage permission only for localextension storage. It may store:
- a random 256-bit installation-local secret used to derive pseudonymous
profile identifiers; - pseudonymous profile identifiers, their stable Profile N display order, and
the last active local profile; - Guest and per-profile favourite-seat records, including NLB library, area,
and seat identifiers, codes, and names; - the last selected library and area for Guest and each profile;
- each profile's signed-out favourite sync decision and the favourite identities
already acknowledged by that decision; - the installation's default adjacent-hour booking mode;
- the storage schema version; and
- whether the first-use privacy and session disclosure was acknowledged.
This local information is not sent to the developer, an analytics provider,
an advertising provider, or any other third party by extension code. It is
not stored using a browser's synced-storage service.
Account details, bookings, quotas, availability results, and seat-plan images
are not written to extension-local storage by the extension. The browser, the NLB
website, or the browser cache may independently retain information under their
own settings and policies.
Information is handled only when necessary to provide the extension's single
purpose: helping a user view NLB seat availability and manage their own NLB
seat bookings.
Library Seats SG uses information to:
- display libraries, areas, seats, rules, availability, quota, and bookings;
- keep Guest and signed-in account preferences separate;
- show which account profile is currently active;
- remember favourite seats and the last selected area;
- check quota, availability, conflicts, and NLB booking rules;
- submit a booking or cancellation only after confirmation; and
- refresh and reconcile the result reported by NLB.
The information is not used for advertising, profiling, credit decisions,
sale, unrelated product development, or behavioural analytics.
Extension code sends information only to NLB over HTTPS when required for the
feature the user is using. For example, selected seat and time information is
sent to NLB when a booking is confirmed, and a booking identifier and reason
are sent to NLB when a cancellation is confirmed.
The extension does not sell user data or transfer it to the developer, data
brokers, advertisers, analytics services, or unrelated third parties. The
developer cannot allow staff or other people to inspect information that the
developer never receives.
Project, privacy, support, and security links open GitHub only after the user
chooses them. Visiting GitHub is governed by GitHub's own privacy policy; the
extension does not automatically send local profile or NLB account data with
those links.
Information held only in memory normally disappears when the Seat Booking tab
is refreshed or closed. The pending sign-in marker expires after five minutes
and also ends with the page session.
Information in extension-local storage remains until the user removes it, the
extension is uninstalled, or the browser clears the extension's storage.
The extension's Settings screen provides separately confirmed controls to:
- clear Guest favourites and its saved area;
- clear favourites and the saved area for the current profile while retaining
its stable Profile N identity; - clear all data owned by Library Seats SG.
Settings shows only Guest while signed out. While signed in, it shows Guest and
the current account; other saved account profiles and their preference counts
remain hidden. People sharing one browser profile still share its extension
storage, so separate browser profiles or a browser guest mode should be used
on a shared computer.
Clearing extension data does not sign the user out of NLB, cancel a booking,
or delete information held by NLB. Users can also remove all extension-local
data by uninstalling Library Seats SG through the browser.
On a shared or public computer, sign out of NLB first and then use Clear all
local data. Clearing while an NLB account remains signed in can cause a new
empty local profile to be created when the extension refreshes that session.
Each unpacked, Chrome Web Store, and Firefox Add-ons installation has separate
extension storage. Local favourites and settings do not automatically transfer
between installations or browsers.
Library Seats SG limits its content script to
https://www.nlb.gov.sg/seatbooking/*, requests only the browser's storagepermission, and packages all executable code with the extension. It does not
load remote executable code.
NLB requests use HTTPS and are made sequentially where required to reduce
duplicate-action and service-load risk. Malformed, failed, timed-out, or
ambiguous availability is treated as unavailable rather than bookable.
No software can promise absolute security. Please do not include NLB account
identifiers, booking references, cookies, raw account responses, or personal
screenshots in a public support report.
Library Seats SG's use and transfer of user information complies with the Chrome
Web Store User Data Policy, including its Limited Use requirements. The
extension handles user information only as necessary to provide or improve
its disclosed, user-facing seat-booking purpose. It does not use or transfer
user information for personalised advertising, unrelated purposes, or sale to
third parties.
The Firefox manifest declares
authenticationInfo, websiteActivity, andwebsiteContent as required data categories. These declarations describe theNLB session state and NLB Seat Booking information processed locally to provide
the extension's features. They do not mean that this information is collected
by or sent to the developer. The extension has no optional data collection and
no technical or interaction telemetry.
Firefox private browsing is disabled for the extension. This prevents NLB
session activity from a private window from being combined with preferences in
the normal profile's extension-local storage.
NLB controls its accounts, authentication, availability, bookings,
cancellations, website, APIs, and records. Information held by NLB is governed
by NLB's own terms and privacy practices. Chrome, Firefox, the Chrome Web Store,
and Firefox Add-ons may process installation or browser information independently
under Google or Mozilla policies. This policy covers only information handled
by Library Seats SG code.
This policy will be updated when the extension's information-handling
practices change. Material changes will be disclosed in the extension or its
applicable browser-store listing before or when the changed practice takes
effect, as required. The effective date at the top records the latest revision.
For privacy questions, open a
GitHub issue.
GitHub issues are public, so do not post personal, account, booking, or
authentication information there. If a question cannot be discussed publicly,
open an issue requesting a private contact method without including the
sensitive details.
For a vulnerability or another report that should remain private, use
GitHub's private security advisory form.