Are coupon extensions safe? Honey, Rakuten & Capital One Shopping privacy review
Coupon and cashback extensions watch every site you visit. I review Honey, Rakuten, and Capital One Shopping on permissions, privacy, and the affiliate mess.

You install a coupon extension because it promises free money. It scans the checkout page, finds a code, and shaves a few dollars off your order. Feels like a no-brainer.
But here's the part nobody puts in the install pop-up: to do that, the extension watches every single site you visit — not just the shopping ones.
I've spent a while staring at the permission strings on these things, and the gap between "saves you money" and "sees everything you do online" is wider than most people realize. So let's go through the big three — Honey, Rakuten, and Capital One Shopping — and figure out whether the discount is worth the trade.
Quick verdict
- They all read every page you visit. Coupon and cashback extensions request the "read and change all your data on all websites" permission. That's the maximum a browser hands out.
- Honey is the cautionary tale. A 2024 investigation and 20+ class-action lawsuits accuse PayPal's Honey of quietly swapping affiliate codes. PayPal disputes the allegations, and the legal picture is still unsettled.
- Rakuten's own privacy notice says it collects the pages you browse to surface offers — and your data can flow across Rakuten's wider business.
- Capital One Shopping comes out as the most transparent of the three, but it still wants the same broad access.
- My take: the savings are real, but so is the surveillance. Run them only when you're shopping, or skip them for built-in browser tools.
What these extensions actually do
The pitch is simple. At checkout, the extension auto-applies coupon codes (Honey's specialty) or routes your purchase through an affiliate link so the retailer pays a cashback rebate (Rakuten and Capital One Shopping's model). Some do both.
To pull this off, they need to know what page you're on, when you reach a checkout, and which retailer you're buying from. The cleanest way to build that is to request access to all sites and watch passively until you land somewhere relevant. Convenient for them. Less convenient for your privacy, because that same access works just as well on your bank's site, your webmail, and your medical portal.
Security analysis: the permission footprint
Every one of these extensions asks for host access to all URLs plus the ability to read your tabs and navigation. In manifest terms, that's <all_urls> host permissions — the single most powerful grant in the extension model. I broke down exactly what that unlocks in my earlier piece on the "all sites" host permission, and the short version is: an extension with it can read and modify the content of any page you open.
That doesn't make a coupon extension malware. Honey, Rakuten, and Capital One Shopping are real businesses with real privacy policies, not the history-exfiltration extensions I've written about before. But the technical capability is identical. The only thing standing between "saves you money" and "logs your browsing" is the company's own policy and restraint — and those vary a lot.
The risk also isn't only about the original developer. Coupon extensions have huge install bases, which makes them attractive acquisition targets. When an extension changes hands, the new owner inherits all those permissions and all those users. That's the scenario where broad access turns from a convenience into a liability.
The Honey problem
Honey is the reason this whole category got a second look. In December 2024, a YouTube investigation by the creator MegaLag alleged that Honey was overwriting affiliate tracking cookies at checkout — taking credit for sales that influencers and other publishers had actually driven. The fallout was fast: Honey lost roughly 3 million users within two weeks, and by the end of 2025 reports put the drop closer to 8 million.
More than twenty lawsuits followed, now consolidated as In Re PayPal Honey Browser Extension Litigation, with creators including Wendover Productions and GamersNexus among the plaintiffs. The allegations include affiliate-link manipulation and unjust enrichment. PayPal has defended the extension, telling The Verge that "Honey follows industry rules and practices, including last-click attribution" — the standard model that credits whoever delivered the customer's final click before purchase.
The courts haven't settled it. A federal judge denied PayPal's attempt to push the case into private arbitration in November 2025, but then dismissed one creators' complaint with leave to amend, finding it didn't yet plead a concrete injury.
So as of mid-2026, this is an active, contested case — not a proven finding of wrongdoing. PayPal has also said it disabled certain code in January 2026 in response to the affiliate concerns.
One concrete outcome did stick: in March 2025, Google tightened its Chrome Web Store policies so extensions can't claim affiliate commissions without giving users a real, disclosed benefit. That's a category-wide change, and it's a decent litmus test for any shopping extension you're considering.
Privacy breakdown: how I'd score them
I won't put a fake number on any of these — go pull the live report and judge for yourself. But the privacy story breaks down along the same axis for all three: how much they collect, and how clearly they tell you.
Rakuten is upfront in its own browser extension privacy notice that it collects the pages you visit so it can surface offers. The catch is scope: independent analyses note it monitors activity across all sites, not just shopping ones, and that data can move across Rakuten's broader empire of e-commerce, payments, and more. Disclosed, but expansive.
Capital One Shopping is, by most accounts, the most transparent of the three. One safety review describes its collection as moderate and clearly documented, with data tied to your account if you link it. Still broad access, but less murky about what happens next.
Honey is hard to score on privacy alone right now, because the live controversy is about affiliate mechanics, not data sale. The lesson isn't "Honey reads your email" — it's that the same permission that powers coupons also powers behavior you'd never approve at install time. As I keep saying in my breakdown of extension privacy policies, the fine print is where the real product lives.
Alternatives worth considering
You don't have to choose between "save money" and "leak your browsing." A few middle paths:
- Use your browser's built-in shopping features. Microsoft Edge ships coupon and cashback tooling natively, which means no third-party extension and no extra all-sites grant. If you're already on Edge, that's the lowest-permission option by default.
- Run the extension only when you shop. Pin it, disable it, and flip it on right before checkout. Chrome and Edge both let you restrict an extension to "on click" so it doesn't watch your non-shopping browsing.
- Pick the most transparent option and link the least. If you want a standalone tool, Capital One Shopping's clearer documentation makes it the easier one to reason about. Don't link more accounts than the rebate requires.
None of these are perfect. Cashback fundamentally depends on the extension seeing where you shop. But "only when shopping" cuts the surveillance window from "always" down to "a few minutes a week," and that's a real reduction.
Final recommendation
Coupon extensions aren't a scam by default, and I'm not telling you to rip them out in a panic. The savings are genuine, and the mainstream ones are run by real companies with policies you can actually read.
But treat the all-sites permission as the price tag it really is. If an extension can see your bank and your inbox just to find a 10%-off code, that's a trade — make it on purpose. My rule: enable on click, keep account linking minimal, and check the security report before you trust any shopping extension with full access.
Want to see exactly what permissions Honey, Rakuten, or Capital One Shopping request before you install? See the security report → in the Extenshi catalog, or scan the extensions you already have to find which ones are quietly watching every tab.
This article is based on publicly available security research and news reporting. Extenshi does not independently verify all claims made by third-party researchers. References to specific companies or products reflect the findings of cited sources and do not constitute accusations of intentional wrongdoing. If you believe any information is inaccurate, please contact us at [email protected].
Related Articles

Are translation extensions safe? Google Translate, DeepL & Immersive Translate privacy review
Translation extensions read the full text of every page you translate. I review Google Translate, DeepL, and Immersive Translate on permissions and data flow.

Extension privacy policies explained: what 'we may sell your data' actually means
LayerX found 82 Chrome extensions legally sell 6.5M users' data via buried privacy policies. Here's how the fine-print loophole works and how to check yours.
Host permissions explained: what 'read and change all your data on all websites' really means
Browser extension host permissions let extensions read and change every website you visit. Here's what that warning actually means and when to be concerned.
Ad blocker extensions reviewed: Stands AdBlocker, Poper Blocker & safer alternatives
Some ad blockers that sell your data are among the most installed on Chrome. LayerX flagged 12 — here's the breakdown of the worst and safer 2026 alternatives.