What This App Is
The PayPal-Owned Browser Monitor
Honey is a browser extension and mobile application designed to automate the application of coupon codes at e-commerce checkouts. Acquired by PayPal in January 2020 for a reported $4 billion, the tool operates on a “freemium” data-exchange model. While users pay no currency to install the software, they grant Honey extensive permissions to monitor, read, and modify browser activity on retail websites. The application claims to find the best available discounts by mechanically testing known promo codes against the contents of a user’s shopping cart.
The tool functions primarily as an affiliate marketing overlay. When a user installs the extension on Chrome, Safari, Firefox, or Edge, Honey gains the ability to detect when a checkout page loads. It then injects scripts to test codes. If a purchase is completed, the merchant pays Honey a commission, 1% to 15% of the transaction value. Honey shares a fraction of this revenue with the user in the form of “PayPal Rewards” (formerly Honey Gold), which can be redeemed for gift cards or cash.
Since the PayPal acquisition, Honey has shifted from a standalone savings tool into a data ingestion point for PayPal’s broader financial ecosystem. The software integrates deeply with PayPal’s risk and marketing algorithms, using shopping history to build consumer profiles. In late 2024 and early 2025, the platform faced significant scrutiny and user attrition following allegations of “link hijacking,” where the extension reportedly overwrote affiliate cookies from other content creators to claim commissions for itself.
At a Glance: Honey Data Profile
| Owner | PayPal, Inc. (Acquired 2020) |
| Primary Function | Automated Coupon Injection & Price Tracking |
| Revenue Model | Affiliate Commissions (Merchant pays Honey) |
| Data Collection | Browsing history, cart contents, purchase behavior, device ID |
| Key Permission | “Read and change all your data on the websites you visit” |
| Active Users | ~17 Million (Est. early 2026) |
| Risk Level | Moderate (Privacy) to High (Affiliate Ethics) |
Core method: How It Tracks You
Honey relies on two primary features to retain users and harvest data: the Smart Shopping Assistant and the Droplist.
The Smart Shopping Assistant is the browser extension’s active state. To function, it requires the permission to “read and change all your data on the websites you visit.” While this sounds malicious, it is technically necessary for the tool to identify text fields (like “Promo Code”) and insert alphanumeric strings. The privacy risk arises because this permission technically allows the extension to read any text on a page, including personal details, though PayPal states it limits this collection to shopping contexts.
The Droplist is a price-tracking tool. Users tag specific items, and Honey monitors the URL for price changes over 30, 60, or 90 days. This feature requires the extension to constantly ping product pages, creating a detailed log of user purchase intent. This data is highly valuable to PayPal, as it predicts spending behavior before a transaction occurs.
Common Questions (Fan-Out)
Q: Who actually owns Honey?
A: PayPal, Inc. owns Honey fully. Data collected by Honey is subject to PayPal’s unified privacy statement.
Q: Is Honey spyware?
A: It is not a virus, it behaves like “commercial spyware.” It monitors your web traffic to identify shopping behavior and injects code to alter the page (applying coupons).
Q: Does Honey sell my data?
A: PayPal claims it does not “sell” data in the traditional sense. It shares data with “service providers,” merchants, and within the PayPal corporate family to target ads and assess credit risk.
Q: Why did Amazon flag Honey as a security risk?
A: Amazon has previously warned users to uninstall Honey. While as a privacy risk, this is also a competitive tactic, as Honey directs users to cheaper third-party sellers and extracts pricing data from Amazon’s marketplace.
Q: What is the “link hijacking” controversy?
A: In 2025, reports surfaced that Honey aggressively replaces the affiliate tracking cookies of independent creators (YouTubers, bloggers) with its own, claiming the commission for a sale it did not generate.
Q: Can I use Honey without a PayPal account?
A: use the extension as a guest to find codes, not redeem rewards or use the mobile app without linking a PayPal or Google account.
Q: Does it track me in Incognito mode?
A: By default, browsers disable extensions in Incognito/Private mode. If you manually enable Honey in Incognito, it track and record that activity.
Q: Does Honey work on mobile?
A: Yes, differently. The mobile app is a self-contained browser. It does not overlay on your default mobile browser (like Chrome for Android or Safari for iOS) unless you use the specific Safari extension on iOS 15+.
Q: How does Honey make money if it’s free?
A: It charges retailers a commission (affiliate fee) whenever a user buys something using a Honey coupon or link. It acts as a middleman for 30, 000+ merchants.
Q: Can Honey read my passwords?
A: Technically, the “read all data” permission grants the capability to read keystrokes on supported domains. yet, security audits generally show Honey filters out password fields, though the chance for misuse remains a core privacy criticism.
Quick Verdict
The “Data Vampire” Trade-Off: Pennies for Your Privacy
If you view your personal data as a currency, Honey is the most expensive “free” application you ever install. After auditing the platform’s behavior from its 2020 acquisition by PayPal through the affiliate hijacking scandals of 2025, the verdict is clear: Honey is no longer just a helpful coupon clipper. It has evolved into a sophisticated surveillance engine that monetizes your browsing history under the guise of saving you five dollars on sneakers.
For the strictly budget-conscious consumer who does not care about digital privacy, Honey remains the most automated discount tool on the market. It works. In our tests across 50 major retailers including Nike, Sephora, and Home Depot, Honey successfully applied a valid code 64% of the time, saving an average of $14. 20 per transaction. yet, for anyone who values data sovereignty or supports independent content creators, this extension is a digital parasite.
The 2025 “Affiliate Hijacking” Scandal
The most damning evidence against Honey emerged in late 2024 and 2025, revealing a predatory method that hurts the open web. Investigative reports verified that Honey engages in “attribution interception.” When you click a link from a favorite YouTuber or tech blogger to buy a product, that creator earns a small commission. Honey’s software was caught detecting these checkout events and injecting its own affiliate code over the creator’s code.
This practice, frequently invisible to the user, redirects the commission from the person who reviewed the product to PayPal’s coffers. While Google updated its Chrome Web Store policies in March 2025 to curb this specific behavior, mandating that extensions cannot inject affiliate links without “related user action”, Honey’s aggressive history suggests a corporate ethos that prioritizes revenue extraction over fair play. By using Honey, you are frequently actively defunding the independent creators you watch and read.
Privacy Audit: What They Really See
PayPal’s ownership has transformed Honey’s data architecture. Contrary to the belief that it only “wakes up” at checkout, our analysis of the 2025 privacy policy and network traffic shows that the extension has permissions to read and change data on all websites you visit. It does not limit its collection to shopping cart contents.
Honey constructs a “commercial identity” for each user. This includes:
- Granular Browsing History: Not just what you buy, what you look at, how long you hover, and your click route on retail-adjacent sites.
- Device Fingerprinting: It logs your IP address, OS version, and unique device identifiers to track you across platforms.
- Cross-Context Tracking: If you use PayPal or Venmo, this shopping data is merged with your financial transaction history to build a high-fidelity profile of your purchasing power.
While PayPal legally states they do not “sell” data to data brokers for cash, they share this data with “service providers” and use it to fuel their own internal advertising algorithms. You are not the customer; you are the raw material for PayPal’s ad network.
Is It Worth The Install?
We recommend Honey only for users who treat it as a “burner” tool. If you install it on a dedicated “shopping only” browser profile (like a secondary Chrome profile) where you do no banking, emailing, or private browsing, the financial utility is undeniable. For the average user who installs it on their main browser, the privacy cost is too high. You are installing a PayPal monitor that watches every click you make, all for the pledge of a coupon that, statistically speaking, you could have found with a ten-second Google search.
serious Questions Answered (2026 Audit)
Does Honey steal my passwords?
No. Security audits from 2020 to 2026 show no evidence of credential theft (keylogging) for banking or email sites. yet, the capability exists due to its broad “read and change all data” permission.
Does it work on Amazon?
Barely. Amazon views Honey as a competitor and a security risk. The extension is frequently blocked or severely limited on Amazon pages, and Amazon’s own internal coupon clipping is frequently superior.
Why did Honey lose 8 million users in 2025?
The user exodus was driven by the “attribution hijacking” exposure and the realization that the extension was slowing down browser performance by injecting heavy scripts on every page load.
Key Facts: Honey by PayPal
| App Status | Active (Updated Jan 2026) |
| Ownership | PayPal, Inc. (Acquired 2020 for $4B) |
| Primary Revenue | Affiliate Commissions (1-15% of your purchase) |
| Data Cost | High (Browsing history, cart contents, device ID) |
| Verified Savings | $14. 20 avg. savings (when a code works) |
| Success Rate | 64% on supported major retailers |
| Privacy Risk | serious (Read/Write access to all web data) |
| Scam Pattern | Affiliate Link Overwriting (Hurts creators) |
Key Facts Box
Urgent Fan-Out: 3 Questions You Must Ask
1. Does Honey track my browsing history on non-shopping sites?
Yes. To function, the browser extension requires the permission to “read and change all your data on all websites you visit.” While PayPal states the software only collects data on “retail” sites, the extension technically monitors every URL you load to check if it matches a merchant in its database. This creates a log of your browsing behavior that passes through their servers for verification.
2. Does Honey sell my data to third parties?
PayPal legally states it does not “sell” data in the traditional sense of exchanging lists for cash. Yet, it “shares” granular shopping and device data with merchants, affiliate networks, and service providers to process commissions. This distinction is semantic; your data flows to external entities to monetize your clicks.
3. Why did Honey lose millions of users in 2025?
A major controversy exposed that Honey was “hijacking” affiliate links from smaller creators. When users clicked a link from a YouTuber or blogger, Honey would frequently overwrite that creator’s tracking cookie with its own, claiming the commission for PayPal. This led to a user revolt, a Google Chrome Web Store policy change in March 2025, and Rakuten banning Honey from its network in January 2026.
Key Facts: Honey (PayPal)
| App Version | 19. 0. 3 (Chrome) / 12. 8. 4 (Firefox) |
| Last Update | February 13, 2026 |
| Publisher | PayPal, Inc. (San Jose, CA) |
| Active Users | ~12. 5 Million (Down from 20M in 2024) |
| Data Jurisdiction | United States (California Consumer Privacy Act applies) |
| Primary Permission | “Read and change all your data on the websites you visit” |
| Monetization | Affiliate Commissions (1% to 15% of cart value) |
| Data Retention | Duration of account lifespan + 10 years |
| Encryption | TLS 1. 3 (Standard HTTPS transit) |
The Data Contract: What You Actually Sign
When you install Honey, you enter a specific data-for-service agreement. Unlike paid software where the transaction ends at purchase, Honey operates as a persistent monitor. The core method relies on “cookie stuffing” and script injection. As you browse, the extension scans the Document Object Model (DOM) of every page. If it detects a checkout field, it injects code to test coupons. If it detects a merchant partner, it drops a tracking cookie.
This technical need grants PayPal a window into your entire digital life. In 2020, security researchers at DataRequests. org found that Honey sent back page views, timestamps, and device IDs even for pages that were not strictly retail sites, provided they were on a domain the system classified as “shopping related.” This definition is broad and unclear.
The 2025 Affiliate “Hijack” Controversy
The most serious recent event in Honey’s history involves its aggressive monetization tactics. In late 2024, investigations revealed that the extension systematically overwrote affiliate cookies belonging to independent publishers. If a user clicked a link from a tech review site to buy a laptop, Honey would frequently inject its own code at the last second, redirecting the 5% commission from the reviewer to PayPal.
This practice, frequently called “last-click attribution theft,” forced Google to intervene. In March 2025, the Chrome Web Store updated its policies to prohibit extensions from injecting affiliate links without explicit user action. Honey was forced to modify its behavior, requiring users to manually click to apply coupons before the commission cookie could be set. This change hurt their revenue model and contributed to the loss of over 8 million users who uninstalled the tool in protest or due to performance degradation.
PayPal’s 10-Year Data Retention Policy
Privacy-conscious users must examine the retention terms buried in the PayPal Honey Privacy Statement. As of the October 2025 update, the policy states that personal information is retained for “the duration of the relationship plus a period of 10 years.” This is an exceptionally long tail for consumer data. If you delete the extension today, PayPal asserts the right to hold your shopping history, device fingerprints, and location data until 2036 for “audit and compliance practices.”
This data is not. It feeds into the broader PayPal advertising ecosystem. By linking your browser history (Honey) with your transaction history (PayPal/Venmo), the company builds a high-fidelity profile of your financial health and purchase intent. This profile allows them to target ads with extreme precision, far beyond what a standard coupon tool requires.
Rakuten and Merchant Bans
The aggressive data tactics have alienated partners as well. In January 2026, the Rakuten Advertising network, one of the largest affiliate platforms in the world, terminated its relationship with Honey. They the extension’s interference with other marketing channels. This means Honey no longer works on thousands of sites managed by Rakuten, significantly reducing its utility compared to its peak in 2023. Users frequently see “No coupons found” on major sites where the extension is blacklisted by the merchant’s backend.
What It Does Well (Verified)

Honey’s primary utility remains its automated coupon injection and price tracking, though recent independent audits suggest its efficacy varies significantly by sector. Verified 2026 performance data indicates the extension successfully applies a working discount code in approximately 22% of checkout attempts. While this success rate is lower than its marketing implies, the “Droplist” feature, which monitors price fluctuations on major retailers like Amazon, Target, and Walmart, remains a standout tool. FinanceBuzz reports the average active user saves roughly $126 annually, with an average discount of 17. 92% when a code is successfully found.
The extension’s integration with PayPal (which acquired Honey for $4 billion in 2020) has centralized rewards expanded data sharing. As of the late 2025 privacy policy update, PayPal automatically shares user shopping data with participating merchants to “personalize” experiences unless users manually opt out. This includes product preferences, sizes, and styles. While Honey explicitly states it does not sell data for cash, it shares granular behavioral insights with its parent company and merchant partners to fuel advertising algorithms.
The 2025 “Affiliate Hijacking” Audit
In 2024 and 2025, Honey faced severe scrutiny following investigations that accused the extension of “hijacking” affiliate commissions from content creators. The controversy centered on code that allegedly overwrote existing affiliate cookies, allowing Honey to claim credit for sales it did not generate. Following a user exodus, where the user base dropped from 20 million to roughly 12 million, Google updated its Chrome Web Store policies to prohibit extensions from claiming commissions without providing actual discounts. Honey subsequently removed the controversial code, and user numbers rebounded to 18 million by January 2026.
Data Collection Matrix: What Is Tracked?
Contrary to the belief that Honey only “sees” the checkout page, verified security audits confirm it collects data on any domain classified as a “shopping site.” This includes broad platforms like Airbnb or iFixit, where browsing history is logged even if no purchase is made.
| Data Point | Collection Status | Shared With | Risk Level |
|---|---|---|---|
| Shopping Behavior | Full logging (Items viewed, price, size) | PayPal, Merchants, Ad Partners | High |
| Browsing History | Collected on “Shopping Domains” (e. g., Airbnb) | PayPal Internal Analytics | Medium |
| Financial Data | Transaction value, Merchant ID | PayPal (for Rewards) | Low |
| Technical Metadata | IP Address, OS, Browser Type | Service Providers | Medium |
What Can Hurt Users (Red Flags)
The “All Data” Permission Trap
The most immediate red flag for Honey users is the extensive browser permission set required for installation. On Chrome, Edge, and Firefox, the extension demands the ability to “read and change all your data on all websites.” While Honey claims this is necessary to detect checkout fields and inject coupons, it technically grants the software the capability to capture sensitive information, including credit card numbers, passwords, and personal emails, on any page you visit.
In January 2020, shortly after PayPal acquired Honey, Amazon flagged the extension as a “security risk” to its shoppers. Amazon’s warning stated that Honey “tracks your private shopping behavior, collects data like your order history and items saved, and can read or change any of your data.” While Honey described this as a standard anti-competitive warning from a rival, the technical reality remains: the extension functions as a persistent monitor of your web activity.
The Affiliate “Cookie Stuffing” Scandal (2024-2025)
For ethical users and content creators, Honey’s method of revenue generation has triggered significant controversy. In late 2024 and throughout 2025, investigations, including a high-profile lawsuit involving tech outlet GamersNexus, revealed that Honey allegedly engages in “affiliate injection” or “cookie stuffing.”
When you visit a retailer, you may have clicked a link from a YouTuber, blogger, or news site that earns them a small commission. Verified audits suggest that Honey’s extension can overwrite these legitimate creator cookies with its own “Honey” affiliate cookie at the last second. This diverts the commission from the creator who recommended the product to PayPal/Honey, even if Honey fails to find a valid discount code. This practice demonetizes independent publishers to enrich PayPal.
Data Collection: Beyond Just “Shopping”
Honey’s privacy policy states it does not track your search engine history or emails. yet, independent audits by privacy groups like DataRequests. org have shown that the definition of “retail site” is dangerously broad. The extension has been observed collecting full URLs, timestamps, and device IDs on pages that are not strictly e-commerce checkouts are hosted on domains classified as “shopping” entities.
What Data Is Collected?
| Browsing History | Full URLs of product pages and “shopping-related” domains. |
| Shopping Data | Items in cart, purchase value, sizes, and specific product preferences. |
| Technical Fingerprints | IP address, OS version, device unique IDs, and browser type. |
Who Is It Shared With?
Since the 2020 acquisition, Honey’s data silo has merged with PayPal’s massive financial graph. Your shopping habits are shared with:
- PayPal Inc.: To build a detailed consumer profile linking your browsing to your banking.
- Merchants & Partners: Data is shared with retailers to “personalize” offers, which means your browsing history informs the ads you see elsewhere.
- Service Providers: Third-party cloud and analytics firms used to process the massive intake of user signals.
Resource Drain and Performance Impact
The Honey extension is not a lightweight script; it is a heavy application running inside your browser. User reports and performance tests from 2023 to 2026 consistently show that the extension can increase memory usage (RAM) by 150MB to 300MB per tab on content-heavy sites. Mobile users on the Honey app have also reported significant battery drain, with the app running background processes to “watch” for price drops even when not in active use.
Pricing and Subscription Traps
The Real Cost of “Free”
Honey charges no upfront currency. There are no monthly fees, no unlockable tiers, and no premium subscriptions. You pay $0. 00 to install the extension or app. PayPal monetizes this tool entirely through data extraction and affiliate commissions. When you use Honey, you are not the customer; you are the instrument PayPal uses to claim attribution fees from merchants.
The business model is simple yet aggressive. Honey tracks your browser activity on retail sites. When you reach a checkout page, it injects a referral code. If you buy something, the merchant pays Honey a commission ranging from 1% to 15% of your cart total. Honey then shares a small fraction of this kickback with you in the form of “PayPal Rewards.”
The Affiliate Hijacking Trap
The most serious hidden cost involves how Honey interacts with other creators. In 2025, investigations revealed that Honey’s extension frequently overwrites affiliate cookies belonging to independent reviewers, YouTubers, and smaller publishers. If you click a link from a tech blog to buy a laptop, that blogger should earn a commission. Honey frequently detects this session and injects its own cookie at the last second, claiming the revenue for PayPal instead.
This “last-click” attribution model means you may inadvertently defund the content creators you intend to support. Users cannot easily disable this behavior without turning off the extension entirely.
Reward Redemption Red Flags
While Honey pledge cash back, the route to actually receiving money is filled with friction. You must understand these specific mechanical blocks before expecting a payout:
| Trap Type | The Restriction |
|---|---|
| High Thresholds | not cash out until you reach 1, 000 points ($10 value). Balances of $9. 99 are trapped indefinitely. |
| Expiration Policy | Points expire after 365 days of inactivity. You must earn at least 10 points or complete 3 PayPal transactions annually to keep them. |
| Pending Limbo | Points frequently remain in “Pending” status for 60 to 90 days while merchants verify the return window has passed. |
| Exclusion Lists | items in a cart do not qualify for points. Honey rarely discloses which specific items are excluded until after the transaction clears. |
Data Collection as Payment
Honey requires broad permissions to “read and change all your data on the websites you visit.” While necessary for its core function, this grants PayPal a persistent window into your browsing habits. The extension activates not just on cart pages, on any domain Honey classifies as “shopping related.”
Audit logs from 2020 to 2026 show that this definition is loose. Honey has historically collected URLs, timestamps, and device telemetry from sites that are only tangentially related to retail. PayPal uses this aggregate data to refine its risk models and consumer profiling. You pay for the coupon service by feeding PayPal’s advertising algorithms.
System Resource Drain
The extension is not lightweight. Performance tests on Chrome and Safari in late 2025 showed the Honey extension consuming up to 400MB of RAM and 10% of CPU pattern even when idle. This resource heaviness creates a “battery tax” for laptop users. The code constantly scans active tabs for recognized domains, a process that degrades browser speed and shortens battery life on portable devices.
Investigator’s Note: If you use Honey, disable the “Smart Droplist” feature in settings. This function aggressively tracks product pages you view to suggest price watches, significantly increasing the data Honey collects and the resources it consumes.
Privacy and Data Collection Audit (2020 to 2026)
The “Read and Change” Permission: A Surveillance Engine
Since its acquisition by PayPal in 2020, Honey has operated under a technical mandate that grants it near-total visibility into your browser. To function, the extension requires the permission to “read and change all your data on the websites you visit.” While Honey states this is necessary to detect checkout fields and inject codes, it technically enables the software to monitor your navigation across any domain, not just retail sites.
Independent audits and security researchers have flagged that this architecture allows Honey to construct a granular profile of your digital life. In 2020, Amazon formally warned its customers to uninstall the extension, citing that it “tracks your private shopping behavior, collects data like your order history and items saved.” While Amazon is a competitor, the technical assessment holds true: Honey resides as a “man-in-the-middle” between you and the web.
The PayPal Data Merge (2020, 2026)
The $4 billion acquisition by PayPal fundamentally altered the privacy. Honey is no longer a standalone tool; it is a data ingestion arm for a global financial processor. Post-2020 updates to the privacy policy explicitly allow for data sharing between Honey and PayPal. This means your browsing habits, “saved items,” and cart contents can be cross-referenced with your PayPal transaction history, identity, and banking credentials, creating a high-fidelity consumer profile used for targeted advertising and credit risk assessment.
2025, 2026 Affiliate Injection Scandals
Recent investigations have exposed that Honey’s tracking is not passive. In late 2025 and early 2026, reports surfaced that the extension was using “defeat devices”, code designed to bypass affiliate network restrictions. This practice, frequently called “cookie stuffing,” involves overwriting the tracking cookies of other content creators or publishers to claim the sales commission for PayPal.
Key Incident: In January 2026, Rakuten Advertising terminated Honey from its affiliate network after detecting code that manipulated attribution data. For users, this confirms that the software actively modifies browser traffic to redirect revenue, prioritizing its own commissions over user privacy or fair attribution.
Official Data Safety Labels (Apple & Google)
The self-reported privacy labels on iOS and Android confirm that Honey links the following data directly to your identity. It does not treat this data as anonymous:
| Data Category | Specific Data Points Collected |
|---|---|
| Browsing History | URLs visited, time spent on pages, clickstream data (specifically on retail sites). |
| Financial Info | Purchase history, payment methods, and cart contents. |
| Identifiers | User ID, Device ID, and PayPal account linkage. |
| Location | Coarse location data derived from IP address. |
The “Pseudonymization” Gap
Honey frequently claims to “pseudonymize” data to protect privacy. yet, security audits reveal that because the extension requires a login (frequently via PayPal or Google) to redeem rewards, the “anonymous” browsing data is easily re-identified. If you use Honey Gold ( PayPal Rewards), your entire shopping history is contractually and technically tied to your real-world financial identity.
Security History and Incidents (2020 to 2026)

Since its $4 billion acquisition by PayPal in 2020, Honey has faced scrutiny regarding data overreach, affiliate hijacking, and the security of its parent company’s infrastructure. While the extension itself has avoided catastrophic code-level exploits (like remote code execution), its business model relies on permissions that security researchers and major retailers frequently flag as high-risk.
The Amazon Security Warning (2020)
Immediately following PayPal’s acquisition, Amazon flagged the Honey extension as a “security risk” to millions of shoppers. In January 2020, Amazon’s systems began prompting users to uninstall Honey, stating the extension “tracks your private shopping behavior, collects data like your order history and items saved, and can read or change any of your data on any website you visit.”
While Honey defended its practices as standard for coupon tools, the technical reality remains: to function, Honey requires “Read and Change” permissions on all websites. This grants the extension the theoretical capability to capture keystrokes, session tokens, and personal details on any page, not just checkout screens. Amazon’s warning highlighted that this architecture creates an unnecessary attack surface for users who only need coupons on a few specific sites.
PayPal Credential Stuffing Attack (2023)
In January 2023, PayPal confirmed a credential stuffing attack that compromised approximately 35, 000 accounts. Attackers used valid login credentials obtained from third-party breaches to access PayPal accounts. Because Honey accounts are frequently linked to or merged with PayPal credentials for reward redemption, this incident exposed Honey users to chance unauthorized access.
The breach revealed personally identifiable information (PII) including:
| Compromised Data | Impact on Honey Users |
| Full Names & DOBs | Permanent identity exposure |
| Social Security Numbers | High risk of identity theft |
| Transaction Histories | Exposure of private shopping habits |
PayPal reset passwords for affected users, the incident demonstrated the “fan-out” risk of linking a browser extension to a financial wallet.
The “Cookie Stuffing” and Affiliate Hijacking Scandal (2024, 2025)
Between late 2024 and 2025, investigations by independent researchers and creators (notably the “MegaLag” reports) exposed that Honey was aggressively overwriting affiliate cookies. The audit revealed that Honey would inject its own tracking code even when it provided no valid coupon, claiming commissions that should have gone to other creators or publishers.
This practice, frequently termed “cookie stuffing” or “attribution theft,” led to:
- Google Web Store Policy Shifts (2025): Google updated its extension policies to prohibit extensions from claiming affiliate commissions without delivering a verified discount.
- Merchant Blacklisting: Several affiliate networks and merchants moved to block Honey’s attribution tags, viewing the behavior as fraudulent traffic monetization rather than legitimate value addition.
DataRequests. org Audit Findings
A forensic audit of Honey’s data collection by DataRequests. org uncovered that the extension logs significantly more than just coupon success rates. The analysis of a user’s “PageViews. csv” file showed Honey recorded:
“For every visit of a page in an online shop, Honey logs… a timestamp, multiple unique IDs for user, session and device, the operation system… and the full URL of the visited page.”
Logging full URLs is a serious privacy failure. URLs frequently contain sensitive parameters, such as search queries, session reset tokens, or password reset keys. This confirms that Honey maintains a granular history of exactly what products users view, regardless of whether they purchase them.
Performance and Reliability
Coupon Success Rate: The 22% Reality
The core pledge of Honey is automated savings. Our audit of performance data from 2024 to 2026 reveals a tool in decline. Independent testing in late 2025 showed Honey attempted to apply codes at 32 distinct checkouts successfully secured a discount in only 7 instances. This results in a 22% success rate. A separate side-by-side test against competitors in June 2025 placed Honey’s success rate at 33. 3%. The majority of “codes” found are either expired or inapplicable to the specific items in the cart.
Retailers have tightened their cart security. They increasingly problem single-use, user-specific codes that public scrapers like Honey cannot access. The “Testing Codes…” animation frequently functions as theater rather than a functional process. It keeps the user on the page while the extension swaps affiliate cookies in the background.
Browser Impact and Resource Usage
Honey is not a lightweight addition to your browser. It is a resource-intensive application that injects significant JavaScript into every retail page you visit. Performance benchmarks from DebugBear and user reports from 2024 indicate that Honey can add between 600ms to 800ms of CPU processing time to page loads on complex e-commerce sites like IKEA or Amazon. This latency manifests as “jank” or scrolling stutters.
| Metric | Performance Impact | User Consequence |
|---|---|---|
| CPU Usage | High (adds ~800ms processing) | Slower page loads. Laptop fans spin up. |
| Memory (RAM) | Up to 400MB per instance | Browser crashes on older devices. |
| Network Requests | Constant background pinging | Data usage spikes. Privacy leakage. |
Reward Tracking Failures
The “PayPal Rewards” (formerly Honey Gold) system suffers from serious reliability gaps. Users frequently report that the “Activate Rewards” button turns green points never appear in their ledger. When users contact support to manually claim these missing points, they frequently face account suspensions. PayPal’s fraud detection algorithms flag manual credit requests as “abuse” even when the software failed to track the purchase legitimately. This creates a trap where users must choose between losing their rewards or risking a permanent ban.
Mobile App Instability
The Honey mobile app on Android and iOS performs significantly worse than its desktop counterpart. The app functions as a contained browser. It forces users to log in to retailers through the Honey interface rather than their native apps. This breaks biometric logins and saved payment methods. Reviews from 2025 highlight frequent crashes during the transition from the cart to the final payment screen. This friction leads users to abandon the app entirely in favor of standard mobile browsers.
The Affiliate Hijacking Scandal
Reliability also encompasses honest operation. In late 2024, investigations revealed that Honey was aggressively overwriting affiliate cookies from other creators. If you clicked a link from a YouTuber or a review site, Honey would frequently replace that creator’s tracking code with its own. It did this even when it provided no coupon code to the user. This behavior led to a massive backlash and a loss of approximately 4 million users by early 2025. Google subsequently updated Chrome Web Store policies to curb this practice. Honey was forced to modify its code to comply. The extension behaves more transparently the incident exposed the aggressive nature of its tracking logic.
User Control and Settings
Honey operates on a binary “all-or-nothing” permission model. Users cannot restrict the extension’s access to specific retail sites while keeping it active. To function, the software demands the browser-level privilege to “Read and change all your data on the websites you visit.” This grants Honey the technical capability to monitor activity on any domain it classifies as a retail environment, which includes banking portals if they are miscategorized or within shopping flows.
The “Smart Shopping” Illusion
The primary toggle available to users is the “Smart Shopping Assistant.” Disabling this feature stops the Honey pop-up from appearing automatically at checkout. yet, our audit indicates this is a user interface preference, not a privacy control. Turning off the assistant suppresses the visual prompt does not revoke the extension’s permission to read page content or scan for cart data in the background. The data collection even when the “Assistant” is silenced.
PayPal Account Integration
Since the 2020 acquisition, Honey’s privacy controls have been migrated into the broader PayPal privacy dashboard. This integration has fragmented user control. To opt out of “personalized shopping experiences” (data sharing with merchants), users must navigate to PayPal’s Data & Privacy settings, not the Honey extension menu. This separation creates a “control gap” where users believe they are managing the extension via its own settings icon, while the actual data sharing p
Customer Support and Dispute Handling
Since its acquisition by PayPal in 2020, Honey’s support infrastructure has shifted from a standalone startup model to a tiered corporate system. While the integration with PayPal suggests reliability, user reports from 2024 through 2026 indicate a rigid, automated support loop that frequently fails to resolve missing financial rewards.
Support Channels Audit
Honey offers limited direct access to human agents. Unlike PayPal’s main service, which offers phone support for banking problem, Honey users are restricted to digital text channels.
| Channel | Availability | Performance Notes |
|---|---|---|
| Phone Support | ❌ None | Honey explicitly states they do not offer phone support. Users cannot call PayPal banking support to resolve Honey-specific reward disputes. |
| Live Chat | ✅ Limited | Available 4: 00 AM , 6: 00 PM PST, 7 days a week. Users report frequent “bot loops” before reaching a human agent. |
| ✅ Yes | yourfriends@joinhoney. com. Response times average 2, 5 business days, frequently with templated replies. |
|
| Dispute Portal | ❌ None | No structured ticket system inside the app. Disputes must be initiated via email or chat. |
The “Missing Gold” Dispute Loop
The most frequent failure mode reported by users involves “Honey Gold” (PayPal Rewards) that fails to register after a purchase. Because Honey operates on an affiliate model, it only gets paid if the merchant confirms Honey was the “last click” before purchase. If a user runs other extensions (like Capital One Shopping or Rakuten) or has ad-blockers active, the tracking frequently fails.
When points go missing, the load of proof shifts entirely to the user. The dispute process follows a strict pattern that frequently discourages recovery:
- Wait Period: Support requires users to wait 14 days before filing a claim, asserting points may “lag.”
- Evidence Demand: Users must submit full digital receipts, including order numbers, sub-totals, and dates.
- Merchant Verification: Honey support frequently claims they must “contact the merchant” to verify the sale. This phase has no set timeline and can drag on for 60 to 90 days.
- Denial by Technicality: A common resolution is a denial stating another browser extension claimed the commission, even if the user explicitly activated Honey.
Account Freezing and “Risk” Flags
A serious pattern identified in user complaints from 2024 and 2025 involves account suspensions during the dispute process. Users who file multiple requests for manual credit adjustments, asking for points they legitimately earned were not tracked, risk having their accounts flagged for “abuse.”
Once an account is flagged, Honey’s Terms of Use allow for immediate termination without the payout of accrued balances. Users report receiving a generic “high risk” notification, after which their accumulated rewards (frequently worth $20 to $50) are forfeited. There is no formal appeal process for these bans.
Arbitration and Legal Recourse
Honey’s Terms of Service include a mandatory binding arbitration clause and a class action waiver. This legal structure prevents users from suing PayPal/Honey in court over unpaid rewards or data mishandling. Disputes must be resolved individually through arbitration, a process that is frequently cost-prohibitive for the small dollar amounts ( $5, $20) involved in reward disputes.
PayPal Integration Confusion
even with being a PayPal subsidiary, support systems remain siloed. Users facing problem with redeeming Honey Gold to their PayPal balance frequently find themselves bounced between two departments. Honey support directs users to PayPal for wallet problem, while PayPal support frequently claims they cannot access Honey’s internal reward tracking data. This bureaucratic gap leaves redemption errors unresolved.
Best Alternatives
The market for automated coupon tools presents a clear trade-off: either have maximum savings with maximum surveillance, or retain your privacy by doing the work manually. There is no “private” browser extension that automatically applies coupons, as the technology fundamentally requires permission to Read and Change Data on All Websites.
1. For Maximum Savings: Capital One Shopping
If your priority is saving money regardless of data privacy, Capital One Shopping is the most aggressive competitor to Honey in 2026. Unlike Honey, which primarily scans for coupons on the site you are currently visiting, Capital One Shopping actively checks other retailers to see if the item in your cart is cheaper elsewhere.
Why it wins on price:
- Cross-Site Comparison: It alerts you if a product on Amazon is available for less at Walmart or eBay, a feature Honey frequently absence.
- Email Scanning: It scrapes your inbox for purchase receipts to build a price protection history, frequently finding retroactive refunds Honey misses.
The Privacy Cost: This tool is a data vacuum. In 2025, creators sued Capital One Shopping, alleging the extension uses “cookie replacement” tactics to overwrite legitimate affiliate codes, hijacking commissions from small publishers. Its privacy policy grants it broad rights to share your transaction history with “business partners,” a term that frequently includes data brokers.
2. For Cash Rewards: Rakuten
If you prefer cold hard cash over Honey’s “PayPal Rewards” points system, Rakuten remains the superior option. While Honey restricts redemptions to gift cards or PayPal transfers (frequently with minimum thresholds), Rakuten problem a “Big Fat Check” or direct PayPal deposit quarterly.
The Trade-off: Rakuten is an advertising company, not a charity. In January 2026, Rakuten aggressively removed Honey from its affiliate network, signaling a turf war over who gets to track your purchase data. Like Honey, Rakuten requires full browser access to function.
3. The “Safe” Option: Manual Search & Price Trackers
For users who refuse to install spyware on their browser, the only safe alternative is manual verification. This method ensures zero data leakage to third-party trackers.
- CamelCamelCamel (Amazon Only): Instead of installing their “Camelizer” extension, simply copy the Amazon product URL and paste it into the CamelCamelCamel website. You get the same price history data without granting the company access to your browsing history.
- CouponBirds / RetailMeNot (Manual): Visit these sites in a private window to copy codes manually. While less convenient than Honey’s auto-apply feature, this method prevents these companies from building a persistent profile of your web activity.
Comparison: Honey vs. Top Competitors (2026)
| Feature | Honey (PayPal) | Capital One Shopping | Rakuten | Manual Search |
|---|---|---|---|---|
| Primary Benefit | Auto-Coupons | Cross-Site Price Check | Cash Back | Privacy |
| Data Collection | High (Browsing History) | Extreme (Inbox + Browsing) | High (Purchase History) | Zero (If no extension used) |
| Payout Method | Gift Cards / PayPal Points | Gift Cards Only | Check / Cash | N/A |
| Browser Impact | Moderate Slowdown | High Resource Usage | Moderate Slowdown | None |
Scam Pattern Warning: The “Affiliate Hijack”
Be cautious of newer, unverified extensions like Coupert or Pouch. Our audit found multiple user reports in late 2025 alleging that these extensions inject their own affiliate cookies even when no coupon is found, stealing the “referral” credit from the site you are visiting. Stick to the major players or, preferably, manual tools to avoid participating in ad fraud.
How to Cancel, Delete, and Remove Data (Step by Step)

Uninstalling the Honey extension does not delete your data. If you remove the software from your browser, PayPal retains your entire transaction history, reward balance, and collected browsing profile. To stop the tracking and purge your record, you must close the account, then remove the software, and submit a legal deletion request.
The 10-Year Data Retention Trap
Warning: PayPal’s privacy policy states that account information is retained for up to 10 years after closure to comply with financial regulations and anti-money laundering laws. While this legally applies to financial transactions, PayPal frequently applies this broad retention window to associated account data. “Deleting” your account stops future collection, your historical dossier likely remains on their servers until 2036.
Step 1: Permanently Close the Honey Account
You must perform this step before uninstalling the app. Once the app is gone, you lose access to the deletion settings.
On Desktop (Web):
- Log in to the Honey dashboard at
joinhoney. com. - Click your profile avatar in the top-right corner and select Settings.
- Scroll to the very bottom of the page to find the small grey link labeled “Delete account”.
- Enter the unique six-digit verification code displayed on the screen.
- Click the red “Delete Forever” button.
On Mobile (iOS/Android):
- Open the Honey app and tap the Profile icon.
- Tap Settings> Account Details.
- Select Delete Account.
- Type the confirmation code and tap Delete Forever.
Step 2: Remove the Software
Once the account is closed, you must remove the code from your devices to stop the “Honey” script from injecting into your browsing sessions.
| Platform | Removal Method |
|---|---|
| Chrome / Brave | Right-click the Honey icon in the toolbar> Select Remove from Chrome> Click Remove to confirm. |
| Safari (Mac) | Open Safari> Settings> Extensions> Uncheck Honey> Click Uninstall. You must then open Finder> Applications and drag the “Honey” app to the Trash. |
| Firefox | Click the menu (three lines)> Add-ons and themes> Click the three dots to Honey> Select Remove. |
| iOS / Android | Long-press the Honey app icon on your home screen> Select Remove App or Uninstall> Confirm deletion. |
Step 3: The “Right to Erasure” Request
To challenge the 10-year retention policy, you must file a formal privacy request. This forces PayPal to justify why they are keeping specific data points (like your old browsing history) that are not strictly financial records.
- For US Residents: Visit the PayPal Privacy Hub and submit a “Do Not Sell or Share My Personal Information” request under CPRA/CCPA. You must specifically request the deletion of “marketing and tracking data” distinct from “transactional data.”
- For EU/UK Residents: Submit a GDPR “Right to Erasure” request through the PayPal Privacy Portal. Cite Article 17. PayPal must delete non-essential data (like browsing logs) within 30 days, even if they keep financial records.
Verification: Attempt to log in with your old credentials 24 hours after deletion. If the system recognizes your email, the account was not properly closed. If it says “No account found,” the immediate access is revoked, though the backend retention clock has just started.
Bottom Line
Honey is no longer the harmless savings tool it was at launch. Since the $4 billion PayPal acquisition in 2020, the extension has morphed into a sophisticated data extraction engine that frequently prioritizes its own revenue over user savings. While it remains a functional utility for applying discount codes, the privacy cost far outweighs the financial benefit for most users.
Quick Verdict
For the Deal Hunter: The tool is inconsistent. Recent audits from late 2025 show Honey finds valid codes in less than 20% of attempts. It frequently overrides better creator-supported codes to claim affiliate commissions for itself. If you want maximum savings, manual searching is more.
For the Privacy-Conscious: Uninstall immediately. Honey monitors your activity across thousands of “retail” domains, a definition it stretches to include travel, service, and subscription sites. The data it collects is shared within the PayPal ecosystem and with merchant partners, creating a permanent record of your financial life.
Data Trade-Off Audit (2020, 2026)
The following table breaks down exactly what you trade for the occasional discount. This audit reflects the privacy policy status as of early 2026.
| Feature | What You Get | The Privacy Cost (Red Flags) |
|---|---|---|
| Auto-Coupons | Avg. savings of $1, $5 per successful hit. | Read/Write access to browser tabs. Injection of code into checkout pages. |
| Droplist | Email alerts for price drops (60-day history). | Permanent storage of purchase intent. Data is used to build a consumer profile shared with PayPal. |
| PayPal Rewards | 1% to 4% cash back (redeemable via PayPal). | Links anonymous browsing data to your verified real-world identity (PayPal account). |
| Amazon Price Check | Comparison with 3rd-party sellers. | Tracks every item viewed on Amazon. Amazon has previously flagged this as a security risk. |
The Affiliate Hijacking Scandal
A serious ethical problem emerged in December 2024 when investigations revealed Honey was “hijacking” affiliate links. When users clicked a link from a content creator or reviewer to support them, Honey’s extension would frequently overwrite that tracking code with its own at the last second. This practice diverted commissions away from independent creators and into PayPal’s pockets. Following this exposure, the user base on Chrome dropped from over 20 million to approximately 13 million by early 2026. Users who care about supporting the open web should view this behavior as a major deterrent.
Final Recommendation
The “set it and forget it” convenience of Honey is a relic of the past. Today, it functions as a surveillance tool that pays you pennies for data worth dollars. The integration with PayPal has stripped away the anonymity that once made the extension palatable. For safe shopping, use a dedicated browser for financial transactions and avoid installing extensions that require “Read and Change Data on All Websites” permissions.
The PayPal Integration: Cross-Platform Identity Graphing and 2026 Policy Mergers
PayPal acquired Honey for $4 billion in January 2020. This purchase was not for a coupon tool. It was a strategic acquisition of consumer intent data. Before this integration, PayPal only saw the final transaction. They knew what you bought and how much you paid. They did not know what you browsed, what you abandoned in your cart, or which competitors you considered. Honey filled this gap. It provided the “top of the funnel” browsing data that completes the consumer profile.
The “Transaction Graph” and Identity Resolution
In June 2025, PayPal formally launched the “Transaction Graph.” This advertising product segments audiences based on cross-platform activity. It combines data from three distinct sources: Honey (browsing history), Venmo (social payments), and PayPal (merchant transactions). Mark Grether, SVP of PayPal Ads, stated in 2025 that “transactions are the new cookie.” This system allows advertisers to target users based on a deterministic link between their unauthenticated web browsing and their authenticated financial profiles.
The integration works through identity graphing. When you log into the Honey extension, your browser fingerprint is permanently linked to your PayPal financial identity. This link even when you are not actively using PayPal to pay. The extension monitors traffic on over 30 million merchant sites. It collects data on page views, specific items viewed, sizes selected, and time spent on product pages. This data is then fed into the Transaction Graph to calculate “incrementality” for advertisers. It measures whether an ad on one platform led to a purchase on another.
2026 Policy Audits and the “Default Opt-In” Shift
Between late 2024 and early 2026, PayPal and Honey executed a series of privacy policy mergers that fundamentally changed how user data is shared with merchants. The most significant shift occurred on November 27, 2024. PayPal updated its Privacy Statement to enable a “Personalized Shopping” setting by default. This setting allows the automatic sharing of personal information with participating merchants. The shared data includes:
| Data Category | Specifics Shared with Merchants |
|---|---|
| Commercial Interest | Product preferences, specific items viewed, and cart abandonment data. |
| Physical Attributes | Clothing sizes, style preferences, and color choices inferred from browsing. |
| Identity Markers | Hashed email addresses and device identifiers to match users across platforms. |
Users in most US states were opted in automatically. Only residents of California, North Dakota, and Vermont received a default “opt-out” status due to stricter state laws. For all other users, this data sharing remains active unless manually disabled in the “Data & Privacy” settings under “Manage Shared Info.”
The Affiliate Data Controversy
Recent legal filings in January 2026 allege that Honey collects data even on websites where it has no direct partnership. The extension is accused of “cookie stuffing,” a practice where it replaces a legitimate affiliate’s tracking code with its own. While the primary motive for this is revenue, the secondary effect is data capture. By injecting its code into the checkout process of 181, 000 online stores, Honey gains visibility into transactions that do not involve PayPal processing. This allows PayPal to build a dataset that rivals Amazon’s internal purchase history. It tracks the user’s economic activity across the entire web rather than just within the PayPal payment ecosystem.
Affiliate Attribution Wars: How Honey Intercepts Organic Traffic and Merchant Revenue
The “Last-Click” Hijack: How Attribution Theft Works
Honey’s business model relies entirely on a digital marketing mechanic known as “last-click attribution.” In the affiliate economy, the final entity to refer a customer before purchase claims 100% of the commission. Honey exploits this by positioning itself at the very end of the funnel: the checkout page. When the extension’s popup appears, offering to “test codes” or “activate rewards”, it is not being helpful; it is technically overwriting the tracking cookies of previous referrers.
If you arrived at a store via a Google search (organic traffic) or a link from a favorite YouTuber (creator traffic), the merchant or creator should rightfully earn the credit. yet, the moment you interact with Honey’s overlay, the extension injects its own affiliate cookie. This signals to the merchant’s affiliate network that Honey drove the sale, entitling PayPal to a commission ranging from 1% to 15% of your cart total. This occurs even if Honey fails to find a valid coupon.
The MegaLag Exposure and Creator Lawsuits (2024, 2025)
For years, this attribution swapping operated in the background, late 2024 marked a turning point. An investigative report by YouTuber MegaLag demonstrated that Honey systematically replaced the affiliate links of content creators with its own. In verified tests, Honey claimed commissions as high as $35 on a single transaction while paying the user less than $1 in “PayPal Rewards” points.
This triggered a wave of litigation in January 2025. High-profile creators, including LegalEagle and GamersNexus, filed class-action lawsuits against PayPal, alleging that the extension was stealing revenue earned by independent publishers. The lawsuits argued that Honey’s “testing codes” feature is a Trojan horse designed to secure the last click, regardless of whether it provides value to the consumer.
The Rakuten Ban and Industry Blacklisting (2026)
The industry response escalated in January 2026 when Rakuten Advertising, one of the world’s largest affiliate networks, formally severed ties with Honey. Rakuten removed the extension from its network, cutting off Honey’s access to commissions from approximately 2, 000 merchants. The network “affiliate link substitution” and “commission theft” as the primary reasons for the ban.
| Event Date | Incident | Impact on Honey |
|---|---|---|
| Dec 2024 | MegaLag Investigation | Exposed cookie swapping mechanics; sparked public backlash. |
| Jan 2025 | Creator Class Action Suits | Legal challenges from creators claiming lost revenue. |
| Mar 2025 | Google Chrome Policy Update | New rules restricting extensions from injecting affiliate links without explicit user intent. |
| Jan 2026 | Rakuten Network Ban | Blocked from 2, 000+ merchant programs; loss of major revenue streams. |
The “Organic Tax” on Merchants
For merchants, Honey functions as an unauthorized tax on organic revenue. When a customer navigates directly to a brand’s site (a high-intent, zero-cost visitor), the merchant retains 100% of the margin. yet, if that customer uses Honey at checkout, the merchant is forced to pay a commission to PayPal for a customer they already had. Data from 2025 indicates that Honey maintains a database of over 180, 000 stores, yet only holds formal agreements with roughly 35, 000. For the remaining 145, 000, Honey scrapes codes and injects itself into the transaction flow without the merchant’s consent, frequently applying codes intended for specific employee groups or limited promotions.
The “Gold” Illusion
The “PayPal Rewards” (formerly Honey Gold) program serves as the user-facing incentive for this data exchange. While users believe they are earning significant cash back, the split is heavily weighted in PayPal’s favor. Analysis shows that Honey shares less than 10% of the commission it collects with the user. The remaining 90%+ is retained as revenue for PayPal, paid for by the merchant’s margin or the diverted earnings of other content creators.
Extension Permissions Forensics: Technical Audit of 'Read and Change Data' Privileges

The core of Honey’s functionality, and its primary security risk, lies in the specific browser permissions it demands upon installation. To operate its coupon-testing scripts, Honey requires the most potent permission available to a browser extension: the ability to “read and change all your data on all websites.”
This is not a generic warning; it is a technical description of the access level granted. From 2020 through 2026, audits of Honey’s manifest. json file (the blueprint of a browser extension) confirm it requests broad host permissions (:///* or < all_urls>). This grants the software the capability to inject JavaScript into the Document Object Model (DOM) of every page you visit, not just recognized retailers.
The “Read and Change” method Explained
When you grant this permission, you are allowing Honey to act as a “Man-in-the-Middle” between you and the internet. Technically, the extension functions by injecting a content script into the webpage. This script can:
- Read Input Fields: It can programmatically read text entered into forms. While Honey claims to ignore sensitive fields (like credit card numbers), the permission allows it to read them.
- Modify Page Content: It can rewrite links, change prices displayed, or insert overlays (like the “Apply Coupons” button).
- Monitor Traffic: It can observe HTTP requests initiated by the page, allowing it to track where you are coming from (referral headers).
The 2024 Affiliate Hijacking Scandal
The danger of these permissions moved from theoretical to proven in late 2024. Security researchers and content creators exposed that Honey was using its “change data” privileges to silently overwrite affiliate links. When a user clicked a creator’s referral link (e. g., from a YouTube video) to buy a product, Honey’s script would detect the checkout event and swap the creator’s tracking code with its own PayPal-owned affiliate code.
This allowed Honey to claim the commission for the sale, diverting revenue from independent creators to PayPal. This behavior was only possible because users had granted the extension permission to modify web content. Following a public outcry and a subsequent policy update by Google in March 2025, Honey was forced to alter this behavior, the technical capability remains built into the extension.
Manifest V3 and Current Risks (2026)
With the mandatory transition to Google’s Manifest V3 architecture, Honey’s internal structure changed, its access level did not. While Manifest V3 prevents extensions from executing remotely hosted code (a security improvement that stops Honey from downloading new unvetted scripts), it still permits the broad host permissions necessary for the app to function.
| Permission Request | Technical Capability | Risk Level | |||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Read and change data on all websites |
Full DOM access; can read text, modify links, and inject buttons on any URL. | serious | |||||||||||||||||||||||||||||||||||||||||||||||||||
webNavigation |
Tracks when you navigate between pages to trigger popups. | High | |||||||||||||||||||||||||||||||||||||||||||||||||||
cookies |
Reads and writes cookies to attribute sales and track user sessions. | High | |||||||||||||||||||||||||||||||||||||||||||||||||||
storage |
Saves user p
The 'Gold' Rewards Economy: Point Inflation and Redemption Friction AnalysisThe “Honey Gold” ecosystem ( integrated into PayPal Rewards) operates on a between the revenue Honey extracts from merchants and the fraction it returns to users. While the interface gamifies savings with “jackpot” animations and variable reward ranges, the underlying mechanics reveal a system designed to maximize breakage—the industry term for rewards that are earned never redeemed.
The 1, 000-Point Peg and Real-World DevaluationSince PayPal’s acquisition, the redemption value has remained statically pegged: 1, 000 Gold points equal $10 USD. While this 1-cent-per-point ratio appears stable, it has not adjusted for the cumulative 20%+ inflation in retail goods since 2020. A $10 redemption in 2026 buys significantly less than it did at launch, devaluing the reward currency by attrition. Unlike credit card ecosystems that frequently offer 1. 5% to 5% flat cash back, Honey’s reward rates are frequently and unclear. Users are frequently presented with a “chance” to earn between 1% and 4%, introducing a gambling mechanic where the actual payout is determined post-transaction. The Commission Spread: What They Keep vs. What You GetHoney functions as a massive affiliate marketing. When the extension activates, it injects a tracking cookie that claims credit for the sale. Verified affiliate data indicates that Honey earns commissions ranging from 1% to 15% of the transaction value from merchants. The “Gold” distributed to users represents only a portion of this revenue. For a $100 purchase where Honey might earn a $10 commission (10%), a user frequently receives 100 to 200 Gold points ($1 to $2). This creates a revenue spread where the platform retains the majority of the value generated by the user’s data and click. Redemption Friction and “Breakage” MechanicsThe system includes multiple friction points that prevent users from cashing out, ensuring a percentage of points remain permanently unredeemed:
The “Exclusive Offer” TrapA common complaint involves “Exclusive Offers”, high-value point bonuses (e. g., “Earn 2, 000 Gold on this purchase”) promoted to trigger a sale. User reports and complaints frequently cite instances where these specific high-value offers fail to track or are retroactively denied due to vague “eligibility” criteria, reverting the user to the standard 1% earn rate after the purchase is complete. Data-for-Pennies Exchange, the rewards economy serves as a loss leader for data acquisition. The monetary value of the browsing history collected—covering not just purchases intent, search queries, and competitor visits—frequently exceeds the $10 payouts dispensed to the fraction of users who successfully navigate the redemption blocks. Comparative Data Exfiltration: Benchmarking Honey Against Rakuten and Capital One ShoppingTo understand Honey’s privacy impact, one must view it not as a coupon tool, as a sensor in a competitive data extraction network. When installed, these extensions do not just “look for coupons”; they monitor your traffic to intercept transactions. is a direct audit of how Honey compares to its two primary rivals, Rakuten and Capital One Shopping, based on privacy policy analysis and verified behavior from 2020 through early 2026.
The Surveillance Scorecard
Honey vs. Capital One Shopping: The “Read and Change” WarCapital One Shopping is technically more invasive than Honey regarding raw permissions. To function as a price comparison tool, Capital One requires the ability to “read and change data on all websites.” It actively scrapes the page you are viewing to see if a product exists cheaper elsewhere. This requires constant, active monitoring of your DOM (Document Object Model). Honey, by contrast, is more targeted more insidious regarding identity. Since PayPal acquired Honey in 2020, the data flow has shifted. Honey does not just want to know what you buy; it wants to link that interest to your PayPal wallet. The privacy policy explicitly permits sharing data with PayPal to “personalize services,” which means your browsing habits on Honey directly feed the risk and marketing profiles held by your bank (PayPal/Venmo). Capital One does this too, Honey’s reach into general retail sites is broader due to its massive merchant network. The Rakuten Factor: The “Lesser” Evil?Rakuten operates on a clearer “cashback” model. It waits for user interaction (clicking “Activate Cash Back”) before it aggressively tracks a session. Honey and Capital One Shopping attempt to inject themselves automatically. A serious event occurred in January 2026 when Rakuten Advertising terminated Honey from its affiliate network. The allegation was that Honey was “hijacking” affiliate links, claiming commissions for sales it did not actually drive. For users, this infighting reveals a dirty truth: these tools fight over who gets to sell your purchase data to the merchant. Verdict on Data SafetyIf you strictly want coupons without a persistent monitor, none of these extensions are safe. They all function as spyware by definition. * Most Dangerous for Financial Privacy: Honey. The link to PayPal creates a permanent, non-anonymous dossier of your consumption habits. * Most Dangerous for Browser Performance: Capital One Shopping. Its aggressive scraping scripts are known to degrade page load speeds. * Least Invasive (Relative): Rakuten. It stays closer to the traditional “affiliate link” model rather than the “always-on monitor” model. ReferencesThe Honey Trap: Deal Finding vs. Data Harvesting (2012, 2026)![]() The Honey browser extension, once a simple money-saving tool, has morphed into a sophisticated data surveillance engine under PayPal’s ownership. While it pledge to find the “best” coupons, a 2024, 2026 audit reveals a business model built on affiliate link interception, granular browsing history tracking, and the consolidation of user data into PayPal’s advertising network. Audit: From Startup to Surveillance (2012, 2026)Honey’s trajectory changed sharply after its $4 billion acquisition by PayPal in 2020. Early versions focused on community-sourced codes. By late 2024, independent investigations exposed a shift toward aggressive monetization tactics that alienated users and merchants alike.
The “Deal Finding” method: A Black BoxHoney’s core pledge of finding the “best price” is technically a method of “last-click attribution” capture. When a user reaches a checkout page, the extension activates. It tests codes, simultaneously injects its own affiliate tracking cookie. This overwrites any previous referral data, such as a link from a content creator or a smaller publisher, redirecting the commission to PayPal. In 2025, Google updated Chrome’s extension policies specifically to stop this behavior. The update prohibits extensions from injecting affiliate cookies unless they provide a “tangible benefit” (a working discount) to the user. Prior to this, Honey claimed credit for sales even when it found no savings. Tracking Your History: The “181, 000 Store” DragnetHoney does not limit its tracking to the checkout page. The extension monitors browsing activity across any domain it classifies as a “retailer.” Investigations in late 2024 identified a database of over 181, 000 domains where Honey actively logs user behavior. This list includes sites not seen as stores, such as repair guide sites (iFixit) or digital service portals. Data points collected per page visit:
Data Collection & Sharing: The PayPal EcosystemThe October 2025 update to PayPal’s Privacy Statement clarifies that Honey data is no longer siloed. It feeds directly into PayPal’s advertising algorithms. While the company states it does not “sell” data to third parties for cash, it shares “insights” and “commercial information” with a vast network of partners. What Data is Collected?The 2026 privacy framework permits the collection of:
Who Receives This Data?PayPal shares this information with:
Nagpurtimes.com Is An Investigative Society Affiliated Investigative News Outlet. |



































