WhatsApp Web Mini-CRM — Chrome Extension
Last Updated: May 13, 2026This Privacy Policy explains how WhatsApp Web Mini-CRM (“we,” “our,” or “the Extension”) collects, uses, stores, and protects your information when you install and use our Chrome extension.
We take your privacy seriously. This Extension is designed with a privacy-first approach: it reads the minimum data necessary to function and never accesses your message content, browsing history, or any data outside its stated purpose.
By installing and using the Extension, you agree to the practices described in this policy. If you do not agree, please uninstall the Extension.
The Extension collects only the data required to provide its CRM functionality. Below is a complete and detailed inventory of all data collected:
| Data Type | How It Is Collected | Purpose | Stored |
|---|---|---|---|
| Contact ID Phone number extracted from WhatsApp Web |
Extracted automatically from the WhatsApp Web interface when you click on a chat | Used as the unique identifier for CRM records (tags, notes, reminders are associated with this ID) | Local + Cloud (if signed in) |
| Email Address | Received from Google OAuth when you sign in with Google | Used for authentication and to associate your data with your account | Cloud only |
| Display Name | Received from Google OAuth when you sign in with Google | Displayed in your profile section within the Extension | Cloud only |
| Profile Photo URL | Fetched from Google People API using your OAuth access token | Displayed in your profile section for visual identification | Cloud only |
| Tags | Created by you through the Extension UI | Core CRM feature: organizing contacts with labels | Local + Cloud (if signed in) |
| Notes | Written by you through the Extension UI | Core CRM feature: storing private notes per contact | Local + Cloud (if signed in) |
| Reminders | Created by you through the Extension UI | Core CRM feature: scheduling follow-up reminders with notifications | Local + Cloud (if signed in) |
The Extension explicitly does not collect or access:
Your data is used exclusively for the Extension’s single purpose: providing a CRM sidebar for WhatsApp Web.
We do not use your data for:
When you use the Extension without signing in, all data is stored locally on your device using
Chrome’s storage.local API. This data remains on your device and is never transmitted
to any server. You can clear this data at any time by uninstalling the Extension or clearing your
browser data for the Extension.
When you sign in with Google, your data is additionally stored in Firebase Firestore, a cloud database provided by Google Cloud. This enables cross-device synchronization. Your data is stored in a dedicated Firebase project and is accessible only to you when authenticated.
We retain your data for as long as you use the Extension. You may delete your data at any time:
To request deletion of your cloud data, contact us at the email address provided in Section 10. We will confirm receipt within 48 hours and complete the deletion within 14 days. After deletion, your data cannot be recovered.
We do not sell, rent, trade, or otherwise transfer your data to third parties. The only third-party services involved in the Extension’s operation are:
These third-party services have their own privacy policies governing the use of your data. We encourage you to review them. We are not responsible for the privacy practices of these third parties.
We may disclose your information if required to do so by law, regulation, or legal process, or to protect our rights or the safety of others.
We implement the following security measures to protect your data:
script-src 'self' CSP, preventing injection of external or unauthorized scripts.While we take reasonable precautions, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at the email in Section 10. We will respond within 30 days.
The Extension is not intended for use by children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us immediately and we will delete that information.
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last Updated” date at the top of this page. In the case of material changes, we will provide notice through the Extension itself (e.g., a notice in the sidebar).
We encourage you to review this Privacy Policy periodically. Your continued use of the Extension after changes constitutes acceptance of the updated policy.
For questions, concerns, data deletion requests, or to exercise your privacy rights:
This Privacy Policy is governed by the laws of Romania. By using the Extension, you consent to the jurisdiction of the courts of Romania for any disputes arising from this policy.