Privacy Policy
Last updated: July 10, 2026
WorkFlow CRM (“WorkFlow CRM”, “the Extension”, “we”, “us”, or “our”) is a browser extension that helps you organize your web-based business chats into custom tabs, folders, tags, notes, reminders, kanban boards, and workflow-based views, and offers message-template, campaign, and optional AI-reply and webhook-automation features.
This Privacy Policy explains what user data we collect, why we collect it, how we handle and store it, when it may be shared, and what choices you have. No category of data handled by the Extension is omitted from this policy - where a feature is optional, that is stated explicitly.
1. Information we collect
We collect only the data required for the Extension’s core and optional features to work properly.
1.1 Account identification data. Our software may collect:
- Your phone number or account identifier shown in the supported messaging web application
- A randomly generated installation ID
- Your license/subscription key and plan/trial status
- A browser or device-related identifier and extension build version, used only to connect your Extension installation with your saved workspace and route requests correctly
This data is required to identify your Extension setup, validate your license/trial, and sync your saved tabs, folders, and settings.
1.2 Contact and chat organization data. When you use the Extension to organize chats, our software may collect limited chat-related metadata, such as:
- Contact names
- Group or chat names
- Chat identifiers
- Custom tabs, folders, tags, and custom attributes created by you
- Notes and reminders you create against a chat
- Kanban cards/boards created by you
- Appointments and calendar events
- Labels, categories, or workflow views created by you
- The relationship between a selected chat and the tab, folder, tag, or category where you placed it
This data is required so the Extension can save, sync, restore, and display your organized chat workspace.
1.3 Settings and preferences. We may collect and store Extension settings such as:
- Display preferences (theme, blur/privacy display settings)
- Tab and folder settings
- Feature preferences and module on/off toggles
- Signature text you configure for outgoing messages
- Workspace configuration
- Extension setup options
This helps the Extension remember your selected settings and provide a consistent user experience.
1.4 Technical and log data. When the Extension communicates with our servers, we may automatically process limited technical data, including:
- Extension version
- Browser type and version
- Device or operating system information
- Request date and time
- IP address
- Basic server logs
- Error logs
This data is used for security, debugging, troubleshooting, service reliability, and abuse prevention.
1.5 Support information. If you contact us for help, we may collect:
- Your name, if provided
- Your email address
- Your support message
- Screenshots or details you voluntarily share with us
This information is used only to respond to your support request.
1.6 Account sign-in data. Signing in is required to use the Extension. You may sign in with your email address and password (“Basic Sign-In”), or with Google Sign-In, on our web sign-in page. Depending on the method you choose, we obtain your email address (and, for Google Sign-In, your name); for Basic Sign-In, your password is used only to authenticate you, is transmitted securely, and is not stored in plain text. A resulting session token is relayed to the Extension. The Extension itself does not request any Google OAuth scope from Chrome and does not use chrome.identity - sign-in happens entirely on our own web page, not inside the Extension.
1.7 Message templates, canned responses, and campaign content. The text and media of message templates, canned/quick replies, and scheduled messaging campaigns that you create are collected so they can be stored, synced across your sessions/devices, and sent on your instruction.
1.8 Files and media you attach. Images, documents, or other files you deliberately attach to a template or campaign are collected and uploaded so they can be sent through the supported messaging application. We do not access or collect media from your general conversations beyond what you explicitly attach through this feature.
1.9 AI feature input (optional). If you enable the optional AI prompt tool or AI Auto-Reply Assistant, we collect:
- The text you type into the AI prompt tool, and/or
- The content of the specific incoming message that the AI Auto-Reply Assistant processes to draft a suggested reply
This text is sent to our server, which forwards it to the AI provider you (or your admin) selected - OpenAI ChatGPT or Google Gemini - solely to generate the suggested text, and is not collected if you do not enable these optional features.
1.10 Webhook configuration and event data (optional). If you create a webhook, we collect the webhook URL(s) you configure and process the chat/message event data that is delivered to that URL when triggered, solely to provide this automation feature at your direction.
1.11 Import/export job data (optional). If you run a contact/CRM import or export job, the data included in that file is processed to generate the file you requested and track job status.
2. Information we do not collect
WorkFlow CRM does not collect, store, sell, or use the general content of your private conversations.
We do not collect:
- Your message history in bulk, or media from conversations you have not explicitly attached to a template or campaign (see 1.8)
- Payment card details
- Precise device location or health data
- Browsing history outside the supported messaging web application and our own domains
- Data for advertising or third-party tracking
Two narrow exceptions apply and are fully disclosed above - we do not claim blanket non-collection of these categories:
- Message content processed by the optional AI Auto-Reply Assistant (Section 1.9) - only the specific message you ask it to draft a reply for, and only if you enable that feature.
- Sign-in data - email, name (for Google Sign-In), and password (for Basic Sign-In) (Section 1.6) - required to use the Extension; your password is used only to authenticate you, is not stored in plain text, and is not collected via any Chrome
chrome.identity/OAuth permission.
The Extension may interact with the supported messaging web application inside your browser only to provide its CRM, tab, folder, chat organization, template, campaign, AI, and webhook features described in this policy.
3. How we collect data
We collect data in the following ways:
3.1 Data created by you. When you create tabs, folders, labels, tags, notes, reminders, kanban cards, templates, canned responses, or campaigns, the Extension saves this information so your workspace can function properly.
3.2 Data read from the supported web application. The Extension may read limited visible information from the supported web application, such as contact names, chat names, and chat identifiers, only when needed to organize your chats or provide the feature you are using.
3.3 Data stored in your browser. Some settings, preferences, and cached workspace data may be stored locally in your browser using browser storage.
3.4 Data sent to our servers. Some data, such as your installation ID, saved tabs, folders, tags, notes, reminders, kanban data, templates, campaigns, and webhook configuration, may be sent to our servers so your workspace can be synced, restored, and maintained.
3.5 Data shared by you for support. If you contact us, we collect only the information you choose to provide.
3.6 Data you submit to optional AI features. If you use the AI prompt tool or enable the AI Auto-Reply Assistant, the input described in Section 1.9 is sent to our server, which forwards it to your selected AI provider to generate a response. This only happens for features you actively enable or use.
3.7 Data triggered by your webhook configuration. If you configure a webhook, the corresponding chat/message event data is collected and delivered to the URL you specify, only when that event occurs and only for webhooks you have created.
4. How we use your data
We use collected data only to provide and operate the Extension’s features. We use data to:
- Identify your Extension installation and validate your license/trial
- Save your custom tabs, folders, tags, notes, reminders, and kanban boards
- Sync and restore your organized workspace
- Store and send your message templates, canned responses, and campaigns on your instruction
- Generate AI-suggested text via our server, only for the AI features you enable
- Deliver event data to webhooks you configure
- Remember your settings and preferences
- Display your saved chat organization structure
- Provide customer support
- Fix bugs and technical issues
- Improve security and reliability
- Prevent misuse or unauthorized access
- Send important service-related updates
We do not use user data for advertising, profiling, retargeting, or selling to third parties.
5. Why our software needs this data
Our software requires limited account, contact, chat identifier, tab, folder, and settings data because these are necessary for the Extension to provide its main features. AI-input and webhook-event data are needed only for the specific optional features you choose to enable.
Without this data, the Extension would not be able to:
- Identify which workspace belongs to which installation
- Save custom tabs, folders, tags, notes, reminders, and kanban boards
- Remember which chats were added to which folders
- Restore your organized workspace after browser refresh or reinstall
- Sync user-created workspace settings
- Generate an AI-suggested reply when you ask for one
- Deliver data to a webhook you configured
- Provide proper support and troubleshooting
We collect only the minimum data required for these features.
6. Browser extension permissions
The Extension requests the following browser permissions, used only as described:
- Run the Extension on supported web pages
- Read limited visible chat metadata needed for organization features
- Save your session, preferences, and cached CRM data locally
We do not use browser permissions to collect unrelated browsing activity or data from unrelated websites.
7. Data storage
We store data in the following ways:
7.1 Local browser storage. Some settings, preferences, and cached workspace data may be stored locally in your browser. This allows the Extension to remember your setup and is removed automatically when you uninstall the Extension.
7.2 Server storage. Your installation ID, account identifier, license/trial state, saved tabs, folders, tags, notes, reminders, kanban data, templates, campaigns, webhook configuration and history, and uploaded files may be stored on our servers so the Extension can sync and restore your workspace. All transmission uses HTTPS/TLS, and template, campaign, and import/export payloads are additionally encrypted at the application layer.
7.3 AI provider processing (optional feature). If you use an optional AI feature, the text described in Section 1.9 is processed transiently by our server and your selected AI provider (OpenAI ChatGPT or Google Gemini) solely to generate the requested response. We do not forward your license key, contact list, or unrelated CRM data as part of this call.
7.4 Your own webhook destination (optional feature). If you configure a webhook, the event payload is delivered to the URL you specify, which is outside our systems and governed by that third party’s own security and privacy practices.
7.5 Support email storage. If you contact us by email, your support request may be stored in our email system for communication and support history.
8. Data security
We take reasonable steps to protect user data. Our security practices may include:
- Secure HTTPS/TLS data transmission
- Access control for server systems
- Limited access to user data
- Server monitoring and error logging
- Protection against unauthorized access
- Collecting only data required for the Extension’s features
No method of internet transmission or electronic storage is fully secure, so we cannot guarantee absolute security.
9. Data sharing
We do not sell, rent, or trade your personal data. We do not share your personal data with third parties for advertising, marketing, or tracking purposes. We may share limited data only in the following cases:
9.1 Service providers. We may use trusted service providers to host, store, secure, or support the Extension. These providers may process limited data only as required to provide their services to us. Examples may include:
- Hosting provider
- Database provider
- Email/support provider
- Server infrastructure provider
These service providers are not allowed to use user data for their own marketing or advertising purposes.
9.2 AI providers (only if you opt in). If you use the AI prompt tool or AI Auto-Reply Assistant, the specific text described in Section 1.9 is shared with the AI provider you selected (OpenAI ChatGPT or Google Gemini), solely to generate the suggested text you requested. This is not shared unless you actively use these optional features.
9.3 Your own configured webhook endpoint (only if you opt in). If you configure a webhook, the event data you chose to include is delivered to the destination URL you specify. This is data sharing you explicitly configure and control, not something we initiate.
9.4 Legal requirements. We may disclose data if required by law, regulation, court order, legal process, or government request.
9.5 Security and abuse prevention. We may disclose limited data if necessary to detect, prevent, or address fraud, security issues, misuse, or technical problems.
9.6 Business transfer. If WorkFlow CRM is involved in a merger, acquisition, sale of assets, or business transfer, user data may be transferred as part of that transaction. Any receiving party will be required to protect user data according to this Privacy Policy or similar protections.
10. Third-party analytics, advertising, and tracking
We do not use third-party advertising tools.
We do not use third-party analytics or tracking SDKs.
We do not sell user data.
We do not use user data for interest-based advertising or marketing profiling.
11. Cookies and similar technologies
The Extension itself does not set or read browser cookies, web beacons, or advertising pixels - it uses the browser’s extension storage APIs described in Section 7, not cookies, to remember your data.
Our separate web admin panel (used only for the sign-in described in Section 1.6) may set a minimal, strictly-necessary session cookie so you stay signed in. We do not use cookies or similar technologies for cross-site tracking, advertising, or building an advertising profile, and we do not currently respond differently to browser “Do Not Track” signals because we do not perform the kind of tracking that signal is designed to limit.
12. Links to other websites
The Extension’s settings menu and in-product prompts may link out to pages we operate for pricing, tutorials, support/bug-report forms, feature requests, and our affiliate program, as well as to this Privacy Policy itself. These open in a new browser tab when you click them.
If any linked page is operated by a third party, or if a webhook destination you configure (Section 1.10) takes you to a third-party service, we are not responsible for that party’s content or privacy practices. We encourage you to review the privacy policy of any third-party site or service before providing information to it.
13. International data transfer
Our servers and the service providers described in Section 9.1 may be located in a country other than your own. By using the Extension, you understand that your information may be processed, stored, and transferred internationally, including to countries that may have different data protection rules than your home jurisdiction. We take contractual and technical measures intended to keep your data protected consistent with this Policy wherever it is processed.
14. Data retention
We keep user data only for as long as needed to provide the Extension’s features, maintain service reliability, provide support, comply with legal obligations, and prevent abuse.
- Saved tabs, folders, tags, notes, reminders, kanban data, templates, campaigns, account identifiers, installation IDs, and related workspace data may be kept while your Extension installation or account remains active.
- Webhook configuration and delivery history is retained so you can review delivery status, and can be cleared from within the Extension or deleted on request.
- AI prompt/reply text is processed transiently by our proxy and the AI provider to generate the requested response and is not used for any other purpose.
- Support emails may be retained for customer support and recordkeeping purposes.
You may request deletion of your data at any time by contacting us.
15. Data deletion
You can request deletion of your server-stored data by contacting us at support@workflow-crm.com.
After receiving your request, we will delete or anonymize your data within a reasonable time, unless we are required to keep certain information for legal, security, or operational reasons.
Uninstalling the Extension removes locally stored data from your browser and deregisters your device, but does not automatically delete data already synced to our servers (including webhook history and uploaded files). To delete server-stored data, please contact us.
16. User rights and choices
Depending on your location, you may have the right to:
- Access the personal data we hold about you, and ask how it is handled
- Correct inaccurate data
- Request deletion of your data
- Receive a copy of your data in a portable, machine-readable format
- Restrict certain processing, or object to processing based on our legitimate interest
- Withdraw consent where applicable, without affecting processing carried out before the withdrawal
- Lodge a complaint with your local data protection authority if you believe we have not handled your data properly
You also have direct control over the optional features in this policy:
- AI features are opt-in - leave the AI prompt tool and AI Auto-Reply Assistant disabled if you do not want message text sent to an AI provider.
- Webhooks are opt-in - no data leaves to a third-party endpoint unless you configure one.
- You can delete individual CRM records (tabs, tags, notes, reminders, templates, campaigns, webhooks) from within the Extension at any time.
To exercise these rights, contact us at support@workflow-crm.com .
17. Children’s privacy
WorkFlow CRM is intended for business and professional use. It is not intended for children under the age of 13.
We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take reasonable steps to delete it.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
When we update this policy, we will revise the “Last updated” date above. If we make material changes, we may provide additional notice through the Extension, website, or other reasonable method.
19. Contact us
If you have questions about this Privacy Policy, user data handling, or data deletion, please contact us:
WorkFlow CRM Support
Email: support@workflow-crm.com