CRM Sidebar is provided by Bristol Web Design, Inc., doing business as CRM Sidebar (“CRM Sidebar,” “we,” “us,” or “our”). This Policy explains how we collect, use, store, and disclose information through crmsidebar.com, the CRM Sidebar browser extension, and related services (the “Service”).
1. Scope and our roles
This Policy applies to information CRM Sidebar handles as operator of the Service.
When a business or organization uses CRM Sidebar with its customer, prospect, employee, or other CRM data, that organization generally determines why and how the information is used. In that context, CRM Sidebar acts as a service provider or processor on the organization’s behalf. Requests about information controlled by an organization may need to be directed to that organization.
CRM Sidebar acts independently for account administration, billing, security, support, and the operation of our website and business.
2. Information we handle
Account and organization information
When you connect or use the Service, we may receive your name, business email address, CRM user and organization identifiers, account role and type, connected CRM location, and the organization’s configured CRM domain.
We store settings needed to provide the Service, such as your connected account, browser pairing, panel configuration, saved views, display preferences, allowed work addresses, never-log rules, and related product settings.
Gmail conversation information
The browser extension runs on Gmail so it can provide the visible CRM features you install it for. While a Gmail conversation is open, the extension may read information needed for those features, including:
- participant names and email addresses;
- message subject and content;
- message and thread identifiers and timestamps;
- attachment names, types, metadata, and contents when an attachment feature is used; and
- the email address of the Gmail inbox in use.
CRM Sidebar does not ask for your Google password and does not continuously synchronize your mailbox in the background. It reads the Gmail page in your browser to provide the features shown there.
Connected CRM information
To display and operate the sidebar, CRM Sidebar may process information available in the connected CRM, including contacts and related records; names and contact details; tags, assigned users, and custom fields; conversations, messages, notes, tasks, appointments, and activity; opportunities, pipelines, stages, and values; calendars, users, workflows, forms, custom objects, and record relationships; and panel layouts and other account configuration.
When you take an action through the Service, CRM Sidebar may create or update the corresponding CRM record on your behalf. CRM Sidebar does not read or write CRM form submissions merely because a form is used to define a panel layout.
Billing information
Payments are processed by Stripe. Stripe may collect payment-card and billing information directly under its own privacy policy. We receive and store limited records such as billing email, Stripe customer and subscription identifiers, subscription status, plan, and connected CRM account. We do not store complete payment-card numbers.
Browser and local-storage information
The extension stores information locally so it can remain signed in, remember your preferences, display recent activity, retry an action that failed, and load CRM information efficiently. This may include a session token, connected-account information, preferences, recent activity, pending message-log requests, and cached CRM responses.
A pending request may temporarily include the message data needed to complete the action. It remains locally until the action succeeds, the retry limit is reached, extension data is cleared, or the extension is removed. Certain CRM message-detail cache entries are configured for use for up to 90 days as an offline fallback; most cached information expires sooner.
Website, support, and technical information
When you visit our website or contact us, we may receive information you submit. Our infrastructure providers may also generate standard technical records such as IP address, browser type, request timestamps, requested pages, error information, and security events. We use cookies or local storage where needed for authentication, preferences, security, and operation of the Service.
3. How we use information
We use information to:
- provide the Gmail sidebar and connected CRM features;
- authenticate users and connect the intended CRM account;
- display CRM context and carry out actions you request;
- save selected Gmail messages into the connected CRM;
- prevent duplicate logging and link Gmail messages to CRM records;
- process subscriptions and determine account entitlement;
- remember preferences and improve reliability and performance;
- provide support, protect the Service, and diagnose errors;
- comply with law and enforce our agreements; and
- create aggregated or de-identified operational information that does not identify an individual.
We do not use Gmail message content or connected CRM customer data for advertising.
Where applicable law requires a legal basis, we rely on performance of a contract, our legitimate interests in providing and securing the Service, consent where requested, and compliance with legal obligations.
4. Google and Chrome Limited Use
CRM Sidebar’s use and transfer of information obtained through Gmail and the Chrome extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. If CRM Sidebar receives information through Google APIs, its use and transfer will also comply with the Google API Services User Data Policy, including its Limited Use requirements.
In particular:
- we use Gmail and Google user data only to provide or improve user-facing CRM Sidebar features;
- we do not sell this data or transfer it to data brokers;
- we do not use or transfer it for personalized, interest-based, or retargeted advertising;
- we do not use it to determine creditworthiness or for lending;
- we do not use it to train or improve generalized artificial-intelligence or machine-learning models; and
- our personnel do not read message content except with your explicit permission for specific support, when necessary to investigate security or abuse, when required by law, or when the information has been aggregated and de-identified for permitted internal operations.
6. Storage and retention
CRM Sidebar does not ordinarily store Gmail message bodies in its server-side logging database. Message content passes through our service to the connected CRM. The CRM stores the resulting message under the organization’s settings and agreement.
We retain a logging ledger containing message and thread identifiers, mailbox and CRM account identifiers, linked contact and conversation identifiers, status, and timestamps. This prevents duplicate entries and supports links between Gmail and the CRM.
We retain account, configuration, preference, and subscription information while an account is active and afterward only as reasonably necessary to complete deletion, meet legal or accounting obligations, resolve disputes, prevent fraud, and enforce agreements. Support and security records are retained for the period reasonably needed for those purposes.
Removing CRM Sidebar does not automatically delete messages or records previously written into the connected CRM. Those records must be managed through the CRM. Contact us to request deletion of CRM Sidebar account data we control.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted network connections, authenticated access, access controls, limited personnel access, and hashed browser-pairing keys.
No method of transmission or storage is completely secure. You are responsible for securing your browser, CRM account, devices, and login credentials and for promptly notifying us of suspected unauthorized use.
8. Your choices and rights
You may choose which messages or threads to save, use never-log rules, clear supported local activity data, sign out, remove the extension, disconnect the CRM application, and cancel a paid subscription under the applicable terms.
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection regarding personal information we control. You may also have the right to appeal our response or complain to a data-protection authority.
Send a request to tom@bristolwebdesign.com. We may need to verify your identity and authority. If the information is controlled by your employer, agency, or another CRM customer, contact that organization first.
9. International processing
CRM Sidebar is operated from the United States. We and our service providers may process information in the United States and other countries whose privacy laws may differ from those where you live. Where required, we use appropriate contractual or legal safeguards for international transfers.
10. Children
The Service is intended for business users and is not directed to children under 13. We do not knowingly collect personal information directly from children through account registration. Organizations using CRM Sidebar are responsible for ensuring that information they place in their CRM is collected and used lawfully.
11. Changes to this Policy
We may update this Policy as the Service or applicable requirements change. We will post the revised version with a new effective date. If a change materially affects how we use Gmail, Google, or other sensitive user data, we will provide prominent notice and obtain consent when required before applying the new practice.
12. Contact us
Doing business as CRM Sidebar
2609 Honolulu Ave. #203
Montrose, CA 91020, United States
Privacy and support: tom@bristolwebdesign.com