Privacy Policy for WhatsApp CRM Extension
Last Updated: February 21, 2026
Overview
WhatsApp CRM ("the Extension") is a Chrome extension that adds Customer Relationship Management features to WhatsApp Web. This privacy policy explains how we collect, use, and protect your data.
Data We Collect
Information Collected
- WhatsApp Phone Number: Used to identify your account and associate your CRM data
- Chat Information: Contact names and chat identifiers (encrypted)
- User-Generated Content: Notes, reminders, tags, and quick reply templates you create
- Usage Data: Timestamps of when you interact with the extension
How We Collect Data
- Directly from your interactions with the extension on WhatsApp Web
- From your browser's local storage
- Through API calls to our backend server
How We Use Your Data
Your data is used exclusively to provide CRM functionality:
- Store and retrieve your notes, reminders, and chat tags
- Send you reminder notifications at scheduled times
- Sync your data across devices where you use the extension
- Organize and filter your WhatsApp conversations
Data Storage and Security
- Encryption: All sensitive data (chat names, identifiers) is encrypted using AES-256-GCM
- Backend Storage: Data is stored on secure servers (Supabase) with TLS encryption
- Access Control: Only you can access your own data using JWT authentication
- Data Retention: We retain your data until you delete your account or uninstall the extension
Data Sharing
We do not:
- Sell your data to third parties
- Share your data with advertisers
- Use your data for marketing purposes
- Access your WhatsApp messages or conversations
We only share data:
- With our secure backend infrastructure (Vercel, Supabase) to provide the service
- When required by law
Your Rights
You have the right to:
- Access your data at any time through the extension
- Delete your data by uninstalling the extension
- Request data export or deletion by contacting us
- Opt out of data collection by not using the extension
Third-Party Services
The extension communicates with:
- WhatsApp Web (web.whatsapp.com): To provide CRM interface
- Our Backend API (Vercel): To store and sync your data
- Supabase: Database hosting with encryption
Permissions Explained
Storage
Stores your CRM data locally and syncs with our backend.
Alarms
Checks for due reminders to send you notifications.
Notifications
Displays reminder alerts at scheduled times.
Host Permissions
- web.whatsapp.com: Required to inject CRM interface into WhatsApp Web
- vercel.app: Required to communicate with our secure backend API
Children's Privacy
This extension is not directed at children under 13. We do not knowingly collect data from children.
Changes to This Policy
We may update this privacy policy. Changes will be posted with a new "Last Updated" date.
Compliance
This extension complies with:
- Chrome Web Store Developer Program Policies
- GDPR (General Data Protection Regulation)
- CCPA (California Consumer Privacy Act)
By using WhatsApp CRM, you agree to this privacy policy.