1. Who we are
CRM Solution BD operates CRM Solution BD Mail Exporter, a Chrome extension and related account, licensing, subscription, and support services. Questions about privacy may be sent to privacy@crmsolutionbd.com.
2. Information we access or collect
Google account information
When you connect Google, the service may access:
- Your Google account identifier.
- Your name, email address, and profile image.
- OAuth permission and token information needed to complete authorization.
Gmail data
With your authorization, the extension uses Gmail read-only access to search messages and retrieve the metadata needed for the features you request. Depending on the feature used, this may include:
- Sender name and sender email address.
- Subject, date, recipient headers, message identifiers, and thread identifiers.
- Labels, brief Gmail-provided snippets, message size estimates, and whether an attachment is present.
- Search results and thread metadata selected for export.
The current extension uses Gmail metadata mode and is not designed to download full message bodies or attachment file contents for the listed extraction and export features.
Google Sheets and Drive data
When you deliberately choose Google Sheets export, the extension creates or updates a spreadsheet in your Google account and writes the selected export rows to that file. The Drive file permission is used only for files created or opened by the app for this user-requested feature.
Account, licensing, and payment information
The Laravel backend may store:
- Name, email address, Google account identifier, avatar URL, and last login time.
- Plan, trial, license, device activation, entitlement, and subscription status.
- A hashed API token and a hashed or pseudonymous device identifier.
- Stripe customer and subscription identifiers. Full payment card details are handled by Stripe and are not stored by us.
Local extension information
Saved searches, interface preferences, dark-mode preference, backend URL, device identifier, and cached entitlement information may be stored in Chrome extension storage on your device.
3. How we use information
We use information only to:
- Authenticate your Google account and provide the features you request.
- Search, filter, display, and export Gmail results on your device.
- Create user-requested Google Sheets exports.
- Manage free, trial, Pro, license, subscription, device, and customer-dashboard access.
- Prevent abuse, secure the service, diagnose errors, and provide support.
- Comply with applicable law and enforce our Terms of Service.
4. Where Google user data is processed and stored
Gmail search results and export data are designed to be processed within the Chrome extension. They are not intentionally uploaded to or stored in our Laravel licensing backend. Export files are generated on your device or, when you choose Google Sheets export, written to a spreadsheet in your Google account.
A temporary Google access token is sent to the backend during sign-in so the backend can verify your Google identity and permissions. The backend is designed not to persist that Google access token. Laravel Sanctum stores only a hash of the API token used to authenticate later licensing and billing requests.
5. Sharing and disclosure
We do not sell Google user data. We may disclose limited information only:
- To Google APIs, as necessary to perform the user-authorized feature.
- To Stripe, for subscription checkout, billing, and customer portal services.
- To infrastructure or hosting providers that process account-system data on our behalf under appropriate obligations.
- When required by law, legal process, or to protect users, the service, or the public.
- In a business transfer, subject to continued protection and notice where required.
We do not use Gmail data for advertising, retargeting, credit decisions, data brokerage, surveillance, unrelated profiling, or general-purpose artificial intelligence model training.
6. Google API Limited Use disclosure
Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy , including its Limited Use requirements.
7. Retention
Local extension data remains until you remove it, sign out where the product provides that option, clear the extension's storage, or uninstall the extension. Backend account, licensing, tax, transaction, and subscription records are kept only as long as reasonably necessary for service delivery, security, legal, accounting, dispute, and compliance purposes.
When an eligible deletion request is completed, account data is deleted or anonymized unless retention is required by law, needed to prevent fraud or abuse, or necessary to resolve an active transaction or dispute.
8. Security
We use reasonable administrative, technical, and organizational safeguards, including HTTPS in production, access controls, token hashing, limited server-side data collection, and restricted administrative access. No method of storage or transmission can be guaranteed to be completely secure.
9. Your choices and rights
- You can decline Google permissions, although related features will not work.
- You can revoke the app's Google access from your Google Account permissions page.
- You can uninstall the extension or clear local extension storage.
- You can request access, correction, or deletion of eligible backend account data.
- You can cancel a subscription using the customer billing portal when available.
See our Data Deletion Instructions for the complete process.
10. Children's privacy
The service is not directed to children under 13, or the minimum age required in their jurisdiction to use Google account-connected services without parental authorization. We do not knowingly collect personal data from children in violation of applicable law.
11. International processing
Service providers may process account and subscription information in countries other than your own. Where required, we use appropriate safeguards for such processing.
12. Changes to this policy
We may update this policy when our product, legal obligations, or data practices change. If a change materially affects how Google user data is used, we will provide appropriate notice and request renewed consent where required before using the data for a new purpose.
13. Contact
Privacy questions and requests may be sent to privacy@crmsolutionbd.com. We aim to respond to verified requests within 30 days, subject to applicable law.