Privacy Policy
Last updated: 16 September 2026
This policy explains what Can It Be Automated? collects, why, and what we do with it. It covers two separate things:
- our website at canitbeautomated.com
- the CRM Quick Access browser extension
They work very differently, so they are described separately below. Can It Be Automated? is a subsidiary of Appency LLC.
Part one: the website
What we collect
Information you give us. When you fill in a form, book a consultation, contact support or buy something, we collect what you enter. That is typically your name, email address, phone number and any message you write.
Information collected automatically. Our website uses cookies and similar technologies that record your IP address, browser and operating system, approximate location, the page that referred you, and how you move through the site. You can block or delete cookies in your browser settings, though some parts of the site may then not work properly. Guidance is available at allaboutcookies.org.
Email engagement. Our marketing emails may include tracking pixels that tell us whether a message was opened and which links were clicked.
How we use it
- To provide our services, answer enquiries and give support
- To improve the website and understand how it is used
- To market our services to you, by email or text, where you have consented
Text messages
We use OpenPhone for text messaging. See the OpenPhone privacy policy. To stop receiving texts from us, reply STOP, QUIT, CANCEL, OPT-OUT or UNSUBSCRIBE to any message.
Part two: the CRM Quick Access extension
The short version. The extension shows you your own CRM data inside your browser. That data travels directly from the CRM to your browser and never passes through our servers. We do not store your contacts, tasks, opportunities, appointments or messages. The extension has no analytics, we only hold your name and email if you choose to sign up for updates, and nothing about you is sold or shared for advertising.
What the extension can access
When you connect an account, you approve access through LeadConnector's standard sign-in flow. The extension then has exactly the access your own login already has, limited to the accounts you choose to connect and to these areas: the account's name, tasks, opportunities and pipelines, contacts and contact notes, conversations and messages, and calendars and appointments.
You can revoke it at any time by disconnecting inside the extension, or by removing the app from your account.
What stays on your computer
The extension keeps the following in your browser's own storage. It is not transmitted to us:
- Your access token and its expiry time
- An installation identifier and secret, used to prove to our server that a token refresh request is genuinely yours
- The identifier and display name of each connected account, so the switcher can show them
- Which tab you last had open, and which calendar the appointment bar follows
- If you turn on Chrome notification reminders: the title, due time and account of tasks due in the next few hours, kept only until their reminders have passed
Uninstalling the extension deletes all of it.
What we store on our servers
Our backend exists for one reason: to hold the credential that lets the extension reconnect, because that credential cannot safely live inside a browser extension. For each installation we store:
| What | Why |
|---|---|
| An encrypted refresh credential | To obtain a new access token when the old one expires. Encrypted with AES-256-GCM before it is written, and never stored in readable form. |
| Your account and company identifiers | To know which installation a request belongs to, and to apply a company-wide subscription across its accounts. |
| The identifier of the user who connected, and the permissions granted | To show only work assigned to you, and to know what the extension is allowed to do. |
| A one-way hash of the installation secret | To verify requests. We cannot recover the secret itself from the hash. |
| Subscription status, plan and renewal date | To know whether the subscription is active. |
| Dates of installation and last reconnection | Support and troubleshooting. |
If you install from the marketplace rather than from the extension, we also create a short pairing code. Only a one-way hash of it is stored, it can be used once, and it expires after fifteen minutes. If a pairing code is entered incorrectly, we record the IP address it came from and a failure count, so that repeated wrong guesses can be blocked. Those records are kept for a short period and used for no other purpose.
What we never store
- Your CRM records. Contacts, tasks, opportunities, notes, conversations and messages are requested by your browser directly from the CRM and displayed to you. They do not pass through, and are not written to, our systems.
- Your CRM password. We never see it. Sign-in happens on the platform's own pages.
- Your card details. Payment is handled entirely by Stripe on their own pages. We receive only a customer reference and subscription status.
- Analytics or usage tracking. The extension has none. It contacts us only to refresh a token, check your subscription, save an updates sign-up if you choose to make one, and note that it was removed (see below).
If you sign up for updates
The extension may ask whether you would like updates. It is optional: nothing is sent unless you tick a box and press Save, and you can dismiss it.
If you sign up, we keep your email address, the first and last name you enter, which updates you asked for (about CRM Quick Access, about other tools we build, or both), when you agreed, and which installation the request came from. We also add you as a contact in our own CRM account, tagged with the product and your choices, so that we can send what you asked for.
We use it only to send the kinds of updates you chose. You can unsubscribe from any update we send, or email support@canitbeautomated.com and we will remove you.
When the extension is removed
When you uninstall the extension, Chrome opens a short page on our server that carries the installation identifier. We use it to note that the installation was removed and, if you signed up for updates, to tag your contact record in our CRM as uninstalled, so that we stop writing to you as a current user. Chrome only does this if you are online at the time.
What the extension does in the background
Normally nothing: it runs only while you have it open. The one exception is optional. If you turn on task reminders as Chrome notifications, the extension checks the CRM every few minutes for open tasks assigned to you, so it can notify you before one is due. That check goes from your browser directly to the CRM, the task details it uses are kept only on your device, and nothing about your tasks is sent to us. Turn reminders off and the checks stop.
Your reminder settings and quick task presets are saved in Chrome's sync storage, so they follow you to other browsers where you are signed in to Chrome. They are never sent to us.
The extension never reads, modifies or monitors the web pages you visit, and it has no ability to see any site other than the CRM API it is authorised to call.
Who else is involved
We use a small number of providers, each for a specific purpose:
| Provider | Purpose | What they hold |
|---|---|---|
| Supabase | Database and server hosting (United States) | The installation records described above |
| Stripe | Subscription payments | Your billing details and payment method. We never receive card numbers. |
| LeadConnector | Our own CRM, for update sign-ups | The name, email and choices of people who sign up for updates |
| OpenPhone | Text messaging (website enquiries only) | Phone number and message content |
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Security
- Refresh credentials are encrypted with AES-256-GCM before storage. The key is held separately from the database.
- Installation secrets and pairing codes are stored only as one-way hashes.
- All connections use HTTPS.
- Database access is restricted to our own server functions. The database is not reachable from the public internet with ordinary credentials.
No system is perfectly secure, but the design deliberately limits what a breach could expose: we do not hold your CRM records, so they cannot be taken from us.
How long we keep things
- Installation records: for as long as the installation exists. Disconnecting the extension removes it from your browser; ask us and we will delete the server record too.
- Update sign-ups: until you unsubscribe or ask us to remove you.
- Failed pairing attempts: a short rolling window, then discarded.
- Billing records: as long as required for tax and accounting purposes.
- Website enquiries and marketing contacts: until you ask us to remove them.
Your rights
You can ask us to give you a copy of the personal information we hold about you, correct it, delete it, or transfer it elsewhere. You can also opt out of marketing at any time.
If you are in the European Economic Area or the United Kingdom, you have these rights under the GDPR, including the right to complain to your data protection authority. If you are a California resident, you have rights under the CCPA including the right to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined there.
To exercise any of these, email support@canitbeautomated.com. We will not treat you differently for asking.
International transfers
Our servers and providers are located in the United States. If you use our services from elsewhere, your information will be processed in the United States, which may have different data protection laws than your own country.
Children
Our services are for businesses and are not directed at children under 13. We do not knowingly collect information from children. If you believe we have, contact us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects how we handle your information, we will tell affected customers directly rather than relying on you to notice.
Contact
Can It Be Automated? (a subsidiary of Appency LLC)
General enquiries: info@canitbeautomated.com
Privacy and data requests: support@canitbeautomated.com
Extension support: chromesupport@canitbeautomated.com
Telephone: 1.916.345.2729

