Privacy Policy

Last updated: 16 September 2026

This policy explains what Can It Be Automated? collects, why, and what we do with it. It covers two separate things:

  • our website at canitbeautomated.com
  • the CRM Quick Access browser extension

They work very differently, so they are described separately below. Can It Be Automated? is a subsidiary of Appency LLC.

Part one: the website

What we collect

Information you give us. When you fill in a form, book a consultation, contact support or buy something, we collect what you enter. That is typically your name, email address, phone number and any message you write.

Information collected automatically. Our website uses cookies and similar technologies that record your IP address, browser and operating system, approximate location, the page that referred you, and how you move through the site. You can block or delete cookies in your browser settings, though some parts of the site may then not work properly. Guidance is available at allaboutcookies.org.

Email engagement. Our marketing emails may include tracking pixels that tell us whether a message was opened and which links were clicked.

How we use it

  • To provide our services, answer enquiries and give support
  • To improve the website and understand how it is used
  • To market our services to you, by email or text, where you have consented

Text messages

We use OpenPhone for text messaging. See the OpenPhone privacy policy. To stop receiving texts from us, reply STOP, QUIT, CANCEL, OPT-OUT or UNSUBSCRIBE to any message.

Part two: the CRM Quick Access extension

The short version. The extension shows you your own CRM data inside your browser. That data travels directly from the CRM to your browser and never passes through our servers. We do not store your contacts, tasks, opportunities, appointments or messages. The extension has no analytics, we only hold your name and email if you choose to sign up for updates, and nothing about you is sold or shared for advertising.

What the extension can access

When you connect an account, you approve access through LeadConnector's standard sign-in flow. The extension then has exactly the access your own login already has, limited to the accounts you choose to connect and to these areas: the account's name, tasks, opportunities and pipelines, contacts and contact notes, conversations and messages, and calendars and appointments.

You can revoke it at any time by disconnecting inside the extension, or by removing the app from your account.

What stays on your computer

The extension keeps the following in your browser's own storage. It is not transmitted to us:

  • Your access token and its expiry time
  • An installation identifier and secret, used to prove to our server that a token refresh request is genuinely yours
  • The identifier and display name of each connected account, so the switcher can show them
  • Which tab you last had open, and which calendar the appointment bar follows
  • If you turn on Chrome notification reminders: the title, due time and account of tasks due in the next few hours, kept only until their reminders have passed

Uninstalling the extension deletes all of it.

What we store on our servers

Our backend exists for one reason: to hold the credential that lets the extension reconnect, because that credential cannot safely live inside a browser extension. For each installation we store:

WhatWhy
An encrypted refresh credentialTo obtain a new access token when the old one expires. Encrypted with AES-256-GCM before it is written, and never stored in readable form.
Your account and company identifiersTo know which installation a request belongs to, and to apply a company-wide subscription across its accounts.
The identifier of the user who connected, and the permissions grantedTo show only work assigned to you, and to know what the extension is allowed to do.
A one-way hash of the installation secretTo verify requests. We cannot recover the secret itself from the hash.
Subscription status, plan and renewal dateTo know whether the subscription is active.
Dates of installation and last reconnectionSupport and troubleshooting.

If you install from the marketplace rather than from the extension, we also create a short pairing code. Only a one-way hash of it is stored, it can be used once, and it expires after fifteen minutes. If a pairing code is entered incorrectly, we record the IP address it came from and a failure count, so that repeated wrong guesses can be blocked. Those records are kept for a short period and used for no other purpose.

What we never store

  • Your CRM records. Contacts, tasks, opportunities, notes, conversations and messages are requested by your browser directly from the CRM and displayed to you. They do not pass through, and are not written to, our systems.
  • Your CRM password. We never see it. Sign-in happens on the platform's own pages.
  • Your card details. Payment is handled entirely by Stripe on their own pages. We receive only a customer reference and subscription status.
  • Analytics or usage tracking. The extension has none. It contacts us only to refresh a token, check your subscription, save an updates sign-up if you choose to make one, and note that it was removed (see below).

If you sign up for updates

The extension may ask whether you would like updates. It is optional: nothing is sent unless you tick a box and press Save, and you can dismiss it.

If you sign up, we keep your email address, the first and last name you enter, which updates you asked for (about CRM Quick Access, about other tools we build, or both), when you agreed, and which installation the request came from. We also add you as a contact in our own CRM account, tagged with the product and your choices, so that we can send what you asked for.

We use it only to send the kinds of updates you chose. You can unsubscribe from any update we send, or email support@canitbeautomated.com and we will remove you.

When the extension is removed

When you uninstall the extension, Chrome opens a short page on our server that carries the installation identifier. We use it to note that the installation was removed and, if you signed up for updates, to tag your contact record in our CRM as uninstalled, so that we stop writing to you as a current user. Chrome only does this if you are online at the time.

What the extension does in the background

Normally nothing: it runs only while you have it open. The one exception is optional. If you turn on task reminders as Chrome notifications, the extension checks the CRM every few minutes for open tasks assigned to you, so it can notify you before one is due. That check goes from your browser directly to the CRM, the task details it uses are kept only on your device, and nothing about your tasks is sent to us. Turn reminders off and the checks stop.

Your reminder settings and quick task presets are saved in Chrome's sync storage, so they follow you to other browsers where you are signed in to Chrome. They are never sent to us.

The extension never reads, modifies or monitors the web pages you visit, and it has no ability to see any site other than the CRM API it is authorised to call.

Who else is involved

We use a small number of providers, each for a specific purpose:

ProviderPurposeWhat they hold
SupabaseDatabase and server hosting (United States)The installation records described above
StripeSubscription paymentsYour billing details and payment method. We never receive card numbers.
LeadConnectorOur own CRM, for update sign-upsThe name, email and choices of people who sign up for updates
OpenPhoneText messaging (website enquiries only)Phone number and message content

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Security

  • Refresh credentials are encrypted with AES-256-GCM before storage. The key is held separately from the database.
  • Installation secrets and pairing codes are stored only as one-way hashes.
  • All connections use HTTPS.
  • Database access is restricted to our own server functions. The database is not reachable from the public internet with ordinary credentials.

No system is perfectly secure, but the design deliberately limits what a breach could expose: we do not hold your CRM records, so they cannot be taken from us.

How long we keep things

  • Installation records: for as long as the installation exists. Disconnecting the extension removes it from your browser; ask us and we will delete the server record too.
  • Update sign-ups: until you unsubscribe or ask us to remove you.
  • Failed pairing attempts: a short rolling window, then discarded.
  • Billing records: as long as required for tax and accounting purposes.
  • Website enquiries and marketing contacts: until you ask us to remove them.

Your rights

You can ask us to give you a copy of the personal information we hold about you, correct it, delete it, or transfer it elsewhere. You can also opt out of marketing at any time.

If you are in the European Economic Area or the United Kingdom, you have these rights under the GDPR, including the right to complain to your data protection authority. If you are a California resident, you have rights under the CCPA including the right to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined there.

To exercise any of these, email support@canitbeautomated.com. We will not treat you differently for asking.

International transfers

Our servers and providers are located in the United States. If you use our services from elsewhere, your information will be processed in the United States, which may have different data protection laws than your own country.

Children

Our services are for businesses and are not directed at children under 13. We do not knowingly collect information from children. If you believe we have, contact us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects how we handle your information, we will tell affected customers directly rather than relying on you to notice.

Contact

Can It Be Automated? (a subsidiary of Appency LLC)
General enquiries: info@canitbeautomated.com
Privacy and data requests: support@canitbeautomated.com
Extension support: chromesupport@canitbeautomated.com
Telephone: 1.916.345.2729