Privacy Policy
Gmail Sync for Bitrix24 — Chrome Extension by GuruX Global
1. Overview
Gmail Sync for Bitrix24 ("the Extension") is a Chrome browser extension developed by GuruX Global ("we", "us", "our") that integrates Gmail with Bitrix24 CRM. This policy explains what data the Extension accesses, how it is used, and how it is protected.
2. Data We Access
The Extension accesses the following data solely to provide its CRM integration functionality:
- Email participant information: Names and email addresses of senders, recipients, and CC participants visible in Gmail threads you open.
- Email metadata: Subject lines and email body snippets from threads you view, used for logging email activities to Bitrix24.
- Bitrix24 account data: Your Bitrix24 portal domain, authenticated session token, and CRM records (contacts, leads, deals) retrieved through the Bitrix24 REST API.
3. How We Use Your Data
All data accessed by the Extension is used exclusively for the following purposes:
- Looking up email participants in your Bitrix24 CRM to display contact, lead, and deal information in the Gmail sidebar.
- Detecting whether email participants are Bitrix24 team members or external contacts.
- Creating new contacts, leads, and deals in your Bitrix24 CRM when you choose to do so.
- Logging email activities to your Bitrix24 CRM when you explicitly click the "Log Email" button.
- Caching your session token and CRM pipeline data locally to reduce server requests and improve performance.
4. Data Storage
The Extension stores a minimal amount of data locally in your browser using Chrome's chrome.storage.local API:
- Your authenticated session token (for API authentication).
- Your Bitrix24 portal domain (for building CRM links).
- Your email address (to identify you in email threads).
- Cached deal pipeline and stage data (to reduce API calls).
This data is stored only in your browser and is cleared when you disconnect your account or uninstall the Extension.
5. Data Transmission
The Extension communicates with our backend server at gmailsync.guruxdev.com over HTTPS to:
- Authenticate your Bitrix24 account via OAuth.
- Proxy CRM lookup and creation requests to the Bitrix24 REST API.
Email participant data (names and email addresses) is sent to our server solely to perform CRM lookups in your Bitrix24 portal. Email body content is only transmitted when you explicitly choose to log an email activity.
6. Data We Do NOT Collect
We do not:
- Read, store, or transmit the full content of your emails unless you explicitly log an email activity.
- Access emails you do not open.
- Track your browsing history or activity outside of Gmail.
- Collect health, financial, location, or authentication information.
- Sell or transfer user data to third parties.
- Use your data for advertising, analytics, or any purpose unrelated to the CRM integration.
- Use your data to determine creditworthiness or for lending purposes.
7. Third-Party Services
The Extension interacts with the Bitrix24 REST API on your behalf using OAuth credentials that you authorize. Your CRM data is accessed through your own Bitrix24 portal and is governed by Bitrix24's own privacy policy and your organization's data policies.
8. Data Security
We protect your data through the following measures:
- All communication between the Extension and our server uses HTTPS encryption.
- OAuth tokens are stored encrypted on our server and are never exposed to the client.
- Session tokens are scoped to individual browser sessions and can be revoked at any time.
- Our server does not persistently store email content or participant data beyond the duration of the API request.
9. User Control
You have full control over your data:
- Disconnect: You can disconnect your Bitrix24 account at any time through the Extension popup, which clears all locally stored data.
- Uninstall: Uninstalling the Extension removes all locally stored data from your browser.
- Data deletion: Contact us to request deletion of any server-side session data associated with your account.
10. Children's Privacy
The Extension is a business productivity tool and is not directed at children under 13. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the Extension after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this privacy policy or your data, please contact us: