Privacy Policy
Last updated: June 26, 2026
This privacy policy describes how the Snapcom CRM Sync Click-to-Call browser extension (the "Extension") and the Snapcom CRM service that powers it (the "Service", hosted at crm.snapcom.com) collect, use, and protect your information.
The Extension is intended for use by employees of organizations that subscribe to Snapcom's phone service. By installing the Extension and signing in, you agree to this policy.
1. Information We Collect
1a. Stored locally on your device
- Snapcom credentials and tokens — your username, the Snapcom API client id, the access token, and the refresh token. The client secret is bundled with the Extension. Tokens are used to authenticate API requests on your behalf.
- Device preference — the Snapcom phone device you have selected to ring when placing calls.
- Detection preferences — whether phone-number detection is enabled and the list of websites you have disabled it for.
- State flags — flags reflecting current sign-in status to the Service and the health of the active-call monitor, used to render banners in the Extension UI.
1b. Sent to Snapcom servers in normal operation
- Authentication requests — when you sign in, your credentials are sent to the Snapcom phone API to obtain access tokens.
- Call origination requests — when you click a phone number or use the dial pad, the destination number and the device you selected are sent to the Snapcom API to start the call.
- Active-call polling — while you are signed in, the Extension periodically asks the Snapcom API which calls are currently active on your extension so it can display the active-call popup. The carrier returns the call legs you are on; the Extension does not access calls belonging to other users.
- Contact lookups — when a call is active, the Extension may send the external party's phone number to the Service so it can look up a matching contact in your organization's connected CRM. Lookups are scoped to your organization's Snapcom domain and CRM configuration.
- Recent-calls requests — when you open the Extension popup, it requests your recent call history from the Service, scoped to your Snapcom extension and domain.
1c. Collected on Snapcom servers
- Call records — the Service ingests call records (date/time, duration, calling and called numbers, direction, call disposition) from the Snapcom phone platform for the organizations that subscribe to it.
- Call summaries and analysis — when enabled by your organization, Snapcom CalliQ may generate an AI-produced summary, key facts (e.g. company, contact name), action items, and quality metrics from a call recording, which are stored alongside the call record.
- CRM contact data fetched on your organization's behalf — when a contact lookup is performed, the Service queries your organization's connected CRM (HubSpot, Salesforce, Pipedrive, Zoho, Close, or Clio) using the credentials your administrator authorized, and may cache the matched contact's name, identifier, and URL for performance.
- Operational logs — standard server logs (request paths, status codes, timestamps, IP address) used for security, debugging, and abuse prevention. Logs are retained for a limited operational window.
2. Phone-Number Detection on Web Pages
To enable click-to-call, the Extension scans the visible text of web pages you visit for phone-number patterns and inserts a small call button next to detected numbers. This scanning happens entirely inside your browser. The Extension does not transmit the page content, page URL, or the detected phone numbers to any server unless you click a call button — at which point the chosen number is sent to the Snapcom API to place the call.
You can turn detection off globally or on a per-site basis from the Extension popup at any time. The Extension does not modify page content beyond inserting call buttons, does not inject advertisements, and does not track your browsing history.
3. How We Use Your Information
- To authenticate you against the Snapcom phone platform and the Snapcom CRM service.
- To originate calls through your Snapcom device when you click a phone number or use the dial pad.
- To display real-time information about your active call (caller, direction, state).
- To match incoming and outgoing calls against your organization's CRM and surface contact information.
- To synchronize call activity to your organization's CRM as activity records.
- To provide your organization's administrators with operational visibility into call activity, sync health, and CalliQ summaries.
- To secure, monitor, debug, and improve the Service.
4. Data Sharing
We do not sell your personal information. The Service shares data only as described below:
- With your organization. Call activity, CalliQ summaries, and sync logs are visible to authorized administrators of your organization within the Service.
- With your organization's connected CRM. When your organization has authorized a CRM connection (HubSpot, Salesforce, Pipedrive, Zoho, Close, or Clio), the Service writes call activity records and updates contact information in that CRM on your organization's behalf.
- With the Snapcom phone platform. Authentication and call-origination requests pass through the Snapcom phone platform.
- With infrastructure providers. The Service uses standard cloud infrastructure (e.g. database, queue, object storage for call recordings) under appropriate confidentiality terms.
- When legally required. We may disclose information if required by law or to protect the rights, safety, or property of Snapcom or others.
5. Data Retention and Deletion
- Locally stored tokens and preferences are cleared when you sign out of the Extension or uninstall it.
- Call records, CalliQ summaries, and CRM sync logs are retained by the Service for as long as your organization remains an active Snapcom CRM Sync customer. Retention windows are subject to your organization's subscription terms.
- Cached CRM contact lookups expire automatically and are refreshed against the source CRM as needed.
- If you would like data associated with you deleted, contact your organization's administrator or email us at the address below.
6. Security
The Extension communicates with Snapcom servers exclusively over HTTPS. Tokens are stored in the browser's extension storage, which is isolated from web pages and other extensions. Access to the Service requires authentication and is scoped by role (user, administrator, reseller administrator) and by organizational domain.
No system is perfectly secure. If you suspect a security issue, please contact us immediately.
7. Children's Privacy
The Service is intended for use by employees of business customers. It is not directed at children under 13, and we do not knowingly collect information from children.
8. Changes to This Policy
We may update this privacy policy from time to time. Changes will be reflected by updating the "Last updated" date at the top of this page. Material changes affecting how we use your information will be communicated in advance where reasonably possible.
9. Contact
If you have questions about this privacy policy or the Extension's data practices, contact us at:
support@snapcom.com