Privacy Policy
Centra — CRM web app and LinkedIn Chrome extension
Last updated: 31 août 2026 · Publisher: Centra
1. Overview
This privacy policy covers Centra, our CRM web app (the “App”, available e.g. at crm.usecentra.com), and our Centra / LinkedIn CRM Chrome extension (the “Extension”). We do not sell your data or use it for advertising.
The App lets you manage your contacts, companies, and conversations, and can connect to your email mailbox if you authorize it (see the “Google User Data” section). The Extension helps you add LinkedIn profiles and company pages to your Centra CRM; it only runs when you use it on LinkedIn and only processes data you choose to save.
2. Data We Collect and Use
2.1 Data stored on your device (Chrome storage)
The Extension stores the following only in your browser’s local storage (Chrome’s storage.local):
- Account and session: Authentication tokens and session data from the Centra web app (after you log in and use “Sync Session”), so you stay logged in.
- Preferences: Your selected workspace/organization, environment (e.g. Test/Live), and similar settings.
- Temporary data: Pending contact or company data you are about to add to the CRM (e.g. after clicking “Add to Centra” and before confirming). This is cleared after the action completes or is cancelled.
None of this data is sent to the Extension developer for analytics or marketing.
2.2 Data read from LinkedIn
When you are on a LinkedIn profile or company page and use the Extension (e.g. “Add to Centra”, “Open in Centra”):
The Extension may read visible information on the current page (e.g. name, headline, company, location, profile/company URL) only to send it to your Centra CRM when you choose to add or update a contact or company. This happens only when you take an explicit action (e.g. click a button in the Extension). We do not continuously scrape or read LinkedIn in the background.
2.3 Cookies
- The Extension may use cookies for the Centra web app domain (e.g. crm.usecentra.com or your configured URL) to sync your login session when you use “Sync Session.”
- The Extension does not use cookies to track you across unrelated websites or for advertising.
3. Where Your Data Is Sent
Data you provide or that the Extension collects from LinkedIn (as above) is sent only to:
- Centra CRM (your account): Via the Centra web app (e.g. crm.usecentra.com) and its backend (e.g. Supabase). This includes contact/company data, session data, and (if you use the feature) LinkedIn connection requests (e.g. profile URL and optional note) sent through your CRM’s API.
- Supabase: Used as the backend for Centra. Data sent there is governed by your (or your organization’s) agreement with Centra and Supabase’s privacy policy.
We do not send your data to the Extension developer’s own servers for analytics, advertising, or resale.
4. Google User Data
Centra lets you connect your Gmail mailbox to your Centra workspace so that your customer email conversations appear alongside your CRM contacts. This connection is entirely optional and is only established when you explicitly authorize it through Google’s consent screen.
What we access. When you connect a Gmail mailbox, Centra accesses your email messages — including sender, recipients, subject, body, and thread information — using the gmail.readonly scope, and sends email on your behalf using the gmail.send scope. We access data only from mailboxes you have personally connected.
How we use it. Google user data is used exclusively to provide the user-facing features of Centra: displaying your emails in your unified inbox, showing conversation history on the matching contact records in your workspace, detecting replies so that automated outreach sequences you have configured stop when a contact responds, and sending emails that you compose or schedule in Centra from your own email address. Centra’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we never do with it. We do not use Google user data for advertising. We do not sell it or transfer it to data brokers or any third party, except as necessary to provide the features described above, to comply with applicable law, or as part of a merger or acquisition with prior notice to you. We do not use Google user data to develop, improve, or train generalized (non-personalized) artificial intelligence or machine learning models. No humans read your email data unless you give us affirmative permission (for example, to resolve a support issue), or it is necessary for security purposes or to comply with applicable law.
How it is processed and protected. Centra uses Aurinko, a unified email API platform, as a data processor to connect to Gmail on your behalf. Google user data is transmitted over encrypted connections (TLS) and stored encrypted at rest. Access is limited to your own workspace: your email data is visible only to you and to workspace members you have authorized, and internal access by our staff is restricted and logged.
Retention and deletion. Synced email data is retained only while your mailbox remains connected. When you disconnect your mailbox from Centra, or delete your Centra account, the associated Google user data is deleted from our systems. You may also request deletion at any time by contacting us at privacy@usecentra.com, and you can revoke Centra’s access to your Google account at any time via your Google Account security settings.
5. Data Retention and Deletion
- On your device: You can clear Extension data by removing the Extension or clearing site/data for the Extension in Chrome. Logging out in the Extension clears stored session and related data.
- On Centra/Supabase: Retention of data in your CRM (Centra and Supabase) is governed by your contract with Centra and their respective policies, not by this Extension alone.
6. Permissions
We use Chrome permissions only as follows:
- activeTab: To access the current LinkedIn tab when you use the Extension on a profile or company page.
- storage: To keep your session and preferences locally (as in section 2.1).
- cookies: To sync your Centra login session when you use “Sync Session.”
- Host access (e.g. linkedin.com, your CRM/Supabase URLs): To read the current LinkedIn page when you act, and to communicate with the Centra web app and its backend.
We do not access other tabs, history, or bookmarks beyond what is needed for these features.
7. Children
The Extension is not directed at children. We do not knowingly collect data from children. If you believe a child has used the Extension and provided data, contact us and we will help delete it where we control the data.
8. Changes to This Policy
We may update this privacy policy. The “Last updated” date at the top will be revised when we do. Continued use of the Extension after changes means you accept the updated policy. For material changes, we will use reasonable means (e.g. in-app notice or store listing) to inform you.
9. Contact
For privacy-related questions or requests (e.g. access, correction, deletion), contact: privacy@usecentra.com or our support page.
