1st Minute Lead Browser Extension
Privacy Policy
The "1st Minute Lead" browser extension (Chrome, Edge) shows, next to your CRM, the leads received by your 1st Minute Lead account, and lets you take, call and qualify them. It is reserved for Advisors invited to a 1st Minute Lead account; it has no standalone mode.
This policy explains what the extension processes, which browser permissions it uses and why, where data goes, and how to exercise your rights. It supplements the documents that govern the 1st Minute Lead platform as a whole: the Privacy Policy, the Data Processing Agreement and the Terms of Use.
- Publisher and roles
- What the extension does
- Data processed
- Permissions and why
- What is stored on your device
- Signing in
- Product usage analytics
- What the extension does not do
- Panel embedded in a CRM
- Recipients, hosting and transfers
- Security
- Retention and deletion
- Your rights
- Changes
- Contact
1. Publisher and roles
The extension is published by REACH TECHNOLOGIES SAS, 1 rue du Quai, 59800 Lille, France — SIREN 953 284 296 ("1st Minute Lead", "we"). Data Protection Officer: dpo@1stminutelead.com.
Two roles apply, exactly as for the rest of the platform:
- Lead Data (the persons who submitted a form on your company's website) and Advisor data (your identity, availability and call metadata) are processed by 1st Minute Lead as processor, on behalf of the company that holds the account (the "Client"), which is the data controller. This processing is governed by the Data Processing Agreement.
- Product usage analytics described in section 7 are processed by 1st Minute Lead as controller, on the basis of its legitimate interest in improving the product.
2. What the extension does
Once you are signed in and "On duty", the extension keeps a real-time connection to 1st Minute Lead's servers. When a
lead arrives for your account, it shows a system notification with "Take" and "Decline" buttons, plays a short sound, and
lists the lead in a side panel with the time left to call back. From the panel you can open the lead's record, call the
number through your own telephony (a standard tel: link — the extension does not carry, record or transcribe
calls), qualify the lead and close it. Everything you do is the same action, on the same account, as in the web dashboard
or the mobile application.
3. Data processed
| Processing | Data | Role / legal basis | Retention |
|---|---|---|---|
| Session | A signed session token identifying you on your account | Processor — contract between the Client and 1st Minute Lead | On your device until you sign out or uninstall; revoked server-side when your password changes |
| Displaying leads | Lead Data of your account: name, phone number, email, form answers, page and source, interest score where the Scoring module is enabled, who took the lead and when | Processor — under the Client's instructions (DPA) | Read from the servers and kept in the browser's session storage only; erased when the browser closes. Server-side retention follows the Client's plan and the DPA |
| Notifications | The lead's name and the website it came from, shown in the system notification | Processor (DPA) | Until you act on the notification or dismiss it |
| Availability | Your "On duty" status and connection presence, as in the dashboard | Processor (DPA) | Live state; history per the Client's plan |
| Preferences | Sound on/off; an optional CRM link template you type yourself | Contract | On your device until you change them or uninstall |
| Product usage analytics | See section 7 — named actions, extension version, browser user agent, random identifiers; never Lead Data | Controller — legitimate interest | 180 days |
The extension collects no data about you beyond what is listed here: no browsing history, no content of the pages you visit, no location, no contacts.
4. Permissions and why
The extension requests the minimum set of permissions for the behaviour described above. Each one is used only for the purpose stated.
| Permission | What it is used for |
|---|---|
sidePanel | Displaying the lead list and lead records in the browser's side panel. |
notifications | The "New hot lead" system notification with its Take / Decline buttons. |
offscreen | Playing the short alert sound (Manifest V3 service workers cannot play audio themselves). |
storage | Keeping your session token and preferences on your device, and the live state shared between the background worker and the panel. |
alarms | Waking the background worker periodically to keep the real-time connection alive. |
cookies | Only for the one-click "Use my dashboard session" sign-in and for Google sign-in: reading the session cookie of app.1stminutelead.com. The extension reads no cookie of any other site. |
Host permission https://app.1stminutelead.com/* | Talking to 1st Minute Lead's own servers. It is the extension's only network destination, and the only site whose cookies it can read. |
The extension has no content script and requests no access to the pages you visit: it cannot read, modify or observe your CRM or any other website.
5. What is stored on your device
- Extension local storage (persists across browser restarts): your session token, your preferences, and a random analytics device identifier (section 7). Signing out removes the token; uninstalling removes everything.
- Extension session storage (erased when the browser closes): the live state shown in the panel — the current leads of your account, your availability, account status — and a random analytics session identifier.
Nothing is written to the storage of any website you visit.
6. Signing in
Three ways to sign in exist; all of them end with the same session token, issued by 1st Minute Lead's servers.
- Email and password: sent over HTTPS to
app.1stminutelead.comonly; the password is never stored by the extension. - "Use my dashboard session": if you are already signed in to the web dashboard in this browser, the extension reads that single session cookie and reuses it, so you do not type anything.
- "Continue with Google": the extension opens 1st Minute Lead's own Google sign-in page in a new tab — the same page the
web dashboard uses. Google's consent screen runs there, on Google's and 1st Minute Lead's servers, and is governed by the platform
Privacy Policy. The extension itself receives nothing from Google: it only
picks up the session cookie that the sign-in page sets on
app.1stminutelead.com, then closes the tab.
7. Product usage analytics
Like the web dashboard and the mobile application, the extension sends first-party usage statistics to 1st Minute Lead's own infrastructure. No third-party analytics, advertising or crash-reporting SDK is embedded.
- What is recorded: named actions — signed in, on/off duty, lead taken, lead declined, lead abandoned, lead qualified,
call started (and the channel, phone or browser) — each tagged with the surface (
extensionorembed), the extension version, the browser user agent, a random device identifier stored in the extension, and a random session identifier. - What is never recorded: the content of leads. Events reference a lead only by its internal identifier — never a name, phone number, email or message. Your IP address is truncated on arrival (last byte removed in IPv4, /48 in IPv6) before storage.
- Retention: raw events are purged after 180 days.
8. What the extension does not do
- It does not read, record or transmit any page you visit, including your CRM. Matching a lead with the contact open in your CRM happens only in the embedded variant (section 9), and only when the CRM itself explicitly sends that contact's email or phone.
- It does not collect your browsing history, bookmarks, location or contacts.
- It does not carry, record or transcribe phone calls: "Call" hands the number to your own telephony.
- It does not sell, rent or share data with third parties, and shows no advertising.
- It never uses your data or Lead Data to train artificial-intelligence models.
9. Panel embedded in a CRM
The same panel can be embedded by the Client inside its own CRM as a frame served from app.1stminutelead.com/embed.
In that variant there is no browser extension and no browser permission: the session token is kept in that frame's own storage,
the CRM cannot read it, and the panel receives from the CRM only what the CRM deliberately posts to it — at most the email address
or phone number of the contact currently displayed, used solely to highlight the matching lead in the list. That value stays in the
browser and is not sent to 1st Minute Lead's servers.
10. Recipients, hosting and transfers
The extension communicates exclusively with app.1stminutelead.com, over HTTPS. The application infrastructure and
the database are hosted in France. Some ancillary functions of the platform rely on specialised providers — for what may concern the
extension, only the sending of transactional emails; the up-to-date list of providers, their role, their location and the safeguards
applied to any transfer outside the European Union is published on the
Subprocessors page. The extension itself embeds no third-party service.
11. Security
All traffic is encrypted in transit (TLS). The session token is signed and is revoked server-side whenever your password changes. The token lives in the extension's isolated storage, which no website can read. Signing out from the panel invalidates it on your device; uninstalling the extension removes all of its storage.
12. Retention and deletion
- On your device: session token and preferences until sign-out or uninstall; live state until the browser closes.
- Lead Data and Advisor data: retained server-side for the history period of the Client's plan and returned or deleted under the terms of the DPA; the extension adds no retention of its own.
- Analytics events: 180 days.
13. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection provided by the GDPR.
- For your data as an Advisor and for Lead Data, the controller is the Client — the company that invited you to its account. Address your request to it; 1st Minute Lead assists the Client as its processor and forwards any request it receives directly.
- For product usage analytics, contact privacy@1stminutelead.com.
You may also lodge a complaint with the French supervisory authority, the CNIL (cnil.fr), or with the authority of your country of residence.
14. Changes
We may update this policy when the extension changes. The date and version at the top of this page are updated accordingly, and any new permission requested by the extension will be explained here before it is used.
15. Contact
- Privacy: privacy@1stminutelead.com
- Data Protection Officer: dpo@1stminutelead.com
- Support: support@1stminutelead.com
This document is published by Reach Technologies SAS. For any question: contact@1stminutelead.com.
See also: Legal Notice ·
Terms of Use ·
Privacy Policy ·
DPA ·
Subprocessors ·
Cookies