1st Minute Lead Browser Extension
Privacy Policy

Last updated September 7, 2026 · Version 1.1 · This document is published in English, which is the authoritative version.

The "1st Minute Lead" browser extension (Chrome, Edge) shows, next to your CRM, the leads received by your 1st Minute Lead account, and lets you take, call and qualify them. It is reserved for Advisors invited to a 1st Minute Lead account; it has no standalone mode.

This policy explains what the extension processes, which browser permissions it uses and why, where data goes, and how to exercise your rights. It supplements the documents that govern the 1st Minute Lead platform as a whole: the Privacy Policy, the Data Processing Agreement and the Terms of Use.

  1. Publisher and roles
  2. What the extension does
  3. Data processed
  4. Permissions and why
  5. What is stored on your device
  6. Signing in
  7. Product usage analytics
  8. What the extension does not do
  9. Panel embedded in a CRM
  10. Recipients, hosting and transfers
  11. Security
  12. Retention and deletion
  13. Your rights
  14. Changes
  15. Contact

1. Publisher and roles

The extension is published by REACH TECHNOLOGIES SAS, 1 rue du Quai, 59800 Lille, France — SIREN 953 284 296 ("1st Minute Lead", "we"). Data Protection Officer: dpo@1stminutelead.com.

Two roles apply, exactly as for the rest of the platform:

2. What the extension does

Once you are signed in and "On duty", the extension keeps a real-time connection to 1st Minute Lead's servers. When a lead arrives for your account, it shows a system notification with "Take" and "Decline" buttons, plays a short sound, and lists the lead in a side panel with the time left to call back. From the panel you can open the lead's record, call the number through your own telephony (a standard tel: link — the extension does not carry, record or transcribe calls), qualify the lead and close it. Everything you do is the same action, on the same account, as in the web dashboard or the mobile application.

3. Data processed

ProcessingDataRole / legal basisRetention
Session A signed session token identifying you on your account Processor — contract between the Client and 1st Minute Lead On your device until you sign out or uninstall; revoked server-side when your password changes
Displaying leads Lead Data of your account: name, phone number, email, form answers, page and source, interest score where the Scoring module is enabled, who took the lead and when Processor — under the Client's instructions (DPA) Read from the servers and kept in the browser's session storage only; erased when the browser closes. Server-side retention follows the Client's plan and the DPA
Notifications The lead's name and the website it came from, shown in the system notification Processor (DPA) Until you act on the notification or dismiss it
Availability Your "On duty" status and connection presence, as in the dashboard Processor (DPA) Live state; history per the Client's plan
Preferences Sound on/off; an optional CRM link template you type yourself Contract On your device until you change them or uninstall
Product usage analytics See section 7 — named actions, extension version, browser user agent, random identifiers; never Lead Data Controller — legitimate interest 180 days

The extension collects no data about you beyond what is listed here: no browsing history, no content of the pages you visit, no location, no contacts.

4. Permissions and why

The extension requests the minimum set of permissions for the behaviour described above. Each one is used only for the purpose stated.

PermissionWhat it is used for
sidePanelDisplaying the lead list and lead records in the browser's side panel.
notificationsThe "New hot lead" system notification with its Take / Decline buttons.
offscreenPlaying the short alert sound (Manifest V3 service workers cannot play audio themselves).
storageKeeping your session token and preferences on your device, and the live state shared between the background worker and the panel.
alarmsWaking the background worker periodically to keep the real-time connection alive.
cookiesOnly for the one-click "Use my dashboard session" sign-in and for Google sign-in: reading the session cookie of app.1stminutelead.com. The extension reads no cookie of any other site.
Host permission https://app.1stminutelead.com/*Talking to 1st Minute Lead's own servers. It is the extension's only network destination, and the only site whose cookies it can read.

The extension has no content script and requests no access to the pages you visit: it cannot read, modify or observe your CRM or any other website.

5. What is stored on your device

Nothing is written to the storage of any website you visit.

6. Signing in

Three ways to sign in exist; all of them end with the same session token, issued by 1st Minute Lead's servers.

7. Product usage analytics

Like the web dashboard and the mobile application, the extension sends first-party usage statistics to 1st Minute Lead's own infrastructure. No third-party analytics, advertising or crash-reporting SDK is embedded.

8. What the extension does not do

9. Panel embedded in a CRM

The same panel can be embedded by the Client inside its own CRM as a frame served from app.1stminutelead.com/embed. In that variant there is no browser extension and no browser permission: the session token is kept in that frame's own storage, the CRM cannot read it, and the panel receives from the CRM only what the CRM deliberately posts to it — at most the email address or phone number of the contact currently displayed, used solely to highlight the matching lead in the list. That value stays in the browser and is not sent to 1st Minute Lead's servers.

10. Recipients, hosting and transfers

The extension communicates exclusively with app.1stminutelead.com, over HTTPS. The application infrastructure and the database are hosted in France. Some ancillary functions of the platform rely on specialised providers — for what may concern the extension, only the sending of transactional emails; the up-to-date list of providers, their role, their location and the safeguards applied to any transfer outside the European Union is published on the Subprocessors page. The extension itself embeds no third-party service.

11. Security

All traffic is encrypted in transit (TLS). The session token is signed and is revoked server-side whenever your password changes. The token lives in the extension's isolated storage, which no website can read. Signing out from the panel invalidates it on your device; uninstalling the extension removes all of its storage.

12. Retention and deletion

13. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection provided by the GDPR.

You may also lodge a complaint with the French supervisory authority, the CNIL (cnil.fr), or with the authority of your country of residence.

14. Changes

We may update this policy when the extension changes. The date and version at the top of this page are updated accordingly, and any new permission requested by the extension will be explained here before it is used.

15. Contact

This document is published by Reach Technologies SAS. For any question: contact@1stminutelead.com.
See also: Legal Notice · Terms of Use · Privacy Policy · DPA · Subprocessors · Cookies