Lead Sync extension
Privacy & data use
Updated September 28, 2026
This notice describes Apex Mob Pipeline — Lead Sync for Chrome and the data it transfers to the connected Pipeline workspace at aopipeline.com. For questions or a data-access/deletion request, contact your workspace owner or malachi@malachietoniru.com.
When it runs
The extension inspects the active supported lead-source page when you click Check source account ID or Sync assigned leads. During a sync it moves through your assigned lead pages and reads supported lead detail cards using your existing signed-in source session. It does not run a background browsing-history collector.
Data handled
- Account and authentication: your Pipeline account email and name, enrolled numeric source account ID, the one-use connection code you enter, and a device token issued by Pipeline.
- Assigned lead information: source lead IDs, names, phone numbers, email addresses, street addresses, city, state, ZIP, market, source/group or affiliation, source status/date fields, security words, and other information printed on the assigned lead card. Depending on the source, card text, tables or images may include dates of birth, policy and coverage details, premiums, balances, payment-related information or health-related information. Scanned cards are saved as images. Some fields may be unavailable on a particular source card.
- Page and sync information: the source page URL, selected account, filters, pagination, lead IDs/counts and sync status needed to check that a complete assigned list was collected. Source HTML is processed temporarily to select supported fields; raw HTML is not uploaded. Structured card text and fields are uploaded. For scanned cards, Pipeline receives the temporary source image address, retrieves the image from the source’s image host, and saves the image without retaining the temporary address.
The extension does not read or send your source-account password, export browser cookies, collect unrelated browsing history, or request microphone access. Pipeline's separate web dialer manages calling permissions.
Purpose and recipients
The assigned lead card information is sent over HTTPS to aopipeline.com to create and refresh lead records and update assignments for your connected account. Pipeline makes those records available under the workspace's owner, manager and agent access controls. The service uses Vercel for application hosting and Supabase for database hosting. The extension does not send lead information to advertising or analytics services and does not sell extension data.
The use and transfer of information received through the extension is limited to providing or improving this lead-sync function, consistent with the Chrome Web Store User Data Policy, including its Limited Use requirements. It is not used for personalized advertising or creditworthiness/lending decisions.
Storage and retention
Chrome local extension storage keeps your connection's device token, account identity and CRM address. Access to that stored credential is restricted to trusted extension contexts. Session storage keeps a progress/error summary until the browser session ends. Lead detail records are not persisted in extension storage.
Pipeline stores synced lead records and sync/audit history on its server. Removing a source assignment ends access through that assignment; it does not erase the CRM record or its existing notes and history. These records remain until removed through an authorized data request or workspace retention process. Uninstalling the extension does not delete server records. Backups may retain earlier copies according to the hosting service's configured backup retention.
Your controls
You choose when to sync and which account to connect. Disconnect this extension clears its local connection and progress. To invalidate the server credential, also use Source sync → Manage connected devices in Pipeline. Your owner can disable the account or revoke access. You may remove the extension in Chrome. Contact the workspace owner or the address above for access, correction or deletion requests; identity and authorization may need to be verified.
Permissions
activeTab identifies the tab on which you invoked the extension. scripting runs the bundled lead parser on the allowed source page. storage retains the account connection and progress. Access to the specific source website listed in Chrome’s extension permissions supports reading assigned lead pages from that source. The extension is restricted to its supported source; it cannot read arbitrary websites. Optional access to aopipeline.com, requested when connecting, allows authenticated sync requests. The store package does not request access to other sites or localhost.
Changes
Changes to this notice will be published here with an updated date. Extension code changes are distributed as versioned Chrome Web Store updates after publication.