This notice describes the Chad Caller Form Chrome extension used by authorized Chad sales representatives. It covers the extension's handling of representative and lead data; the general website privacy policy has a different scope.
Purpose and scope
The extension places a movable caller-form panel on ordinary HTTP and HTTPS pages, including supported dialer pages. It does not read the host page's content to find leads, collect browsing history, access the microphone, or upload call recordings. The panel loads its form only when opened.
Information handled
A representative enters an email address and password to sign in. The password is sent to Chad's caller-form API for authentication and is not saved by the extension. The resulting scoped session token and representative identity are stored in this Chrome profile's extension-local storage. The extension can display lead contact details returned by Chad's API and retains one draft containing the selected lead, outcome selections, notes, callback details, do-not-contact progress, and confirmed booking details. The draft can remain after session expiry or an unresolved submission; confirmed submission, explicit reset, or an eligible logout can remove it. It also stores the panel position and editing ownership needed to resume across tabs.
Where information goes
The extension service worker sends authentication, lead lookup, and submitted caller-form data to Chad's fixed caller-form API endpoint. The production extension uses api.internal.trychad.com; a separate staging build uses api-staging.internal.trychad.com. When a representative opens meeting scheduling, a Cal.com-hosted booking iframe receives booking prefill information, including lead contact details and representative attribution, and returns confirmed booking details to the form. The extension does not sell this information or share it with the website underneath the panel. Submitted data is handled under Chad's applicable agreements and notices.
Local storage and control
The session and draft are local to this extension installation in the Chrome profile, not Chrome account sync. A successful explicit logout clears the token and a draft whose stored rep email matches the signed-in representative, even if that draft is damaged. Logout is blocked while that representative has an unresolved submission. A foreign draft or damaged draft without a matching rep email remains for explicit recovery. Session expiry clears the token but retains the draft for the same representative to restore after login. After confirmed submission and successful local cleanup, the completed draft is cleared; an unresolved submission is retained for review rather than automatically retried. Removing the extension also removes its local data. Before replacing a developer-mode pilot with the Web Store version, submit or deliberately clear the current draft; the two installations do not share storage. Contact Chad to request access to or correction of information already submitted to its API.
Contact
Questions about this extension or its data handling can be sent to hello@trychad.com.