DealFlo Chrome Extension — Privacy and Data Disclosure
The DealFlo extension shows a salesperson the DealFlo text conversation for the customer they are viewing in their dealership CRM, puts an SMS button beside the customer phone numbers the CRM shows, and lets them text, call and take notes without leaving it. To do that it reads a small amount of information from the CRM page on screen. This page describes exactly what that means, in the order the questions usually get asked.
Where it runs
The extension is installed with permission to read pages on these sites only:
- VinSolutions:
*.vinsolutions.com,*.vinmanager.comandvinsolutions.app.coxautoinc.com - Elead:
*.eleadcrm.com,*.elead-crm.com,*.forddirectcrm.com, andcrm.connectcdk.com,elead.connectcdk.comandprod-crm.connectcdk.com, where Elead runs when a salesperson signs in through CDK Unify - DealFlo’s own sample CRM page,
www.dealflo.tech/extension-demo, which contains invented customers and exists so a salesperson can try the SMS buttons before using them on a real CRM. No other DealFlo page is read.
It does not run on any other website unless the salesperson turns it on for that one site, at which point Chrome shows its own permission prompt naming the site. It never requests access to all websites. It has no access to browsing history, bookmarks or downloads, and it does not record which pages are visited.
On the sites above it reads a page only while that page is on screen. A CRM page open in a background tab is read when the salesperson switches to it, not before.
What it reads from a customer screen
When a salesperson opens a customer record in a supported CRM, the extension reads the following from that page and nothing else:
- The customer’s phone number.
- The customer’s name.
- The customer’s email address, if the page shows one.
- A vehicle of interest and VIN, if the page shows them.
- A customer or opportunity identifier, when the CRM puts one in the page.
Reading happens entirely inside the browser. The page’s HTML is never transmitted. The fields above go to the DealFlo panel beside the CRM, which sends only the phone number and the CRM’s identifiers to DealFlo to find the matching customer in your DealFlo account. The name, email and vehicle stay in the browser, where they are shown to the salesperson, and reach DealFlo only if the salesperson chooses to add a customer who is not in DealFlo yet. Salespeople can turn this automatic reading off in the extension’s settings.
The SMS and Email buttons
On a supported CRM page, including list screens such as a desk log, the extension finds the customer phone numbers and email addresses the page shows and draws a small DealFlo SMS button beside each number and an Email button beside each address, so a customer who only gave an email can be reached the same way. It is designed to leave out numbers and addresses in page headers, navigation and footers, numbers and addresses inside notes and other text, fax numbers, automated no-reply addresses, and anything the salesperson is typing into.
- While the salesperson is signed in, the extension sends those phone numbers and email addresses, and nothing else from the page, to DealFlo so each button can show whether that customer is already in your DealFlo account and whether they have replied or opted out. DealFlo checks them against your own store’s records and does not store them. Signed out, nothing is sent.
- When the salesperson taps a button, the extension reads that number or email address again, along with the customer name shown on the same row, and hands them to the DealFlo panel. The number or address is used to find the customer. The name is only used to pre-fill a form the salesperson reviews if the customer is not in DealFlo yet.
- Salespeople can turn the buttons off in the extension’s settings, and DealFlo can switch them off for every store at once without an update.
What it refuses to read
The extension does not read credit applications, financing or payment pages, or any screen showing a Social Security, driver’s licence, bank or card number, and draws no SMS buttons on them.
Before reading anything, it checks the page address for a credit, finance, payment or deal page, and checks what is on screen for a field or label for a Social Security number, a driver’s licence number, bank routing or account details, a card number, or a password. If any are present, or the page is too large to check in full, the extension reads nothing, and the panel tells the salesperson that it did not read that screen. The check runs again whenever the page changes, so a tab or window that opens with any of those details on it takes the SMS buttons down for as long as it is showing.
An ordinary customer record is not refused because it shows a birthday or because its notes mention a credit application. On those screens the extension reads only what is listed above, never anything else on the page.
The side panel
The side panel shows DealFlo’s own web application, loaded from www.dealflo.tech each time the panel opens, the same as opening DealFlo in a browser tab. It signs in with the extension’s own DealFlo session rather than the salesperson’s website login. Everything the salesperson does there, such as sending a text, logging a note or starting a call, is an ordinary DealFlo action governed by our main Privacy Policy.
The extension also downloads a small settings file from DealFlo, including while signed out, which says whether the SMS buttons are switched on and how they are labelled. It contains no information about anyone, and nothing about the salesperson or the page is sent to fetch it.
What is stored, and for how long
- On the salesperson’s computer: their DealFlo sign-in session (kept until they sign out), the settings file above, and the panel’s working state: the customer read off the current screen, the conversation that is open, and any message they have started typing. The working state is cleared when the browser closes. Their extension preferences (automatic reading, SMS buttons, notifications, which store they are working in) are saved in Chrome’s sync storage, so they follow the salesperson to another computer if Chrome sync is on.
- On DealFlo’s servers: nothing new. Information read from a CRM page is used to look up an existing DealFlo record and is not stored as a copy. If the salesperson chooses to add a customer who is not yet in DealFlo, that is an explicit action they confirm, and it creates an ordinary DealFlo lead governed by our main Privacy Policy.
- Diagnostics: DealFlo records whether each read succeeded, which CRM it was, and which version of the extension ran, so we can tell when a CRM changes its pages and breaks compatibility. These records contain no customer name, phone number, email address, record identifier, or page address.
What the extension never does
- It does not sell, rent, or share any information with anyone.
- It does not use any information for advertising, profiling, or credit decisions.
- It does not transmit page content, screenshots, or keystrokes.
- It does not contain analytics, advertising, or tracking software of any kind. The code that reads CRM pages and draws the SMS buttons is contained in the extension package Chrome installs.
The use of information received through the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements: it is used only to provide the extension’s single purpose, showing and working the salesperson’s DealFlo conversations beside their CRM.
Who controls it
A dealership must be switched on for the extension by DealFlo before any of its salespeople can use it; until then the extension refuses every request for that store. Salespeople see only the customers their DealFlo role already lets them see. Individual salespeople can turn off automatic reading and the SMS buttons in the extension’s settings. Signing out, or removing the extension, ends its access immediately.
Questions
A dealership’s IT or compliance team can reach us at joshuas@dealfloai.com. If you need a written answer for a vendor review, say so and we will provide one.