Privacy Policy

Effective Date: 2026-08-21  |  Last Updated: 2026-09-01

This Privacy Policy explains how Bartosz Cioch ("we," "us," "our") collects, uses, stores, and protects information through the PingBack (LinkedIn) Chrome extension and associated backend service (together, the "Service").

1. What Data We Collect

We collect only what the Service needs to let you tag, note, and track your professional contacts inline on LinkedIn. We do not collect data from LinkedIn beyond what is described here. We do not access your email. The Service requests no access to Gmail or any other mailbox.

1.1 LinkedIn Profile Data

When you view a LinkedIn profile with the extension active, we read fields already visible to you as a logged-in LinkedIn user directly from the page you're viewing:

We do not collect LinkedIn connection lists, messages, or any data from profiles the extension does not actively render a sidebar on. We do not use LinkedIn's API or any automated scraping/bulk-export mechanism — data is read only from the DOM of the single profile page you have open, in the same browsing session you're already in. The extension makes zero outbound network requests to linkedin.com from any code path, performs no auto-scroll/auto-pagination/synthetic clicks to force additional content to load, and does not read or capture data from background or inactive tabs.

1.2 Email Data — None

We do not access your email. The Service requests no Gmail scope and no access to any other mailbox. We do not read your messages, their headers, their subject lines, or their metadata; we do not send, draft, modify, or delete email on your behalf; and we cannot do any of these things, because the permission required to do so is not requested at install or at sign-in.

Signing in with Google shares only your name, email address, and profile picture (the openid, userinfo.email, and userinfo.profile scopes — all classified non-sensitive by Google), and is used solely to identify your account. Interaction history in the Service is therefore entirely user-created: entries you log yourself, such as a call, a meeting, or a reply.

1.3 Account & Billing Information

1.4 Contact/Interaction Data You Create

1.5 Product Usage

We record a small number of first-party events about how the Service is used — that a sign-in happened, that a note or tag was saved, that a free-tier limit was reached, that a checkout was opened, that a subscription started or ended — so we can tell which parts of the product work and which do not.

These records hold counts and short labels only. They never contain the text of your notes, the names of your tags, the names or profile details of the people you save, or your IP address. They are generated on our own servers when the extension calls our backend; there is no third-party analytics provider, no script running in your browser, and nothing shared with anyone. If you follow one of our install links, we also record which campaign it came from, using a random identifier that is created per click and cannot be used to recognise you across visits.

Product-usage records are kept for 12 months. If you delete your account, they are immediately unlinked from it, leaving anonymous counts that cannot be traced back to you.

1.6 If You Join the Pre-Launch List

If you enter your email address in the signup form on our homepage, we store that address and, if you arrived from one of our campaign links, the short label identifying which one. That is the entire record — no name, no IP address, no other detail about you.

We use it for exactly one thing: to email you once when the extension is available to install. It is not a newsletter, it is not shared with anyone, and it is not used for advertising. There is no third-party email service involved at the time of writing. You can have your address deleted at any moment, without giving a reason, by emailing contact@pingback-crm.com; we delete the list once the launch email has been sent and it has served its purpose.

Joining this list does not create an account and is entirely separate from the account data described above.

1.7 What We Do Not Collect

2. Why We Collect It (Purpose)

All data described in Section 1 is collected for one purpose: to power the core CRM functionality of the Service — letting you tag, annotate, and track professional contacts you encounter on LinkedIn, in a sidebar next to the page you're already viewing.

We do not use your data to train third-party AI models, do not use it for advertising, and do not use it for any purpose beyond delivering and improving the Service you signed up for and billing you for your subscription tier.

3. How We Store Data and For How Long

4. Your Rights

Regardless of your location, you may exercise the following rights by contacting us at contact@pingback-crm.com:

If you are in the EU/EEA, UK, or California, you have specific statutory rights under GDPR or CCPA/CPRA respectively (right to know, delete, correct, and opt out of sale/sharing — noting we do not sell or share data, so this right is satisfied by default). We will respond to verified requests within the legally required timeline (30 days under GDPR, extendable once; 45 days under CCPA, extendable once).

5. Third Parties We Share Data With

We share data only with the following categories of service providers (subprocessors), each bound by a data processing agreement limiting their use of your data to providing their service to us.

Third PartyPurposeData Shared
StripeSubscription billing and payment processingYour email address and billing/subscription status are sent to Stripe to create and manage your subscription. Stripe collects your payment card details directly (we never receive, transmit, or store your full card number, CVV, or bank account details). Stripe acts as an independent data controller for its own payment-processing and fraud-prevention obligations under its own privacy policy (see stripe.com/privacy).
Hosting providerBackend infrastructure and database hostingAll account and contact/interaction data described in Section 1, as needed to run the Service. Backend/database: Railway (European Union — Amsterdam, Netherlands). Public website/privacy policy pages: Cloudflare Pages.
Google APIsOAuth sign-in onlyOAuth token exchange and identity lookup against Google's userinfo/tokeninfo endpoints, scoped to openid, userinfo.email, and userinfo.profile — all non-sensitive. No mail, calendar, or drive scope is requested, so no such data is ever transmitted.

We do not sell your personal data. We do not share your data with data brokers or advertisers. No analytics, advertising, or marketing subprocessor is currently in use.

We never share your data with LinkedIn. The extension reads publicly-visible-to-you profile data locally in your browser; we do not report your usage, notes, or tags back to LinkedIn, and LinkedIn has no access to our backend or database.

We may disclose data if required by law, subpoena, or valid legal process, or to protect the rights, safety, or property of our users or the Service.

6. Children's Privacy

The Service is not directed at, and we do not knowingly collect data from, individuals under 16. If we learn we have collected data from a child under 16, we will delete it.

7. Security

We apply industry-standard technical and organizational measures — encryption in transit and at rest, access controls limiting who can view production data, and least-privilege API scopes — to protect your data. No system is perfectly secure; if a breach occurs that affects your data, we will notify affected users without undue delay, consistent with applicable law.

8. Changes to This Policy

We may update this Privacy Policy as the Service evolves. Material changes will be notified via the extension or email to your account address at least 14 days before taking effect. The "Last Updated" date at the top of this document reflects the most recent revision. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.

9. Contact Us

For any privacy question, data subject request, or concern:

Email: contact@pingback-crm.com
Location: Wrocław, Poland.

If you are in the EU/EEA or UK and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority.