Privacy Policy
Effective: July 23, 2026 · Version 2.0 · ContactID Chrome Extension & Dashboard
This Privacy Policy describes how ContactID collects, uses, stores, shares, and protects your personal information, including data obtained through Google APIs. It is published at https://contactus-extension.watchthemlive.com/privacy and is the policy linked from our Google OAuth consent screen.
1. Who We Are
ContactID ("ContactID", "we", "us", "our") is a bulk contact-form outreach product consisting of a Chrome extension and a web dashboard, operated by WATCHTHEMLIVE, a corporation incorporated under the laws of Ontario, Canada, with its registered office at 41 Old Indian Trail, Ramara, Ontario, Canada, L0K 1B0.
This Privacy Policy applies to the ContactID Chrome extension, the dashboard at contactus-extension.watchthemlive.com, and all interactions with the ContactID service, including Google Sign-In. It is the exact policy linked from our Google OAuth consent screen, in conformance with the Google API Services User Data Policy.
2. Information We Collect
Account Information
- Name, email address, and (optionally) a password when you create a ContactID account
- Google account information (name, email address, Google account identifier) if you register or sign in via Google OAuth
Sender Profile Data
- Contact details you choose to save in sender profiles: name, email, phone, company, job title, website, address, social links, and default message templates. This information is used to fill the contact forms you direct ContactID to submit.
Outreach & Campaign Data
- Website URLs you import (via CSV, TXT, XLSX, or paste) as outreach targets
- Form submission results (success/failure status, timestamps, target URL)
- Custom per-website messages you configure
- AI prompts and message templates you create or install from the prompt library, if you use the optional AI Personalized Messages feature
Payment Information
- Subscription billing details processed securely through Stripe. We do not store full card numbers.
Usage Data
- Extension version, browser type, and platform information
- Feature usage statistics and submission success rates
- Device identifier for session management and abuse prevention
3. How We Use Your Information
- Provide our services — create and manage your account, fill and submit contact forms you direct us to, and track your campaign results
- Authenticate you — verify your identity at sign-in via password, email code, or Google OAuth
- Process payments — handle subscription billing and credit purchases through Stripe
- Send notifications — deliver sign-in codes, receipts, and account-related emails
- Improve the platform — analyze aggregated, de-identified usage patterns to enhance features and fix issues
- Ensure security — detect and prevent fraud, abuse, and unauthorized account access
- Generate AI messages (opt-in) — when you enable "Use AI to write personalized messages" on a sender profile, we process your message template, your saved AI prompts, the target website's URL and name, and the profile fields you chose to include (name, company, job title) through an AI language model to produce a unique message for each website you submit to
- Provide support — respond to your questions and troubleshoot issues
4. Google API Services — Limited Use Disclosure
ContactID's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.1 Exact OAuth Scopes We Request
For Google Sign-In, ContactID requests only the following Google OAuth scopes:
| Scope | Purpose & user-facing feature | Data accessed |
openid | Standard OpenID Connect sign-in | Google account identifier |
.../auth/userinfo.email | Sign in with Google and provision a ContactID account | Email address associated with your Google Account |
.../auth/userinfo.profile | Display your name inside ContactID | Name and Google account identifier |
We do not request and do not access any other Google scopes — including Gmail content, Google Drive files, Google Calendar, Google Photos, Google Contacts, location history, or any other Google service.
4.2 How We Use Google User Data
We use Google User Data solely to authenticate you and provision your ContactID account. Specifically: verifying your identity at sign-in, creating your account with your Google-verified email address, and displaying your name inside the product.
4.3 Limited Use Compliance — What We Do Not Do
- We do not transfer Google User Data to third parties except as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after obtaining your explicit prior consent
- We do not use Google User Data for serving advertisements, including retargeted, personalized, or interest-based advertising
- We do not allow humans to read Google User Data, except: (a) with your explicit consent; (b) where necessary for security investigations; (c) to comply with applicable law; or (d) for aggregated, anonymized internal analysis where data cannot be re-identified
- We do not use Google User Data to train, fine-tune, or evaluate any generalized or non-personalized AI or ML model, including large language models
- We do not sell, rent, or trade Google User Data to any party for any purpose
- We do not use Google User Data to determine creditworthiness or for lending purposes
4.4 Storage, Retention, and Deletion of Google User Data
- The Google profile data we store is limited to your email address, name, and Google account identifier, stored alongside your ContactID account record
- We do not store Google access or refresh tokens after sign-in completes — the OAuth exchange is used only to verify your identity at that moment
- When you delete your ContactID account, or revoke access at myaccount.google.com/permissions and request deletion, we delete stored Google User Data within 30 days, except where retention is required by law
5. Data Sharing, Transfer & Disclosure
ContactID does not sell, rent, or trade your personal information — including Google user data — to any third party, for any purpose. We share data only in the limited circumstances below.
Service Providers We Share Data With
- Google (Google OAuth) — authentication only. We do not share your data with Google beyond the sign-in flow itself.
- Stripe — payment-related information (billing details, transaction amounts) to process subscriptions and credit purchases. Stripe acts as an independent controller under its own privacy policy.
- AI language-model provider — only when you enable the opt-in AI Personalized Messages feature, your message template, saved prompts, target website URL and name, and the profile fields included in the template are sent to an AI language-model provider to generate the personalized message. This data is used solely to produce your message and is not used by us to train AI models (see Section 12).
- CAPTCHA solving service — when a target contact form displays a CAPTCHA, the CAPTCHA challenge parameters (site key and page URL of the target website) are sent to a solving service. Your personal information is never included.
- Email delivery provider — recipient address and message content for transactional emails (sign-in codes, receipts), bound by contractual data-protection obligations.
- Cloud hosting provider — encrypted-at-rest storage with a reputable provider bound by data-protection terms.
When We May Disclose Data
- Legal requirements — when required by law, regulation, subpoena, or court order
- Safety & fraud prevention — to protect the rights, safety, or property of ContactID, our users, or the public
- Business transfers — in connection with a merger, acquisition, or sale of assets. Where the transfer would include Google User Data, we will obtain your explicit prior consent as required by the Google API Services User Data Policy.
- With your consent — when you explicitly authorize a specific share
International Data Transfers
Your data may be processed on servers located outside your country of residence. We ensure appropriate safeguards for international transfers, including encryption in transit and at rest and the European Commission Standard Contractual Clauses where applicable.
6. Third-Party Service Providers
- Google (Privacy Policy) — OAuth authentication
- Stripe (Privacy Policy) — payment processing
- AI language-model provider — message generation for the opt-in AI Personalized Messages feature only
- Transactional email provider — email delivery for account communications
We only share the minimum data necessary for each integration to function. We do not sell your personal information to any third party.
7. Cookies & Tracking
- Essential cookies — maintain your session and authentication state
- Preference storage — remember your settings inside the extension (stored locally in your browser via extension storage)
We do not use third-party advertising cookies or cross-site tracking technologies. We do not use cookies to collect data for advertising purposes.
8. Data Retention & Deletion
- Account data — retained until you delete your account
- Campaign and submission history — retained while your account is active, for your own reporting
- Payment records — retained as required by applicable financial regulations (typically 7 years)
- Usage logs — retained for 90 days for security and debugging
When you delete your account, we remove your personal data within 30 days, except where retention is required by law. To request deletion, delete your account in the dashboard or email us at [email protected].
9. Your Rights (GDPR, CCPA, PIPEDA)
Depending on your location, you may have the following rights under GDPR, UK GDPR, CCPA/CPRA, PIPEDA, or other applicable laws:
- Access — request a copy of the personal data we hold about you
- Correction — update or correct inaccurate personal data
- Deletion — request deletion of your personal data ("right to be forgotten")
- Export — receive your data in a portable, machine-readable format
- Restriction / Objection — limit or object to certain processing
- Opt-out of sale — we do not sell personal data; California residents may still make this request
- Revoke consent — withdraw consent for consent-based processing (e.g., revoke Google access at myaccount.google.com/permissions)
- Lodge a complaint — with your data protection authority
To exercise any of these rights, contact [email protected]. We respond within 30 days.
10. Security Measures
- All data transmitted via HTTPS/TLS 1.2 or higher
- Passwords hashed using bcrypt with salt
- Authentication with signed JWT tokens and server-side session management
- Data stored in MongoDB with role-based access controls and regular encrypted backups
- Rate limiting and abuse detection on authentication endpoints
- Principle of least privilege for all third-party API access
- Regular security reviews and dependency updates
11. Children's Privacy
ContactID is not intended for use by children under the age of 16 (or the equivalent minimum age in your jurisdiction, including 13 under COPPA in the United States). We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without verifiable parental consent, we will delete that information promptly. Contact [email protected] if you believe a child has provided us data.
12. AI / ML Model Training Disclosure
ContactID does not use any user data — including Google user data, sender profile data, campaign data, or personal information — to train, fine-tune, or evaluate any generalized or non-personalized artificial intelligence or machine learning models, whether our own or those of any third party. This restriction is binding regardless of any other provision of this Policy.
For clarity: the optional AI Personalized Messages feature uses an AI language model to generate messages at your request (see Section 3). That is real-time processing to deliver a feature you enabled — it is not, and does not permit, training on your data.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a prominent notice at least 30 days before the changes take effect, except where immediate updates are required by law. The "Effective" date at the top reflects the most recent revision.