This policy explains how the PracticeStacks LinkedIn Lead Capture Chrome extension collects, uses, and protects your data.
Last updated: July 8, 2026
Data We Collect
The PracticeStacks Practice Automation Suite extension collects two distinct categories of data, each tied to a specific feature you choose to use:
LinkedIn profile data — name, headline, current company/job title, location, email, phone, website, about section, and profile URL, extracted only when you open the extension popup on a LinkedIn profile page.
GST / Income Tax / TRACES portal login credentials (PAN or username, and password) — read from your PracticeStacks client-credentials records, solely to automate sign-in to these government portals on your behalf.
Compliance notices and filing status shown on the Income Tax / GST / TRACES dashboards after auto-login, so they can be synced back into your PracticeStacks compliance records.
LinkedIn data extraction only happens when you actively open the popup. Government portal auto-login only happens when you or a scheduled sync explicitly triggers a notice-fetch for a specific client. No background or automatic LinkedIn scraping occurs.
How We Use Your Data
Data is used solely to power features inside your own PracticeStacks account. Specifically:
LinkedIn profile data is displayed in the extension popup for your review and editing before saving as a CRM lead.
When you click 'Add as Lead', the data is sent to the PracticeStacks API and stored in your CRM account.
For government portal auto-login, the extension fetches your client's encrypted credentials from PracticeStacks over HTTPS, decrypts them in memory, and fills the official GST/Income Tax/TRACES login form so the portal itself authenticates the session — the extension never sends credentials anywhere except the portal's own login page and the PracticeStacks API that stores them.
After login, the extension reads notice/filing information already rendered on the portal page and reports it back to PracticeStacks so it appears in your compliance dashboard.
Your authenticated PracticeStacks session token is stored locally in Chrome storage so you don't need to re-login each time.
No data is collected, stored, or transmitted unless you explicitly initiate the action or have explicitly enabled automated notice checks for a client.
Government Portal Credentials & Auto-Login
The 'auto-fill saved logins' feature is a paid-firm feature that signs into GST, Income Tax, and TRACES portals using credentials the firm has already stored in PracticeStacks for a client (e.g. to check compliance status or fetch notices), so staff don't have to re-enter them by hand.
Credentials are stored encrypted at rest in the PracticeStacks database (AES encryption) — never in plain text.
The extension requests a credential only at the moment of an auto-login action, over an authenticated HTTPS request to practicestacks.in.
The decrypted password exists only transiently in the extension's background service worker memory to fill the portal's password field; it is never written to Chrome storage, disk, or logs.
Auto-login only runs against the official government domains: services.gst.gov.in, eportal.incometax.gov.in, tdscpc.gov.in, and traces-app.tdscpc.gov.in.
Data Sharing & Third Parties
We do not sell, trade, rent, or transfer your data, LinkedIn profile data, or client portal credentials to any third parties. Your data is stored exclusively in your own PracticeStacks account.
No data is shared with advertisers or analytics providers.
No data is used for profiling, creditworthiness assessment, or lending purposes.
The extension communicates only with practicestacks.in (our platform), linkedin.com (to read profile data), and the official GST/Income Tax/TRACES government portals (to perform auto-login you request).
Website enrichment requests (to find contact details from a lead's own linked website) are made directly from the extension to that website and no data is routed through third-party servers.
Permissions Explained
The extension requests the following Chrome permissions, each for a specific purpose:
storage — Saves your login session locally so you stay signed in.
activeTab — Checks if you're on a LinkedIn profile page before extracting data.
scripting — Reads profile data from the LinkedIn page, checks your PracticeStacks session, and fills the login form on GST/Income Tax/TRACES portals when you trigger auto-login.
cookies — Reads your PracticeStacks session cookie to authenticate API requests.
notifications — Shows a desktop alert when a saved GST/Income Tax session is about to expire or a new notice is found.
Host access to linkedin.com — Required to extract profile data from the page.
Host access to practicestacks.in — Required to save leads, verify your login session, and fetch/store encrypted portal credentials.
Host access to services.gst.gov.in, eportal.incometax.gov.in, tdscpc.gov.in, traces-app.tdscpc.gov.in — Required to perform auto-login and read notices on the official government portals.
Broad host access (https://*/*, http://*/*) — Used only for the optional 'website enrichment' feature, which fetches publicly visible contact details from a lead's own website when you ask the extension to enrich that lead. It is never used to read or inject scripts into arbitrary pages you browse.
Automated Notice Checks
If a firm enables scheduled notice checks for a client, the extension periodically opens the relevant government portal in the background, signs in using that client's stored credentials, and reports any new notices back to PracticeStacks.
Only runs for clients a firm admin has explicitly enabled automated checks for.
Only reads notice/filing metadata already visible on the portal after login — it does not download, alter, or file anything on your behalf.
Can be turned off at any time from the client's record in PracticeStacks.
Data Retention & Deletion
You have full control over your data at all times:
Scraped LinkedIn profile data is held temporarily in memory only during your active session. It is not persisted locally.
Decrypted government portal passwords exist only in memory for the duration of a single auto-login attempt and are discarded immediately after — never written to disk or Chrome storage.
Your PracticeStacks session token is stored in Chrome local storage and is cleared when you click 'Logout' or uninstall the extension.
Lead data and stored client credentials can be edited or deleted at any time from your PracticeStacks dashboard.
Uninstalling the extension removes all locally stored data automatically.
Questions or Concerns?
If you have any questions about this privacy policy or how the extension handles your data, please contact us at support@practicestacks.in