Privacy Policy
Effective date: 6 October 2026 · Last updated: 6 October 2026
This policy explains how Rathod Group of Companies, trading as Inbound Labs ("Inbound Labs", "we", "us"), handles personal data when you use the Inbound Labs website at inboundlabs.app, our platform, and the Inbound Labs Chrome extension (the "Extension"). It covers two groups of people: customers who use our services, and individuals whose professional contact details appear in our database.
1. Who we are and how to contact us
Controller: Rathod Group of Companies (Inbound Labs).
Location: Bengaluru, India
Privacy and data requests: privacy@inboundlabs.app
General support: support@inboundlabs.app
2. Data we collect through the Extension
| Category | What and why | Where it is stored |
|---|---|---|
| Account and authentication data | Your Inbound Labs account email and a session token created when you sign in with email and password or with Google. If you use Google sign-in, we receive your name and email address from Google. Used to authenticate lookups and apply your plan and credits. | Session token in the Extension's local storage on your device; account record on our servers. |
| Website content (LinkedIn profile pages you view) | On LinkedIn profile and company pages, the Extension uses the page address (profile or company URL) and the visible name, headline and current company to match the person or company you are viewing in our database. This is read only on LinkedIn, and is sent to Inbound Labs only when the side panel performs a lookup. | Sent over HTTPS to Inbound Labs to run the lookup. Kept only if you save the contact to a list. |
| Domain of the website you are viewing | On websites other than LinkedIn, the Extension reads the address of your active tab and sends only the website's domain name (not the full address, path, search terms or page content) to find people at that company. Pages on search engines, webmail, chat apps and browser-internal pages are skipped. | Sent over HTTPS to Inbound Labs to run the lookup. Not kept as a browsing history. |
| Contact results and lists | Emails and phone numbers you reveal, their verification status, and contacts you choose to save to a list. | Your Inbound Labs account on our servers. |
| Usage and diagnostics | Reveals and credits used, recorded by our servers to bill for usage and prevent abuse. The Extension contains no third-party analytics or tracking. | Our servers. |
The Extension does not collect a record of your browsing history, the content of pages outside LinkedIn, your LinkedIn messages, your LinkedIn credentials or cookies, financial information, health information, keystrokes, or location. Its page-reading script runs only on LinkedIn. It reads the address of your active tab only while the side panel is open.
3. How we use data
- To provide the single purpose of the Extension: finding and verifying business contact details for people and companies you view, and saving them to your Inbound Labs lists.
- To authenticate you, apply plan limits, and bill for usage.
- To secure the service, prevent fraud and abuse, and troubleshoot.
- To comply with legal obligations.
We do not use data obtained through the Extension for advertising, profiling for credit or employment decisions, or to build data products unrelated to the Extension's purpose. We do not sell Extension user data.
4. Chrome Web Store Limited Use disclosure
Inbound Labs's use and transfer to any other app of information received from Google APIs and Chrome extension APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically: we use website content and authentication data only to provide and improve the Extension's single purpose; we do not transfer it to third parties except as needed to provide that purpose, to comply with law, or as part of a merger or acquisition with notice to you; we do not use or transfer it for personalized advertising or to determine creditworthiness or lending; and no human reads it except with your consent, for security investigations, to comply with law, or where aggregated and anonymized for internal operations.
5. Data about the people in our database
Inbound Labs provides a B2B contact database. If your professional details appear there, we process them (business name, job title, employer, work email, work phone, public professional profile URL) on the basis of our legitimate interests in enabling business-to-business outreach, balanced against your rights. You may ask us at any time to access, correct, or delete your record, or to opt out, by emailing privacy@inboundlabs.app or using our opt-out portal. We act on requests within 30 days and keep a suppression record so that opted-out individuals are not re-added.
6. Legal bases (EEA, UK, Switzerland)
Contract (providing the service you signed up for), legitimate interests (security, product improvement, B2B contact data), consent (where we ask for it, which you can withdraw at any time), and legal obligation.
7. Sharing and service providers
We share data only with service providers acting on our instructions, such as cloud hosting and database infrastructure, authentication, payment processing, email delivery and error monitoring, and with CRM or outreach tools you connect yourself. We may disclose data if required by law or to protect rights and safety. Our current infrastructure providers include Supabase (authentication and database), Netlify (web hosting) and cloud server providers that host our search service. A current list is available on request at privacy@inboundlabs.app.
8. International transfers
We are based in India and our providers may process data in other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
9. Retention
Lookup inputs are processed to return results and are not kept unless you save the contact. Saved contacts and lists are kept while your account is active and deleted within 30 days of account deletion. Billing records are kept as required by tax law. Logs are kept for a limited period for security and debugging.
10. Security
We use encryption in transit (TLS) and at rest, role-based access controls, and multi-factor authentication for internal systems. The Extension loads no remote code and communicates only over HTTPS. No system is perfectly secure; we will notify affected users and regulators of a qualifying breach as the law requires.
11. Your rights
Depending on where you live (including under GDPR, UK GDPR, India's Digital Personal Data Protection Act 2023, and the CCPA/CPRA), you may have the right to access, correct, delete, port, restrict or object to processing of your personal data, and to withdraw consent. California residents: we do not sell or share personal information of Extension users for cross-context behavioral advertising. To exercise rights, email privacy@inboundlabs.app. You may also complain to your local data protection authority.
12. Removing the Extension
Uninstall the Extension from chrome://extensions to remove locally stored data. To delete your account and server-side data, email us or use account settings.
13. Children
Our services are for business users and are not directed to anyone under 18.
14. Changes
We will post updates here and change the date above. Material changes will be notified in the Extension or by email.