Last updated: July 15, 2026
SyncSpot (“the extension”) is a Chrome browser extension that lets you create and update contacts in your own HubSpot CRM from a LinkedIn profile or conversation you are viewing. This policy explains what data the extension handles and where it goes.
The short version: your CRM data moves in exactly one direction — from the page you are looking at, in your browser, to your own HubSpot account — and only when you ask it to. We never see, collect, store, or sell any of it. The only thing the extension sends to us is optional usage statistics (event names, your display name and your own profile link — never page content, messages, contacts or your token), and you can turn that off in Settings.
SyncSpot is developed and maintained by an independent developer. Contact: mykhailo.pihosh@gmail.com
When you open a LinkedIn profile, SyncSpot reads the information already visible to you on
that page (name, headline, job title, company, location, profile URL, profile photo) and
shows it in a side panel. When you click “Add to HubSpot” or “Sync”, that information is
sent directly from your browser to the HubSpot API (api.hubapi.com) using the HubSpot
Private App token you created and pasted into the extension’s settings.
If you use the message features (manual “Sync to HubSpot” button in a conversation, or the optional auto-sync setting, which is off by default), the text of the currently opened LinkedIn conversation is sent to your HubSpot account as a logged communication on the matched contact.
All settings and caches are stored locally in your browser using Chrome’s extension
storage (chrome.storage.local). The extension has no backend of its own; the only data
we hold outside your browser is the optional usage statistics stored with our processor
(PostHog, EU) — see the “Usage statistics” section below.
Your CRM data goes to exactly one place: the HubSpot API (api.hubapi.com), over HTTPS,
authenticated with your own token, into your own HubSpot account. If usage statistics are
enabled (see below), small usage events additionally go to our analytics provider (PostHog,
EU-hosted). Beyond the LinkedIn page you are already on, the extension talks to no host
other than the HubSpot API and (if enabled) PostHog. LinkedIn pages are only read, never
written to, and no data is sent to LinkedIn.
LinkedIn profile information is personal data of the people whose profiles you view. You (and your organization) act as the data controller for whatever you choose to save into your CRM; SyncSpot is a local tool and does not itself retain that data. Please make sure your use of the extension complies with the privacy laws that apply to you.
SyncSpot sends usage statistics to our analytics provider (PostHog, hosted in the EU): event names (e.g. “sync”, “contact_created”), for some events a coarse mode flag (e.g. whether a sync was manual or automatic), a timestamp, the extension version, a random installation identifier, a display name and the URL of your own LinkedIn profile. The name and URL identify you, the operator — the name is the one you enter in Settings or, if left blank, the name derived from your OWN profile (read once from your feed); they are never the name or data of anyone whose profile you view.
The same channel carries diagnostic events (e.g. “dom_selector_miss”, “hubspot_api_error”) so we learn about breakages early; on top of the standard fields above, these add only coarse technical attributes of the failure — e.g. which category of API endpoint failed and its HTTP status code, or which part of the page layout was not recognized — never record identifiers, free-text error messages or page content.
Usage statistics never include message contents, LinkedIn profile data of people you view, HubSpot contact data or your token. Sharing is on by default and you can turn it off at any time in Settings → Usage stats.
Usage statistics already sent (including your name and profile link) are stored with our processor PostHog (EU) and are not deleted by uninstalling the extension. We keep them only while the tool is in active use by the team; email mykhailo.pihosh@gmail.com and we will delete your events and person profile. As with any web request, our provider technically receives your IP address when an event is sent; we have disabled geolocation enrichment and do not use IP addresses.
If the extension’s data handling ever changes (for example, a future version adds new kinds of telemetry or a backend service), this policy will be updated and the “Last updated” date changed before the new version ships.
Questions or concerns: mykhailo.pihosh@gmail.com