Privacy Policy for Marketplace Assistant
Effective date: July 19, 2026
Marketplace Assistant is a Chrome extension that helps a signed-in user read the user's own Facebook Marketplace vehicle listings and prepare a new draft listing. The extension processes data only as described below.
1. Data we collect or process
Facebook Marketplace listing content
When the user starts a scan, the extension processes summaries of the user's visible active listings, including listing title, price, thumbnail, listing URL, listed date, and publication status. When the user selects a listing for copying or draft creation, the extension processes that listing's vehicle attributes, description, approximate listing location, and photographs. This data comes from Facebook Marketplace pages opened as part of the user-requested workflow.
Account and authentication data
If the user creates or signs into a Marketplace Assistant account, the extension processes the user's email address, Marketplace Assistant password, Supabase user ID, authentication session tokens, and Free/Pro access status. The password is transmitted directly to Supabase over HTTPS for authentication and is not stored by the extension. Authentication session tokens are stored locally so the user can remain signed in. Facebook passwords, Facebook authentication cookies, and Facebook access tokens are not collected.
Optional donations
Marketplace Assistant is currently free. If the user voluntarily chooses to support the project, the extension opens a Stripe-hosted payment page in a new browser tab. Payment details are entered directly on Stripe and are not collected or stored by the extension. Stripe may process payment, billing, device, and transaction information under Stripe's own privacy policy.
Support communications
When the user voluntarily submits a support request, the extension collects the subject, message, associated account identifier and email address, interface language, extension version, and submission time so the developer can respond and investigate the request.
News and poll responses
The extension downloads developer-published news, maintenance notices, links, and poll options from Supabase. If a signed-in user voluntarily answers a poll, the selected option, poll identifier, Supabase user ID, and response time are stored so that one account has one current answer per poll. Poll responses are not used for advertising or profiling.
Technical diagnostics
When an unexpected extension error occurs for a signed-in user, the extension may automatically send a limited diagnostic report containing the extension version, browser user-agent string (which may include general browser and operating-system/platform information), interface language, extension component, operation name, workflow status, sanitized error message, sanitized stack trace, time, and a duplicate-error fingerprint. Email addresses, authentication tokens, long numeric identifiers, and full URLs are removed or redacted before transmission. Diagnostic reports do not include listing photographs, Facebook messages, Facebook credentials, general browsing history, full page contents, mouse movements, keystrokes, or a record of the user's general browsing activity.
Optional local photo helper
If the user has installed and started the optional Marketplace Assistant photo helper, the extension may send selected photograph data to a loopback address (127.0.0.1) on the same device. The helper creates temporary local image files so Chrome can attach them to the Facebook draft. This transfer remains on the user's device and is not sent to the developer or another remote server.
Locally stored extension data
The extension stores interface language, account session, selected listing data, Marketplace listing URLs selected by the user, workflow state, action log, copied listing content, temporary photograph data, cached announcements, and identifiers of read or dismissed announcements in Chrome extension storage. It does not access or collect the user's general Chrome browsing history.
The extension does not collect medical information, creditworthiness information, payment-card information, precise device location, or communications from Facebook Messenger.
2. How data is used
Data is used only to provide or improve the extension's user-facing functions:
- find and display the user's Marketplace listings;
- copy a listing selected by the user;
- transfer listing text and photographs into a new Marketplace draft for the user to review;
- authenticate Marketplace Assistant accounts and determine Free/Pro access;
- open the optional Stripe donation page when the user requests it;
- display developer-published product news and maintenance notices;
- record a poll answer only when the signed-in user chooses to vote;
- respond to support requests;
- diagnose errors, prevent duplicate reports, secure the service, and improve reliability.
Marketplace Assistant does not automatically publish a listing, send Facebook messages, build advertising profiles, determine creditworthiness, or use data for unrelated purposes.
3. Storage, security, and retention
Listing content, photographs, workflow state, preferences, and session information are stored locally in Chrome extension storage, Chrome-managed downloads, or temporary files on the user's device. When the optional local helper is used, it also creates temporary photograph files on the same device. Temporary photograph files and related download records are removed after the operation where possible. Local data remains until it is replaced, cleared through Chrome, removed by the helper, or the extension is uninstalled.
Account records, poll responses, support requests, and sanitized diagnostic reports are stored in the developer's Supabase project. Data sent to Supabase is transmitted over HTTPS. Database access is restricted through authenticated requests and row-level access controls. Authentication session tokens are stored locally and are used only to maintain the user's signed-in session.
Account information and poll responses are retained while the account is active, until the related poll is deleted, or until deletion is requested. Support and diagnostic records may be retained for up to 12 months, unless a longer period is reasonably required to resolve an open support or security issue or to comply with law.
4. Data sharing and disclosure
The developer does not sell, rent, or use user data for advertising. Data is disclosed only in these limited circumstances:
- Supabase: acts as the service provider for account authentication, access status, product announcements, poll responses, support requests, and sanitized diagnostic storage. See the Supabase Privacy Policy;
- Stripe: processes an optional donation only when the user chooses to open the donation page and submit a payment; payment-card details are provided directly to Stripe and are not received by the extension. See the Stripe Privacy Policy;
- Meta/Facebook: listing data is read from and written back to Facebook Marketplace only when the user requests the corresponding extension action; the extension does not provide Meta with a separate diagnostic or account database;
- Legal or security requirements: data may be disclosed when reasonably necessary to comply with law, prevent fraud or abuse, or protect users and the service;
- Business transfer: data may be transferred as part of a merger, acquisition, or sale of assets only after obtaining the user's explicit prior consent and subject to applicable law.
Human access to support data is limited to responding to the request voluntarily submitted by the user. Human access to non-aggregated diagnostic data is limited to investigating security incidents or troubleshooting a specific issue after obtaining the user's explicit consent. Other internal reliability review uses aggregated or anonymized information. Data may also be accessed when required by applicable law.
Marketplace Assistant's use and transfer of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
5. User choices and deletion
Users can stop a workflow at any time, choose whether to answer a poll, change a poll answer, dismiss an announcement, sign out, clear extension storage, or uninstall the extension. To request access to, correction of, or deletion of account, poll, support, or diagnostic data stored in Supabase, email musicyt200@gmail.com from the email address associated with the account.
6. Third-party services
Facebook Marketplace is operated by Meta. Supabase provides authentication and database services. Stripe provides the optional hosted donation page and payment processing. Their processing is also governed by their respective privacy policies and terms. See the Meta Privacy Policy, Supabase Privacy Policy, and Stripe Privacy Policy. Marketplace Assistant is not affiliated with, endorsed by, or sponsored by Meta or Facebook.
7. Changes to this policy
This policy may be updated when the extension's data practices change. The effective date above will be updated, and material changes will be disclosed through the extension or its Chrome Web Store listing when required.
8. Contact
For privacy questions or data requests, contact: musicyt200@gmail.com