Privacy Policy for Marketplace Assistant

Effective date: July 19, 2026

Marketplace Assistant is a Chrome extension that helps a signed-in user read the user's own Facebook Marketplace vehicle listings and prepare a new draft listing. The extension processes data only as described below.

1. Data we collect or process

Facebook Marketplace listing content

When the user starts a scan, the extension processes summaries of the user's visible active listings, including listing title, price, thumbnail, listing URL, listed date, and publication status. When the user selects a listing for copying or draft creation, the extension processes that listing's vehicle attributes, description, approximate listing location, and photographs. This data comes from Facebook Marketplace pages opened as part of the user-requested workflow.

Account and authentication data

If the user creates or signs into a Marketplace Assistant account, the extension processes the user's email address, Marketplace Assistant password, Supabase user ID, authentication session tokens, and Free/Pro access status. The password is transmitted directly to Supabase over HTTPS for authentication and is not stored by the extension. Authentication session tokens are stored locally so the user can remain signed in. Facebook passwords, Facebook authentication cookies, and Facebook access tokens are not collected.

Optional donations

Marketplace Assistant is currently free. If the user voluntarily chooses to support the project, the extension opens a Stripe-hosted payment page in a new browser tab. Payment details are entered directly on Stripe and are not collected or stored by the extension. Stripe may process payment, billing, device, and transaction information under Stripe's own privacy policy.

Support communications

When the user voluntarily submits a support request, the extension collects the subject, message, associated account identifier and email address, interface language, extension version, and submission time so the developer can respond and investigate the request.

News and poll responses

The extension downloads developer-published news, maintenance notices, links, and poll options from Supabase. If a signed-in user voluntarily answers a poll, the selected option, poll identifier, Supabase user ID, and response time are stored so that one account has one current answer per poll. Poll responses are not used for advertising or profiling.

Technical diagnostics

When an unexpected extension error occurs for a signed-in user, the extension may automatically send a limited diagnostic report containing the extension version, browser user-agent string (which may include general browser and operating-system/platform information), interface language, extension component, operation name, workflow status, sanitized error message, sanitized stack trace, time, and a duplicate-error fingerprint. Email addresses, authentication tokens, long numeric identifiers, and full URLs are removed or redacted before transmission. Diagnostic reports do not include listing photographs, Facebook messages, Facebook credentials, general browsing history, full page contents, mouse movements, keystrokes, or a record of the user's general browsing activity.

Optional local photo helper

If the user has installed and started the optional Marketplace Assistant photo helper, the extension may send selected photograph data to a loopback address (127.0.0.1) on the same device. The helper creates temporary local image files so Chrome can attach them to the Facebook draft. This transfer remains on the user's device and is not sent to the developer or another remote server.

Locally stored extension data

The extension stores interface language, account session, selected listing data, Marketplace listing URLs selected by the user, workflow state, action log, copied listing content, temporary photograph data, cached announcements, and identifiers of read or dismissed announcements in Chrome extension storage. It does not access or collect the user's general Chrome browsing history.

The extension does not collect medical information, creditworthiness information, payment-card information, precise device location, or communications from Facebook Messenger.

2. How data is used

Data is used only to provide or improve the extension's user-facing functions:

Marketplace Assistant does not automatically publish a listing, send Facebook messages, build advertising profiles, determine creditworthiness, or use data for unrelated purposes.

3. Storage, security, and retention

Listing content, photographs, workflow state, preferences, and session information are stored locally in Chrome extension storage, Chrome-managed downloads, or temporary files on the user's device. When the optional local helper is used, it also creates temporary photograph files on the same device. Temporary photograph files and related download records are removed after the operation where possible. Local data remains until it is replaced, cleared through Chrome, removed by the helper, or the extension is uninstalled.

Account records, poll responses, support requests, and sanitized diagnostic reports are stored in the developer's Supabase project. Data sent to Supabase is transmitted over HTTPS. Database access is restricted through authenticated requests and row-level access controls. Authentication session tokens are stored locally and are used only to maintain the user's signed-in session.

Account information and poll responses are retained while the account is active, until the related poll is deleted, or until deletion is requested. Support and diagnostic records may be retained for up to 12 months, unless a longer period is reasonably required to resolve an open support or security issue or to comply with law.

4. Data sharing and disclosure

The developer does not sell, rent, or use user data for advertising. Data is disclosed only in these limited circumstances:

Human access to support data is limited to responding to the request voluntarily submitted by the user. Human access to non-aggregated diagnostic data is limited to investigating security incidents or troubleshooting a specific issue after obtaining the user's explicit consent. Other internal reliability review uses aggregated or anonymized information. Data may also be accessed when required by applicable law.

Marketplace Assistant's use and transfer of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

5. User choices and deletion

Users can stop a workflow at any time, choose whether to answer a poll, change a poll answer, dismiss an announcement, sign out, clear extension storage, or uninstall the extension. To request access to, correction of, or deletion of account, poll, support, or diagnostic data stored in Supabase, email musicyt200@gmail.com from the email address associated with the account.

6. Third-party services

Facebook Marketplace is operated by Meta. Supabase provides authentication and database services. Stripe provides the optional hosted donation page and payment processing. Their processing is also governed by their respective privacy policies and terms. See the Meta Privacy Policy, Supabase Privacy Policy, and Stripe Privacy Policy. Marketplace Assistant is not affiliated with, endorsed by, or sponsored by Meta or Facebook.

7. Changes to this policy

This policy may be updated when the extension's data practices change. The effective date above will be updated, and material changes will be disclosed through the extension or its Chrome Web Store listing when required.

8. Contact

For privacy questions or data requests, contact: musicyt200@gmail.com