Privacy Policy for Meta Listing Tool
Last Updated: July 8, 2026
This Privacy Policy explains how Meta Listing Tool ("we", "our", or "the extension") handles user data when you use our Chrome extension.
1. Overview
Meta Listing Tool is a browser extension designed to help users import vehicle inventory listings from admin-assigned dealer/inventory websites and manage and interact with Facebook Marketplace listings more efficiently.
We are committed to protecting user privacy and ensuring transparent data handling practices.
2. Information We Access
2.1 Page Content on Admin-Assigned Sites and Facebook (On-Page Data)
When you use the extension on a website assigned to you by your organization's admin (for scanning vehicle inventory), or on Facebook Marketplace (for posting/managing listings), it may temporarily access:
- Public listing titles
- Product/vehicle descriptions
- Prices
- Images visible on the page
- Listing metadata displayed by the page
👉 This data is only used to provide extension functionality while you are actively using an admin-assigned page or Facebook Marketplace.
We do NOT permanently store this data unless explicitly saved by the user, or automatically saved as part of a user-initiated or user-scheduled scan (see Sections 2.2 and 2.4).
2.2 User Actions Inside Extension
The extension may process:
- Button clicks
- Selection of which listings to scan (via on-page "Scan" / "Scan All" / "Skip" controls)
- Filtering or sorting actions
- User-selected settings
- Auto-scan scheduling preferences (interval duration set by the user)
This data remains local to your browser unless explicitly sent for processing.
2.3 Local Storage Data
We may use Chrome's local storage to save:
- User preferences
- Extension settings
- UI configuration
- Auto-scan schedule settings (on/off state and interval)
- The list of URLs assigned to you by your admin (cached locally so the extension can verify which pages it is authorized to run on)
This data stays on your device and is fully controlled by you.
2.4 Backend Communication & User Accounts
The extension communicates securely with our backend server to provide account management and data persistence:
- Account Data: We securely process and store your name, email, account password hashes, and user roles to manage authentication tokens (JWT).
- Assigned URLs: Your admin assigns specific dealer/inventory website URLs to your account; these are retrieved from and stored in our backend so the extension knows which pages it is authorized to operate on.
- Saved Progress: When explicitly triggered by user actions (or by a user-enabled auto-scan), the extension saves vehicle listing details (VIN, Title, Price, Mileage, Images, and posting statuses) to your secure private workspace database.
- All communication is encrypted via HTTPS. We do NOT sell, rent, or share user data with third parties.
3. How We Use Information
We use accessed information strictly for:
- Enabling core extension features
- Verifying that a page is authorized for scanning by your admin
- Improving inventory-import and Facebook Marketplace workflow efficiency
- Processing user-initiated actions
- Providing optional backend-powered features
- Running scheduled background tasks (auto-scan and listing health checks) as configured by the user
We do NOT use data for advertising or profiling.
4. Data Storage & Retention
- Account registration details and user-saved listings are stored securely in our private backend database until explicitly deleted by the user or account owner.
- Local data cached inside "chrome.storage.local" is fully controlled by the user and can be cleared instantly by logging out or uninstalling the extension.
- Auto-scan schedule settings are stored locally in chrome.storage and are cleared when the user disables the feature or uninstalls the extension.
5. Third-Party Services
Meta Listing Tool interacts with:
- Facebook (facebook.com) for listing management functionality
- Admin-assigned third-party dealer/inventory websites, for the purpose of reading publicly displayed vehicle listing data
- Our backend API (secure cloud-hosted service)
We are not responsible for the privacy policies or data handling practices of Facebook or of third-party dealer/inventory websites.
6. Permissions Used
The extension requests only the permissions necessary to provide its features:
- Host permissions (<all_urls>) — Meta Listing Tool is used across a variety of dealer/inventory websites, which differ by organization and are assigned individually by each admin rather than being fixed to one domain. Because the specific sites vary per customer and are not known in advance, we cannot scope host permissions to a fixed list of domains. The extension only activates its scanning UI and scraping logic on pages that the background script has verified are on the current user's admin-assigned URL list (see Section 2.4); on all other pages the extension remains idle and does not read or transmit page content. Facebook Marketplace access under this same permission is used to auto-fill and manage listings the user creates.
- storage — to save user preferences, settings, scan schedules, and the locally cached list of admin-assigned URLs.
- activeTab — to interact with the currently active browser tab when the user triggers an action from the popup.
- downloads — to allow users to export or download listing images/data.
- scripting — to programmatically inject the extension's content-script logic into tabs that the extension itself opens or navigates during automated workflows, such as: the navigation-based inventory scanner moving between listing URLs, the scheduled auto-scan opening a background tab, and the automated Facebook Marketplace listing-removal flow. This ensures the scanning/interaction logic is present in tabs that are created or navigated programmatically, outside of a normal user-initiated page load.
- alarms — to schedule and run two periodic background tasks without requiring the extension popup to remain open:
- Auto-scan: When enabled by the user, the extension schedules a recurring inventory scan at a user-defined interval (e.g., every 2 hours). This uses
chrome.alarms because Chrome's Manifest V3 service workers do not support persistent timers like setInterval.
- Listing URL health checks: A background alarm fires every 6 hours to verify that saved Facebook Marketplace listing URLs are still active, so users can be notified of removed or expired listings.
- Network access — to communicate securely with our backend API via HTTPS.
We follow the principle of least privilege: the extension only reads or acts on page content for (a) pages explicitly assigned by an admin, or (b) Facebook Marketplace pages the user is actively using to manage their own listings.
7. Background Activity
The extension runs limited background tasks using Chrome's alarms and scripting APIs. These tasks are:
- Only active when enabled by the user (auto-scan), necessary for data integrity (URL health checks), or triggered directly by a user action (e.g. deleting a sold listing).
- Restricted to admin-assigned pages and Facebook Marketplace, per Section 6.
- Do not collect, transmit, or store any personal data beyond what is described in this policy.
- Can be fully disabled by turning off auto-scan in the extension settings or by uninstalling the extension.
8. Data Security
We implement industry-standard security practices:
- HTTPS encrypted communication
- No unauthorized sensitive data storage
- Secure storage of data profiles explicitly requested by user features
- Restricted access to server resources
However, no system can guarantee absolute security.
9. User Control
Users may:
- Disable or remove the extension at any time
- Clear all stored data via Chrome settings
- Block or restrict permissions through browser controls
- Disable the auto-scan feature at any time from the extension popup to stop all scheduled background activity
- View the list of URLs currently assigned to their account via the "Allowed Links" section of the extension popup
10. Changes to This Policy
We may update this Privacy Policy occasionally to reflect improvements or changes in functionality.
Updated versions will always include a revised "Last Updated" date.
11. Contact Information
If you have any questions about this Privacy Policy or Meta Listing Tool, you may contact us at:
Email: colin@ikonicdigitalmarketing.com
Website: https://marketplace-ext-admin-lemon.vercel.app/