Privacy Policy
Last updated September 4, 2026
AutoPosting Pro (“AutoPosting Pro,” “we,” or “us”) provides dealership-inventory and listing tools through our website and Chrome extension. This policy explains what information the service handles, where it is handled, how it is used, and the choices available to you. Questions or privacy requests can be sent to [email protected].
Information we collect
- Account and dealership information — your name, email address, hashed password, organization and dealership details, membership, settings, and license or subscription status. A phone number is optional and, if provided, is used for account support.
- Billing information — Stripe processes payment-card details. We receive and store identifiers and records needed to manage the customer, subscription, plan, and payment status; we do not store full payment-card numbers.
- Vehicle inventory — information published on the dealership website, such as VIN, stock number, year, make, model, trim, price, mileage, colors, description, features, vehicle URLs, photos, and inventory status.
- Marketplace and listing activity — listing status, platform, timestamps, resulting listing links when available, queue state, attempts, errors, renewal or delisting results, and the vehicle associated with an action.
- Marketplace and Messenger information — when you use inbox or reply features, the extension may read bounded conversation information needed for that feature, including buyer display name, listing title, thread identifier, message preview, recent buyer and seller messages, whether a reply is waiting, drafts, reply history, notification state, and recent responder activity. It does not copy your entire Facebook account.
- AI inputs and results — the vehicle facts, dealership instructions, selected photos, scene or removal instructions, and bounded conversation context needed for the AI feature you request, together with generated captions, reply drafts, selector configurations, or edited-image results.
- Usage, support, and security information — login and activity timestamps, device or extension version, IP address received by our servers, feature usage, rate-limit information, scan progress, quality checks, errors, bounded diagnostic evidence, best-effort anonymous public phone/email-link activation counts grouped only by fixed channel and coarse acquisition source, and bounded UTC daily counts for fixed campaign codes registered by AutoPosting Pro.
- Optional Facebook and Instagram business connections — if you separately choose a legacy Meta connection, we receive the Pages, Instagram Business accounts, permissions, and access tokens that you authorize. This connection is optional and separate from the normal signed-in Chrome Marketplace workflow.
How the Chrome Marketplace and Messenger features work
Marketplace actions use the Facebook session that is already signed in to the same Chrome profile as the extension. The extension opens or reads the relevant Marketplace or Messenger pages and performs only the feature you enabled or initiated. The extension does not request Chrome’s cookies permission, does not ask for your Facebook password, and does not send your Facebook password, Facebook cookies, or Facebook session token to AutoPosting Pro’s servers as part of this workflow.
The Messenger reader uses a background connector tab created for AutoPosting Pro, rather than taking over a conversation tab you opened. Inbox monitoring and reply drafting are controlled separately. Every outgoing buyer reply remains unsent until you review its exact content and intended recipient and confirm the send through the extension or phone remote.
How local inventory scanning works
After you grant permission for the dealership website, the extension can read its inventory listing and vehicle-detail pages in your browser. It extracts and normalizes vehicle records, follows same-site vehicle links, checks required fields and photo ownership, and uploads the resulting inventory candidate and quality evidence to AutoPosting Pro. This lets the reader work with sites that require a normal customer browser session.
Page HTML used during a local scan is normally processed in memory. Raw page HTML is not stored in the local scan database. If the service needs to build or repair a dealership-specific reader, the extension may send the rendered listing-page HTML to an authenticated AutoPosting Pro endpoint, subject to a 3 MB request limit. The server reduces that markup before sending a smaller, focused representation to an AI provider. When a reader cannot be built, a bounded reduced page snapshot and diagnostic trail may be retained for support and repair. Normalized vehicle records, page URLs, hashes, progress, and validation evidence may be stored locally and in the service.
AI providers and information sent to them
AutoPosting Pro makes these AI requests from its servers using service-owned credentials; provider API keys are not returned to the extension. Depending on the feature and server configuration:
- OpenAI may receive vehicle facts, dealership-provided text or instructions, and requested channel context to generate captions with
gpt-5.6-lunaby default. It may also receive a reduced page representation and requested inventory fields to propose a structured reader configuration, or bounded vehicle, dealership, playbook, and recent-conversation context to draft a buyer reply. Our OpenAI Responses requests are configured withstore: false. - Z.AI (GLM) may receive the caption inputs described above only when OpenAI is not configured on the server. In that same missing-OpenAI-key situation, Z.AI may receive a reduced page representation for reader configuration or bounded vehicle, playbook, and conversation context for a buyer-reply draft. An OpenAI error, timeout, or rate limit does not cause the request to be sent to Z.AI.
- Black Forest Labs receives the selected vehicle image bytes, the requested backdrop and removal instructions, and a consistency seed to generate an edited image. It returns a provider-hosted delivery result that the extension downloads into browser-local storage.
We use AI inputs to provide the requested feature, enforce usage limits, troubleshoot failures, and protect the service. Provider handling and provider-side retention are also governed by each provider’s applicable terms and privacy policy. The OpenAI store: false request setting describes our API configuration; it is not a promise that a provider keeps no security, abuse-prevention, or request metadata or that every provider deletes content immediately. Generated text and images should be reviewed for accuracy before they are used in a public listing or buyer conversation.
Remote support, presence, and commands
While the extension is signed in, it may send a bounded presence update so your authorized portal can show that the extension is available. That update can include extension version, demo state, queue state, up to 12 recent activity lines, and up to five pending reply drafts with shortened buyer, listing, question, and draft text. An authorized portal user can request a supported inbox scan or send one specifically approved reply after confirming its exact buyer, listing, and text. The phone remote can display inventory and photos, but Marketplace listing creation remains in Caption Studio on the signed-in Chrome computer so the final description and destinations can be reviewed there. Commands are tied to the same organization, audited, and executed by the extension through its existing browser session. Unclaimed remote commands expire after six hours, although related database and audit records may remain for operations, support, security, and accountability.
Information kept in your browser
The extension uses Chrome local, session, and sync storage and IndexedDB. Browser-local data can include authentication state, non-secret account display information, preferences, vehicle inventory, queue and posting state, captions, photo choices and order, scan jobs and validation records, edited-image bytes, and Marketplace or Messenger drafts, reply history, settings, and summaries. Messenger and Marketplace data is separated by AutoPosting Pro organization and member within the Chrome profile. Older unscoped messaging data is quarantined instead of being exposed to a newly signed-in account.
The extension’s developer inspector is off by default for ordinary customer scans. If enabled, or when an administrator deliberately runs an inspected support scan, it keeps a bounded, credential-scrubbed diagnostic trace in Chrome session storage; that trace is cleared when tracing is turned off and does not survive Chrome closing.
How we use information
We use information to authenticate users, maintain and verify inventory, prepare and manage listings, provide inbox and reply tools, generate requested AI content, meter plan usage, process billing, show progress and results, measure fixed-code arrival checkpoints for our registered campaigns and which acquisition channels produce checkout or public contact-link activations, provide support, diagnose failures, prevent misuse, and secure the service. For campaign arrivals, the normal site client submits only one fixed campaign code after a visible page matches the registered path and four campaign parameters. The server derives source and landing labels from that code. The application table stores only the UTC day, fixed code, and a count bounded at 5,000 per code per day; it has no per-event timestamp, raw URL or UTM value, account, organization, visitor or device identifier, or stored IP address. The request omits cookies and browser referrer. The request IP may be processed transiently into a short-lived HMAC rate-limit key, and ordinary Vercel infrastructure logs still apply outside this application counter. This measurement is separate from our first-touch attribution cookie. A recorded checkpoint means only that the endpoint incremented a registered key’s daily counter. It does not prove that the URL rendered, a link was clicked, a referring site sent the request, or a unique or human visitor, dealership, lead, signup, purchase, or customer exists and cannot be joined to an account. Direct or replayed requests, copied links, reloads, multiple tabs, automation, and previews may count, while blockers, hidden pages, network failures, request limits, and write failures may cause missed records. A count of 5,000 means at least 5,000 recorded submissions because the counter stops increasing at that cap. A public contact-link activation record contains only a fixed phone/email channel and coarse source category; it is not tied to an account, organization, visitor identifier, or stored IP address and does not prove that a call connected, an email was sent, or a qualified lead exists. We do not sell personal information. We do not use dealership inventory, Marketplace conversations, or Messenger conversations to build advertising profiles.
When we share information
We disclose information only as needed to operate the service, follow your instructions, protect users and the service, or comply with law. Service providers can include Stripe for billing, Resend for transactional email, Vercel for hosting, Supabase for database services, OpenAI and Z.AI for the AI features described above, Black Forest Labs for requested image edits, and Facebook, Instagram, Marketplace, or Messenger when you direct the extension or service to interact with those platforms. These providers process information under their own applicable terms and privacy policies.
Retention and deletion
We keep cloud account, inventory, listing, usage, support, command, and audit records for as long as reasonably needed to provide and secure the service, maintain accurate business records, resolve disputes, and meet legal obligations. Not every cloud record currently has the same automatic deletion schedule. Checkout and public contact-link activation audit records currently use this general retention practice and do not have a separate automatic deletion deadline. Registered-campaign daily aggregate rows also follow this general retention practice; the admin report reads a rolling 90-day window, but rows are not automatically deleted solely because they become older than that report window. Unclaimed remote commands expire after six hours, but an expiration is not the same as deletion of the command or its audit trail.
The local inventory scanner automatically prunes eligible completed jobs and cached records after approximately 30 days and also applies count limits; active, resumable, and not-yet-submitted passing work can be kept longer. AI caption cache entries, edited images, and Marketplace or Messenger state can remain in the Chrome profile until they are replaced, deleted through an available extension control, cleared through Chrome, or removed with the extension. The extension includes a control to delete local Marketplace and Messenger data, including account-scoped and quarantined legacy copies. Signing out stops messaging automation and separates the next account’s data, but does not by itself delete every local vehicle, caption, photo, or scan record.
If you used the optional legacy Meta connection, disconnecting it stops future use of the stored Meta authorization and removes the connection data that AutoPosting Pro controls. Platform copies or public posts may also need to be removed through the platform itself.
Security
Passwords are stored as cryptographic hashes. Provider credentials and other server secrets are restricted to server-side systems, and organization checks are used to separate customer records. We use request limits, bounded payloads, validation, and audit records to reduce misuse. Data held inside Chrome is protected by Chrome and your device’s operating-system account; AutoPosting Pro does not separately encrypt every browser-local record. No service or transmission method can be guaranteed completely secure.
Your choices and rights
- You can choose whether to grant the extension access to a dealership website and can remove that site permission in Chrome.
- You can turn off inbox watching, reply automation, posting automation, and developer tracing in the extension.
- You can delete local Marketplace and Messenger data with the extension control, or clear all extension storage through Chrome.
- You can disconnect an optional Facebook or Instagram business connection and manage platform permissions in the relevant platform account.
- You may request access, correction, export, or deletion of personal information by emailing [email protected] from your account email. We may need to verify your identity and may retain limited records when required for legal, accounting, fraud-prevention, security, or dispute-resolution purposes. We will respond as required by applicable law.
Cookies and sign-in
Our website uses essential first-party cookies for sign-in and security. A first-party attribution cookie records how you first arrived so we can understand which channels bring customers to us. The separate registered-campaign arrival checkpoint does not read that cookie; its application payload contains only one fixed campaign code and omits cookies and browser referrer. We do not use advertising cookies or cross-site tracking cookies. See our Cookie Policy for details. Email-and-password sign-in may use an email verification code; where Google or Apple sign-in is offered, we receive the basic account information needed to identify your AutoPosting Pro account, not your Google or Apple password.
Children
AutoPosting Pro is a business service and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
Changes to this policy
We may update this policy as the product, providers, or legal requirements change. We will post the updated policy here and change the “Last updated” date. Material changes may also be communicated through the service or by email when appropriate.
This policy describes the product’s current technical behavior but is not legal advice. Have qualified counsel review it for the jurisdictions in which you operate.