Privacy Policy
Last updated: August 4, 2026
This Privacy Policy explains how Market Auto Reply("we", "us", or "our") collects, uses, shares, and protects your information. It applies to our Chrome extension, our website, the user dashboard, our backend services and APIs, and the features they power — including AI-assisted auto-replies, the listing importer, the Deal Finder and saved searches, match email alerts, support chat, and our subscription and account services (together, the "Service"). By using the Service you agree to the practices described here.
The Service processes marketplace conversations, listings, and user-configured searches only to provide features requested by users on accounts they own or are authorized to manage. We do not sell personal data, conversation content, or listing data, and the Service is not designed for spam or unsolicited mass outreach.
1. Information We Collect and Process
We collect and process only the categories below, each of which the Service actually handles.
A. Account and subscription information
- Your first and last name, email address, and (optionally) phone number. If you sign in with Google, we verify your Google ID token and receive your name, email, profile picture, and Google account identifier. We never receive your Google password.
- If you register with email and password, your password is stored only as a salted bcrypt hash — never in plain text. Google-based accounts have no password.
- Your activation key and the AI prompt you configure, your plan, reply allowance, subscription and billing status, and — for referrals — your referral code and who referred you.
- Payment metadata from our processor (plan, subscription and payment status, customer identifier, and the customer email/name contained in the payment event). We do not receive or store full card numbers.
- Messages you send us through support chat or the contact form.
B. Marketplace account and listing identifiers
- The Facebook account identifier(s) and account name for the account(s) you connect through the extension, which account is selected, and the buyer's Facebook identifier and display name when a conversation is processed.
- Listing identifiers, seller name and profile image reference, and (for locations) the Marketplace location identifiers you select for a search.
- These identifiers come from the Marketplace page content your extension reads and from the account you connect — not from your browser cookies or passwords.
C. Conversation data (auto-reply)
- When you enable auto-reply, the extension reads the incoming Marketplace conversations you choose to process and sends them to our backend. This includes the conversation transcript (recent messages), the buyer's latest message, the conversation identifier, the related listing title, and any contact details a buyer shares (such as a name, phone number, or email).
- This content is transmitted to and stored by the Market Auto Reply backend so it appears in your dashboard as leads and conversations, and so we can avoid re-processing the same message.
- To generate a reply and to extract lead details (name, phone, email, whether the buyer wants an appointment), the relevant conversation turns and the buyer's message are sent to our AI provider (OpenAI) to process on our behalf. Only token counts and cost — not message content — are recorded for usage accounting.
- Conversation content is not processed only on your device, and it is not ephemeral: it is retained in our database and shown in your dashboard until deleted. See "Data Storage and Retention" and "Your Controls and Deletion."
D. Listing importer data
- When you run the importer, we process and store the listings you import: title, description, price, category, delivery type, seller-provided details, vehicle or real-estate/item attributes, listing identifiers and status, and the raw listing data received from the page. Listing images are downloaded and stored on our servers.
E. Deal Finder and saved-search data
- Your saved searches — name, keyword, category, selected location, price range and other filters, search options, and email-alert settings — and the listings that match them (title, price, location, URL, images, seller and attribute details, and the raw listing data). We keep a short-lived record of listings already seen by a search to avoid duplicate matches.
F. Browser and extension data
- On the website and dashboard we use your browser's local storage (not tracking cookies) to keep you signed in (a session token), to store a minimal profile (your name, email, and role), your onboarding progress, and a referral code if you arrived from an invite link.
- The Chrome extension stores its operational data — such as your activation key, the selected account, settings, and identifiers used to avoid re-processing the same conversation or listing — locally in the browser using the extension's storage. You can clear this by removing the extension or clearing its data.
G. Technical and log data
- We store your IP address at sign-up, sign-in, and verification (and with the contact form and referral records) for security and abuse prevention. We do not keep a per-request access log of your browsing.
- Our servers write basic operational logs (for example, which action a request performed and the associated account) to diagnose problems. We do not run third-party website analytics or advertising trackers, and we do not currently transmit data to an external error-monitoring provider.
2. How We Use Information
- To validate activation keys, subscriptions, and reply allowances.
- To generate AI-assisted replies that you initiate, and to extract lead details from conversations you process.
- To import and organize the listings you choose to import.
- To run your saved searches and identify matching listings, and to email you match digests when you enable alerts.
- To maintain your workflow state and reduce duplicate processing.
- To provide the dashboard and support chat.
- To secure the Service, prevent fraud and abuse, and diagnose technical problems.
- To process subscriptions and billing, and to comply with legal obligations.
We do not use this information for unrelated purposes.
3. Data Sharing and Service Providers
We do not sell personal information or conversation content, and we do not use conversation, listing, or extension data for advertising. We share information only with the service providers that help us run the Service:
- OpenAI — to generate replies and extract lead details from the conversations you process.
- Stripe — to process payments. Stripe collects your name, email, billing address, and payment details under its own privacy policy. We never receive your full card number.
- Google — to verify your identity when you choose Google sign-in.
- Our email provider — to send verification codes, password resets, and match-alert digests over SMTP.
- Hosting, database, and infrastructure providers — to run and secure the Service.
We may also disclose information if required by law, to respond to lawful requests, or to protect our rights, our users, or the public.
4. Chrome Web Store Limited Use
Our use of information received through the Chrome extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Market Auto Reply uses extension-related data only to provide and improve the user-facing features described in the extension, and does not use or transfer that data for advertising, credit decisions, or unrelated purposes.
5. Data Storage and Retention
We store different categories for different periods:
- Browser-local settings and session token — remain in your browser until you sign out, clear your browser storage, or remove the extension.
- Email verification codes and the "already seen" search dedup records expire automatically (verification codes shortly after issue; seen-listing records after about 30 days).
- Conversation content and generated replies, leads, imported listings and their images, saved searches, match results, connected-account records, support messages, subscription records, and billing/security records are retained while your account is active and as needed to provide the Service and meet legal, accounting, and fraud-prevention obligations. We do not currently apply a fixed automatic deletion period to most of these records; you can request deletion as described below, and we plan to introduce explicit retention limits.
6. Your Controls and Deletion
- Stop automation at any time — pause or stop auto-reply and stop a Deal Finder search from the extension and the dashboard.
- Delete a saved search from the Deal Finder, dismiss match results, and remove a connected account from your dashboard.
- Clear extension data by removing the extension or clearing its local data.
- To delete leads, conversations, imported listings, or your entire account and backend data, email support@marketautoreply.com and we will process your request. Depending on where you live (including under the GDPR and CCPA), you may also have rights to access, correct, export, or restrict processing of your data; we will not discriminate against you for exercising them.
7. Security
We use reasonable technical and organizational measures to protect your information, including HTTPS encryption in transit, bcrypt password hashing, token-based authentication and an activation-key gate for extension calls, restricted administrative access, signature-verified payment webhooks, and secret management through server configuration. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Children's Privacy
The Service is not intended for anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
9. International Users
We may process and store information in countries other than yours. Where we transfer data internationally, we take steps to keep it protected in line with this policy and applicable law.
10. Third-Party Platforms
The Service operates alongside third-party platforms (such as Facebook Marketplace) that you access with your own account, and may link to external sites. We are not responsible for the privacy practices of those platforms or sites; their own policies apply.
11. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after changes take effect means you accept the updated policy.
12. Contact
Questions about this policy, a data request, or a legal request? Email us at support@marketautoreply.com.