Skip to main content

Legal

Chrome Extension Privacy Policy

Version 1.0 · Effective September 20, 2026

18092516 Canada Inc., operating as CarcoCRM, publishes a Chrome extension called CarcoCRM Marketplace Lister. It fills in a Facebook Marketplace vehicle listing from a dealership’s own inventory so a salesperson does not have to retype it. This page describes exactly what that extension reads, what it stores, and what it deliberately refuses to do.

It supplements our Privacy Policy, which governs. Where this page is more specific, it is because the extension runs inside a salesperson’s own browser on a website we do not operate, and that deserves to be spelled out rather than inferred.

Who we are

18092516 Canada Inc. o/a CarcoCRM
3-1124 Stellar Drive, Newmarket, Ontario L3Y 7B7, Canada
carcocrm.com · support@carcocrm.com

CarcoCRM is a business-to-business software platform used by Canadian automobile dealerships to manage inventory, customers and vehicle transactions. The extension is an optional part of that platform and is useless without a CarcoCRM account.

The single thing it does

The extension pre-fills Facebook’s vehicle listing form with a vehicle already in the dealership’s CarcoCRM inventory: the year, make, model, mileage, price, description and photographs that the dealership itself entered.

A person presses Publish. Every time. There is no code path in the extension that submits a listing, and there never will be. It does not take a listing down either. The software fills a form; a human decides what to do with it.

Where it runs

The extension is active on exactly two pages, and nowhere else on Facebook or on the internet:

  • The Facebook Marketplace vehicle composer, where it fills the form in.
  • The salesperson’s own Marketplace listings page, where it reads the listings they ask it to sync.

It also talks to CarcoCRM’s own servers — our API, and the content delivery host that serves the dealership’s vehicle photographs — because that is where the listing it fills in comes from. Those are the only other addresses it is permitted to reach, and they are ours. It does not request permission to read your browsing history, your tabs, or your cookies, and it does not ask for access to every website. On the listings page it reads nothing at all until the salesperson presses Sync my listings. It then reads only the listing cards already visible on screen — the title, the price and the link — so the CRM can work out which of the dealership’s vehicles are currently advertised. It does not scroll the page for you, it does not click anything, and it cannot delete, edit or renew a listing.

What we store

  • Which vehicle was posted, when, and whether it is still live. This belongs to the dealership, in their CarcoCRM account.
  • The web address of the listing itself (facebook.com/marketplace/item/…), captured when the salesperson publishes it. It is how the CRM knows the advertisement is still running and can say so when the vehicle sells. It is a link to the listing, never to a profile.
  • The titles, prices and links of listings the salesperson asks us to sync, for the same purpose.
  • Which browser was paired, and when the salesperson accepted our account-risk statement. If they do not name the browser themselves, the extension supplies a plain description of it — “Chrome on macOS” — so the device list is readable. That is browser family and operating system family only: the same two facts every website already receives on every request.
  • A device token, held in the browser’s own extension storage. It identifies the paired browser to the dealership’s CarcoCRM account and nothing else.

What we deliberately do not store

  • Any Facebook profile identifier. Not the profile, not the ID, not the username, not the link — not in our database, not in a token, not in a log. We do not need it, and not holding it keeps a salesperson’s personal account out of our systems entirely.
  • Facebook credentials. The extension never sees a password and never signs in as anybody.
  • Facebook cookies. The extension does not request that permission.
  • Anything about other pages. It runs on the two pages named above and is inert everywhere else.
  • Anything on the listings page that was not already on screen. The salesperson scrolls, decides how much to show, and the extension reads what is visible when the button is pressed — nothing above it, nothing below it, nothing on another tab.
  • Messages. It does not open Messenger, does not read a conversation, and does not record who made contact. Buyer messages stay between the buyer and the salesperson.

Who the data is shared with

Everything the extension sends goes to the dealership’s own CarcoCRM account and nowhere else. We do not sell it, we do not rent it, and we do not transfer it for advertising or to a data broker. It is not used to build a profile of you, and it is not used as training data for machine-learning models. It is used for one purpose: letting a dealership see and manage its own vehicle advertisements. Our subprocessors are listed in our Subprocessors page.

Posting from a personal account

Facebook closed its official dealer path for Marketplace vehicle listings on 30 January 2023, so only a personal profile can create one. That is true whether a listing is typed by hand or filled in by this extension — the extension changes how much typing it costs, and nothing else.

Before pairing a browser, every salesperson is shown a statement saying so in plain terms: that the account is their own, that Facebook may disable it at their discretion, and that sharing a login or using an account created for the dealership is the clearest violation in this area. The version they accepted is recorded against their device, so what they agreed to stays answerable.

Retention, access and deletion

Listing records belong to the dealership and are kept for as long as their CarcoCRM account is active, under the retention terms in our Privacy Policy.

Disconnecting a browser. There are two ways, and both really do revoke it.

  • In CarcoCRM, from Settings → Marketplace Lister. This revokes that browser’s token immediately and is the reliable path.
  • By removing the extension from Chrome. Chrome tells us the moment you uninstall, and we revoke the pairing then. Your browser’s own copy of the token is erased by the uninstall itself, so nothing can be sent from that machine either way.

We should be honest about the limit of the second one, because it is a promise we can only keep most of the time: Chrome notifies us when you uninstall the extension, but not when an entire browser profile is deleted, when Chrome itself is removed, when a workplace policy pulls the extension, or when the machine happens to be offline at that moment. If you want to be certain the pairing is gone, disconnect it in CarcoCRM — that path does not depend on anything reaching us.

To ask what is held about you, or to have it corrected or deleted, write to support@carcocrm.com. We answer within the timeframes PIPEDA sets.

Which version this describes

This policy describes CarcoCRM Marketplace Lister version 1.0.0 and the account-risk statement version 2026-09-12, which is the text a salesperson accepts before a browser can be paired.

Naming both is deliberate. A privacy policy that does not say which build it describes cannot be checked against one, and this document only means anything if you can hold it against the thing it is about.

Changes

If what the extension reads or stores changes, this page changes with it and the account-risk statement is re-issued — which means salespeople accept the new version before they can keep using it, rather than being migrated onto it quietly.