Privacy PolicyPolitique de confidentialitéPolítica de privacidad

Effective: 2026-08-25 · Version 1.5En vigueur : 2026-08-25 · Version 1.5Vigente: 2026-08-25 · Versión 1.5

Lire en français →Leer en español →Read in English →

Privacy Policy

Effective: 2026-08-25 · Version 1.5

In one sentence: Your listings and photos stay on your device. The publisher does not collect your name, email, or listing content. Optional anonymized product metrics exist but are off by default until you choose to share (section 5).

1. Who we are

SyncListing is a browser extension published by SyncListing, based in Quebec, Canada (the "publisher"). Privacy officer under Quebec's Law 25: A. Khan, reachable at info@synclisting.com.

2. What the extension stores (locally only)

To work, SyncListing saves in your browser's local storage (chrome.storage.local) only content you create yourself:

  • your listings (titles, descriptions, price, pickup area, tags, and optional item attributes such as size, brand, or color);
  • your listing photos (resized JPEGs). iPhone HEIC and HEIF files you add in the listing editor are converted to JPEG on your device with a decoder packaged in the extension; conversion does not upload the file to the publisher;
  • your quick-reply templates and description-variable snippets;
  • your settings (language, enabled marketplaces, listing card view such as Classic or Filmstrip, relist thresholds, licence key, and, if you provide them, your personal API keys for the optional services in section 5);
  • per-marketplace posting metadata (for example last posted date, posted price, optional live listing URL when you mark posted or import, and flags such as price-outdated);
  • the dates on which you mark a listing as posted, and your sales (sold price, cost) if you use sales tracking.

This listing data stays on your device. It is not transmitted for the extension's core features. The publisher does not operate a server for your listings. It is deleted when you uninstall the extension or clear it yourself. If you enable optional sync (section 5), your listings' text travels through Chrome's built-in sync (a Google service tied to your own Google account), never through a SyncListing listings server. Separately, if you opt in to optional product metrics (section 5), coarse anonymous event counts may be sent to synclisting.com; that never includes listing text or photos.

3. What the extension does not do

  • No collection of personally identifiable information by the publisher (no name, email, or account with SyncListing).
  • No transmission, sale, rental or sharing of your listing content (titles, descriptions, prices, photos) or of your marketplace browsing history.
  • No cookies, no web-advertising trackers, and no third-party analytics scripts in the extension. Optional product metrics (section 5) are separate. The marketing website (synclisting.com) may set a first-party referral cookie (sl_aff, up to 60 days) when you open a partner link (/r/…) so a promotion code can be suggested at checkout — not for ads retargeting.
  • install-level feature counters only, off by default, and are not ad tracking or keystroke logging.
  • No reading of other users' marketplace data; no background scraping. Bulk import and single-ad import read only the listing pages you open in your browser (read-only DOM capture).
  • No automatic posting, deleting or messaging: you always click Post or Send yourself.

4. Why these permissions

  • storage / unlimitedStorage: keep your listings and photos locally.
  • alarms: a periodic local check that flags your stale listings (toolbar badge). No network activity.
  • Site access to facebook.com, messenger.com, kijiji.ca, craigslist.org, lespac.com, ebay.ca/.com, varagesale.com, poshmark.com, poshmark.ca, karrotmarket.com, and vinted.com / .co.uk / .fr: show the assistant panel and pre-fill listing forms and message composers on the pages where you sell. The extension only writes text you provided. Access to selected marketplace image hosts (including Facebook CDN and fbsbx hosts, Kijiji media, eBay images, VarageSale and Poshmark CDNs, Karrot CloudFront, and Vinted vinted.net CDNs) is used solely to import photos from your own ads when you click Import or bulk import.
  • synclisting.com (optional): (1) if the extension is installed, this website may send a one-way message to open your SyncListing dashboard or check that the extension is present - it does not receive your listings or settings; (2) if you opt in to product metrics (section 5), the extension POSTs anonymized event data to synclisting.com/api/product-metrics/ over HTTPS.

5. Optional services and payments

Listing writer (optional). SyncListing can draft titles and descriptions from your photos and notes. Free Gemini AI for photo listings uses your own Google Gemini API key (AI Studio free tier). Chrome's built-in on-device AI (Prompt API / Gemini Nano) can also draft from notes, and from listing photos when your device supports image input. Alternatively, you may provide your own API key for Anthropic, OpenAI, or DeepSeek. Gemini, Anthropic, and OpenAI use notes + photos when you attach images. DeepSeek is notes-only. Keys and content go directly from your browser to that provider under your account and their privacy policy. SyncListing does not see the key or the content.

Product metrics (optional, off by default). SyncListing always keeps local install-level counters on your device (for the owner metrics panel in Settings). Sending anything to the publisher is optional and off by default.

  • How you opt in or out: the first time you open the dashboard, a one-time dialog explains what would be shared and asks for your choice (default: No thanks). You can turn sharing on or off anytime in Settings → Product metrics.
  • If sharing is off: nothing is sent to synclisting.com; local counters remain on your device only.
  • If sharing is on: each eligible action sends one HTTPS POST to https://synclisting.com/api/product-metrics/ containing: a random install ID (UUID generated locally on first use), extension version, event name, timestamp, and coarse detail fields only (see below). Data is not sold and is used only to measure feature adoption and improve the product.
  • Event types (examples): metrics opt-in; cloud writer key saved or cleared (provider name only); listing writer run (provider, whether photo or fill-gaps was used); post handoff (marketplace and mode such as first post, relist, or price update); import (marketplace, single/bulk/enrich, count); autofill completed (marketplace, fields-filled counts); mark posted or mark updated; quick reply inserted; relist playbook opened or completed; sold-elsewhere mark removed; dashboard tab viewed; listing-count bucket (0, 1-10, 11-50, 51+); enabled-marketplace count and which marketplaces are on (ids only: facebook, kijiji, craigslist, lespac, ebay, varagesale, poshmark, karrot, vinted); seller region pack (ca / us / eu) and Vinted site locale (us / uk / fr) when set; trial state (paid / active / not started / expired, plus days remaining or days since the 3-day trial ended as integers only; when available, trial start and end as Unix milliseconds so remaining time can be shown accurately — never an email or payment id); UI language; default post language (en / fr / both) and whether a default pickup city is set (boolean only, never the city text); HEIC/HEIF convert counts; listing translate direction (EN ↔ active second language FR/ES/DE); new/duplicate/sold listing actions; backup/export kind; Open & enrich clicks; live-link saved (marketplace and method such as paste or bulk, never the URL); analytics drill-down (kind such as kpi, chart, or status, and a slice label such as revenue or day, never listing ids or titles); reminder dismiss (kind such as stale, price, or sold-still-live, plus scope such as this site, this listing, or all listings); Cross-post wizard funnel (start with site count, step, skip by marketplace, done, or cancel — never listing ids); Analytics chart grain (day / week / month); viewport List override (enter / restore / stay, plus preferred view id such as classic or compact).
  • Install ID on your device: Settings → Help improve SyncListing can display the same local install UUID so you can quote it in support. Showing it is not a new transmission.
  • Never included: API keys, listing titles, descriptions, prices, photos, buyer/seller messages, marketplace page content, live ad URLs, pickup city text, browsing history, clicks, scroll position, or keystrokes.

Background removal (optional). Separate from the listing writer. Same principle with your remove.bg key: the processed photo goes directly to remove.bg's API, under your account and its policy. Leave the key blank to skip.

Sync (optional, off by default). Your listings' text (never photos) is replicated across your Chrome browsers by Chrome's built-in sync, a Google service attached to your Google account and governed by Google's privacy policy.

Payments. If you purchase a licence, payment is handled by a third-party processor (e.g. ExtensionPay/Stripe) under its own privacy policy. The publisher never sees or stores your card details.

6. Your rights

Because the publisher holds no personal information about you, access, correction and deletion requests are resolved directly on your device: your data is under your exclusive control. For privacy questions or complaints, contact the privacy officer listed in section 1. Quebec residents may also contact the Commission d'accès à l'information du Québec.

7. Minors

SyncListing is intended for people old enough to use the marketplaces it supports under each platform's terms (typically 18+).

8. Changes

Any change to this policy will be published at this address with a new effective date. Material changes will be flagged in the extension's release notes.

9. Independence

SyncListing is not affiliated with, endorsed by, or connected to Meta Platforms, Inc., Poshmark, Inc., Kijiji Canada Ltd., Craigslist, Inc., LesPAC, eBay Inc., VarageSale Inc., or Karrot Market Inc. (Karrot / Danggeun).