Information handled by LotBridge
- Account information: the email address used to sign in, account-access status, plan name, and session tokens needed to keep the user signed in.
- Dealer vehicle information: vehicle details, source page address, dealer descriptions, warnings, and selected dealer-hosted image addresses from supported inventory pages.
- Locally created workflow information: settings, description templates, selected photos, and Needs Posting/Posted queue records.
- Service operations: installed extension version, connection state, last-seen time, allowlisted workflow events, a hashed vehicle key, short year/make/model/trim label, stock number, renewal status, and safe error codes.
- Problem reports: only when the user selects Report a problem. The report includes the selected problem type, category, extension version, failed step, and safe error code. It has no free-text field.
- Support diagnostics: only when the user chooses to download and share a diagnostic report. Reports exclude passwords, session tokens, vehicle descriptions, and photo addresses.
How information is used
LotBridge uses this information only to authenticate approved users, verify account or subscription access, prepare reviewed vehicle drafts, fill supported Facebook Marketplace vehicle-form fields, maintain posting and renewal status, monitor service reliability, and troubleshoot user-reported problems.
Passwords and account security
A LotBridge password is transmitted over HTTPS directly to the configured authentication provider for verification. The extension does not save the password. Short-lived access credentials and a refresh token are stored in the user’s Chrome extension storage so the account can remain signed in. Signing out removes the local account session.
Storage and sharing
Vehicle drafts, settings, and queue history are stored locally in the user’s Chrome profile. Account authentication, heartbeat, allowlisted activity, vehicle lifecycle, and user-submitted problem reports are processed by LotBridge Supabase. These server records do not accept passwords, authentication tokens, API keys, descriptions, VINs, source page addresses, photo addresses or files, or Facebook messages. Facebook receives vehicle information and selected images only when the user starts the Facebook posting workflow.
LotBridge does not sell personal information, use it for advertising, or use it for lending or credit decisions. Information is not shared except with service providers required to operate authentication and the user-directed Marketplace workflow, or when required by law.
AI descriptions
Secure AI descriptions are generated through a LotBridge server function after it verifies the signed-in user and active access. Vehicle facts, optional dealer equipment notes, and optional writing direction may be sent to OpenAI. Page addresses, photos, passwords, session tokens, and the server OpenAI key are not sent. No personal OpenAI API key is collected or stored by the extension.
User control and deletion
Users can edit or delete saved vehicles, export or import their queue and settings, sign out, or uninstall the extension to remove its locally stored data. To request deletion of a LotBridge account or server-side account record, email privacy@lotbridge.app.
Authorized use
Users must access and reuse only inventory content they are authorized to use and remain responsible for reviewing each listing before publication. LotBridge does not access Facebook messages and does not complete Facebook’s final Publish action.
Changes and contact
This policy may be updated as LotBridge changes. Material changes will be reflected by a new effective date. Questions can be sent to privacy@lotbridge.app.