Privacy Policy
ListLot is a hosted service, so your inventory, your photos and your listing history live on our servers rather than yours. This page says plainly what that means: what we hold, why we hold it, who else touches it, and how you get it back or get rid of it.
01Who we are
“ListLot”, “we” and “us” mean the operator of the ListLot service, an independent developer based in Arizona. “You” means the dealership whose workspace holds the data, and the people it invites into that workspace.
Questions about anything on this page go to emery@listlot.app, and a person reads them.
02What we collect
All of it comes from you or from your own inventory — there is no data broker in this product and nothing is bought in.
- Account and team — name, email address, phone number, role, and a password stored only as a PBKDF2-SHA256 hash. Never the password itself.
- Dealership profile — lot name, address, phone, hours, logo and branding — the details that end up in listing copy.
- Inventory — every vehicle read from the dealership website URL you give us: year, make, model, VIN, mileage, price, options, photos.
- Photos — images you upload from a phone or a desktop, plus the branded covers we generate from them.
- Listing activity — the copy we generated, where and when a vehicle was posted, when it is due for a repost, and when it sold.
- Sales and payouts — who released a package to whom, and what a referral is worth — the trail your own payouts run on.
- Buyer conversations — if you use the extension's Marketplace inbox sync, the buyer's display name and the text of the thread, so replies can be drafted against the right car.
- Waitlist — the email address you enter and which page you entered it on.
- Operational logs — IP address, browser, and request timestamps, kept for security, rate limiting and debugging.
03What we deliberately do not collect
- Payment card numbers — checkout runs through Paddle. Card details are entered on Paddle's form and go to Paddle — they never touch our servers, and all we ever see is that a subscription is active.
- Your Facebook or Craigslist credentials — the extension never sees a password for either platform. You are already signed in; it works inside that session and nothing more.
- Your browsing — the extension runs on Facebook and Craigslist pages only, and reads nothing outside the posting form and the Marketplace inbox.
- Location — GPS coordinates in a photo are destroyed on upload — see below.
04How photos are handled
Every uploaded image is re-encoded before it is stored, which destroys the EXIF block — GPS coordinates, device serial, capture time. What reaches storage is pixels. A photo shot on the lot cannot leak the salesperson's home address because they shot the first one in their driveway.
Stored photos are served from a public CDN URL. They have to be public: when you post to Marketplace or Craigslist, the platform fetches the image from that URL. The URLs are unlisted and not indexable, but treat them as public — do not put anything in a vehicle photo you would not put in the listing.
05What the Chrome extension can see
The extension is the part of ListLot that touches somebody else's website, so it is worth being exact about it.
- What it stores — your ListLot server URL and your bearer token, in chrome.storage.local, on your device. Nothing else, and nothing that leaves the browser except to authenticate to ListLot.
- Where it runs — facebook.com and craigslist.org. Host access to your ListLot server is requested at runtime, after you sign in — the extension ships with no default access to any site.
- What it reads — the vehicle posting form, so it can fill it, and the Marketplace inbox, if you use reply drafting. Not your feed, not your friends, not your personal messages.
- What it never does — submit a listing. Publish is a click you make, every time, on purpose.
06Who else touches your data
We use a short list of vendors to run the service. Each gets only what its job requires, and none of them may use your data for their own purposes.
| Vendor | What it does | What it sees |
|---|---|---|
| Anthropic | Listing copy and buyer-reply drafts | Vehicle specs, listing text, and the buyer message you ask for a reply to. Not used to train models. |
| Cloudflare | Photo storage (R2) and CDN delivery | Vehicle photos and the requests that fetch them. |
| Paddle | Payments and subscription billing (merchant of record) | Your billing email, plan and payment details. Card numbers go to Paddle and never reach us. |
| Resend | Transactional email | Recipient address and message content — invites, waitlist mail, and the notifications a workspace chooses to receive (repost reminders, released listings, sales and payouts, inventory sync problems). |
| DigitalOcean | Application and database hosting (United States) | Everything in your workspace, at rest. |
| Google Fonts | Web fonts on public pages | Your IP address and browser, when a page loads a font. No cookie is set. |
07What we never do
- Sell, rent or trade your data. There is no version of this product where your inventory is the thing being sold.
- Run ad pixels, third-party analytics or cross-site trackers. The app and the marketing pages load no tracking script at all.
- Train our own models on your listings, your photos or your buyer messages.
- Share one dealership's data with another. Workspaces are isolated at the query level, and a rooftop cannot see another rooftop's cars.
08Where it lives and how long we keep it
- Location — United States. Application, database and photo storage are all US-hosted.
- While you're a customer — we keep your workspace as long as the account is open, because that history is the product — repost cadence and payout trails are worth nothing without it.
- After you cancel — your data stays available for 30 days so you can export it, then is deleted. Say the word and we will delete it sooner.
- Removed team members — the login is destroyed and the email address released immediately; the row survives so the postings and payouts it signed still have an author.
- Waitlist — until you unsubscribe or ask us to remove you.
- Logs — rotated within 30 days.
09Your choices
- See it — everything in your workspace is visible in the app. Ask and we will send a full export.
- Correct it — Settings → Profile and Settings → Dealership, or email us.
- Delete it — an admin can delete vehicles, photos and team members directly. For the whole workspace, email us and we will confirm when it is gone.
- Stop the email — Settings → Notifications turns off any product notification, for you alone, and every one of them carries a one-click opt-out in its footer; an admin can pause email for the whole dealership. Every non-transactional email has an unsubscribe link. Only mail the account itself depends on — an invite, a billing notice — comes with the account.
If you are covered by the CCPA, the GDPR or a similar law, the rights those give you are the rights above; we do not run a separate process for them and we do not charge for a request. We answer within 30 days.
We have never received a government request for customer data. If we receive one we will tell the affected dealership unless we are legally barred from doing so.
10Security
Passwords are hashed with PBKDF2-SHA256 at 200,000 iterations. Sessions are opaque bearer tokens, not signed blobs. Everything moves over TLS, and the app sends HSTS, a strict Content-Security-Policy, and a frame-ancestors deny.
The full picture — tenant isolation, extension permissions, what we have not built yet — is on its own page.
11Not for consumers, not for children
ListLot is a tool for licensed dealerships and the people who work at them. It is not directed at children, we do not knowingly collect data from anyone under 16, and a buyer who messages your Marketplace listing is not a ListLot user — their message reaches us only as part of the thread you chose to sync.
12Changes to this policy
We will post the new version here with a new date. For a change that materially affects what we collect or who we share it with, we email every workspace admin before it takes effect — not after. Questions: emery@listlot.app.