AutoStream Privacy Policy
Effective date: May 28, 2026 ยท Last updated: September 15, 2026
AutoStream (the “extension,” “we,” or “our”) is a manual listing
assistant for automotive dealership representatives. It helps dealership reps post
their own dealership's vehicle inventory to Facebook Marketplace by pre-filling
the listing form with vehicle data the rep has chosen to use. The rep
always reviews and submits each listing manually. This policy explains
exactly what data we collect, how we use it, where it goes, and what we
never do.
The short version, up front:
- We read your dealership’s own inventory data (vehicles, photos, prices) so we can pre-fill Facebook Marketplace listings.
- We do not auto-post. You click Submit on every listing.
- We do not sell, share, or transfer your data to advertisers.
- We do not read or collect any data from Facebook users.
- We do not run scripts on random pages you visit, only your configured dealership URL and Facebook Marketplace, and only when you explicitly initiate the action.
1. Who we are
AutoStream is operated by AutoStream, LLC. AutoStream is a
managed B2B product, to use the extension, your dealership must be onboarded
by AutoStream and you must be invited by your dealership manager. The extension
is not designed for, or intended to be used by, consumers without a managed
dealership account.
2. Data we collect
2.1 Account credentials
- Your email address and a password hash, used to authenticate you against the AutoStream backend. Passwords are hashed and are never stored or transmitted in plaintext.
- Your full name (if provided by your dealership manager during invitation).
- Your role within the dealership (sales rep, manager, admin).
- Your dealership association, which dealership invited you.
2.2 Dealership configuration data
The following are configured per-dealership by an AutoStream administrator (typically your dealership manager) and are visible to the extension when you sign in:
- Your dealership’s inventory URL, the public URL of your dealership’s own inventory page (e.g. the dealer’s website).
- Your dealership’s optional CarGurus dealer-page URL, used by the marketplace lane to read your dealership’s inventory from CarGurus for manual posting. CarGurus-sourced vehicles remain manual-post only and are not written to the dealership website or treated as dealer-site inventory.
- Optional dealership-level configuration: brand name, timezone, contact phone, and optional server-side AI configuration for caption generation.
2.3 Vehicle inventory data (read on your behalf)
When you click Refresh Inventory in the extension popup, the extension reads vehicle data from your dealership’s configured inventory URL and/or CarGurus URL. This includes:
- Vehicle title (year, make, model, trim)
- Price (and pricing history if visible on the source page)
- Mileage / odometer reading
- VIN (Vehicle Identification Number)
- Stock number
- Exterior and interior color, body style, transmission, drivetrain
- Features and equipment list
- Photo URLs, references to vehicle photos hosted by the dealership website or CarGurus. The extension reads the URLs and presents the images to you for selection. We do not re-host or modify the images.
- Vehicle detail page URLs, links the rep can use to verify data against the source.
This vehicle data is your dealership’s own data. We read it on your dealership’s
behalf, at the dealership manager’s direction, via the configured URL.
2.4 Posting activity
- Which vehicles you posted to Facebook Marketplace, and the timestamp of each post (used to track posting streaks and to detect stale listings).
- The vehicle title, VIN, and price at the time of posting, retained so we can detect if your dealership later changes the price and flag the listing for re-posting.
- Your acceptance of the AutoStream User Agreement and the timestamp of acceptance.
We do not store the content of the listing you submitted to
Facebook (description text, caption, etc.) on our servers, that lives only on
Facebook’s platform after you submit.
2.5 What we do NOT collect
- We do not collect your browsing history.
- We do not collect keystrokes, mouse events, screen captures, or behavioral telemetry beyond what you actively choose to send (e.g. clicking Refresh Inventory).
- We do not read data from websites other than (a) the URLs configured by your dealership admin, and (b) Facebook Marketplace pages when you click Create Listing.
- We do not collect or store any data about other Facebook users, your Facebook friends, your Marketplace browsing activity, or any non-listing content on Facebook.
- We do not collect personally identifiable information about the end consumers who will see your Facebook Marketplace listings.
- We do not track you across websites.
3. How we use your data
3.1 Inventory display + manual listing pre-fill
We read your dealership's vehicle inventory to populate the extension's
inventory list. When you click Create Listing on a vehicle,
the extension opens Facebook Marketplace and pre-fills the listing form with
that vehicle's title, price, mileage, photos, and other fields. You then
review the pre-filled listing and click Submit yourself.
AutoStream does not submit listings on your behalf.
3.2 Optional AI caption assistance
If your dealership has AI assistance enabled and you click
“Generate Caption,” the extension sends the selected vehicle’s
title, features, and (optionally) photo URLs to AutoStream’s authenticated
backend. AutoStream then forwards the request to one of our AI providers
(see section 4.3) server-side to generate a suggested listing description.
The extension never receives or stores an AI provider API key. The suggestion
appears in the extension; you can edit, accept, or discard it before posting.
We do not store the AI-generated text on our servers; it lives only in your
current popup session and (if you submit it) on Facebook.
3.2a AI reply drafting (AutoStream Respond)
AutoStream Respond is a separate extension that drafts replies to buyer
enquiries. When a salesperson opens a conversation and asks for a draft, the
following is sent to AutoStream’s authenticated backend and forwarded to
one of our AI providers (see section 4.3) for the sole purpose of generating
that suggested reply:
- the messages in that conversation, from both the buyer and the salesperson, and the buyer’s first name as it appears in the conversation header;
- the vehicle the conversation is about, from your own inventory, and, where the salesperson has opened one, the vehicle history report summary;
- your dealership’s own saved answers, standing rules and store details.
The reply is a suggestion only. Respond never sends a message: a salesperson
reads every draft and sends it themselves. We keep the conversation record so
your team can follow up, and we do not store the drafted text beyond the
session and that record. Respond reads only the pages the extension asks
permission for, and never a personal profile or friends list.
3.3 Posting history and analytics
We use posting timestamps, vehicle identifiers, and price snapshots to
surface helpful workflows: posting streaks, stale-listing reminders, and
price-change alerts when your dealership updates a vehicle’s price after
you've already posted it. These analytics are visible only to you and to
your dealership manager.
3.4 Account authentication and dealership scoping
Your email and password hash are used to authenticate you against the
AutoStream backend. Once authenticated, your dealership association is used
to enforce that you can only see inventory and posting history for your own
dealership.
4. Where your data goes
4.1 Local storage on your device (Chrome storage.local)
- Your inventory list (vehicles + photos), cached locally for fast popup load.
- Posting history.
- Your UI preferences (sort order, filters, etc.).
This local data is wiped when you uninstall the extension.
4.2 AutoStream backend
Our backend is hosted on Supabase, a managed cloud database platform. It stores:
- Your account credentials (email, hashed password, role, dealership association).
- Your dealership’s configuration (inventory URL, CarGurus URL, brand, etc.), managed by your dealership admin.
- Server-side cached inventory data for your dealership.
- Posting activity log.
Each dealership’s data is isolated: a sales rep at Dealership A cannot
read inventory, posting history, or any other data belonging to Dealership B.
AutoStream staff access for support and operations purposes is restricted
and logged.
4.3 AI providers
AutoStream uses more than one AI provider, and which one handles a given
request depends on the task and on availability. All of them are accessed
server-side from AutoStream’s authenticated backend; API keys are never
exposed to the extension, and no provider is given your data for any purpose
other than returning the suggestion we asked for. Our providers are:
- Anthropic (
api.anthropic.com), for listing captions, reply drafting, and photo checks.
- Google (
generativelanguage.googleapis.com), for reply drafting.
- OpenAI (
api.openai.com), for reply drafting and vehicle photo labelling.
Each of these is used under its commercial API terms, under which request
content is not used to train that provider’s models. If we add or change
a provider we will update this page and the
subprocessor list.
4.4 Facebook (only when you click Create Listing)
When you click Create Listing in the extension, AutoStream opens
facebook.com/marketplace in a new tab and pre-fills the listing
form using vehicle data you have already reviewed. The data flows from your
browser to Facebook the moment you click Submit on Facebook’s form. We do not
send anything to Facebook automatically; the submission is always your
manual action.
4.5 What we do NOT do with your data
- We do not sell, share, or transfer user data to advertisers, data brokers, or other third parties.
- We do not share your dealership’s inventory with competing dealerships.
- We do not use your data to train any machine-learning model, and our AI providers do not train on it either, under the commercial API terms we use.
- We do not send marketing email or any unsolicited communication based on data collected via the extension.
5. Data security
- All network traffic between the extension and our backend is encrypted in transit (HTTPS).
- Account passwords are hashed and never stored or transmitted in plaintext.
- Each dealership’s data is isolated from every other dealership’s.
- Staff access to production data is limited to authorized personnel.
6. Data retention
- Local extension data is retained on your device until you uninstall the extension or sign out, at which point it is wiped.
- Account data is retained for as long as your dealership has an active AutoStream subscription, plus a 90-day grace period for re-onboarding.
- Posting history is retained for the duration of your dealership’s subscription. Your dealership manager can request earlier deletion.
- Server-cached inventory snapshots are overwritten on each refresh; historical snapshots are retained for 30 days for diagnostic purposes, then deleted.
7. Your rights and how to exercise them
You have the right to:
- Request a copy of the data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your account and associated data.
- Object to or restrict processing of your data.
- Withdraw consent for optional features (e.g. AI caption assistance) at any time, with no effect on your access to the rest of the extension.
To exercise any of these rights, contact us at the email address below.
Most requests are processed within 14 days.
8. AutoStream Respond (reply assistant extension)
AutoStream Respond is a separate Chrome extension for dealership salespeople.
It reads the sales conversation the salesperson has open in Facebook
Marketplace, Messenger, TECOBI or Outlook and drafts a suggested reply. The
salesperson reviews, edits and sends every message; the extension never
sends anything on its own.
8.1 What we collect
- The text of conversations the salesperson opens while signed in, including the buyer’s name as shown in that conversation and any vehicle mentioned.
- The salesperson’s saved drafts, notes and buyer requests (the “watchlist”) entered in the panel.
- Vehicle information from the dealership’s own inventory, its inventory system and, when the salesperson opens one, a vehicle history report.
- The salesperson’s AutoStream account and sign-in session.
8.2 How we use it
- To draft replies. Conversation text, together with the dealership’s inventory and playbook, is sent to AutoStream’s servers and to our AI providers (Anthropic, Google and OpenAI, see section 4.3) for the sole purpose of generating the suggested reply. Providers process it under their commercial API terms and do not use it to train their models.
- To keep the dealership’s records: which buyer asked about which vehicle, what was answered, and what buyers are looking for, so the team can follow up.
8.3 What we do not do
- We do not sell or rent this information.
- We do not use it for advertising or share it with anyone outside the dealership and the service providers above.
- We do not read pages other than the ones the extension asks permission for, and the dealership’s own website only after the salesperson grants it.
8.4 Retention and deletion
Conversation records are kept for the dealership while the account is active
and deleted within 30 days of the dealership closing its account. A
dealership can request deletion of any buyer’s conversation data at any
time by emailing hello@getautostream.com.
9. Children
AutoStream is a B2B workplace tool. It is not directed to children under
16, and we do not knowingly collect data from children. If you believe a
child has provided data to AutoStream, please contact us so we can delete it.
10. Changes to this policy
We may update this policy from time to time to reflect changes in features
or in legal requirements. We will update the “Last updated” date at the
top of this page when we do. If a change materially expands what data we
collect or how we use it, we will notify your dealership manager via the
AutoStream backend.
11. Contact
Questions or concerns about this privacy policy, or to exercise any of the
rights listed in Section 7:
- Email: hello@getautostream.com