Extension and portal

Privacy policy

AcqPilot is a dealer tool. It appraises the vehicle listing a buyer is already looking at and, when the buyer chooses, saves it to their dealership's queue. This page describes exactly what leaves the browser, where it goes, and what is never collected.

Single purpose

The AcqPilot extension does one thing: appraise a vehicle listing the user is viewing, and save that vehicle to their dealership's acquisition queue. Every permission it requests exists to serve that one purpose.

What the extension reads, and when

On a marketplace listing page (craigslist.org, facebook.com/marketplace, offerup.com, nextdoor.com, kijiji.ca) the extension reads the listing's own published details: title, asking price, mileage, description text, listing URL, and the VIN when the seller published one. On Facebook Marketplace the buyer pastes the listing text themselves; nothing is scraped.

Nothing is read, and no request is made, until the buyer opens the appraisal card on that listing.

What is transmitted, and to which host

A VIN and listing content are transmitted when present. The extension contacts exactly four vendor hosts and no others:

mc-api.marketcheck.com
MarketCheck — retail listing comparables and vehicle taxonomy facets (trim, drivetrain, body type).
Sent: Year, make, model, trim, drivetrain, mileage, your dealership ZIP code, search radius, and the VIN when the listing publishes one.
api.auto.dev
Auto.dev — secondary comparable-listing provider used when MarketCheck coverage is thin.
Sent: Year, make, model, trim, mileage, your dealership ZIP code, and search radius.
vpic.nhtsa.dot.gov
NHTSA vPIC — public U.S. government VIN decode and make/model taxonomy for the manual identity fields.
Sent: The VIN, or a make name when loading the model dropdown.
acqpilot.com
AcqPilot's own backend — extension pairing, your session, and saving a vehicle to your dealership's queue.
Sent: Your session token, the appraisal snapshot you chose to save, and the listing URL, VIN, price, mileage, and listing text of that vehicle.

One optional host, www.googleapis.com, is requested only if a dealership enters its own Google Custom Search credentials to widen dealer-site comp coverage. It is off by default and the permission is requested at that moment, not at install.

Sessions and account binding

Signing the extension in uses a one-time pairing code minted by the portal after the user has already authenticated on acqpilot.com. Redeeming that code returns a session token that is stored locally in the browser's extension storage and binds the extension to that specific rep's account and dealership. Every vehicle saved from the extension is attributed to that rep and written only into that dealership's queue. The token can be revoked from the portal's session settings, which immediately stops the extension from writing anything.

What is never collected

  • Your browsing history. The extension has no access to any site other than the marketplace listing pages it is declared for.
  • Page content on non-listing sites. Nothing is read on any page outside craigslist.org, facebook.com/marketplace, offerup.com, nextdoor.com and kijiji.ca.
  • Keystrokes. There is no keylogging of any kind, on any page.
  • Cookies. The extension does not request or read cookies from any site.
  • Credentials. No passwords, payment details, or authentication cookies are read, stored, or transmitted.
  • Analytics or advertising trackers. There are none in the extension.

Nothing is sold

AcqPilot does not sell, rent, license, or transfer user data to any third party, and does not use it for advertising, profiling, or any purpose unrelated to appraising a vehicle and saving it to a dealership's queue. Data is shared only with the vendor hosts listed above, and only the fields listed above, purely to fulfil the user's own appraisal request.

What the portal stores

  • Your dealership account, its users, and their roles.
  • Vehicles saved to the queue and the appraisal snapshot frozen at the moment of saving.
  • Notes, status changes, and assignments made inside the portal.
  • Public marketplace listing details for the leads in your feed, including the VIN when the seller published one.

Isolation and retention

Every record is scoped to a dealership, and database row-level policies prevent one dealership from reading another's data. Pairing codes are single-use and expire within minutes. Saved vehicles and appraisal snapshots are retained until your dealership deletes them or asks us to close the account, at which point they are removed.

Questions or deletion requests

Reach out via the contact page and we will action deletion requests directly.