Privacy
Privacy Policy
Effective August 26, 2026
This policy explains what AutoRep HQ processes when an automotive sales representative uses the website, browser extension, membership access, and support tools.
What the extension processes
The extension acts only after you choose a public vehicle-detail page and request a draft. It may process the public page URL, vehicle facts, pricing, mileage, VIN, stock number, colors, descriptions, photo URLs, and video URLs. It combines those facts with the sales profile you provide, including your name, phone number, dealership, location, website, listing preferences, call-to-action, and disclaimer.
Your profile is stored using Chrome storage. When you choose Connect Whop account, Whop handles sign-in and returns a short-lived authorization to AutoRep HQ. AutoRep HQ uses the resulting Whop user identifier to find the matching AutoRep HQ membership and issue a revocable AutoRep HQ access token. Whop OAuth tokens are not retained after this one-time connection. A reviewer or support access code may also be exchanged for an AutoRep HQ access token when that fallback is deliberately used. The AutoRep HQ token, consent timestamp, most recent draft, and most recent compatibility-report receipt are stored locally in the browser. Chrome may sync profile settings according to your signed-in Chrome configuration.
How information is used
- To import a selected public vehicle page and generate a review-ready draft.
- To connect a Whop account and verify active paid access when subscriptions are enabled.
- To measure plan usage and apply fair-use limits.
- To relay public vehicle photos when a dealership or media host blocks a direct browser download.
- To generate listing copy through OpenAI when AI-assisted descriptions are enabled on the service.
- To diagnose compatibility failures and protect the service from abuse.
- To measure privacy-minimized activation and reliability events when product analytics are enabled.
Facebook receives draft fields or photos only when you click the corresponding fill or upload control. The extension does not publish a listing automatically. You must review the Marketplace form and click Post yourself.
Compatibility reports
When you deliberately submit a compatibility report, it includes a category, any note you choose to write, the public page hostname and URL, extension version, import method, extraction method, photo and video counts, and whether a price or VIN was detected. Query parameters, URL fragments, credentials, your sales profile, membership information, and your AutoRep HQ access token are excluded from the report payload. Do not include private customer or login information in the optional note.
Product analytics and referrals
The website uses a random local visitor identifier to count page views, membership-button clicks, referral visits, product-demo engagement, and the mobile-to-desktop setup steps. Device reporting is limited to a general mobile or desktop category. The extension offers a separate product-analytics choice for onboarding completion, first-draft completion, photo preparation, Marketplace opening, and review or referral prompts. These events do not include a vehicle URL, VIN, listing copy, sales profile, Facebook activity, customer information, or access token.
A member referral link contains a random referral code. AutoRep HQ records referral-page visits and link-sharing activity so members and the business can understand referral performance. The code does not expose a membership identifier.
Desktop setup email
If you request a desktop setup link, AutoRep HQ sends the email address you enter to Resend to deliver that requested transactional message. The message contains the AutoRep HQ website, Whop membership page, and official extension-install page. The request also creates a random handoff identifier so AutoRep HQ can count the request and a later desktop visit without putting your email address in a URL or analytics event.
The optional product-updates checkbox is separate and unchecked by default. The desktop-link email is sent whether or not you choose marketing updates. If you opt in, Resend stores your address as an AutoRep HQ marketing contact until you unsubscribe or request deletion and may send the disclosed desktop-setup and founding-access follow-ups. AutoRep HQ temporarily associates the random handoff identifier with that opted-in address for up to seven days so a completed extension setup can stop the reminder sequence; the address is never placed in the extension, URL, or analytics event. Marketing messages include an unsubscribe method. AutoRep HQ does not maintain a second raw-email marketing list in website analytics. Resend may retain ordinary transactional delivery, automation, and suppression records under its own terms.
Advertising and funnel measurement
When you select Allow ad measurement, AutoRep HQ loads the Meta Pixel and Whop's website analytics pixel on its public marketing pages. The Meta Pixel records a page-view event, an initiate-checkout event when you choose an AutoRep HQ link that opens the Whop offer, and Lead and DesktopLinkRequested events only after Resend accepts the requested desktop-link email. Those handoff events describe the offer and request source but do not include the email address. Whop's pixel records page visits and referral information so AutoRep HQ can understand which landing pages and traffic sources lead visitors toward membership. Neither pixel records a purchase merely because you clicked a link.
When ad measurement is allowed, AutoRep HQ may send a matching server-side Lead event through Meta's Conversions API after Resend accepts the desktop-link email. The browser and server events use the same random handoff event identifier so Meta can deduplicate them. The server event may include a one-way SHA-256 hash of the normalized email address, IP address, and browser user agent for attribution; it does not include the raw email address.
When Whop confirms a successful first payment for the AutoRep HQ product, AutoRep HQ may send a server-side Purchase event to Meta through the Conversions API for advertising measurement and attribution. The event includes the purchase value and currency, event time, AutoRep HQ product identifier, and unique event identifier. Matching fields available in the Whop payment notification—such as email, phone number, or a Whop user or membership identifier—are normalized and one-way hashed with SHA-256 before transmission. AutoRep HQ does not send Meta raw contact details, payment-card data, or a Whop membership access credential. Recurring subscription renewals are excluded from this acquisition event.
Meta and Whop may use cookies, web beacons, device or browser identifiers, IP address, page URL, referrer, and interaction information to measure visits and attribute traffic. Meta may also use this information to build advertising audiences and improve ad delivery. AutoRep HQ does not send either provider vehicle VINs, listing descriptions, extension sales profiles, customer records, membership access tokens, Facebook passwords, or dealership credentials through these browser integrations.
Your advertising-measurement choice is stored in your browser. Use the Privacy choices button on any public marketing page to change it. You can also manage or disconnect activity through Meta's activity-off-Meta controls and review industry opt-out choices through the Digital Advertising Alliance.
Testimonials and reviews
Submitting a testimonial is optional and requires explicit permission. The submitted display name, dealership name, and feedback remain pending until an AutoRep HQ administrator approves or rejects them. Approved testimonials may appear publicly on AutoRep HQ marketing pages. Chrome Web Store reviews are submitted directly to Google and are governed by Google's policies; AutoRep HQ does not require a positive review.
Information we do not request
AutoRep HQ does not request or intentionally collect your Facebook password, Facebook cookies, private messages, dealership employee credentials, customer records, payment-card details, or Whop API keys. The extension is designed for public dealership inventory pages, not internal dealer systems.
Service providers and retention
Vercel hosts the website and API and may process ordinary request and security logs. Resend processes requested transactional emails and consented marketing contacts. Upstash stores hashed access tokens, minimum Whop entitlement identifiers and statuses, webhook event receipts, usage counters, privacy-minimized product-event counts, referral records, testimonial approval records, and—only for opted-in desktop follow-ups—a temporary address-to-random-handoff association that expires within seven days. Whop processes membership, billing, community access, any affiliate program enabled through Whop, and consented website-attribution events. Meta processes consented browser Pixel events and the server-side first-payment Purchase event described above. OpenAI may process draft-generation inputs when that optional server feature is enabled. Public dealership and media hosts provide the inventory data and images you select.
Operational and compatibility records may be retained for up to 90 days unless a longer period is required for security, legal compliance, or an unresolved support matter. Temporary opted-in desktop-handoff records expire after no more than seven days. Browser-stored settings remain until you clear extension data or uninstall the extension. Payment and membership records are retained by Whop under its own policies.
Sharing, sale, and advertising
We do not sell personal information or transfer it to data brokers. If a visitor allows ad measurement, limited website activity is shared with Meta and Whop for measurement and attribution as described above; Meta may also use it for audience creation and ad delivery. Other information is shared only with service providers needed to deliver the requested feature, comply with law, or protect the service and its users.
Your choices
You can decline or change advertising measurement through the website's Privacy choices button, leave the product-updates checkbox unchecked, unsubscribe from a marketing email, edit your extension profile, disable optional product analytics, decline a compatibility report or testimonial request, clear the extension's storage, or uninstall it. To request deletion of a marketing contact or server-side support, compatibility, referral, or testimonial information, contact support through the AutoRep HQ Whop membership or the support page and include the relevant report or testimonial identifier when available.
Chrome Web Store limited use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Security and changes
We use reasonable technical and organizational safeguards, but no online service is completely secure. We may update this policy as the product or legal requirements change. Material changes will be posted here and communicated through the member community when appropriate.
Contact
For privacy questions or requests, use the AutoRep HQ support channel in Whop or follow the instructions on the support page.