Curb Syndication — Chrome Extension Privacy
Last updated: August 26, 2026
Who this is for
The Curb Syndication Chrome extension is a workplace tool used by authorized employees of dealerships that subscribe to the Curb platform at app.curb.direct. The extension is not offered to the general public and has no consumer use case.
What it does
The extension fills in Facebook's own Marketplace vehicle form using inventory the dealership has already entered in Curb — year, make, model, mileage, price, description and photos. It opens the Marketplace listing form in a new tab, enters those details, highlights the Publish button, and stops. The user reviews the listing and clicks Publish themselves. The extension never submits a listing.
On a private-party Marketplace listing or an existing Marketplace/Messenger thread, the extension can also draft a first note or follow-up. It may insert that draft into Facebook's own message box. The user reviews the text and clicks Facebook Send themselves. The extension never sends a message, never uses the Messenger Platform API, and never scrapes Marketplace search results into a queue.
After the user publishes, the extension reads the resulting listing ID from the page address so the vehicle can be marked as posted in Curb. If the user closes the tab or abandons the form, nothing is posted and Curb records the attempt as incomplete.
The extension does not log in to Facebook on the user's behalf, does not ask for or store Facebook credentials, and cannot fill anything unless the user is already signed in to Facebook in the same browser profile.
Data the extension reads
- Curb session cookie — read implicitly by the browser when the extension makes requests to
app.curb.direct. Used to authenticate the user against their own dealership's data. The extension never reads, copies, or transmits the cookie itself. - Curb syndication queue — vehicle listings the dealership has queued for the signed-in user (year, make, model, price, description, photo URLs). Fetched from
app.curb.directover HTTPS. - Photos for queued vehicles — Curb supplies the dealership's own photo URLs, and the extension requests those images directly from
inventoryrsc.comorcontent.homenetiol.com, the CDNs hosting them. If a direct request is unavailable, the extension retries the image throughapp.curb.direct. The CDN request carries no Curb data and no identifying information beyond the image address itself. - The Marketplace listing form — the content script reads the labels and fields of Facebook's own vehicle form in order to fill them in, and reads back the values it entered to confirm they were accepted. It does not read Facebook cookies or session tokens.
- A private Marketplace listing or open thread — when DM assist is active, the content script reads the visible title, price, year, make, model and mileage on that page, and visible messages in the open thread, so Curb can draft a note and log it on the user's own tenant lead. It does not scrape Marketplace search or browse pages into a list.
- The published listing address — after the user clicks Publish, the extension reads the listing ID from the resulting page address so the vehicle can be marked posted in Curb.
Data the extension stores locally
Stored only in chrome.storage.local on the user's device:
- A flag indicating whether the extension is connected to Curb
- A cached copy of the user's queue for badge counts
- Transient posting state while a post is in progress
The extension does not use chrome.storage.sync, does not maintain a server-side profile, and does not use cookies of its own.
Data the extension sends
- To
app.curb.direct: standard authenticated API calls to read queued listings, update listing status to active or failed after a post completes, create or tie an acquisition lead, request an AI draft, and write lead timeline events (drafted / sent / seller replied). - To Facebook: nothing is sent by the extension. Listing details reach Facebook only when the user clicks Publish. Message drafts reach Facebook only when the user clicks Send.
No Curb or Facebook data is sent to any other destination. The extension contains no analytics, telemetry, ad tracking, or third-party SDKs.
What it does not do
- It does not collect personal information beyond what the user has already entered into Curb or Facebook.
- It does not read browsing history, content from non-Facebook tabs, form fields on other sites, or financial information.
- It does not sell, share, or transfer user data to anyone. Data does not leave the user's browser except as described above.
- It does not use any data for purposes unrelated to posting the user's own dealership inventory.
Permissions justification
storage— local connected/queue flags described above.sidePanel— side-panel UI listing the user's queue.alarms— schedule a periodic queue refresh while connected.- Host permission for
facebook.com/marketplace— the content script must run on the Marketplace listing form in order to fill it in, and on a private item page for DM assist. - Host permission for
facebook.com/messagesandmessenger.com— DM assist on an existing thread. The extension never clicks Send. - Host permission for
app.curb.direct— read the queue, retrieve the dealership's vehicle photos, and update listing status. - Host permissions for
inventoryrsc.comandcontent.homenetiol.com— retrieve the dealership's own vehicle photos directly from the CDNs that host them, with Curb as the fallback when a direct request is unavailable.
Relationship to Facebook
The extension is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. or Facebook. Posting through Facebook Marketplace is subject to Facebook's own terms; users are responsible for using the extension in a manner consistent with those terms and with their employer's policies.
Retention and deletion
Local extension state is removed when the user uninstalls the extension or clears Chrome's site data. Data stored on the Curb platform follows the main Curb Privacy Policy.
Contact
Questions about this notice or the extension's data handling:
Curb Direct
Email: [email protected]