Effective July 24, 2026
Privacy policy
TacTech Catalog Studio turns an equipment photo selected by the user into a seller-reviewed Instagram post or Facebook Marketplace draft.
Data the extension handles
- The equipment photo the user explicitly selects.
- The selling location the user enters.
- AI-generated listing data, including title, category, suggested price, condition notes, description, and tags.
- For Instagram connections: the account ID, username, account type, granted permissions, token expiration, and an encrypted OAuth access token.
- Limited technical status data needed to complete or diagnose the requested listing transfer.
TacTech does not collect Instagram or Facebook passwords, authentication cookies, private messages, contacts, payment information, or general browsing history.
How data is used
The selected photo and selling location are transmitted over HTTPS to TacTech's analysis service. The service uses an AI processing provider, currently Google Gemini, only to identify visible equipment details and prepare the requested listing fields. Generated fields are returned to the extension and filled into the Facebook Marketplace create-item form.
When a user connects Instagram, authorization occurs on Instagram's own sign-in screen. TacTech uses the resulting OAuth permission only to identify the selected Professional account and publish posts that the user explicitly reviews and approves.
The extension reads and changes only the Marketplace form elements needed for this user-requested workflow. It does not transmit the user's Facebook page content to TacTech.
Storage and retention
The selling location and the user's consent record are stored locally in Chrome so they do not need to be entered again. Temporary task status is removed after the draft is completed, fails, or its Marketplace tab closes.
Uploaded photos are placed in protected temporary storage only when needed to transfer the photo to Marketplace. Access uses a signed link that expires within 24 hours. After a successful transfer, the extension requests immediate deletion of the temporary server copy. Users may request deletion of residual failed-transfer data by contacting TacTech.
Instagram access tokens are encrypted before storage and retained until they expire, the user reconnects, or the user disconnects the account. OAuth connection requests expire after ten minutes.
Sharing and sale of data
TacTech does not sell extension data, use it for advertising, or use it to determine creditworthiness. Data is shared only with service providers necessary to deliver the photo-analysis and listing-draft feature, or when required for security or law. TacTech does not allow humans to read user data except with the user's explicit consent for support, for security, or when required by law.
User control
Users can disconnect Instagram from the web application at any time. They can clear locally stored extension data from Chrome's extension settings or by uninstalling the extension. To request access to or deletion of server-side data, email hanyu01@tactechs.net.
Chrome Web Store Limited Use
TacTech's use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the extension's disclosed single purpose.
Changes and contact
Material changes to data handling will be disclosed in the extension before new data practices take effect. Questions about this policy can be sent to hanyu01@tactechs.net.