Privacy Policy · v1.0

Privacy Policy

Effective: 2026-05-16  ·  Last updated: 2026-05-16
Short version: The Chrome extension assigns your browser a random anonymous ID and sends what it scanned (listing URLs, our verdict, friction flags it found) back to a database we operate so we can improve the rules. No names, no emails, no Google account info, no cross-site tracking. You can wipe your local data in two clicks. The long version below tells you exactly what we collect, why, and who else touches it.

1 · What this covers

This policy covers the GavelGap Chrome extension (the "Extension") and the gavelgap.com website (the "Site"), collectively the "Service." It explains what we collect, why, who we share it with, and how you can opt out or delete your data.

GavelGap is an independent third-party tool. We are not affiliated with, sponsored by, or endorsed by GovDeals, Liquidity Services Inc., eBay Inc., Google LLC, or any government agency.

2 · What we collect

2.1 · From the Extension (automatic)

When you open a GovDeals listing while the Extension is installed, it analyses the page locally and sends a "scan event" to our backend. Each scan event contains:

If your auction has ended when you revisit a listing, the Extension may also send an "outcome event" recording whether the listing sold, the final bid price (visible publicly on the page), and a SHA-256 hash of the winning bidder's username — never the raw username.

2.2 · From the Extension (only if you take action)

2.3 · From the Site

2.4 · What we do NOT collect

3 · Why we collect it

4 · Third parties we share data with

We use a small number of vendors to run the Service. They process data on our behalf:

VendorWhat they handlePrivacy policy
Supabase Database hosting (Postgres). All scan events, feedback, outcomes, waitlist emails, and support messages are stored here. supabase.com/privacy
Cloudflare Website hosting (Pages), API proxy (Workers), and DNS for gavelgap.com. Receives request metadata including your IP address (used for routing and DDoS protection; we do not log IPs ourselves). cloudflare.com/privacypolicy
Resend Email delivery for support replies. Sees the contents of email notifications we send. resend.com/legal/privacy-policy
eBay The Extension fetches public sold-listing search results from ebay.com to estimate resale values. Your search query is the cleaned listing title. ebay.com
Google Shopping Used as a fallback when eBay returns few results. The Extension fetches public Google Shopping search results with the cleaned listing title. policies.google.com/privacy
OpenStreetMap Nominatim Geocoding seller city/state to estimate shipping distance. We send city + state strings; no personal data. openstreetmap.org
NHTSA vPIC Decoding Vehicle Identification Numbers for vehicle listings. Sends the VIN (no PII). nhtsa.gov

We do not sell your data to advertisers, data brokers, or other third parties. We do not run ad networks on the Site or Extension at this time.

5 · How long we keep it

6 · Cookies and similar tech

The Site sets a Cloudflare bot-management cookie (__cf_bm) to distinguish humans from bots. We do not set advertising or analytics cookies. The Extension uses Chrome's local storage APIs (chrome.storage.local / chrome.storage.sync) to keep your device ID and preferences; these are not cookies and are not accessible to other websites.

7 · Your rights and choices

7.1 · Wipe your local extension data

To clear your local device ID, ZIP, and cached data: in Chrome, open chrome://extensions → GavelGap → "Site settings" or "Clear data" → reload the extension. Or uninstall the Extension entirely.

7.2 · Delete server-side data

To remove server-side scan / feedback / outcome rows associated with your anonymous device ID, send a request to gavelgap.com/support with the topic "Account / data" and check the "Include my anonymous device ID" box so we can find your rows. We will delete them within 30 days and confirm by email.

7.3 · Opt out of telemetry entirely

Disable or uninstall the Extension. There is no separate telemetry toggle yet; we plan to add one. Until then, uninstall = full opt-out.

7.4 · Unsubscribe from the waitlist

Email us via gavelgap.com/support with topic "Account / data" and your waitlist email. We'll remove you and confirm.

7.5 · California residents (CCPA / CPRA)

You have the right to know what personal information we collect about you, to request deletion of that information, and to opt out of the "sale" or "sharing" of personal information (we do neither). To exercise these rights, contact gavelgap.com/support. We will not discriminate against you for exercising them.

7.6 · EU / UK residents (GDPR)

You have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing. To exercise these rights, contact gavelgap.com/support. Our lawful basis for processing scan telemetry is your consent (installing the Extension); our basis for processing waitlist / support emails is your contractual request.

8 · Children

The Service is not directed to children under 13 (or under 16 in the EU/UK). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

9 · Security

All traffic to and from gavelgap.com and api.gavelgap.com uses HTTPS / TLS 1.2+. Server-side tables enable Postgres row-level security; only a privileged Edge Function can write or read them. We use a small number of well-known vendors (above) and rotate access tokens periodically. No system is perfectly secure; if you discover a vulnerability, please report it via gavelgap.com/support.

10 · Data location

Our database is hosted in the United States (Supabase, AWS us-east-1). Cloudflare's edge serves the Site from data centers worldwide. If you're outside the U.S., your data is transferred to and processed in the U.S.

11 · Changes to this policy

We may update this policy as the product evolves. Material changes will be posted here with an updated "Last updated" date. If we make a significant change (e.g., adding a new third-party data processor, adding ads), we'll prominently notify visitors on the Site.

12 · Contact

Questions about this policy, requests for data deletion, or anything else privacy-related — gavelgap.com/support (topic: "Account / data" works best). We typically respond within 1–2 business days.