Privacy Policy
Effective Date: February 2, 2026 | Version: 1.0
This Privacy Policy describes how the Rent Crew Chrome extension ("Extension", "we", "our", or "us") collects, uses, stores, and shares information when you use our Extension and the associated website at rent-crew.com ("Website").
By installing and using the Extension, you agree to the practices described in this Privacy Policy.
1. Information We Collect
1.1 Information You Provide Directly
- Email address — provided during sign-in via Google OAuth or Magic Link email authentication. Used solely for account creation and authentication.
- Display name and profile picture — obtained from your Google account (if you sign in with Google) or derived from your email address. Displayed within the Extension to identify workspace members.
- Workspace names — custom names you assign to collaborative workspaces.
1.2 Information Collected Automatically
- Listing data from Bazaraki.com — when you visit a property listing page on bazaraki.com, the Extension reads publicly available listing information (title, price, location, property characteristics) from the page. This data is used to display listing details within the Extension and to share context with workspace members.
- User actions on listings — your interactions with the Extension's controls: marking a listing as "viewed", "hidden", or classifying the listing poster as "owner" or "realtor". These actions are stored to enable collaborative filtering.
- Workspace membership data — your user ID, workspace ID, role (owner or editor), and join date, necessary for workspace collaboration.
- Authentication tokens — access and refresh tokens issued by Supabase Auth, stored locally in your browser to maintain your signed-in session.
- Filter preferences — price range and owner-type filter settings, stored locally in your browser.
1.3 Information We Do NOT Collect
- We do not collect or access your browsing history, bookmarks, or any activity outside of bazaraki.com pages.
- We do not collect personal or financial information beyond what is described above.
- We do not use any analytics, telemetry, crash reporting, or tracking services.
- We do not read or modify cookies on any website.
- We do not collect passwords. Authentication is handled entirely by Supabase Auth (Google OAuth or Magic Link).
2. How We Use Your Information
| Data |
Purpose |
| Email, name, avatar |
Authenticate your identity, display your profile to workspace members |
| Listing data (title, price, location, etc.) |
Cache listing details so workspace members can see shared context (e.g., in the hidden-adverts list) |
| User actions (viewed, hidden, owner type) |
Enable collaborative filtering: show/hide listings, highlight viewed ones, classify posters across the workspace |
| Workspace membership |
Manage workspace access, enforce roles and participant limits |
| Authentication tokens |
Maintain your authenticated session with the backend |
| Filter preferences |
Persist your price and owner-type filter settings between sessions |
We use your data exclusively to provide and operate the Extension's functionality. We do not use your data for advertising, profiling, or any purpose unrelated to the Extension.
3. How We Store Your Information
3.1 Local Storage (Your Browser)
- chrome.storage.local — stores authentication tokens, workspace ID, user ID, filter preferences, and panel state. This data remains on your device and is not accessible to websites.
- IndexedDB (via Dexie) — caches listing data, workspace advert state, and an offline operation queue. This is a local cache to reduce server requests and enable offline support. Data stays on your device.
3.2 Server-Side Storage
- Server-side data is stored in a Supabase (PostgreSQL) database hosted in the EU (eu-central-1, Frankfurt) region.
- All data is protected by Row Level Security (RLS) policies, which ensure that users can only access data within workspaces they belong to.
- Authentication is managed by Supabase Auth, which handles credential storage, token issuance, and OAuth flows. We do not store passwords.
4. Data Transmission and Security
- All communication between the Extension and our backend occurs over HTTPS (TLS-encrypted connections).
- Authentication tokens are transmitted via HTTPS headers and are never included in URL parameters or query strings.
- The Extension communicates only with the following domains:
- *.supabase.co — backend API (database, authentication)
- rent-crew.com — authentication callback page
- www.bazaraki.com — the target website where the Extension operates
- No data is transmitted to any other third parties, advertising networks, analytics services, or data brokers.
5. Data Sharing
5.1 Within Workspaces
When you join a workspace, the following information becomes visible to other workspace members:
- Your actions on listings (viewed, hidden, owner-type classifications)
- Your user ID (internal identifier, not your email)
Your email address is not shared with other workspace members.
5.2 Third-Party Service Providers
- Supabase, Inc. — provides database hosting, authentication, and API infrastructure. Supabase processes your data on our behalf and is bound by their Privacy Policy. Data is hosted in the EU (Frankfurt).
- Google — if you choose to sign in with Google, Google processes your authentication as an OAuth provider. See Google's Privacy Policy.
5.3 We Do NOT Share Data With
- Advertising platforms or ad networks
- Data brokers or information resellers
- Credit agencies or lending institutions
- Any other third parties not listed above
6. Data Retention
- Account data — retained as long as your account exists. When you sign out, local tokens are deleted from your browser.
- Workspace data — retained as long as the workspace exists. When the workspace owner deletes a workspace, all associated data (advert states, member records) is permanently deleted via cascading deletion.
- Listing cache — listing data stored on the server is retained indefinitely to provide historical context. Locally cached data can be cleared by uninstalling the Extension.
- Offline queue — pending operations are processed when connectivity is restored and then removed from the local queue.
7. Your Rights and Choices
- Access and portability — you can request a copy of your personal data by contacting us at the email below.
- Correction — you can update your profile information through your Google account or by signing in with a different email.
- Deletion — you can request deletion of your account and all associated data by contacting us. If you are a workspace owner, deleting your workspace removes all workspace data. Uninstalling the Extension removes all locally stored data.
- Withdraw consent — you can stop using the Extension at any time by uninstalling it. You can leave a workspace at any time through the Extension popup.
- Local data — you can clear all locally stored data by uninstalling the Extension or clearing site data for the Extension in Chrome settings.
If you are located in the European Economic Area (EEA), you may have additional rights under the GDPR, including the right to lodge a complaint with your local data protection authority.
8. Chrome Extension Permissions
The Extension requests the following browser permissions, each necessary for its core functionality:
| Permission |
Why It's Needed |
storage |
Store authentication tokens, workspace settings, and filter preferences locally in your browser |
tabs |
Open the authentication page in a new tab when you sign in, and broadcast updates to open Bazaraki tabs |
declarativeNetRequest |
Allow map geometry API requests on Bazaraki to pass through for map marker filtering |
Host: bazaraki.com |
Inject the content script that provides the panel UI and map filtering on Bazaraki listing pages |
Host: *.supabase.co |
Communicate with our backend API for data synchronization and authentication |
Host: rent-crew.com |
Process the authentication callback after sign-in |
9. Children's Privacy
The Extension is not directed at children under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly.
10. Limited Use Disclosure
The Rent Crew Extension's use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Effective Date" at the top of this page. If we make material changes, we will notify you through the Extension (e.g., via a notice in the popup interface) or through the Website.
We encourage you to review this Privacy Policy periodically.
12. Contact Us
If you have any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us at:
Email: [email protected]