Privacy
The short version. BuyerSpotter runs inside your browser. It reads only sources your signed-in accounts can already open, keeps the product inbox on your machine, and never sends messages or posts on your behalf.
What the extension reads
Only the supported networks you switch on and the sources you choose inside them. This can include selected Facebook groups, Nextdoor areas, LinkedIn searches, X feeds, and public Reddit searches or subreddits. BuyerSpotter reads through the browser session you are already signed into; Reddit is read as a visitor, without signing in.
It cannot see anything your account cannot see. A private source you cannot open is not available to BuyerSpotter.
What the extension stores
Saved matches, match explanations, source choices, and extension settings are stored locally in your browser's extension storage. Removing the extension removes that local storage, subject to your browser's behavior.
Your BuyerSpotter account
You sign in to BuyerSpotter with Google or with an email address and password. The BuyerSpotter account service (hosted on Google Firebase and Vercel) keeps your email address, an account identifier, your trial and plan status, the extension installations linked to your account, and the alert destinations you connect (a Telegram chat or a webhook address). It also keeps delivery records for alerts (time and status, not the post) so an alert is not sent twice. It does not keep your inbox, your saved matches or your notes.
Payments are handled by Paddle (Paddle.com Market Limited), our reseller and merchant of record. Card and payment details go to Paddle, not to BuyerSpotter; we receive the subscription and transaction status Paddle reports.
Your sign-in on the networks you choose
To read the sources you selected, the extension uses the session your browser already has on those networks. It reads a small, fixed set of cookies on Facebook, LinkedIn, X and Nextdoor, only to check that you are signed in, to add the security token those sites require on their own requests, and to notice when you switch to a different Facebook account or Page. On Reddit, which is read without an account, it only checks that Reddit's visitor cookie (loid) is present; if it is missing, the extension loads reddit.com once — the same as opening the site in a tab — so Reddit issues its usual visitor cookies. Nobody is signed in by this. These values are used only inside your browser, only for requests to the same site. They are never sent to BuyerSpotter's servers, error reports, analytics or anyone else, and the extension never changes or deletes them.
What the extension never does
- It never asks for or handles your network passwords.
- It never bypasses access controls or reveals content your signed-in account cannot already open.
- It never posts, comments, reacts, or sends a message on your behalf.
- It never builds or sells contact lists.
- It does not sell or rent the conversations it reads. Connected alerts can send selected match details as described below.
Local matching and connected alerts
The current extension uses keyword matching, exclusions and rule-based request signals. It does not offer an active AI integration or send posts to an AI provider.
If you enable and connect a webhook or Telegram alerts, the extension sends selected match details through the BuyerSpotter account service to your configured destination. These details can include a short excerpt, source and platform, original post URL and matched phrase. Your destination provider's terms and privacy policy apply. The local inbox remains in Chrome; connected alerts are a separate transfer of the selected information. Only connect destinations appropriate for the content you monitor.
Error reports
To find and fix problems, the extension and the BuyerSpotter account service send error reports to Sentry (Functional Software, Inc.), our error-monitoring provider, hosted in the United States. A report is sent when something fails: for example an error in the extension, a supported network that could not be read, a group list that could not be loaded, an alert that could not be delivered, or a sign-in or checkout step that failed.
A report contains the type of failure, a technical code and short error message, the part of the product and network it came from, simple counts (such as how many requests were made), the extension version, browser and operating system, and an opaque account identifier so repeated failures can be connected. Web addresses are shortened to the site and the first part of the path, and email addresses and access tokens are removed.
Error reports never include post or comment text, author names, search phrases, your saved matches, passwords, cookies, Telegram chat identifiers or webhook addresses. Each installation sends a small, limited number of reports per day. Reports are kept by Sentry for up to 90 days.
Product analytics in the extension
To understand how BuyerSpotter is used and where people get stuck, the extension, its dashboard and the account service send product analytics to PostHog (PostHog, Inc.) and Amplitude (Amplitude, Inc.), both hosted in the United States. Both receive the same events described below.
This includes which screens and setup steps you open, actions you take (for example marking a match, turning a network on or off, changing the schedule, connecting an alert channel, starting a trial or checkout), which networks are enabled, the number of sources, keywords and matches, daily counts of scans and matches per network, whether scans are succeeding, your plan and access status, the extension version, and an account identifier that connects these events. We also record dashboard sessions in PostHog to see where the interface is confusing (Amplitude receives events only, never recordings); in these recordings every piece of text, every input field, element attribute and image is masked, so they show layout and clicks only. Like any web service, PostHog and Amplitude receive the IP address the events come from and may use it to estimate an approximate location (country and city).
Product analytics never include post or comment text, author names, group or source names, search phrases or keywords, your saved matches, reply drafts, notes, links, passwords, cookies, email addresses, Telegram chat identifiers or webhook addresses.
Analytics on this website
The public website may use Vercel Web Analytics for anonymous, aggregate traffic measurement and Vercel Speed Insights for real-world performance metrics. These tools are used to understand page usage and site quality.
Google Analytics 4 and Microsoft Clarity are supported but load only when their project identifiers are configured and you consent. Clarity elements containing customer material are explicitly masked, and strict masking must also remain enabled in the Clarity project settings.
Website analytics events contain the event name, public page path and general labels such as button placement, selected example category or tool action. We do not send email addresses, post content, monitored-source names, extension results, tool input or your BuyerSpotter inbox in these events. Optional Google Analytics may receive campaign source, medium and campaign labels from the link you visited.
These general actions can include starting or completing the guided example, copying a template and downloading a worksheet. A click to the Chrome Web Store is recorded as a click, not as an installation or a purchase. Private design previews do not deliver analytics events or load analytics providers.
You can reject optional analytics or withdraw consent using Cookie preferences in the website footer. Your choice is stored locally in your browser. Withdrawing consent disables optional analytics and reloads the page to unload their scripts.
Advertising measurement (Meta)
We also advertise on Facebook and Instagram. This website loads the Meta pixel (Meta Platforms), which records page views and clicks on our install buttons, and writes Meta's own first-party cookies (_fbp, _fbc) on buyerspotter.com. A click on an install button is reported as a click; the installation itself happens on the Chrome Web Store, which we cannot measure.
When an account is created or a subscription starts, the account service reports that event to Meta's Conversions API with your email address and account identifier as irreversible SHA-256 hashes, Meta's cookie values if present, and for a new account your browser type and IP address. We never send post or comment text, sources, keywords, matches or payment details.
If you reject optional analytics using Cookie preferences in the website footer, the Meta pixel is not loaded.
Advertising measurement (OpenAI Ads)
We advertise in ChatGPT. To learn whether those ads lead to visits, sign-ups and subscriptions, this website loads the OpenAI Ads measurement pixel (OpenAI), and the account service reports two events to OpenAI's Conversions API: an account being created, and a subscription being started.
When you arrive from an ad, the pixel keeps the ad's click reference in a first-party cookie on buyerspotter.com (for up to 30 days), and records page views. When your account is created or a subscription starts, we send OpenAI that event, the click reference if there is one, and your email address and account identifier as irreversible SHA-256 hashes, plus your browser type and IP address for matching. We never send post or comment text, sources, keywords, matches or payment details.
If you reject optional analytics using Cookie preferences in the website footer, the pixel is told not to measure and the click reference is not kept.
Free website tools and product examples
The keyword builder and opportunity checklist run in your browser without a signup. The website does not send your entries to a server or persist them in browser storage. Do not enter private customer information. Copy and download actions happen only when you choose them. A downloaded plan or review is a plain-text file on your device; manage or delete that file yourself. A link from a product example may include a general category such as SaaS, but never your tool entries.
Product examples are fictional demonstrations, not real customer posts or performance results. These examples do not connect to your accounts or run a live scan.
Google Preferred Sources button
If a Preferred Sources link is available on this website, it does not contact Google until you click it. Google then handles the preference through your Google experience under Google's own terms and privacy policy. BuyerSpotter does not receive your Google account details or the sources saved in your Google preferences.
Customer stories
A customer story is published only after we have the person's approved name, role, company, exact quote, stated result, photo, consent date, and publication approval. The story remains hidden until those requirements are met.
Chrome Web Store user data policy
The use of information received from the BuyerSpotter Chrome extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide and improve BuyerSpotter's single purpose (finding and reviewing potential customer requests in the sources you choose). It is not sold, not used for advertising or credit decisions, and not transferred to anyone except the service providers named on this page, as needed to run the product, or when the law requires it.
Deleting your data
Removing the extension deletes its local data. To delete your BuyerSpotter account and the data the account service keeps, email hello@buyerspotter.com from your account address. Paddle keeps transaction records it is legally required to keep.
Contact
Questions about privacy can be sent to hello@buyerspotter.com.
