Privacy Policy

What we collect, why we collect it, who else touches it, and how to get it deleted.

Effective date: TODO: set the date this is published · Operator: TODO: registered company legal name and entity type

Draft — not yet legally reviewed. This document is an unreviewed template. It has not been checked by a lawyer, and the highlighted items below are unresolved. Do not rely on it, and do not treat it as a final agreement.

1. Who we are

Door Pirate is operated by TODO: registered legal name and entity type, of TODO: registered business address. We are the controller of the personal data described here. Privacy questions and requests: TODO: privacy contact email.

2. What we collect

  • Account details — your email address, the full name you enter at signup, whether you opted in to product email, and how you heard about us (the referral-source dropdown).
  • Your password — when you sign up, sign in, or change it, the password you type is sent over an encrypted connection to our server, which passes it straight to our authentication provider (Supabase Auth) and keeps nothing. We do not store it, log it, or write it to our database, and it is never retained after the request that carried it. Supabase Auth stores only a one-way hash, which is what your sign-in is checked against — nobody at Door Pirate or Supabase can read your password back out. We cannot recover it for you; that is why the only route back in is the emailed reset link.
  • Billing details — we store your Stripe customer identifier and your subscription status. Card numbers, expiry dates, and security codes go directly to Stripe and are never received or stored on our systems. That is true of the card form inside Settings → Billing as well: the field is hosted by Stripe and embedded in our page, so what you type there goes from your browser to Stripe without passing through us. Stripe returns only the card brand and last four digits for display.
  • Content you create — saved deals, notes, what-if assumptions, and portfolio records. Portfolio records can include property addresses, unit labels, contract rents, tenant rent portions, housing-agency names, lease dates, and free-text notes.
  • Technical data — server and error logs generated when you use the site, which can include your IP address, browser user agent, requested pages, and timestamps.
  • Cookies — see section 4.

We do not ask for and do not want government identifiers, financial account numbers, health data, or other sensitive categories. Please do not send them to us.

3. Please don't put tenant personal data in the product

The portfolio feature is designed for property economics, not for tenant files. It has no field for a tenant’s name, and the free-text note fields are not intended for personal information about your tenants or applicants — no names, contact details, Social Security numbers, income documentation, immigration status, or household composition.

If you enter such information anyway, you do so as its controller and you are responsible for having a lawful basis to do so. We are not offering the Service as a tenant record system.

4. Cookies

We use a small number of strictly necessary cookies to keep you signed in and to protect the session — the sign-in session itself, plus a short-lived cookie set only while you are completing a password reset, so that step cannot be replayed later. They are required for the site to function and cannot be switched off from within the product; blocking them will prevent you logging in.

As of the effective date we run no advertising, tracking, or third-party analytics cookies. Stripe may set cookies on its own checkout pages under its own policy. TODO: if analytics or advertising tooling is ever added, this section must be rewritten and a consent banner is likely required

5. Why we use it

  • To provide the Service: authenticate you, enforce the subscription gate, and show your saved deals and portfolio.
  • To take payment and manage your subscription, invoices, and renewals.
  • To support you when you contact us.
  • To keep the Service secure and to enforce the acceptable-use rules. As of the effective date this means fixed result caps and pagination limits applied to every request — we do not analyse your activity over time to detect shared credentials or bulk extraction. We reserve the right to add such monitoring, and will update this policy if we do.
  • To send service and billing emails (these are not optional while you have an account), and product or marketing email only if you opted in.
  • To comply with legal, tax, and accounting obligations.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use your portfolio data to advertise to you.

6. Who processes it for us

A small set of outside companies is involved. Except where an entry says otherwise, each is a processor contractually bound to handle data only on our instructions:

  • Supabase — application database and authentication. Our project is hosted in the United States (AWS us-east-2, Ohio).
  • Stripe, Inc. — payment processing, invoicing, and subscription management. Stripe is an independent controller for payment data under its own privacy policy.
  • Vercel, Inc. — application hosting, edge delivery, and request logs.
  • Zillow’s image CDN, Google, and CARTO — listing photographs (Zillow, and Google for a small number of listings whose photograph is a Google Maps image) and map tiles (CARTO). These are not processors acting on our instructions: your browser requests those files from them directly, so they receive your IP address and browser user agent independently of us. See the note at the end of this section.
  • TODO: list the transactional email provider once one is wired up
  • TODO: add any error-monitoring or analytics provider here before enabling it; keep this list complete — it doubles as the subprocessor list

We may also disclose data where legally required, to enforce our terms, or to a successor in a merger or sale of the business (you would be notified).

We do not send our listing-data vendors your account details, your saved deals, or your portfolio. You should know that listing photographs are served directly from Zillow’s image CDN — or, for a small number of listings whose only photograph is a Google Maps image, directly from Google — and map tiles directly from CARTO. Your browser fetches all of these itself, so those companies receive your IP address, your browser user agent, our site as the referring origin, and which photograph or map tile you asked for. We do not control what they do with that information.

7. Third-party listing and agent data

The catalogue is built from third-party and public sources, not from our own observations: for-sale listing data from real-estate data providers (currently a Zillow-derived feed and RentCast), Fair Market Rent figures published by HUD, and geographic boundaries from U.S. Census TIGER files.

Some of that data is business contact information about real people — the name, phone number, email address, brokerage, and website of the listing agent, as supplied by the source. We store and display it so a subscriber can contact the agent about that listing. We did not collect it from those individuals directly, and we do not enrich, score, or resell it.

If you are a listing agent and want your details corrected or removed from our copy, email TODO: privacy contact email with the listing address; we will action it within TODO: response window for agent data removal — e.g. 30 days. Note that our copy will repopulate from the source feed unless corrected upstream as well, and we will tell you which source the record came from so you can do that.

8. How long we keep it

We keep account and content data for as long as your account exists. After deletion we remove or irreversibly anonymise your personal data within TODO: deletion SLA — e.g. 30 days, plus backup rotation, except records we are required to retain: invoices and payment records for tax and accounting purposes (Stripe retains these under its own obligations, typically TODO: confirm the retention period your accountant requires — often 7 years), and security logs for a short rolling window. Encrypted backups age out on their normal rotation.

9. Deleting your data

You have two separate things you can do, and they are not the same:

  • Stop being billed — cancel from Settings → Billing. This ends the subscription; it does not delete your account.
  • Delete your account and data — email TODO: privacy contact email from the address on the account with the subject “Delete my account”. We will verify it is you, cancel any active subscription, and delete your account, saved deals, and portfolio records within the window in section 8. Deletion is permanent and we cannot restore the data afterwards.

TODO: self-serve deletion is not built yet — this is an email-only path. Either build the in-app button or commit to actually monitoring this inbox, because the promise above is binding once published

10. Your rights

Depending on where you live you may have the right to access, correct, delete, or receive a portable copy of your personal data, to object to or restrict certain processing, and to withdraw consent. You can exercise any of these by emailing TODO: privacy contact email. We will not discriminate against you for exercising them.

We record your marketing-email preference at signup, but we do not currently send product or marketing email at all — the only mail the Service sends is account mail from Supabase Auth (confirmations, password resets) and billing receipts from Stripe. If we start sending product or marketing email, every one will carry a one-click unsubscribe link; you can also opt out at any time by emailing us. You cannot opt out of transactional service and billing email while you hold an account.

California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process sensitive personal information for inferring characteristics.

TODO: confirm whether you serve EEA/UK customers. If yes, this policy needs a lawful-basis table, an international-transfer mechanism (SCCs) for the US hosting, and a supervisory-authority complaint route. This draft is written for a US-only customer base.

11. Security

Data is encrypted in transit. Every product read runs through per-user row-level security in the database, so one account cannot read another account’s saved deals or portfolio even if an application-layer check were missed. Access to production data is limited to those who need it.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data we will notify you and any regulator as required by law.

12. Children

The Service is for adults. It is not directed to anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

13. Changes

We may update this policy. Material changes will be notified in the product before they take effect, and the effective date at the top will change.

14. Contact

Privacy questions, access requests, and deletion requests: contact us.