Privacy Policy
Last updated: June 25, 2026
This Privacy Policy describes how PropertySight LLC, an Indiana limited liability company ("PropertySight", "we", "our", or "us"), collects, uses, and shares information when you use the PropertySight mobile application (the "App"). PropertySight is a tool intended for use by U.S. real estate professionals to capture, organize, and act on property leads. We do not independently verify license status.
- Information We Collect
- How We Use Your Information
- Third-Party Service Providers
- Sharing Properties With Other Agents
- Sharing for Legal Reasons
- Skip-Trace and TCPA Compliance
- Data Retention and Sunset
- Your Rights
- Additional Disclosures
- International Data Transfers
- Children's Privacy
- Security
- Changes to This Policy
- Contact Us
1. Information We Collect
1.1 Account information
When you sign in with Google or Apple, we receive your name, email address, and (where provided) profile photo via the OAuth provider. We assign you a unique internal user ID. We do not receive your sign-in password.
We generate a unique referral code on your account and, if you signed up after clicking another user's referral link, we record which user referred you. The referral relationship is used to attribute future referral programs.
1.2 Property data you create
When you scan or save a property, the App stores:
- The property's address, latitude/longitude, and your saved photos
- Notes you write, links you attach, and your activity log entries (timestamped free-text)
- Public-records property data we look up on your behalf (see §3)
- Paid-tier unlocks you purchase (comparable sales, financials, permits, owner intel, contact information)
- Tags / categories you assign
1.3 Skip-trace contact information (paid feature)
When you unlock contact details for a property owner, our server retrieves phone numbers, email addresses, and related identifiers from a licensed data provider. You must affirmatively attest to a lawful basis for the lookup at the moment of unlock — see §6 for details.
We retain the contact data on your account so you do not re-pay for it, and we retain the attestation as a compliance record.
1.4 Location
The App reads your device's GPS only at the moment you initiate a scan, to identify the property in front of you. Location is sent to our server with the scan request and is stored with the resulting find. The location reading is precise (GPS-grade) when your device permission allows; you can revoke the App's location permission in your OS settings, in which case the manual address-entry / map-pin entry methods still work. We do not run background location tracking.
1.5 Purchase information
Subscriptions are processed by Apple App Store / Google Play and managed via RevenueCat. Credit-pack purchases are processed by Apple or Google. We receive a purchase token to verify the transaction and credit your account; we do not see or store your payment card details.
1.6 Usage and diagnostic data
We collect basic technical information (app version, OS version, error logs, server-side request metrics) to keep the App working. Diagnostic logs that include user-submitted addresses are stored with the street and ZIP hashed (not in plaintext) so logs can be correlated without exposing the underlying address.
PropertySight does not intentionally collect special-category personal information (health, biometric, genetic, racial/ethnic, religious, political, or trade-union data). Public-records data from licensed providers may incidentally include demographic indicators tied to property ownership; we do not infer or aggregate such indicators into user profiles.
1.7 Photos and incidental content
You are responsible for the lawful capture of any photo you upload. The App is not intended for surveillance use. When you photograph a property, please avoid capturing identifiable third parties, license plates, or minors — incidental capture may occur and you should review/crop before saving. Photos are stored on Firebase Storage and accessible only to your account (other users cannot read your photo URLs). See §7 for storage caps and retention.
2. How We Use Your Information
- To deliver the App's core features: property scanning, finds, activity log, search, photo gallery, sharing, and exports.
- To manage your subscription, credit balance, and in-app purchases.
- To process and deliver paid-tier unlocks (comps, financials, permits, owner intel, contact information) on your behalf.
- To maintain compliance records for skip-trace lookups (§6).
- To send you account notices (e.g., security or service-impacting updates). We do not send marketing emails.
- To diagnose technical problems, prevent abuse, and improve the App.
- To honor your data-rights requests (access, deletion, correction) under applicable U.S. state and international laws.
3. Third-Party Service Providers
We use the following providers to operate the App. Each processes data on our behalf under its own privacy and security commitments:
- Google Firebase — authentication (Firebase Auth + Google/Apple Sign-In), Firestore (your saved finds and account data), Firebase Storage (your photos and OAuth-provided profile picture). We do not use Firebase Analytics, Crashlytics, or Remote Config.
- Railway — server hosting (United States).
- BatchData — public-records property data and skip-trace contact data. We transmit property-related query information (address components) rather than profile information about you, but property queries may themselves be considered personal information under some state privacy laws when tied to your account ID for billing/audit purposes.
- Google Maps Platform — geocoding, address autocomplete, and Street View tile imagery. Persistent identifiers (a per-installation API key) are sent with each request.
- Google Sunroof, FEMA, and other public/commercial data sources — to enrich properties with solar potential, flood-zone, and similar context. We may add, remove, or change enrichment providers without separate notice; the categories of data they receive (property address only) do not change.
- Apple App Store / Google Play — processing in-app purchases.
- RevenueCat — subscription state management.
Property and enrichment data from third-party providers may be incomplete, outdated, or inaccurate. You should independently verify any data point relied upon for business decisions.
We do not sell your personal information. We also do not share your personal information for cross-context behavioral advertising as defined by U.S. state privacy laws (including the California Consumer Privacy Act as amended by the CPRA).
4. Sharing Properties With Other Agents
You can generate a one-time-use share link for a saved find. When another PropertySight user opens that link and accepts the share, a copy of the find is created on their account.
Shared content includes the address, our cached public-records property data, your enrichment data, and optionally your photos and links if you explicitly include them. Your private notes and your activity log are never shared. Paid-tier unlocks (comps, financials, permits, owner intel, contact information) are also never shared — the recipient must pay to unlock those themselves.
Each accepted share writes an attribution note (currently rendered as "Shared by another agent on YYYY-MM-DD") and a sharedFrom record containing the sender's internal account ID and a timestamp to the recipient's scan, so the recipient can see where the find came from. The sender's display name is not transferred unless the sender has explicitly set one (a feature currently disabled in the App).
Share links are designed to expire after 30 days and to be accepted by a single recipient. The sharedFrom record we write to the recipient's scan is an internal account identifier; while we do not display your account ID to the recipient, the existence of the record is operational metadata used to attribute the find and to support future audit needs.
5. Sharing for Legal Reasons
We may disclose information if required by law, in response to valid legal process, or to protect the rights, property, or safety of our users, our company, or the public.
6. Skip-Trace and TCPA Compliance
U.S. federal law (the Telephone Consumer Protection Act, "TCPA") and various state laws restrict the circumstances under which consumer phone numbers may be obtained, retained, or contacted for marketing purposes. When you initiate a skip-trace contact unlock in PropertySight, you must attest to one of the following lawful bases:
- Established business relationship with the property owner;
- Express consent previously obtained from the property owner; or
- Public-records use only — you intend to use the data for property-records research, not for telemarketing or text-message campaigns.
We record the attestation, your account ID, and the timestamp of each contact unlock as a compliance ledger. You are solely responsible for ensuring that your use of contact information complies with the TCPA, the Telemarketing Sales Rule, the National Do Not Call Registry, and any applicable state laws. PropertySight is not a service for sending automated calls or text messages.
Prohibited uses. You may not use PropertySight or any data accessed through it to:
- Conduct mass marketing, robocalling, automated calling, SMS marketing, or any other communications prohibited by the TCPA, the Telemarketing Sales Rule, the National Do Not Call Registry, or applicable state law.
- Build, train, or augment your own consumer-data product using PropertySight contact data.
- Resell, redistribute, or otherwise transfer PropertySight contact data to a third party.
- Initiate communications based on PropertySight contact data without a lawful basis (an established business relationship, express consent, or a recognized exemption).
We reserve the right to suspend or terminate accounts engaged in suspected unlawful contact activity, and we may decline to provide contact-data unlocks to accounts with a history of attestation patterns inconsistent with lawful use. Contact data may be incomplete, outdated, or inaccurate; you must independently verify any phone number, email address, or other identifier before initiating communication. PropertySight is a research tool, not a dialer or marketing automation platform.
7. Data Retention and Sunset
We retain different categories of data for different periods. Active subscribers keep their data for the lifetime of the account. If you cancel your subscription, or if you create an account but never subscribe, your data is governed by the sunset schedule described in §7.1 below — a long retention window followed by an in-app warning period and then permanent deletion.
- Your saved finds, notes, links, activity entries, tags, and paid-tier unlocks you have purchased: retained for as long as your account is active. While you are an active subscriber, retention is tied to your account lifecycle. After your subscription lapses or if you never subscribe, retention follows the sunset schedule in §7.1. PropertySight is designed as a long-term prospecting log; we do not impose an absolute calendar window on the data of active subscribers. Closing your account at any time triggers immediate deletion per §8.
- Skip-trace contact data: retained on the same schedule as your finds, so you do not re-pay for the same lookup while your account is active. We do not automatically purge skip-trace contact data outside the sunset schedule. Each contact record is timestamped at the moment of lookup, and the age of the record is visible in the App so you can judge freshness before relying on the data. You remain responsible under §6 for re-verifying contact information before initiating communication. You can ask us to delete specific contact records at any time via §14.
- Your credit balance: retained for as long as your account is active and is removed when the account is deleted (manually or via sunset). The credit-transaction ledger may be retained in anonymized form beyond the sunset window for billing and audit purposes required by law.
- Photos: stored on Firebase Storage for the lifetime of your account, subject to per-plan storage caps (currently 2 GB on Basic, 8 GB on Pro, plus any storage add-ons you have purchased). When you exceed your cap, your oldest find's photos are removed first to bring you back under the cap; the find itself is preserved. If you downgrade from Pro to Basic and end up over the new Basic cap, you get a 30-day grace period before eviction begins. Account-level deletion (manual via §8 or via the sunset schedule in §7.1) removes all photos as part of the account deletion.
- Cached with short TTLs: third-party property and enrichment API responses, geocoding results, and Street View tile metadata are cached briefly so we don't re-charge you and don't re-call the upstream provider. These caches are refreshed on subsequent scans.
- One-time-use, auto-cleaned: share tokens expire after 30 days and are auto-deleted by a nightly job. RevenueCat webhook deduplication records are deleted after 30 days.
7.1 Account Sunset for Non-Subscribers
If you cancel your subscription, or if you never subscribe, we retain your saved finds, notes, photos, and account data on the following schedule:
- Former subscribers: 36 months from the date your subscription ended. Re-subscribing at any point during this window resets the retention clock; on the next lapse, a fresh 36-month window begins.
- Trial-only users (you created an account but never subscribed): 6 months from the date you created your account. Subscribing during this window converts your account to the subscriber retention model above.
We notify you before your data is deleted, so you have the chance to re-subscribe and preserve what you've built:
- Former subscribers: a persistent in-app banner appears on every app launch during the last 6 months of your retention window, showing the months remaining and a Subscribe button. In the final 30 days, the banner color shifts to red. We may also send an email reminder to the address associated with your Google sign-in during the final 30 days.
- Trial-only users: a persistent in-app banner appears on every app launch during the final 30 days of your retention window. Trial-only users do not receive email reminders.
At the end of the retention window we permanently delete: your saved finds; notes; photos (all of them, regardless of how recent); activity log; profile information; server-side cached property data tied to your finds; and your credit balance. The credit-transaction ledger may be retained in anonymized form for billing and audit purposes required by law (see §7 bullet on credit balance).
What survives the sunset. Your Google sign-in record is not deleted by the sunset process. If you choose to return to PropertySight in the future, you can sign in with the same Google account and create a fresh account from scratch — but your prior saved finds, photos, and activity will not be recoverable. This is different from manual account deletion in §8, which removes the sign-in record as well.
A minimal re-use marker survives the sunset. Because the sunset process preserves your sign-in record (above), the one-time welcome benefits we grant new accounts — your free trial scans and your signup credits — could otherwise be claimed repeatedly by letting an account lapse and signing back in. To prevent that, when a dormant account is sunset-deleted we retain a single permanent, irreversible marker derived from your sign-in identifier (a salted one-way hash — not your actual identifier, name, email, or any other personal information). The marker records only that the one-time welcome benefits were already granted to that identity; it contains no finds, notes, photos, contact data, or profile information, and it cannot be reversed to recover your identifier. If you return and create a fresh account with the same Google sign-in, your account works normally but those one-time welcome benefits are not granted a second time. This marker is written only by the sunset process; manual account deletion under §8 removes your sign-in record entirely, so no such marker is created on that path.
Re-subscribing cancels a pending sunset. If you re-subscribe at any point — including during the final-month warning phase — the scheduled deletion is cancelled and your full retention is restored. The Subscribe button on the in-app warning banner opens the subscription paywall directly.
Immediate deletion remains available. You can delete your account immediately at any time from More > Delete account; this bypasses the sunset schedule and removes both your data and your sign-in record. See §8.
7.2 Skip-Trace Compliance Ledger (Legal Exception to Deletion)
When you initiate a skip-trace owner lookup, the App requires you to attest to a lawful basis under §6 (e.g., public-records-only, an existing business relationship, or express consent). The App records that attestation — capturing your selected lawful basis and the timestamp — before we issue the underlying contact-data request, so the record exists even if the lookup itself fails. This record is the App's defensive evidence in the event of a Telephone Consumer Protection Act ("TCPA") claim or analogous state-law claim.
When your account is deleted (either by sunset under §7.1 or by your request under §8), each skip-trace attestation is anonymized and moved to a separate compliance ledger before the rest of your account data is removed. The anonymized record preserves only:
- The lawful basis you attested to;
- The timestamp of the attestation;
- A non-reversible hash of the scan identifier (no address, no phone number, no user identifier).
Anonymized ledger entries are retained for four (4) years from the timestamp of the original attestation, matching the federal TCPA statute of limitations (28 U.S.C. § 1658) and corresponding state mini-TCPA windows. A daily job automatically deletes entries older than four years. Apart from the minimal, irreversible re-use marker described in §7.1 (which carries no personal information), this anonymized compliance ledger is the only category of data that survives account deletion, and it does so only in anonymized form for legal-defense purposes.
8. Your Rights
You can exercise the following rights directly in the App:
- Access / portability. Export your activity log and find data via the "Export" actions on the Finds tab and on each find detail.
- Correction. Edit any find's notes, links, or tags directly in the App.
- Deletion of a single find. Use the delete action on each find.
- Deletion of your account. Use More > Delete account. This permanently removes your finds, activity, photos, profile, and credit balance. The Firebase Auth user (your Google sign-in record for PropertySight) is also deleted, so the account no longer exists. Allow up to 30 days for the deletion to propagate through backups. This path is immediate and bypasses the sunset schedule in §7.1; use this if you want to leave PropertySight entirely. (The sunset schedule in §7.1 is the alternative auto-deletion path for accounts that simply go dormant; it preserves your sign-in record so you can return later, but does not preserve your data.) Exception: any skip-trace attestation records associated with your account are not removed by either path; they are anonymized and retained under §7.2 for up to four years for legal-defense purposes, after which they are also deleted.
To request access to data not exposed in the App, to ask questions about how we process your data, or to exercise rights granted by your state's privacy law, contact us at the address in §14. We will not discriminate against you for exercising a privacy right. See §9.2 for the full list of statutory rights, response times, and appeal mechanics by jurisdiction; see §9.1 for the structured map of personal-information categories we collect.
9. Additional Disclosures
9.1 Personal Information Categories Collected (U.S. State Law Disclosure)
U.S. state privacy laws (including the California Consumer Privacy Act as amended by the CPRA) require us to describe the categories of personal information we collect using their enumerated taxonomy. The table below maps that taxonomy onto what PropertySight actually collects, what we use it for, and which service providers receive it. We do not sell personal information and we do not share it for cross-context behavioral advertising.
| Category (CCPA §1798.140) | What We Collect | Source | Business Purpose | Disclosed to Service Providers |
|---|---|---|---|---|
| A. Identifiers | Name, email, profile photo (via OAuth), internal user ID, referral code, referrer user ID (if any), IP address (server logs) | From you; from your Google or Apple sign-in; from your device | Account creation, authentication, security, audit logging | Firebase (Auth, Firestore), Railway (server) |
| B. Customer records (Cal. Civ. Code §1798.80(e)) | Name, email address | From you; from your OAuth provider | Account management, billing receipts, service notices | Firebase, RevenueCat |
| D. Commercial information | Subscription state, credit-pack purchases, paid-feature unlocks (comps, financials, permits, owner intel, contact information) | From your in-app purchases via Apple / Google | Billing, paid-feature delivery, refund processing, audit | RevenueCat, Apple App Store, Google Play, Firebase, Railway |
| F. Internet or other electronic network activity | App version, OS version, request logs, error logs, server-side metrics, hashed addresses in diagnostic logs | From your device; from your interactions with the App | Operating the App, security, debugging, abuse prevention | Firebase, Railway |
| G. Geolocation data (treated as Sensitive Personal Information under CPRA) | Precise GPS coordinates at the moment you initiate a scan | From your device, only when you tap Scan | Identify the property in front of you; attach lat/long to the saved find; geocoding and Street View imagery for that property | BatchData (address only, derived from lat/long), Google Maps Platform |
| H. Audio, electronic, visual, thermal, olfactory, or similar information | Photos you capture or import of properties | From your device, when you choose to upload | Display in your finds; optional inclusion in shares you create | Firebase Storage |
| I. Professional or employment-related information | Brokerage name, license number, and similar fields if you choose to enter them in your profile | From you, voluntarily | Display on shared finds where you choose to include them | Firebase |
We do not knowingly collect categories C (protected classifications such as race, religion, age), E (biometric information), J (non-public education information), or K (inferences drawn to create a profile). Although BatchData and other public-records providers may incidentally return demographic or financial indicators tied to property ownership, we do not aggregate such indicators into user profiles.
Sensitive personal information (CPRA §1798.140(ae)). Precise geolocation is the only category of sensitive personal information PropertySight collects. We use it solely to identify the property at your scan location and to support paid-feature lookups you initiate. We do not use it to infer characteristics about you. California residents may request that we limit the use of this sensitive PI to those purposes (see §9.2).
9.2 Your Rights Under U.S. State Privacy Laws
The following rights apply, in some form, to residents of every U.S. state with a comprehensive privacy statute currently in force or scheduled to take effect within the next twelve months. To exercise any right, contact us at privacy@propertysightapp.com.
- Right to know / access the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the recipients.
- Right to receive a portable copy of your personal information in a structured, machine-readable format.
- Right to delete personal information we have collected from you, subject to legally permitted exceptions (e.g., maintaining a TCPA-attestation compliance ledger required by law).
- Right to correct inaccurate personal information. Utah and Iowa do not require a correction right by statute; we will nonetheless honor correction requests from residents of any U.S. state on a best-effort basis.
- Right to opt out of "sale" or "sharing" of personal information. PropertySight does not sell or share personal information for cross-context behavioral advertising; this right is satisfied by default.
- Right to opt out of targeted advertising. Same — we do not engage in targeted advertising.
- Right to limit the use and disclosure of sensitive personal information (California only). Submit a request to limit our use of your precise geolocation to the purposes described in §9.1.
- Right to non-discrimination for exercising any right above.
- Right to appeal a denied request. Most states require an appeal mechanism; Utah and Iowa do not. We accept appeals from all U.S. residents — reply to our denial email and we will respond within the time required by your state's law (typically 45 to 60 days).
Response time. We respond to verifiable requests within 45 days of receipt and may extend by an additional 45 days where reasonably necessary and where permitted by your state's law. Iowa residents: up to 90 days under §715D.4 of the Iowa Consumer Data Protection Act, extendable by 45.
Authorized agents. California, Colorado, and Oregon residents may submit requests through an authorized agent who provides written permission and proof of the agent's authority.
Universal opt-out signals. We honor browser-level universal opt-out preferences (such as the Global Privacy Control signal) where they are legally recognized. Because PropertySight does not engage in sale, sharing, or targeted advertising, these signals have no practical effect on our processing today.
State-specific additions.
- California. You may also request a list of the categories of personal information disclosed to third parties for a business purpose in the preceding 12 months. We have made disclosures only to the service providers listed in §3 and §9.1.
- Colorado, Connecticut, Oregon, Texas. If we engage in profiling that has legal or similarly significant effects, you may opt out — we do not engage in such profiling today.
- Oregon. You may obtain a list of the specific third parties to whom we have disclosed your personal information; the list mirrors §3 and §9.1.
- Maryland. Our practices are subject to data-minimization principles; we collect only what is necessary to operate the App's features that you use.
- Minnesota. You may question the result of consequential automated decision-making. We do not engage in automated decision-making with legal or similarly significant effects today.
9.3 Legal Bases for EEA / UK / Swiss Visitors
PropertySight is intended for U.S. real estate agents. If you nonetheless access the App from the European Economic Area, United Kingdom, or Switzerland, we process your personal data under the following legal bases under the GDPR (or UK / Swiss equivalents):
- Contract performance — to deliver the App's features that you have requested.
- Legitimate interests — to maintain security, prevent fraud, run diagnostic logs, and improve the App.
- Legal obligation — to retain certain compliance records (e.g., TCPA attestations, IAP receipts).
- Consent — for any optional processing where you have explicitly opted in. You may withdraw consent at any time.
10. International Data Transfers
Our servers are operated in the United States. If you access the App from outside the U.S., your data will be transferred to and processed in the U.S. Where required, we rely on Standard Contractual Clauses (SCCs) or equivalent mechanisms with our subprocessors. We acknowledge that U.S. data may, under specific legal-process scenarios, be subject to government-access requests; we do not voluntarily disclose user data and we comply with requests only when legally required (see §5). PropertySight is intended for licensed U.S. real estate agents, and we do not market the App to EEA/UK/Swiss consumers.
11. Children's Privacy
PropertySight is a professional tool for licensed real estate agents and is intended for use by adults engaged in U.S. real estate. The App is not directed to anyone under 18 (under 16 in the EEA). We do not knowingly collect personal information from anyone under those ages. If you believe we have inadvertently collected such information, contact us and we will delete it.
12. Security
We use commercially reasonable administrative, technical, and organizational safeguards to protect your data:
- All traffic between the App and our servers is encrypted with HTTPS / TLS 1.2 or later.
- Authentication is handled by Firebase Auth (Google, Apple); we never see your sign-in password.
- Data at rest in Firestore and Firebase Storage is encrypted by Google's underlying infrastructure (AES-256 envelope encryption).
- Server access is restricted to engineering personnel under role-based controls; access is logged.
- Each user's data is isolated at the Firestore-security-rules and Storage-rules layer — other users cannot read your finds, photos, or account profile.
No system is perfectly secure. If we determine that a security incident has materially affected your personal information, we will notify you consistent with applicable law and after we have reasonably determined the scope, cause, and impact of the incident. We do not currently operate a public bug-bounty program; security researchers can email §14 to coordinate disclosure.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page, by an in-App notice on the next launch, and where we have a current email address on file, by an email to the address you signed in with. Continued use of the App after the effective date of a material change constitutes acceptance of the revised policy.
14. Contact Us
For the purposes of U.S. state privacy laws, PropertySight acts as a business (CCPA terminology) with respect to your account data; our subprocessors (Firebase, Railway, BatchData, Google Maps, RevenueCat, etc.) act as service providers. For the purposes of GDPR, where applicable, we are the data controller for account and platform data, and those subprocessors are our processors. You are independently responsible for your downstream use of data obtained through the App.
If you have questions about this Privacy Policy or wish to exercise any of the rights described above, please contact us:
PropertySight LLC
Indiana, United States
Email: privacy@propertysightapp.com
When you use the in-app Contact Support or Send Feedback buttons, the email's subject line is pre-filled with the app version and OS version of your device so we can help you faster. You may edit or remove this before sending.