Privacy Policy
Your privacy is important to us
Effective Date: April 7, 2026 | Last Updated: April 7, 2026
Table of Contents
1. Introduction
Welcome to DealFlow ("Company," "we," "our," or "us"). DealFlow operates the website located at dealflow.app and any related mobile applications, services, and tools (collectively, the "Platform").
We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Platform, create an account, use our services, or interact with us in any way.
Please read this Privacy Policy carefully. By accessing or using our Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, please do not use our Platform.
This Privacy Policy applies to all information collected through our Platform, as well as any related services, sales, marketing, or events (collectively referred to as the "Services").
2. Information We Collect
We collect information in various ways depending on how you interact with our Platform:
2.1 Personal Information You Provide
When you register for an account, use our services, or contact us, you may provide:
- Identity Information: First name, last name, username, and similar identifiers
- Contact Information: Email address, phone number, mailing address
- Account Credentials: Password and security questions
- Profile Information: Profile photo, bio, company name, years of experience, professional licenses
- Professional Details: States and cities you serve, areas of expertise, certifications
- Financial Information: Proof of funds documentation, financing preferences, investment ranges
- Property Information: Addresses, prices, ARV estimates, property photos, and deal details you post
- Communication Data: Messages, inquiries, and correspondence through our Platform
2.2 Information Collected Automatically
When you access or use our Platform, we automatically collect:
- Device Information: Device type, operating system, unique device identifiers, browser type and version
- Log Data: IP address, access times, pages viewed, time spent on pages, referring URLs
- Location Data: General geographic location based on IP address
- Usage Data: Features used, search queries, deals viewed, actions taken on the Platform
- Performance Data: Page load times, errors, and other technical metrics
2.3 Information from Third Parties
We may receive information about you from:
- Social Media Platforms: If you connect your social media accounts
- Other Users: When other users provide your information (e.g., referrals)
- Public Sources: Property records, business registrations, professional licenses
- Business Partners: Joint marketing partners, affiliate networks
3. How We Collect Information
We collect information through the following methods:
- Direct Collection: When you create an account, fill out forms, post deals, or communicate with us
- Automated Technologies: Through cookies, web beacons, pixels, and similar tracking technologies
- Third-Party Sources: From partners, public databases, and social media platforms
- User Interactions: When you interact with other users, view deals, or use Platform features
4. How We Use Your Information
We use your information for the following purposes:
Service Delivery
- Create and manage your account
- Process and display your deal listings
- Connect you with buyers or wholesalers
- Facilitate communications between users
- Provide customer support
Platform Improvement
- Analyze usage patterns and trends
- Develop new features and services
- Optimize Platform performance
- Conduct research and analytics
- Test new functionalities
Communication
- Send account notifications
- Deliver marketing communications (with consent)
- Respond to inquiries and requests
- Send deal alerts and updates
- Provide transaction confirmations
Security & Compliance
- Detect and prevent fraud
- Enforce our Terms of Service
- Comply with legal obligations
- Protect user safety and rights
- Investigate suspicious activities
5. Information Sharing and Disclosure
We may share your information in the following circumstances:
5.1 With Other Users
Your public profile information, deal listings, and buyer criteria may be visible to other registered users based on your privacy settings. When you post a deal or create a buyer profile, other users can view the information you choose to make public.
5.2 Service Providers
We share information with third-party vendors who perform services on our behalf, including:
- Cloud hosting and data storage providers (e.g., Vercel, Supabase)
- Email service providers for transactional and marketing emails
- Analytics providers to understand Platform usage
- Customer support and communication tools
- Payment processors (if applicable)
5.3 Legal Requirements
We may disclose your information when required by law, regulation, legal process, or governmental request, including:
- To comply with subpoenas, court orders, or legal processes
- To protect our rights, privacy, safety, or property
- To enforce our Terms of Service
- To protect against legal liability
- To respond to lawful requests by public authorities
5.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Platform of any change in ownership or uses of your personal information.
5.5 With Your Consent
We may share your information for other purposes with your explicit consent or at your direction.
What We Don't Do
- We do NOT sell your personal information to third parties
- We do NOT share your information with advertisers for their direct marketing purposes
- We do NOT share your contact information with other users without your permission
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
To determine the appropriate retention period, we consider:
- The nature and sensitivity of the information
- The potential risk of harm from unauthorized use or disclosure
- The purposes for which we process your information
- Applicable legal requirements
When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain certain information for legal or compliance purposes.
7. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
Our Security Measures Include:
- Encryption: All data transmitted between your browser and our servers is encrypted using TLS/SSL
- Secure Storage: Personal data is stored in encrypted databases with restricted access
- Access Controls: Role-based access controls limit who can access your information
- Password Security: Passwords are hashed using industry-standard algorithms
- Regular Audits: We conduct regular security assessments and vulnerability testing
- Employee Training: Our team receives regular security and privacy training
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security. You are responsible for maintaining the confidentiality of your account credentials.
8. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
Right to Access
Request a copy of the personal information we hold about you
Right to Rectification
Request correction of inaccurate or incomplete personal information
Right to Erasure
Request deletion of your personal information (with certain exceptions)
Right to Data Portability
Receive your data in a structured, commonly used format
Right to Object
Object to processing of your personal information for certain purposes
Right to Withdraw Consent
Withdraw consent where we rely on consent to process your information
To exercise these rights, please contact us at dealflow.support@gmail.com. We will respond to your request within 30 days.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect and track information about your use of our Platform.
Types of Cookies We Use:
- Essential Cookies:
Required for the Platform to function properly (e.g., authentication, security)
- Functional Cookies:
Remember your preferences and settings (e.g., language, theme)
- Analytics Cookies:
Help us understand how you use our Platform (e.g., Vercel Analytics)
- Performance Cookies:
Monitor Platform performance and speed (e.g., Speed Insights)
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, disabling cookies may affect your ability to use certain features of our Platform.
10. Third-Party Services
Our Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you use.
Third-party services we use include:
- Supabase: Database and authentication services
- Vercel: Hosting and analytics
- Resend: Transactional email delivery
- Stripe: Payment processing and subscription management - processes your payment information securely
- Sentry: Error monitoring and performance tracking - collects technical error data to improve Platform stability
- Upstash Redis: Caching and rate limiting services - improves Platform performance and security
Payment Information
When you subscribe to DealFlow, your payment information is processed directly by Stripe. We do not store your full credit card number, CVV, or other sensitive payment details on our servers. Stripe maintains PCI-DSS compliance and uses industry-standard encryption to protect your financial information. For more information, please review Stripe's Privacy Policy.
11. Children's Privacy
Our Platform is not intended for children under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at dealflow.support@gmail.com.
If we discover that we have collected personal information from a child under 18, we will take steps to delete that information as quickly as possible.
12. International Data Transfers
Your information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction.
If you are located outside the United States and choose to provide information to us, please note that we transfer the data to the United States and process it there. Your consent to this Privacy Policy followed by your submission of information represents your agreement to that transfer.
13. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the sale of your personal information (note: we do not sell personal information)
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
To exercise your California privacy rights, please contact us at dealflow.support@gmail.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email (if you have an account)
- Display a prominent notice on our Platform
We encourage you to review this Privacy Policy periodically to stay informed about our information practices.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
DealFlow Privacy Team
Email: dealflow.support@gmail.com
General Inquiries: dealflow.support@gmail.com
We will respond to your inquiry within 30 business days.
© 2026 DealFlow. All rights reserved.
