Privacy Policy
Last updated: July 21, 2026
1. Data We Collect
We collect the following data when you use REIT Stack:
- Account and profile data: Email address, display name, authentication-provider identifiers, and optional profile details such as phone number, LinkedIn URL, domicile, preferred currency, and markets of interest.
- Research workspace data: Saved screens and comparisons, watchlists, reviews, theses, notes, portfolio positions and transactions, course progress, alert read state, and other settings or free text you choose to save.
- Subscription data:Subscription status, plan, billing cycle, Stripe identifiers, and entitlement history. Card and bank details are collected and processed by Stripe and do not pass through REIT Stack's application database.
- Newsletter data: Email address, market interests, subscription status, and subscribe, confirmation, or unsubscribe timestamps where available.
- Contact and sales inquiries: Your name, email address, company, team size, and the content of your message when you submit a form on our contact, contact-sales, or enterprise pages. We also record the kind of inquiry (for example: support, bug report, data discrepancy, or privacy request) so we can route it. These records are retained for up to 24 months after your inquiry is resolved (see Data Retention below).
- Q&A data: Questions you submit, model responses, the REIT and source scope used for the answer, and usage and request records needed to operate quotas, security controls, and conversation history.
- Usage, security, and diagnostics: Page views (including route or URL data), low-cardinality product events, last-active timestamps, feature-use counts, request and security metadata, and scrubbed error or performance diagnostics. Our custom Umami event-property contract excludes names, email addresses, user IDs, portfolio values, and user-entered free text. Pageview URLs and technical requests can still contain or reveal identifiers, and hosting and security providers can receive technical data such as an IP address.
- Owner-notification records: We create internal delivery records for operational alerts. Depending on the event, these can contain account or subscriber email addresses, billing or subscription status, operational errors, and contact-inquiry data described below. The delivery payload is erased after delivery reaches a terminal state or, if still unfinished, after 24 months; limited delivery metadata remains.
- Owner-assisted response records:For inquiries categorized as general support, consulting, bug reports, or data discrepancies and explicitly reviewed by an authorized operator as eligible, we can store an AI-generated reply draft, the owner's approval or rejection, delivery identifiers, and related audit timestamps. These records are linked to the inquiry. Unreviewed inquiries and inquiries categorized as privacy/legal, copyright/IP, or unclassified are excluded from this remote drafting flow. We also use an automated screen to block detected sensitive language.
2. How We Use Your Data
- Provide, secure, and personalize the REIT screening, research, portfolio, and Q&A services.
- Process payments and manage subscriptions via Stripe.
- Send transactional emails (account confirmation, password reset) via Supabase Auth.
- Send newsletter emails via Beehiiv if you subscribe, and record your unsubscribe choice.
- Respond to contact, support, and sales inquiries you send us.
- Alert the owner to account, billing, newsletter, content, pipeline, and inquiry events, and prepare daily or weekly operational reports.
- Help the owner draft and, only after the required owner approval, send a response to an eligible contact inquiry.
- Measure product performance, diagnose errors, prevent abuse, and improve the service.
3. Why We Process Your Data
Depending on the service you use and the law that applies, we process data to provide a service you requested or perform our agreement with you, with your consent (including newsletter marketing), for legitimate business purposes such as support, security, billing, and service improvement, and to meet legal obligations. You can unsubscribe from marketing at any time.
4. Service Providers and Recipients
We use the following services to operate REIT Stack:
- Supabase (database, authentication, and authentication email delivery). Privacy policy.
- Google and LinkedIn (optional sign-in providers) — if you choose one of these methods, that provider processes the authentication request and supplies account information to Supabase under its own policy. Google privacy policy; LinkedIn privacy policy.
- Stripe (payment processing and subscription management). Stripe receives billing and payment information; REIT Stack stores the resulting customer, subscription, and entitlement state. Privacy policy.
- Beehiiv (newsletter delivery) — receives your email address and subscription status if you opt in to the newsletter. Privacy policy.
- Cloudflare (hosting, content delivery, and bot protection) — requests to REIT Stack pass through Cloudflare. Forms use Cloudflare Turnstile; the verification request includes a challenge token and an idempotency identifier, while the form message itself is not sent to Turnstile. Cloudflare can process network data, including IP addresses, as the hosting and security provider. Privacy policy.
- Umami Analytics (cookieless product and traffic analytics). Custom event properties are restricted and exclude names, email addresses, user IDs, portfolio values, and user-entered free text. Pageview URL data and technical request metadata are also processed. Privacy policy.
- Sentry(error and performance monitoring). REIT Stack disables Sentry's default PII collection and scrubs request headers, cookies, email addresses, tokens, and common free-text fields before sending events; a pseudonymous account ID can be retained for diagnosis. Privacy policy.
- Q&A model provider(currently configured to use DeepSeek by default) — receives the question you submit and the REIT source context assembled to answer it. Do not put unnecessary personal or confidential information in a Q&A question. DeepSeek privacy policy.
- Anthropic Claude Code (owner-assisted inquiry replies) — when the owner requests a substantive response to an inquiry categorized as general support, consulting, a bug report, or a data discrepancy, Anthropic receives the inquiry and its relevant CRM history to generate a draft only after an authorized operator has reviewed and marked that exact current context as AI-eligible. The owner must separately approve the exact draft before it can be sent. Unreviewed inquiries and inquiries categorized as privacy/legal, copyright/IP, or unclassified are excluded; an automated screen also blocks detected sensitive language. Processing is subject to the configured Claude account and its data-use settings. Do not include unnecessary personal or confidential information in an inquiry. Anthropic Privacy Center.
- Telegram(owner alerts and approvals) — receives account, billing, newsletter, content, pipeline, and digest notifications. General-support, consulting, bug-report, and data-discrepancy inquiries can include the sender's name, email, company, team size, role, and message when full-content alerts are enabled. Inquiries categorized as privacy/legal, copyright/IP, or unclassified, plus messages detected by our sensitive-language screen, use a content-free Telegram alert; their complete submission remains in REIT Stack's CRM under its lead-retention rule and can remain in the internal delivery payload until that payload is erased. Telegram can also receive an AI-generated draft for an eligible inquiry so the owner can approve or reject it. Telegram groups are cloud chats and are not end-to-end encrypted. Privacy policy.
- Google Gmail (configured owner notification inbox and inquiry replies) — can receive the same enabled notification categories as Telegram. After the required approval, Gmail can also send a response to an eligible inquiry address from a verified REIT Stack alias. Privacy policy.
5. Cookies
REIT Stack uses authentication and security-related cookies or similar technologies needed to operate the service. Our Umami integration is cookieless, and we do not use advertising or cross-site marketing cookies. Third-party payment or security services may apply their own necessary technologies under their policies.
6. Data Retention
- Account and research-workspace data is generally retained while your account is active and until a deletion request is processed, subject to records we must retain for legal, security, billing, or audit purposes.
- Billing and transaction records are retained as needed for subscription administration, accounting, dispute handling, and applicable legal obligations.
- Unsubscribing marks the local newsletter record and Beehiiv subscription inactive. We retain the unsubscribe record so we can honour the choice and operate the list.
- Closed contact and sales-inquiry records — including message content and internal CRM notes — are deleted after 24 months. Reopened or unresolved inquiries remain active until they are closed.
- Q&A conversation messages can be deleted from the applicable REIT conversation. Limited usage, security, or audit records can remain after a conversation is deleted.
- Owner-notification payloads are erased when all configured delivery channels reach a terminal state, or after a 24-month ceiling for an unfinished delivery. Limited delivery metadata and copies already sent to Telegram or Gmail have separate operational and provider-account retention; they are not automatically deleted when the primary CRM or account record is deleted.
- Owner-assisted response records linked to a contact inquiry are deleted when that inquiry is deleted under the lead-retention rule. Copies already processed by Anthropic, Telegram, Google, or the recipient's email provider follow those providers' and account settings and cannot be recalled by deleting the CRM record.
- Analytics and error-monitoring retention follows the settings and terms of the configured Umami and Sentry accounts.
7. Your Rights
Depending on where you live and the law that applies, you may have rights to:
- Access: Request a copy of your personal data.
- Correction: Update supported profile fields in account settings, or ask us to correct other inaccurate data.
- Deletion:Delete individual Q&A conversations in the product, or request deletion of your account and associated data through our contact form.
- Portability: Download an export of available profile and research-workspace data from your profile page. Contact us if you need a broader copy.
- Consent and objection: Unsubscribe from newsletters using the link in an email, withdraw consent where processing depends on it, or object to or request restriction of certain processing where applicable.
- Complaint: Contact us first, and complain to an applicable privacy regulator if you believe your rights were not respected.
8. International Transfers
The providers listed above operate infrastructure and support services in multiple jurisdictions, so your data may be processed outside your province or country and may be subject to the laws of those places. This includes global Cloudflare delivery and the locations used by Supabase, Stripe, Beehiiv, Umami, Sentry, Telegram, Google, LinkedIn, Anthropic, and the configured Q&A model provider. Contact us if you need information about transfers or safeguards relevant to your data.
9. Security
We use access controls, encrypted network transport, restricted server credentials, provider security settings, error-data scrubbing, and authenticated owner-notification routes. Telegram alerts also request Telegram's protected-content setting. No storage or transmission method is completely secure, and a private Telegram cloud chat is not the same as end-to-end encryption.
10. Contact
Submit privacy or legal requests — including questions or requests to exercise your rights — through our contact form (choose the “Privacy / legal request” topic). We store the request in our CRM and internal delivery record, but Telegram and Gmail alerts for that topic omit your contact fields and message content.