Privacy Policy

Last updated: July 15, 2026

This policy explains what data PropContact (“we”) collects about users of the service and how we handle the property and contact data that the service provides. It applies to propcontact.net and the PropContact dashboard.

Our promise about your searches and lists.

The areas you search, the filters you save, and the property and owner lists you build are yours. We promise: (1) we never use your lists, saved searches, or the owners in them to market on our own behalf; (2) we don’t sell or share that data with other customers or third parties — only the service subprocessors listed below ever handle it, and only to operate the product; and (3) you can export your data from the app at any time.

1. Two kinds of data

  • Account and customer-input data - information you give us when you sign up or use the dashboard/API (email, password hash, billing details, support tickets, saved searches, uploaded address inputs, external record IDs, and results associated with your account). This is governed by the practices below.
  • Property & contact data - public-record property data and skip-trace contact information that we license from third-party providers and surface inside the product. We are a redistributor of this data, not the originator.

2. Account data we collect

  • Identity: email address, full name (optional), profile role.
  • Authentication: hashed password, OAuth tokens for Google sign-in.
  • Billing: Stripe customer ID, last four digits of card, card brand, billing country. We never store full card numbers - Stripe handles that and is PCI DSS Level 1 certified.
  • Usage: exports run, credits used, filter searches, search history, IP address, browser user-agent.
  • Communications: support emails and in-app messages you send us.

3. How we use account data

  • Provide the service, run your exports, settle credits, and bill you.
  • Detect abuse - automated scraping, credential sharing, chargeback fraud.
  • Email you about your account: receipts, build completion, expiry warnings, security alerts.
  • Send product updates and pricing changes. You can opt out of non-essential email at any time.
  • Comply with legal obligations (tax, subpoenas, lawful requests from authorities).

We do not sell customer account credentials, billing data, uploaded lists, saved searches, or support communications for unrelated advertising or marketing. The separate property and contact data product is licensed or provided to customers and partners; applicable privacy law may define that activity as a “sale” or “sharing” even when no money is exchanged for a particular individual’s record. Section 7 explains how to submit a request.

4. Subprocessors we share data with

  • Supabase - auth, database, file storage.
  • Stripe - payment processing (PCI DSS Level 1).
  • Vercel - web hosting.
  • Hetzner - backend compute (FastAPI + DuckDB).
  • Resend - transactional email.
  • Enterprise integration partners - only when you use or are an authorized end customer of that integration, to submit and receive the records you requested under the applicable agreement.
  • Verification and compliance providers - no optional provider-backed enrichment check is enabled in the current pilot. If one is offered later, it will require separate activation and the provider will receive only the minimum email, phone, and seller/campaign context needed for the requested check.
  • OpenFreeMap / Geoapify / MapTiler / Mapbox / TomTom / LocationIQ / Stadia Maps - map tiles and address autocomplete. Only the geocoding query string is sent, never your account data.

Each subprocessor is bound by data-processing terms and only handles the data necessary to perform their function.

5. Property & contact data

The property records and skip-trace phone matches you see in PropContact are sourced from public records (county assessors, recorders, tax rolls, MLS feeds) and licensed third-party data providers. We perform record matching, deduplication, and quality scoring before surfacing them.

If you are an individual whose contact information appears in PropContact and you wish to exercise an applicable access, correction, deletion, or opt-out right, email privacy@propcontact.net. We will explain the information needed to verify and process the request, apply it within the period required by applicable law, and notify service providers, contractors, or partners where the law and our agreements require propagation. We may retain limited information needed to honor a suppression request and prevent the record from being reintroduced.

6. Cookies & tracking

We use cookies for authentication and to remember your preferences (theme, last-used filter). We do not use third-party advertising cookies. Aggregated analytics may be collected via Vercel Analytics - these do not include personally identifying information.

7. Your rights (GDPR / CCPA / CPRA)

  • Access - request a copy of the account data we hold about you.
  • Correction - fix inaccuracies in your account.
  • Deletion - close your account and have account data deleted (we retain billing records for 7 years for tax purposes).
  • Portability - receive your data in a machine-readable format.
  • Opt-out of sale or sharing - request that we stop making covered personal information available where applicable law grants that right. A verified suppression record may be retained to keep the opt-out effective.

Exercise any right by emailing privacy@propcontact.net.

8. Data retention

  • Account data: kept while your account is active and for up to 90 days after closure.
  • Lead-list export files: retained for the download period shown in the product or applicable agreement, and then scheduled for deletion. Legacy exports may have a longer configured lifecycle while the shorter retention rollout is completed.
  • Address-enrichment inputs and results: scheduled for deletion 14 days after submission, or earlier after an accepted deletion request. A signed Enterprise Order Form may require a shorter period.
  • API security and usage logs (including key/account identifiers, IP address, user-agent, request status, row/credit totals, and idempotency records): retained only as long as reasonably needed for security, billing, abuse prevention, disputes, and legal obligations under our internal schedule.
  • Billing records: retained for 7 years to comply with tax law.
  • Aggregated, anonymized usage stats: kept indefinitely.

9. Security

Data is encrypted in transit using TLS. Managed databases and approved object-storage services use their configured at-rest protections; backend property snapshots and temporary/export storage are protected through host access controls and operational safeguards. We do not claim host-level disk encryption where it has not been enabled and verified. Authentication credentials are stored using the authentication provider’s password-hashing controls. Service-role database keys are kept on backend infrastructure only - never shipped to the browser. No security method is perfect; we maintain dependency, access, backup, incident-response, and vulnerability-management processes proportionate to the service.

10. International transfers

PropContact stores account data in the United States. If you access the service from outside the US, you consent to your data being transferred to and processed in the US under our subprocessors' standard contractual clauses.

11. Children's privacy

PropContact is not intended for use by anyone under 18. We do not knowingly collect data from children.

12. Changes

We may update this policy from time to time. The current version is always at propcontact.net/privacy. Material changes are communicated by email to active users at least 14 days before they take effect.

13. Contact

Email privacy@propcontact.net for any privacy question or to exercise a right under this policy. For account or billing matters, reach our support team at support@propcontact.net or +1 (941) 991-5772 (Adam).