What we collect, why we have it, which vendors see it, and what you can ask us to do about it.
This policy explains what Verstavo Technologies LLC collects, why, who else sees it, and what you can ask us to do about it. It covers our websites and the Verstavo CRE Intelligence Platform (the “Service”). It forms part of our Terms of Service.
Two things up front, because they are the questions people actually have. We do not sell your personal information for money, and we do not use your loan tape to train anything. The detail is below, including the one place where an advertising tag on our marketing pages may count as “sharing” under California law.
Account information — your name, email address, a hash of your password (never the password itself), your role and organization membership, and, if you enable it, multi-factor authentication settings.
Billing information — your plan, subscription status, and the identifiers our payment processor gives us. Card numbers are handled entirely by Stripe and never reach our servers.
Your Content — the loan tapes, portfolios, assumptions and notes you put into the Service. Ownership and our use of these are governed by §9 of the Terms. In privacy terms: we process them only to run the Service for you.
Support correspondence — the subject and content of tickets you open, and our replies.
Technical and usage information — your IP address, browser and device details, pages and features used, and timestamps. We use these to operate the Service, to rate-limit and detect abuse, and to understand what is used.
How you found us — if you arrive from a campaign link, the first campaign parameters are stored in your own browser and attached to your account only if you choose to sign up. Until then that information never leaves your device.
A session cookie, which is strictly necessary — it is what keeps you signed in. It is HttpOnly, SameSite=Lax, sent only over HTTPS, and expires after 12 hours of inactivity. You cannot use the application without it.
Local browser storage for the first-touch campaign value described above. It is first-party, it is not a cookie, and nothing reads it but our own signup form.
The LinkedIn Insight Tag, on our public marketing pages only. It is not present inside the application. See §7.
Where the GDPR or UK GDPR applies, we rely on contract (providing the Service you signed up for), legitimate interests (security, abuse prevention, understanding usage, marketing measurement), consent where we ask for it, and legal obligation where we must keep records.
We use a small number of vendors to run the Service. Each receives only what it needs, and each is bound to protect it.
We may also disclose information if the law requires it, to enforce our Terms, to protect rights and safety, or to a successor in a merger or sale of assets — in which case this policy continues to apply until you are told otherwise.
Traffic is encrypted in transit; data is encrypted at rest by our hosting provider. Passwords are stored as salted hashes. Multi-factor authentication is available and we recommend it. Access to production data is limited to those who need it to operate and support the Service. What we hold and how it is protected is set out in more detail on our security page. No system is perfectly secure, and we do not claim otherwise; if a breach affects you we will notify you as the law requires.
Our public marketing pages carry the LinkedIn Insight Tag so we can measure whether our advertising works. It is not present inside the application, so it never observes your use of the product itself.
We receive no money for this. But under the California Consumer Privacy Act as amended, this kind of advertising tag may nonetheless count as “sharing” personal information for cross-context behavioural advertising, and we would rather say so than claim a blanket “we never share”. You can prevent it by browsing our marketing pages with tracking protection or an ad blocker enabled, by opting out through LinkedIn’s own opt-out, or by sending a request under §9. Opting out changes nothing about your account or your access.
We keep account and content data for as long as your account is open. When you close your account we delete your content and personal information from our live systems. Deletion is not instantaneous: residual copies persist in encrypted backups for a limited period before being overwritten. We keep billing and tax records for as long as the law requires, and support correspondence for a reasonable period afterwards.
Depending on where you live, you may have the right to know what we hold about you, to get a copy, to correct it, to delete it, to limit how we use it, to opt out of “sharing” as described in §7, and not to be discriminated against for exercising any of these.
Ask us at support@verstavo.com and we will respond within the time the applicable law allows. We will need to verify who you are before acting on a request — usually by confirming control of the account email. An authorized agent may act for you with proof of authorization.
If you are in the EEA or UK you may also complain to your supervisory authority. We would rather you told us first.
The Service is hosted in the United States, and our vendors are mostly US based. If you use the Service from outside the US, you are sending your information to the US, where privacy law differs from your own.
The Service is a business product and is not directed at anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, tell us and we will delete it.
We will update this policy as the Service changes. The version and effective date are at the top. If a change is material we will tell you — by email, in the application, or by asking you to accept an updated Terms of Service.