Privacy Policy for Realest

Last Updated: October 15, 2025

1. Introduction

Welcome to Realest. This privacy policy covers our browser extension, website, user accounts, and internal API (collectively referred to as "Realest" or "our Services"). We are committed to protecting your privacy while providing valuable insights into housing complaints. This Privacy Policy explains our practices regarding data collection, handling, and use.

2. Data Collection and Usage

Realest collects data to ensure the functionality and improvement of our Services. Here's what we collect and how we use it:

2.1 User Account Information

When you create an account with Realest, we collect and store:

  • Name: To personalize your experience and identify you in communications
  • Email Address: For account authentication, communication, and account recovery
  • Password: Securely hashed and stored for account security
  • Account Settings: Your preferences and subscription status

2.2 Property Search Data

  • When you use Realest to view information about a property, either through our browser extension or website, a request is sent to our API with the property's address.
  • Our API processes this request and returns relevant public data about housing complaints for that address.
  • This data is then displayed to you within the browser extension or on our website.
  • If you are logged in, your searches may be associated with your account for service improvement purposes, but we do not store detailed search history.

3. Internal API Tracking

To maintain and improve our Services, we use internal API tracking. This tracking is designed with privacy in mind and includes:

  • Anonymized API usage statistics
  • Error logging for service improvement
  • Temporary storage of IP addresses for security and debugging purposes

This data is used solely for internal purposes to enhance user experience and maintain service quality. We do not use this data for user profiling or share it with third parties.

4. Server Logs

Our servers automatically collect and store certain information in server logs. This includes:

  • IP addresses
  • Date and time of the request
  • The requested URL

These logs are kept for operational purposes only:

  • Logs are searchable for 48 hours to assist with debugging and maintaining the security and stability of our service.
  • After 48 hours, logs are archived for an additional 7 days.
  • All logs are permanently deleted after this 7-day archive period.

We do not use these logs for user tracking or profiling.

5. Third-Party Authentication (Google OAuth)

You can sign up or sign in with your Google account. When you approve the Google OAuth prompt, Google shares your name, email address, and Google user ID with us so we can create or update your Realest profile.

6. Email Communications

We send only transactional emails needed to operate your account, such as confirmations, password resets, and security notifications. To meet legal requirements and keep our email deliverability healthy, we log delivery status and suppression events (for example, bounces or complaints). You cannot opt out of these operational messages while your account is active, and we do not send marketing emails.

7. Cookies and Tracking

Realest uses cookies for the following purposes:

  • Authentication Cookies: To keep you logged in to your account and maintain your session securely. These are essential for the service to function.
  • Analytics Cookies: We use Google Analytics on our website to understand how visitors interact with our site. For more information, see the "Google Analytics" section below.

You can control cookie settings through your browser, but disabling authentication cookies will prevent you from staying logged in to your account.

8. Google Analytics

We use Google Analytics on our website to help us understand how visitors interact with our site. Here's what you need to know:

  • Google Analytics uses cookies to collect information and report website usage statistics without personally identifying individual visitors to Google or Realest.
  • The information collected includes data such as your IP address, time of visit, device used, and browser information.
  • This data helps us track site performance, analyze user behavior, and improve our services.
  • You can opt-out of Google Analytics tracking by using the Google Analytics Opt-out Browser Add-on, available at https://tools.google.com/dlpage/gaoptout.
  • For more information on how Google Analytics collects and processes data, visit https://policies.google.com/technologies/partner-sites.

9. Data Sharing

We share data with third parties only as described below:

  • Google OAuth: When you choose to authenticate with Google, we share authentication requests with Google as described in the "Third-Party Authentication" section above.
  • Google Analytics: Analytics data is collected and processed by Google as described in the "Google Analytics" section above.
  • Email Service Providers: We use third-party email service providers to send transactional emails as described in the "Email Communications" section above.
  • Legal Compliance: We may disclose your information if required by law, court order, or governmental request, or to protect our rights, property, or safety, or that of our users or others.

The information displayed about properties is based on public records. We do not sell your personal data to third parties.

10. User Rights and Choices

We respect your privacy rights and provide you with control over your personal data. Depending on your location, you may have the following rights:

10.1 Access and Portability

  • Access: You can access your account information by logging into your account settings at any time
  • Data Portability: You can request a copy of your personal data in a structured, commonly used format

10.2 Correction and Updates

  • You can update your name, email address, and other account information through your account settings page
  • Contact us if you need assistance updating your information

10.3 Deletion and Account Closure

  • Account Deletion: You can request deletion of your account and associated personal data by contacting us at [email protected]
  • We will delete your account within 30 days of verification
  • Some data may be retained as required by law or for legitimate business purposes (e.g., prevention of fraud, resolution of disputes)
  • Server logs and anonymized usage data may be retained according to our retention policies

10.4 Objection and Restriction

  • You can object to certain processing of your data by contacting us
  • You can request restriction of processing in certain circumstances

10.5 Cookie Choices

  • You can opt out of Google Analytics tracking using the Google Analytics Opt-out Browser Add-on
  • You can control cookies through your browser settings

10.6 Exercising Your Rights

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. We may need to verify your identity before processing your request.

11. Data Retention

We retain your personal data for as long as necessary to provide our Services and fulfill the purposes described in this Privacy Policy. Specifically:

  • Account Data: Retained for the duration of your account plus 30 days after deletion request
  • Server Logs: Searchable for 48 hours, archived for 7 days, then permanently deleted
  • Email Delivery Records: Retained as necessary for compliance and suppression management purposes
  • Legal Retention: Some data may be retained longer if required by law or for legitimate business purposes

12. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Passwords are securely hashed using industry-standard algorithms
  • Data transmission is encrypted using HTTPS/TLS
  • Access to personal data is restricted to authorized personnel only
  • Regular security assessments and updates

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify users of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this policy.

14. Contact Us

If you have any questions about this Privacy Policy, requests regarding your personal data, or concerns about how we handle your information, please contact us at [email protected].

We will respond to all privacy-related inquiries within 30 days.

15. Compliance with Privacy Laws

Realest is committed to complying with applicable privacy laws and regulations. This includes, but is not limited to:

  • GDPR (General Data Protection Regulation): For users in the European Union and European Economic Area
  • CCPA (California Consumer Privacy Act): For California residents in the United States
  • CAN-SPAM Act: For email communications in the United States
  • Other applicable state and federal privacy laws

If you are a resident of the EU/EEA or California, you have additional rights as described in the "User Rights and Choices" section above.

16. Your Consent

By creating an account and using Realest, you consent to this Privacy Policy and agree to our collection, use, and disclosure of your information as described herein, including our use of cookies, Google Analytics, Google OAuth, and email communications.

You can withdraw your consent at any time by deleting your account or contacting us, though this may limit your ability to use certain features of our Services.