1. Information We Collect
A. Information You Provide Directly
- Email address
- First and last name
- Profile photo
- Organization name
- CRM OAuth tokens (GoHighLevel access + refresh tokens)
- OpenAI API key
- AI preferences
- Billing information (stored by Stripe, not by DealOrbit)
B. Information We Collect Automatically
- Session tokens
- Session cookies (auth only)
- Usage analytics
- Event logs (errors, performance, system events)
C. Information We Process About Your Contacts and Leads
- Contact names, phone numbers, emails
- Property addresses & details
- Property photos & attachments
- SMS/message history (inbound & outbound)
- Notes, tags, motivation, status
- ARV, rehab budgets, property financials
- URLs and AI-generated descriptions
- Lead summaries and metadata
2. How We Use Your Information
- Operate and maintain the Service
- Automate SMS conversations (at your direction)
- Sync CRM data
- Personalize your AI workflows
- Improve system performance
- Provide support
- Protect, secure, and debug the platform
3. What We Do Not Use Your Data For
- We do not train AI models with your data
- We do not sell or rent personal data
- We do not use your contacts' data for marketing
- We do not share data unnecessarily
4. How We Share Information
We only share data with service providers that help us run DealOrbit:
- Supabase (database)
- Vercel (hosting)
- Cloudflare (network/security)
- Stripe (payments)
- GoHighLevel (CRM syncing)
- Dash0 (logging)
- Email delivery tools
We do not share message or lead content with OpenAI.
5. Data Retention
We store all data indefinitely unless you request deletion.
This includes account data, contacts/leads, conversations, property data, attachments, AI preferences, and logs.
6. Data Deletion
You may request permanent deletion of your data at:
📧 admin@dealorbit.ai
Deletion is irreversible.
7. Cookies
DealOrbit uses:
- Session cookies for authentication only
DealOrbit does not use:
- Analytics cookies
- Preference cookies
- Advertising cookies
8. Data Security
We use:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest (Supabase/Postgres)
- OAuth for Google & GHL
- Token rotation
- Role-based access control
- Logging & monitoring
- Regular code reviews
Users are responsible for protecting their passwords and API keys.
9. Data Storage Location
Data is primarily stored and processed in the United States.
10. Children's Privacy
DealOrbit is not intended for individuals under 18.
We do not knowingly collect data from minors.
11. Your Rights
You may request access, correction, deletion, or a copy of your data by contacting:
📧 admin@dealorbit.ai
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically.
Continued use of the Service indicates acceptance of changes.
13. Contact Us
For privacy concerns or data requests:
📧 admin@dealorbit.ai
Deal Orbit LLC