Legal
Privacy Policy
Exactly what RE Income Tracker collects, why, who else can see it, and what you can demand we do with it.
- Effective
- 17 August 2026
- Last updated
- 17 August 2026
- Governing law
- Florida, United States
- Operator
- Real Estate Income Tracker
You are trusting us with financial records about property you own. This policy is written to be checked rather than skimmed: every category of data below corresponds to something the software actually stores, and section 7 lists every third party that can touch it — including the ones that are not switched on yet.
In plain language
- We do not sell your data
- Not to anyone, for any consideration. No advertising networks, no data brokers, no cross-site tracking, no profiling.
- Almost no cookies
- One cookie, for keeping you signed in. Our analytics are self-hosted and cookieless, so there is no consent banner because there is nothing to consent to.
- You can delete it yourself
- Account deletion is in Settings and is real deletion, not a hidden flag. The screen names every workspace and record that will be destroyed before you confirm.
- Your books are not training data
- We do not use your records to train machine-learning models, and there is no AI processing of your financial data in the product today.
This summary is for orientation only. The numbered sections below are the agreement.
1.Who we are and what this covers
Real Estate Income Tracker operates realestateincometracker.com and is the controller of the personal information described here. This policy covers the website, the application, and our support correspondence.
Where you use the Service to keep records about other people — tenants, applicants, contractors — you are the controller of that information and we process it for you. See section 13.
2.What we collect
Account information
- Your name and email address.
- A password, stored only as a salted hash. We cannot read it, and neither can our staff.
- Whether your email is verified, and your account status.
- Your workspace name and your role in it, and who invited whom.
The records you create
- Properties: address, type, status, purchase price, closing costs, land value, improvements, and sale details.
- Units: labels, bedrooms, bathrooms, size, market rent.
- Your ledger: every transaction, its date, description, amount, category, and the property it belongs to.
- Documents you upload — receipts, invoices, statements — and their file names and types.
This is the sensitive part. It describes your assets, income, and spending, and we treat it accordingly.
Technical information
- Sessions: the IP address and browser user-agent recorded when you sign in, so you can review your own active sessions and we can investigate suspicious access.
- Error reports: when something breaks, a report containing the error, the page, and your account id. Session cookies, authorization headers, and anything credential-shaped are stripped before the report leaves our servers.
- Server logs: requests, timestamps, and status codes, kept for operations and abuse investigation.
- Bot-protection signals: when you sign in, sign up, or request a password reset, Cloudflare Turnstile receives your IP address and browser signals to distinguish you from automated traffic. It receives no account data.
Payment information
Handled by our payment processor. We receive the plan, status, and the last four digits and card brand for your reference. We never receive or store your full card number.
Support correspondence
Emails you send us, and notes our staff attach to your account about a support conversation. Those notes are visible to our support staff and are part of your account record.
3.Where it comes from
- From you — everything you type, upload, or import.
- From your devices — technical information above, sent automatically when you use the Service.
- From your bank, if you connect one — account and transaction records, retrieved through a bank-data provider on your authorization. You give your banking credentials to that provider, never to us, and the connection is read-only.
- From our payment processor — subscription status and payment outcomes.
We do not buy personal information, and we do not enrich your profile from third-party data sources.
4.Why we process it
We process personal information only for these purposes. For customers in the UK, EU, or EEA, the lawful basis is given alongside each one.
| Purpose | Lawful basis |
|---|---|
| Providing the Service you signed up for | Performance of a contract |
| Authenticating you and keeping you signed in | Performance of a contract |
| Taking payment and preventing payment fraud | Contract; legitimate interests |
| Transactional email — resets, verification, invitations, receipts | Performance of a contract |
| Protecting accounts from bots, credential stuffing, and abuse | Legitimate interests; legal obligation |
| Diagnosing errors and keeping the Service reliable | Legitimate interests |
| Measuring how the public site and sign-up funnel perform | Legitimate interests (no cookies, no cross-site identifiers) |
| Responding to support requests | Performance of a contract |
| Keeping records we are required to keep, and defending claims | Legal obligation; legitimate interests |
| Product news or marketing email, if you opt in | Consent — withdrawable at any time |
5.What we never do
Stated plainly, so it can be held against us:
- We do not sell personal information, and we do not “share” it for cross-context behavioural advertising, in the sense those terms carry under US state privacy laws.
- No advertising or tracking networks. There are no ad pixels, no social-media trackers, and no third-party cookies on this site.
- No training data. We do not use your records to train machine-learning models, and no part of the product sends your financial data to an AI service.
- No browsing your books. Staff access is limited by role, used only to operate the Service, and logged with the identity of the person who took the action.
- No dark patterns on deletion. You can delete your account yourself, and it deletes.
7.Who else can see it
Every third party that can process personal information on our behalf is listed here. Each is bound by a contract limiting them to processing on our instructions.
| Processor | Purpose | Data | Status |
|---|---|---|---|
| Dokploy on operator-controlled infrastructure United States | Application and database hosting | All customer data at rest and in transit | In use |
| Cloudflare (Turnstile) Global | Bot protection on sign-in, sign-up, and password reset | IP address, browser signals. No account data | In use |
| Resend United States | Transactional email — password resets, verification, invitations | Email address, recipient name, message contents | In use |
| Bugsink (self-hosted) Operator-controlled | Error reporting | Error details and account id. Credentials and cookies are stripped before sending | In use |
| Umami (self-hosted) Operator-controlled | Website analytics on public and sign-in pages only | Page path, referrer, coarse device data. Cookieless; no cross-site identifiers | In use |
| Plaid United States | Bank account connection and transaction import | Bank credentials handled by Plaid directly; we receive account and transaction records | Planned, not yet live |
| Stripe United States | Subscription billing and rent collection | Payment details handled by Stripe directly; we receive tokens and status | Planned, not yet live |
Note that error reporting and analytics are self-hosted — those two categories of data do not leave infrastructure we control, which is why no third-party vendor appears against them.
Other disclosures
We may also disclose information:
- To your own workspace members — anything in a shared workspace is visible to its members according to their role.
- To professional advisers — our accountants and lawyers, under duties of confidentiality.
- When the law requires it — in response to a valid legal demand. Where we are permitted to, we will notify you before disclosing anything, so that you can object.
- In a business transfer — if the Service is acquired, your information transfers with it, and the acquirer is bound by this policy until it gives you notice of any change.
- To protect people — where disclosure is necessary to prevent imminent harm or investigate fraud or abuse.
We will publish material changes to this list here, and give notice before a new processor starts handling customer records.
8.How long we keep it
| Data | Kept for |
|---|---|
| Your account and records, while active | As long as your account exists |
| After you cancel or delete | Deleted immediately on request; otherwise 30 days after cancellation, so you can reactivate or export |
| Encrypted backups | Up to 35 days, then overwritten on their own cycle |
| Billing and tax records | 7 years, as required by tax and accounting law |
| Staff action audit log | 2 years. Records which staff member did what to which account; retained because it is the accountability record |
| Error reports | 90 days |
| Server logs | 30 days, longer where an incident is under investigation |
| Support correspondence | 2 years after the conversation ends |
Deleting your account removes your login, your sessions, your workspace memberships, and any workspace of which you are the only member — including its properties, ledger, and documents. A backup taken before deletion is overwritten on the cycle above rather than being edited, which is why the backup window is longer than the deletion window.
9.How we protect it
Passwords are salted and hashed. Traffic is encrypted in transit. Every record is scoped to a workspace and that scoping is enforced on the server, not in the browser. Staff access is role-limited and logged. Sign-in, sign-up, and password reset are rate limited and bot-protected.
The Security Overview describes all of this in detail, including what is implemented today and what is still planned — stated honestly rather than aspirationally.
No system is perfectly secure. If you find a weakness, please tell us: see the vulnerability disclosure policy.
10.Your rights and how to use them
Whatever jurisdiction you are in, you can:
- See what we hold — most of it is visible in the app, and we will provide the rest on request.
- Correct it — your name and records are editable in the app; email us for anything that is not.
- Export it — machine-readable exports of your ledger and reports are built into the product.
- Delete it — from Settings, or by asking us.
- Object or restrict — ask us to stop a particular processing activity, and we will unless we have a lawful reason to continue, which we will explain.
- Withdraw consent — for anything based on consent, such as marketing email. Every marketing email has a one-click unsubscribe.
- Complain — to us first, and to your data-protection authority if we do not resolve it.
How to exercise them
Email privacy@realestateincometracker.com from the address on your account. We respond within 30 days, and within 45 days where a US state law sets that period. If we need more time we will tell you why before the deadline. We do not charge for a reasonable request, and we will never make your service worse because you exercised a right.
To protect you, we verify requests against your account. If we cannot verify that a request comes from you, we will say so rather than hand over your records.
11.US state privacy rights
If you live in a US state with a comprehensive privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as they take effect — you have the rights above, and specifically: to know what we collect and why, to access and port it, to correct it, to delete it, and to be free from discrimination for asking.
We do not sell personal information and we do not share it for cross-context behavioural advertising. Because we do neither, there is no “Do Not Sell or Share My Personal Information” process to operate — but if you would like written confirmation of that for your own records, ask and we will provide it.
We do not use personal information for profiling that produces legal or similarly significant effects, and we do not knowingly process the sensitive-data categories those laws single out, such as precise geolocation, biometric identifiers, or health information.
You may use an authorized agent, and California residents may designate one in writing. We will verify the agent’s authority and your identity before acting.
12.GDPR, UK GDPR, and transfers
If you are in the UK, EU, or EEA, you have the rights in section 10 under the GDPR or UK GDPR, including the right to lodge a complaint with your supervisory authority.
Our infrastructure and several of our processors are in the United States, so using the Service involves transferring your information there. Where we transfer personal data out of the UK, EU, or EEA we rely on the European Commission’s Standard Contractual Clauses, the UK Addendum where applicable, and additional technical measures including encryption in transit and access controls.
We do not carry out automated decision-making that produces legal or similarly significant effects about you. Reports and categorization suggestions are tools for you to review, never decisions made about you.
13.Data about your tenants
If you record information about tenants, applicants, or contractors, you are its controller and we are your processor. You are responsible for having a lawful basis to hold it and for telling those people what you do with it.
On that data, we act only on your instructions: we store it, make it available to your workspace, and delete it when you do. We do not use it for our own purposes, and we will pass any request we receive directly from one of those individuals to you rather than answering it ourselves.
Please do not upload more than you need. In particular, do not store full Social Security numbers, bank credentials, or screening report contents in the Service — we do not need them, and screening is deliberately handled by a provider that is the consumer reporting agency for that purpose.
14.Children
The Service is for adults running a property business. We do not direct it to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to privacy@realestateincometracker.com and we will delete it.
15.If something goes wrong
If a breach affects your personal information, we will notify you without undue delay and, where the law sets a deadline — 72 hours under the GDPR — within it. The notice will say what happened, what data was involved, what we have done, and what you should do.
We will also notify the relevant regulators where required. We would rather tell you about a suspected problem early and be wrong than be quiet and be right.
16.Changes to this policy
When this policy changes we update the date at the top. For changes that materially reduce your rights or expand what we do with your information, we will give at least 30 days’ notice by email before they take effect, and you can close your account first.
We keep this document accurate as the software changes — adding a processor or a new data category means updating this page in the same release.
17.How to reach us
Real Estate Income Tracker — operator of realestateincometracker.com
- Privacy and data requests: privacy@realestateincometracker.com
- Security: security@realestateincometracker.com
- Legal notices: legal@realestateincometracker.com
A postal address for data-protection correspondence is available on request and will be published here once the operating entity is registered. We have not appointed an EU or UK representative, as we do not currently target those markets; if that changes, this section changes with it.
Questions about this document
Write to legal@realestateincometracker.com. For anything about your own data, use privacy@realestateincometracker.com. To report a vulnerability, use security@realestateincometracker.com.