Skip to content

Legal

Privacy Policy

Exactly what RE Income Tracker collects, why, who else can see it, and what you can demand we do with it.

Effective
17 August 2026
Last updated
17 August 2026
Governing law
Florida, United States
Operator
Real Estate Income Tracker

You are trusting us with financial records about property you own. This policy is written to be checked rather than skimmed: every category of data below corresponds to something the software actually stores, and section 7 lists every third party that can touch it — including the ones that are not switched on yet.

In plain language

We do not sell your data
Not to anyone, for any consideration. No advertising networks, no data brokers, no cross-site tracking, no profiling.
Almost no cookies
One cookie, for keeping you signed in. Our analytics are self-hosted and cookieless, so there is no consent banner because there is nothing to consent to.
You can delete it yourself
Account deletion is in Settings and is real deletion, not a hidden flag. The screen names every workspace and record that will be destroyed before you confirm.
Your books are not training data
We do not use your records to train machine-learning models, and there is no AI processing of your financial data in the product today.

This summary is for orientation only. The numbered sections below are the agreement.

1.Who we are and what this covers

Real Estate Income Tracker operates realestateincometracker.com and is the controller of the personal information described here. This policy covers the website, the application, and our support correspondence.

Where you use the Service to keep records about other people — tenants, applicants, contractors — you are the controller of that information and we process it for you. See section 13.

2.What we collect

Account information

  • Your name and email address.
  • A password, stored only as a salted hash. We cannot read it, and neither can our staff.
  • Whether your email is verified, and your account status.
  • Your workspace name and your role in it, and who invited whom.

The records you create

  • Properties: address, type, status, purchase price, closing costs, land value, improvements, and sale details.
  • Units: labels, bedrooms, bathrooms, size, market rent.
  • Your ledger: every transaction, its date, description, amount, category, and the property it belongs to.
  • Documents you upload — receipts, invoices, statements — and their file names and types.

This is the sensitive part. It describes your assets, income, and spending, and we treat it accordingly.

Technical information

  • Sessions: the IP address and browser user-agent recorded when you sign in, so you can review your own active sessions and we can investigate suspicious access.
  • Error reports: when something breaks, a report containing the error, the page, and your account id. Session cookies, authorization headers, and anything credential-shaped are stripped before the report leaves our servers.
  • Server logs: requests, timestamps, and status codes, kept for operations and abuse investigation.
  • Bot-protection signals: when you sign in, sign up, or request a password reset, Cloudflare Turnstile receives your IP address and browser signals to distinguish you from automated traffic. It receives no account data.

Payment information

Handled by our payment processor. We receive the plan, status, and the last four digits and card brand for your reference. We never receive or store your full card number.

Support correspondence

Emails you send us, and notes our staff attach to your account about a support conversation. Those notes are visible to our support staff and are part of your account record.

3.Where it comes from

  • From you — everything you type, upload, or import.
  • From your devices — technical information above, sent automatically when you use the Service.
  • From your bank, if you connect one — account and transaction records, retrieved through a bank-data provider on your authorization. You give your banking credentials to that provider, never to us, and the connection is read-only.
  • From our payment processor — subscription status and payment outcomes.

We do not buy personal information, and we do not enrich your profile from third-party data sources.

4.Why we process it

We process personal information only for these purposes. For customers in the UK, EU, or EEA, the lawful basis is given alongside each one.

PurposeLawful basis
Providing the Service you signed up forPerformance of a contract
Authenticating you and keeping you signed inPerformance of a contract
Taking payment and preventing payment fraudContract; legitimate interests
Transactional email — resets, verification, invitations, receiptsPerformance of a contract
Protecting accounts from bots, credential stuffing, and abuseLegitimate interests; legal obligation
Diagnosing errors and keeping the Service reliableLegitimate interests
Measuring how the public site and sign-up funnel performLegitimate interests (no cookies, no cross-site identifiers)
Responding to support requestsPerformance of a contract
Keeping records we are required to keep, and defending claimsLegal obligation; legitimate interests
Product news or marketing email, if you opt inConsent — withdrawable at any time

5.What we never do

Stated plainly, so it can be held against us:

  • We do not sell personal information, and we do not “share” it for cross-context behavioural advertising, in the sense those terms carry under US state privacy laws.
  • No advertising or tracking networks. There are no ad pixels, no social-media trackers, and no third-party cookies on this site.
  • No training data. We do not use your records to train machine-learning models, and no part of the product sends your financial data to an AI service.
  • No browsing your books. Staff access is limited by role, used only to operate the Service, and logged with the identity of the person who took the action.
  • No dark patterns on deletion. You can delete your account yourself, and it deletes.

6.Cookies and analytics

The Service sets one cookie:

CookiePurposeLife
Session tokenKeeps you signed in. Strictly necessary — the Service cannot work without it. HttpOnly, Secure, SameSite, and revocable by signing out.Up to 30 days, or until you sign out

Cloudflare Turnstile may set a short-lived token on the auth pages to avoid re-challenging you. It is used solely for bot protection, not to identify or track you.

Analytics

We use a self-hosted, cookieless analytics tool on the public pages and the sign-in and sign-up pages only. It records the page path, referrer, and coarse device and country information. It sets no cookies, assigns no cross-site identifier, and the data stays on infrastructure we control.

Analytics do not run inside the application. The pages where your properties and ledger live are deliberately excluded, because their URLs contain identifiers for your records and there is no good reason for an analytics store to hold a map of your portfolio.

Query strings are stripped before a page view is recorded, and we honour the Do Not Track signal. Because we set no non-essential cookies and build no profiles, there is no consent banner — there is nothing to consent to.

7.Who else can see it

Every third party that can process personal information on our behalf is listed here. Each is bound by a contract limiting them to processing on our instructions.

ProcessorPurposeDataStatus
Dokploy on operator-controlled infrastructure
United States
Application and database hostingAll customer data at rest and in transitIn use
Cloudflare (Turnstile)
Global
Bot protection on sign-in, sign-up, and password resetIP address, browser signals. No account dataIn use
Resend
United States
Transactional email — password resets, verification, invitationsEmail address, recipient name, message contentsIn use
Bugsink (self-hosted)
Operator-controlled
Error reportingError details and account id. Credentials and cookies are stripped before sendingIn use
Umami (self-hosted)
Operator-controlled
Website analytics on public and sign-in pages onlyPage path, referrer, coarse device data. Cookieless; no cross-site identifiersIn use
Plaid
United States
Bank account connection and transaction importBank credentials handled by Plaid directly; we receive account and transaction recordsPlanned, not yet live
Stripe
United States
Subscription billing and rent collectionPayment details handled by Stripe directly; we receive tokens and statusPlanned, not yet live

Note that error reporting and analytics are self-hosted — those two categories of data do not leave infrastructure we control, which is why no third-party vendor appears against them.

Other disclosures

We may also disclose information:

  • To your own workspace members — anything in a shared workspace is visible to its members according to their role.
  • To professional advisers — our accountants and lawyers, under duties of confidentiality.
  • When the law requires it — in response to a valid legal demand. Where we are permitted to, we will notify you before disclosing anything, so that you can object.
  • In a business transfer — if the Service is acquired, your information transfers with it, and the acquirer is bound by this policy until it gives you notice of any change.
  • To protect people — where disclosure is necessary to prevent imminent harm or investigate fraud or abuse.

We will publish material changes to this list here, and give notice before a new processor starts handling customer records.

8.How long we keep it

DataKept for
Your account and records, while activeAs long as your account exists
After you cancel or deleteDeleted immediately on request; otherwise 30 days after cancellation, so you can reactivate or export
Encrypted backupsUp to 35 days, then overwritten on their own cycle
Billing and tax records7 years, as required by tax and accounting law
Staff action audit log2 years. Records which staff member did what to which account; retained because it is the accountability record
Error reports90 days
Server logs30 days, longer where an incident is under investigation
Support correspondence2 years after the conversation ends

Deleting your account removes your login, your sessions, your workspace memberships, and any workspace of which you are the only member — including its properties, ledger, and documents. A backup taken before deletion is overwritten on the cycle above rather than being edited, which is why the backup window is longer than the deletion window.

9.How we protect it

Passwords are salted and hashed. Traffic is encrypted in transit. Every record is scoped to a workspace and that scoping is enforced on the server, not in the browser. Staff access is role-limited and logged. Sign-in, sign-up, and password reset are rate limited and bot-protected.

The Security Overview describes all of this in detail, including what is implemented today and what is still planned — stated honestly rather than aspirationally.

No system is perfectly secure. If you find a weakness, please tell us: see the vulnerability disclosure policy.

10.Your rights and how to use them

Whatever jurisdiction you are in, you can:

  • See what we hold — most of it is visible in the app, and we will provide the rest on request.
  • Correct it — your name and records are editable in the app; email us for anything that is not.
  • Export it — machine-readable exports of your ledger and reports are built into the product.
  • Delete it — from Settings, or by asking us.
  • Object or restrict — ask us to stop a particular processing activity, and we will unless we have a lawful reason to continue, which we will explain.
  • Withdraw consent — for anything based on consent, such as marketing email. Every marketing email has a one-click unsubscribe.
  • Complain — to us first, and to your data-protection authority if we do not resolve it.

How to exercise them

Email privacy@realestateincometracker.com from the address on your account. We respond within 30 days, and within 45 days where a US state law sets that period. If we need more time we will tell you why before the deadline. We do not charge for a reasonable request, and we will never make your service worse because you exercised a right.

To protect you, we verify requests against your account. If we cannot verify that a request comes from you, we will say so rather than hand over your records.

11.US state privacy rights

If you live in a US state with a comprehensive privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as they take effect — you have the rights above, and specifically: to know what we collect and why, to access and port it, to correct it, to delete it, and to be free from discrimination for asking.

We do not sell personal information and we do not share it for cross-context behavioural advertising. Because we do neither, there is no “Do Not Sell or Share My Personal Information” process to operate — but if you would like written confirmation of that for your own records, ask and we will provide it.

We do not use personal information for profiling that produces legal or similarly significant effects, and we do not knowingly process the sensitive-data categories those laws single out, such as precise geolocation, biometric identifiers, or health information.

You may use an authorized agent, and California residents may designate one in writing. We will verify the agent’s authority and your identity before acting.

12.GDPR, UK GDPR, and transfers

If you are in the UK, EU, or EEA, you have the rights in section 10 under the GDPR or UK GDPR, including the right to lodge a complaint with your supervisory authority.

Our infrastructure and several of our processors are in the United States, so using the Service involves transferring your information there. Where we transfer personal data out of the UK, EU, or EEA we rely on the European Commission’s Standard Contractual Clauses, the UK Addendum where applicable, and additional technical measures including encryption in transit and access controls.

We do not carry out automated decision-making that produces legal or similarly significant effects about you. Reports and categorization suggestions are tools for you to review, never decisions made about you.

13.Data about your tenants

If you record information about tenants, applicants, or contractors, you are its controller and we are your processor. You are responsible for having a lawful basis to hold it and for telling those people what you do with it.

On that data, we act only on your instructions: we store it, make it available to your workspace, and delete it when you do. We do not use it for our own purposes, and we will pass any request we receive directly from one of those individuals to you rather than answering it ourselves.

Please do not upload more than you need. In particular, do not store full Social Security numbers, bank credentials, or screening report contents in the Service — we do not need them, and screening is deliberately handled by a provider that is the consumer reporting agency for that purpose.

14.Children

The Service is for adults running a property business. We do not direct it to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to privacy@realestateincometracker.com and we will delete it.

15.If something goes wrong

If a breach affects your personal information, we will notify you without undue delay and, where the law sets a deadline — 72 hours under the GDPR — within it. The notice will say what happened, what data was involved, what we have done, and what you should do.

We will also notify the relevant regulators where required. We would rather tell you about a suspected problem early and be wrong than be quiet and be right.

16.Changes to this policy

When this policy changes we update the date at the top. For changes that materially reduce your rights or expand what we do with your information, we will give at least 30 days’ notice by email before they take effect, and you can close your account first.

We keep this document accurate as the software changes — adding a processor or a new data category means updating this page in the same release.

17.How to reach us

Real Estate Income Tracker — operator of realestateincometracker.com

A postal address for data-protection correspondence is available on request and will be published here once the operating entity is registered. We have not appointed an EU or UK representative, as we do not currently target those markets; if that changes, this section changes with it.

Questions about this document

Write to legal@realestateincometracker.com. For anything about your own data, use privacy@realestateincometracker.com. To report a vulnerability, use security@realestateincometracker.com.