Privacy Policy
At AvaroAI (“we”, “us”, “our”), we value the privacy of our users (“you”, “your”). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our real estate operations management platform.
By using our services, you consent to the collection and use of your personal information as outlined in this policy.
Information we collect
We may collect the following types of personal information when you interact with our services:
- Personal Identification Information: Name, email address, and profile avatar.
- Organization Information: Organization name, email, phone number, postal code, country, time zone, and organization logo/watermark.
- Contact and Customer Data: Names, email addresses, phone numbers, postal addresses, company information, websites, professional details, property requirements, notes, and communication history for contacts managed within your organization.
- Property Listing Information: Property details including addresses, coordinates, descriptions, pricing, photos, floor plans, property features, and transaction information (instruction dates, agreement dates, completion dates).
- Payment Information: Credit card details and payment methods (handled securely by Stripe, our payment processor). We store only non-sensitive payment information such as card type and last four digits.
- Subscription and Billing Information: Subscription plans, billing cycles, payment history, tax identification numbers, and credit balance.
- Usage Information: Information about your tasks, events, calendar activities, team collaborations, and system usage patterns.
- Device and Technical Information: IP address, browser type, device information, and interaction data with our platform.
- File Uploads: Property photos, organization documents, contact import files, and other files you upload to our platform.
How we use your information
We may use the information we collect for the following purposes:
- Service Delivery: To provide access to our real estate operations management platform, including contact management, property listings, task tracking, calendar events, and team collaboration features.
- Property Portal Integration: To sync your property listings with third-party property portals such as RightMove, sharing property details, descriptions, photos, and agent information to advertise your listings.
- AI-Powered Features: To process contact requirements and property descriptions using artificial intelligence for semantic search, contact matching, and enhanced search functionality.
- Payment Processing: To process subscription payments, manage billing, handle credit purchases, and maintain your account’s payment methods through our payment processor, Stripe.
- Communication: To send you account notifications, team invitations, password reset emails, subscription updates, credit balance alerts, and other service-related communications.
- Team Management: To manage team memberships, role-based access control, and collaboration features within your organization.
- Customer Support: To assist with any queries, technical issues, or support requests related to our platform.
- Improvement of Services: To analyze usage patterns, enhance our platform features, improve user experience, and develop new functionality.
- Legal Compliance: To comply with applicable laws, regulations, and legal obligations.
Sharing your information
While we do not sell or rent your personal information, we may share certain details with trusted third-party partners for the following reasons:
- Payment Processors: Payment information is processed through Stripe, our secure third-party payment processor. Stripe receives your payment details, billing address, tax information, and subscription data. We do not directly store your complete card information.
- AI Service Providers: Contact requirements and property descriptions are processed by OpenAI to generate semantic embeddings for enhanced search functionality. OpenAI receives text content you enter into specific fields but does not store this data beyond the processing period.
- Property Portals: When you choose to sync listings with property portals like RightMove, we share complete property details, descriptions, photos, pricing, and agent information with these platforms to advertise your properties.
- Email Service Providers: We use Resend to deliver transactional emails, notifications, and service communications. They receive email addresses and message content necessary for delivery.
- Cloud Storage Providers: We use DigitalOcean to store uploaded files, photos, and documents.
- Mapping Services: We use Google Maps to provide address search and coordinate selection functionality. Google receives address queries and location data when you use these features.
- Error Tracking: We use Bugsnag to monitor application errors and performance. Bugsnag may receive technical information such as IP addresses, browser type, and error context to help us diagnose and fix issues.
- Legal Compliance: If required by law, we may disclose your personal information to comply with legal obligations, protect our rights, or respond to valid legal requests.
Data security
We implement comprehensive security measures to protect your information:
- Secure Connections: All data transmission uses SSL/TLS encryption (HTTPS).
- Password Protection: User passwords are hashed using bcrypt, an industry-standard one-way hashing algorithm.
- Encryption at Rest: Sensitive integration credentials and API keys are encrypted using AES-256 encryption.
- Access Controls: Role-based access control ensures team members only access data appropriate to their role (manager or associate).
- Secure File Storage: Files and photos are stored in separate public and private storage clouds with appropriate access restrictions.
- Payment Security: We are PCI-compliant through our use of Stripe. We do not store complete card numbers or security codes.
However, please note that no security system is completely foolproof, and we cannot guarantee the absolute security of your data. We continuously monitor and update our security practices to protect your information.
Your rights and choices
You have the right to:
- Access: Request a copy of the personal information we hold about you, including your user profile, organization data, contacts, listings, and usage history.
- Update or Correct: Request that we update or correct any personal information. You can also update most information directly through your account settings.
- Delete: Request the deletion of your personal information. When you delete your account, we will remove your user data, avatar, and associated records. When an organization is deleted, we remove all organization files, contacts, listings, photos, tasks, events, and team memberships.
- Export: Request a copy of your data in a portable format (subject to technical feasibility).
- Opt-Out: You may opt out of non-essential communications. Note that certain service-related emails (password resets, subscription notifications, critical account alerts) cannot be opted out of while maintaining an active account.
- Object: Object to processing of your personal information for specific purposes where we rely on legitimate interests.
To exercise any of these rights, please contact us through the AvaroAI website.
Retention of your information
We retain your personal information as follows:
- Active Accounts: Personal information is retained while your account remains active and for a reasonable period afterward to comply with legal and business requirements.
- Deleted Accounts: When you delete your account, we will remove your personal information. However, some information may be retained in backup systems for up to 90 days.
- Organizations: When an organization is deleted, all associated data (contacts, listings, photos, tasks, events) is permanently removed from our active systems.
- Expired Data: Tasks, events, and feed dismissals marked as expired are automatically purged from the system.
- Legal Requirements: We may retain certain information longer when required by law, regulation, legal proceeding, or to protect our legal rights.
- Aggregated Data: We may retain anonymized, aggregated data indefinitely for statistical analysis and service improvement.
Once your information is no longer needed, we will securely delete or anonymize it.
International data transfers
AvaroAI may store and process your personal information in various locations to provide our services. If you are located outside the country where our servers are located, please note that your information may be transferred to, stored, and processed in a different jurisdiction. We take appropriate measures to ensure your data receives adequate protection wherever it is processed.
Cookies and tracking technologies
We use cookies and similar tracking technologies to provide functionality and enhance your experience:
- Session Cookies: Essential cookies that maintain your logged-in session and enable core platform functionality.
- Remember Me: Optional persistent cookies that keep you logged in across browser sessions when you select “remember me.”
We do not use third-party advertising or analytics cookies.
Children’s privacy
AvaroAI is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately and we will take steps to delete such information.
Data breach notification
In the event of a data breach that affects your personal information, we will notify affected users within 72 hours of becoming aware of the breach, in accordance with applicable data protection laws. Notifications will include the nature of the breach, the data affected, and steps you should take to protect yourself.
Changes to this privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or for other operational reasons.
For material changes that significantly affect your rights or how we process your personal information, we will provide prominent notice through email notification or a notice on our platform before the changes take effect.
We encourage you to review this policy periodically to stay informed about how we protect your personal information.