Privacy Policy
Effective July 27, 2026
The plain-English version
We collect what we need to run your account and nothing we can avoid. We never sell your personal data. Your card details live at Stripe, not with us. Your data-provider API keys are used only server-side to fulfill your own requests. The property records we display come from public government sources.
1. Who we are
WhoseTitle (“we,” “us”) operates whosetitle.com, a map-based lead generation and CRM platform for real estate professionals. Questions about this policy: hello@whosetitle.com.
2. Information we collect
Account data: your email address, name, and password (managed by our authentication provider, Supabase; we never see your password in plain text).
Content you create: leads you discover, import, or enter; notes, statuses, action plans; and team structure (who is on your team and what role they hold).
Provider API keys: if you connect a data source (BatchData, idiCORE, Regrid, ATTOM, Google Places), we store the key you provide, visible only to your team's head broker and used exclusively server-side to run the searches and enrichments your team requests. We never use your keys for any other purpose.
Billing data: payments are processed by Stripe. We store your subscription status and seat count; your card number never touches our servers.
Usage data: which data sources are used and how many records searches return, so we can operate and improve the service.
3. Property records and public data
The owner and property information WhoseTitle displays comes from publicly available government records (county tax rolls and assessor data) or from data providers whose accounts you connect and control. We do not create, sell, or license databases of personal information. If you have concerns about a public record, the county that publishes it is the authoritative source for corrections; you may also contact us and we will review suppression of specific records in our systems.
4. How we use information
To provide the service, process your subscription, send transactional email (invites, receipts, account notices — sent via Resend), respond to support, and improve the product. We do not sell or rent your personal data, and we do not use your leads or CRM content for advertising.
5. Sharing
We share data only with the service providers that run WhoseTitle — Vercel (hosting), Supabase (database and authentication), Stripe (payments), Resend (email), and Google Maps (map display) — each bound by their own security and privacy obligations, and with the data providers whose keys you connect (your queries necessarily flow to them). Beyond that, only if the law requires it.
6. Retention and deletion
Your data stays as long as your account does. To delete your account and its data, email hello@whosetitle.com and we'll complete the deletion within 30 days, except records we must keep for legal or accounting purposes.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Email us and we'll honor applicable requests. We don't discriminate against you for exercising them.
8. Security
Data is encrypted in transit, access is scoped by row-level security so teams can only see their own data, and provider keys are readable only by your team's head broker. No system is perfectly secure; if a breach affects your data, we'll notify you as the law requires.
9. Children
WhoseTitle is a professional tool, not directed at anyone under 18, and we don't knowingly collect their data.
10. Changes
We'll post updates here and adjust the effective date; material changes get an email or in-app notice. Continued use after changes means acceptance. See also our Terms of Service.