Back to Sign Up Legal
Attorney Review Required: This is a structural draft covering all required privacy policy topics for a B2B SaaS platform operating in the United States. All bracketed items must be reviewed and completed by a licensed attorney before publication. Specific state privacy law requirements (California CCPA, Virginia VCDPA, etc.) should be assessed based on your user base.
The short version: We collect only what we need to run the platform. We don't sell your data. We don't share it with anyone except the payment processor (Stripe) and the database provider (Supabase) needed to deliver the service. You own your data and can request its deletion at any time.

1. Who We Are

[LEGAL ENTITY NAME — TO BE COMPLETED] ("Aethralion," "we," "us," or "our") operates the Aethralion platform at aethralion.com. We are a real estate technology company incorporated under the laws of the State of Wisconsin.

For questions about this Privacy Policy or your data, contact our privacy contact at: [PRIVACY EMAIL — TO BE COMPLETED]

2. Information We Collect

2.1 Information You Provide Directly

Data TypeExamplesWhy We Collect It
Account InformationName, email address, phone numberTo create and manage your account, communicate with you
Brokerage InformationOffice name, city, state, zip codeTo set up your office account and enable multi-user access
Professional InformationReal estate license number, role (broker, agent, TC)To configure appropriate access permissions
Payment InformationCredit/debit card details, billing addressTo process subscription payments — handled directly by Stripe, not stored by us
Transaction DataProperty addresses, sale prices, commission structures, client names and contactsTo provide HelmOrbit transaction management services
Deal Analysis InputsRent estimates, expense figures, cap rate targetsTo provide Deal Analyzer outputs and save deals

2.2 Information Collected Automatically

Data TypeDetails
Login ActivityDate and time of sign-ins, approximate location via IP address (not stored permanently)
Usage DataWhich tools you use, feature interactions, session duration — used to improve the platform
Device InformationBrowser type, operating system, screen size — used for compatibility and display purposes

2.3 Information We Do Not Collect

3. How We Use Your Information

We use the information we collect for the following purposes:

We do not use your data for advertising, profiling, or any purpose other than those listed above.

4. How We Share Your Information

We do not sell your personal information to any third party. Period.

We share your information only in the following limited circumstances:

4.1 Service Providers

ProviderPurposeData Shared
Supabase, Inc.Database and authentication infrastructureAll account and platform data — stored on Supabase servers in the United States
Stripe, Inc.Payment processingBilling information, subscription status — Stripe's Privacy Policy applies to payment data
Netlify, Inc.Web hosting and content deliveryWeb traffic data (IP addresses, request logs) — Netlify's Privacy Policy applies
Google FontsTypography deliveryFont file requests — no personal data transmitted

All service providers are bound by contractual obligations to protect your information and use it only for the specified purposes.

4.2 Legal Requirements

We may disclose your information if required by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Platform if such a transfer occurs and your data is subject to a materially different privacy policy.

4.4 Within Your Brokerage

Users you add to your office account (agents, transaction coordinators) can access data within your office as determined by the role permissions you assign. You are responsible for managing access within your account.

5. Data Storage and Security

5.1 Where Your Data Lives

Your data is stored in secure cloud databases operated by Supabase, Inc., hosted on Amazon Web Services (AWS) infrastructure in the United States. Data does not leave the United States under normal operating conditions.

5.2 Security Measures

We implement and maintain the following security measures:

While we implement strong security measures, no system is completely immune to security risks. We encourage you to use a strong, unique password and enable any available account security features.

5.3 Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you by email within [72 hours / as required by applicable law — TO BE COMPLETED WITH ATTORNEY] of becoming aware of the breach.

6. Data Retention

Data TypeRetention Period
Active account dataRetained for the life of your account
Data after subscription cancellation[30/60/90 — TO BE DETERMINED] days, then permanently deleted upon request or automatically
Billing records7 years (required for tax and accounting compliance)
Security logs[90 days — TO BE DETERMINED]
Deleted account dataPermanently deleted within [30 — TO BE DETERMINED] days of account deletion request

7. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

To exercise any of these rights, contact us at [PRIVACY EMAIL — TO BE COMPLETED]. We will respond within [30 — TO BE DETERMINED] days. We may need to verify your identity before processing your request.

Account Deletion: You may delete your account at any time from within the Platform settings. Upon deletion request, we will permanently delete your personal information within [30] days, except where retention is required for legal or billing purposes.

8. Cookies and Tracking

The Aethralion platform uses minimal cookies and local storage:

We do not use advertising cookies, third-party analytics cookies, or any tracking technology designed to follow you across websites. We do not use Google Analytics, Facebook Pixel, or similar services.

9. Children's Privacy

The Platform is designed for professional real estate use and is not directed at children under 18 years of age. We do not knowingly collect personal information from anyone under 18. If we become aware that a user is under 18, we will promptly delete their account and associated information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email at the address on your account at least [30] days before the changes take effect, and update the "Last Updated" date at the top of this policy. The version of this policy you agreed to at signup is recorded in your account.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We take all privacy concerns seriously and will respond within [30] business days.