2. Information we collect from you
Account details — name, email address, phone (if provided), brokerage / team name, real-estate license number, state, role (agent or transaction coordinator), and an optional avatar / headshot.
Authentication — a hashed password (bcrypt), and if you sign in with Google, the Google account ID associated with your email. We never receive or store your Google password.
Email integration credentials — when you connect Gmail, we store an OAuth refresh token; when you connect via SMTP, we store your SMTP host/port/username/password. SMTP passwords and OAuth refresh tokens are encrypted at rest with a per-deployment key.
Listing data — property addresses, target listing dates, marketing checklist entries, vendor assignments, photo uploads, and any custom tasks you add to the prep plan.
Showing data — date, time, buyer-agent and brokerage you record for each private showing; feedback collected from buyer agents via the no-login follow-up form (rating, pros/cons, free-text comments). Showings flagged as "seller-visible" appear in the seller portal; the rest stay internal.
Open-house data — events you schedule, plus the visitor sign-in submissions through the QR code (name, email, agent association, optional feedback ratings + comments). Visitors are told at sign-in that the agent will see their information.
Offer data — submissions through the public offer-submission link (/o/<slug>): buyer-agent contact details, buyer names, price, financing terms, contingencies, dates, the uploaded purchase agreement PDF, and any documents or notes the buyer agent attaches. The buyer agent receives a private token-authed revise/withdraw link by email.
Seller-portal share data — magic-link tokens you generate for sellers (no login required for them), the listing identifier they grant access to, expiry time, revocation status, and a view count.
Transaction data — property addresses, contract dates, parties, contacts (name, email, phone, brokerage), tasks, deadlines, vendor assignments, and uploaded files (executed contracts, inspection reports, property photos, headshots, other supporting documents).
Communications data — emails ClosingDay sends on your behalf are recorded in the relevant transaction or listing's communication log (sender, recipient, subject, body, timestamp). We do not read your inbox.
AI-derived data — checklists, deadlines, email drafts, contract / offer extractions, offer-comparison summaries, and tone-profile training samples generated from the data you upload or paste in.
Billing data — Stripe customer + subscription IDs, current period end, subscription status. We do not store your card number — Stripe holds payment details directly.
Audit log — every meaningful action (task status change, document upload, draft sent, deadline adjustment, offer status change, comparison export) is recorded against the user who performed it.
Device & usage data — IP address (transient, used for rate limiting and abuse prevention), browser/device info from your User-Agent header (used in support and audit contexts), and any feedback you submit through the in-app "Share feedback" widget (with an optional screenshot you choose to attach).