1. Information We Collect
1.1 Information You Provide
When you create an account or use the Service, you may provide:
- Name, email address, and account credentials
- Property and unit information (addresses, rental amounts, lease dates)
- Entity and ownership structure details (LLC names, ownership interests)
- Financial account information connected through Plaid (bank account numbers, routing numbers, transaction data)
- Documents you upload (leases, invoices, receipts)
- Communications with our team
1.2 Information Collected Automatically
When you use the Service, we automatically collect:
- Log data (IP address, browser type, pages visited, timestamps)
- Device information
- Usage data (features used, actions taken)
1.3 Financial Data via Plaid
We use Plaid Technologies, Inc. to connect to your financial institutions. When you connect a bank account:
- Plaid retrieves transaction history, account balances, and account metadata on your behalf
- This data is transmitted securely to our servers and stored in encrypted form
- We use this data solely to provide bookkeeping and financial reporting services to you
- We do not sell your financial data to third parties
Plaid's privacy policy is available at plaid.com/legal. By connecting a financial account, you also agree to Plaid's terms.
1.4 Email Data via Gmail and Outlook
You may optionally connect a Gmail or Microsoft Outlook inbox to allow PurelyREI to automatically scan for receipt and invoice emails. When you connect an email account:
- We access only the subject line, sender, date, and body content of emails that match receipt or invoice patterns. We do not read, store, or process other emails.
- Email data is used solely to extract vendor, amount, and date information for matching against your financial transactions.
- We do not use your email data to serve advertisements or for any purpose unrelated to your bookkeeping service.
- We do not share your email data with third parties, except as required to operate the Service (e.g., secure storage infrastructure).
- You may disconnect your email account at any time from within the Service. Disconnecting revokes our access to your inbox.
Our use of data obtained via Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Google's privacy policy is available at policies.google.com/privacy.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process and categorize financial transactions
- Generate reports, summaries, and portfolio insights
- Communicate with you about your account and the Service
- Respond to your requests and provide customer support
- Comply with legal obligations
- Detect and prevent fraud or unauthorized access
3. How We Share Your Information
We do not sell your personal information. We may share information in the following limited circumstances:
3.1 Service Providers
We share data with vendors who help us operate the Service, including Supabase (database and authentication infrastructure), Plaid (financial account connectivity), Resend (transactional email), and Anthropic (AI-powered features). These providers are bound by confidentiality obligations and are not permitted to use your data for their own purposes.
3.2 Our Team
Our bookkeeping staff (including contracted virtual assistants) access your financial data to perform the services you've engaged us for. All team members are subject to confidentiality agreements.
3.3 Legal Requirements
We may disclose information if required by law, subpoena, or court order, or if we believe disclosure is necessary to protect the rights, property, or safety of PurelyREI, our clients, or others.
3.4 Business Transfers
If PurelyREI is acquired or merges with another entity, your information may be transferred as part of that transaction. We will notify you before your data is subject to a materially different privacy policy.
4. Data Retention
We retain financial transaction data and records for seven (7) years from the date of creation, consistent with IRS recordkeeping requirements for business tax purposes. Account information is retained for the duration of your service relationship and for a reasonable period thereafter.
You may request deletion of your account and associated data at any time, subject to our legal obligation to retain certain financial records.
5. Categorization Rules and Shared Learning
To improve accuracy, PurelyREI may use anonymized, aggregated patterns from transaction categorizations to improve categorization suggestions across the platform. No personally identifiable information or specific transaction details are shared between clients.
You have the right to opt out of this feature. To opt out, contact us at privacy@purelyrei.com.
6. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption in transit (TLS 1.2 or higher)
- Encryption at rest for financial data
- Role-based access controls limiting staff access to client data
- Multi-factor authentication for staff accounts
- Regular security reviews
No method of transmission over the internet is 100% secure. While we use reasonable measures to protect your data, we cannot guarantee absolute security.
7. Your Rights and Choices
7.1 Access and Correction
You may access and update your account information at any time through the Service or by contacting us.
7.2 Data Portability
You may request an export of your data in a machine-readable format.
7.3 Deletion
You may request deletion of your account and data, subject to our retention obligations described in Section 4.
7.4 California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at privacy@purelyrei.com.
8. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
10. Contact
If you have questions about this Privacy Policy or our data practices, please contact us:
PurelyREI LLC
Email: privacy@purelyrei.com
Website: purelyrei.com