Skip to main content

Privacy Policy

How BrickPads handles personal information.

This Privacy Policy explains the current data practices for the BrickPads service at brickpads.com in plain language.

Scope

This policy applies to the BrickPads service at brickpads.com, including its public pages, account features, property-search and analysis tools, saved content, and Contact page.

People may access BrickPads generally, but its property data and analysis are limited to properties located in the United States.

Information users provide

Account and profile information

Account creation uses a name, email address, password, verification status, and related account metadata. Supabase provides authentication and secure session handling.

Billing information

BrickPads stores the Stripe customer, subscription, price, status, billing-period, trial, and Founding Member identifiers needed to provide plan access. Stripe processes payment-card and billing details; BrickPads does not store raw card data.

Investor onboarding and preferences

Users may provide strategy, experience, target-market, budget, financing, property-type, renovation, neighborhood, and return preferences used to maintain an investor buy box.

Saved Deals and Saved Searches

BrickPads stores saved-property references and snapshots, saved-search names and criteria, and information needed to reopen saved work for the authenticated user.

Alert and match information

BrickPads stores Saved Search alert preferences, evaluation state, match-event information, and email-delivery status when a user enables scheduled matching and alerts.

Contact-form information

The Contact form collects a name, email address, selected topic, message, privacy acknowledgement, bot-verification token, and an empty anti-bot field. The verification token is submitted to Cloudflare Turnstile for validation.

After verification, the name, email address, topic, and message are transmitted to Resend and the configured receiving mailbox. They are not stored in the BrickPads application database. Information may remain in the email provider and receiving mailbox as needed to respond, maintain reasonable business records, prevent abuse, or comply with legal obligations.

Do not submit passwords, authentication secrets, payment-card or banking details, government identification, or other sensitive financial information.

Information collected automatically

BrickPads and its hosting, authentication, security, property-data, and email providers may process technical request information needed to operate and protect the service. This may include IP address, browser or device information, request timing, error information, and security events.

BrickPads also records limited first-party acquisition information, such as landing page, referring website, UTM campaign values, Google advertising click identifiers, referral codes, a random visitor identifier, measurement-consent choice, and conversion milestones. This information is used to understand which acquisition efforts lead to signups, useful product activity, trials, and subscriptions.

BrickPads does not claim that no technical logs exist. Operational logs may be generated by the application or service providers, but contact message bodies, visitor email addresses, names, and bot-verification tokens are not intentionally written to application logs by the Contact endpoint.

Cookies, attribution, and analytics choices

BrickPads uses necessary authentication, session, security, and functional technologies, including cookie-based sessions managed through Supabase. A first-party, random visitor cookie is used to preserve acquisition attribution across signup and subscription workflows.

The Google tag uses Consent Mode with analytics storage and advertising-related consent signals set to denied by default. In that state Google may receive privacy-safe consent and service-status pings, but BrickPads does not send page, product, or conversion events and does not grant analytics or advertising storage. Selecting Allow measurement enables Google Analytics and Google Ads measurement and permits the Meta Pixel to load. Visitors may select Necessary only or reopen Analytics preferences from the footer. Advertising personalization remains disabled even when measurement is allowed.

Consent-controlled measurement may process page paths, page titles, limited product and conversion events, hashed account identifiers, campaign parameters, and provider click or browser identifiers. BrickPads does not send passwords, raw payment-card details, tax-profile answers, property underwriting inputs, or saved-property details to advertising platforms.

How information is used

  • Create, authenticate, secure, and support user accounts.
  • Maintain investor preferences, saved content, alert preferences, and persisted match information.
  • Provide property search, analysis, and account workflows.
  • Respond to contact, support, privacy, and account-deletion requests.
  • Protect the service, investigate failures or abuse, and improve product reliability.
  • Attribute acquisition sources and evaluate signup, activation, trial, subscription, and renewal performance.
  • Maintain records or respond to legal obligations when reasonably necessary.

Service providers

BrickPads uses providers only as needed for current product functions:

  • Supabase for authentication, session support, and application data.
  • RentCast for property-related information when that integration is configured.
  • Resend for Contact-form and enabled Saved Search alert email delivery.
  • Cloudflare Turnstile for Contact-form abuse prevention.
  • Vercel for the documented application-hosting and delivery environment.
  • Stripe for Checkout, subscriptions, invoices, payment-method management, and Customer Portal.
  • Google Maps Platform for Street View and map imagery when property images are enabled.
  • Vercel Analytics for privacy-conscious aggregate website measurement.
  • Google Analytics for consent-controlled website and product measurement; Google Ads conversion measurement may be enabled without advertising personalization.
  • Meta for consent-controlled Pixel and conversion measurement without sharing property underwriting details.

These providers may process information needed to perform their services under their own terms and policies. BrickPads does not make unverified claims about their locations, certifications, retention periods, or contractual protections.

Property imagery and Google Maps Platform

When an image nears the visible page area, BrickPads may send property coordinates or a formatted address to Google Maps Platform to check Street View availability and display Street View or Static Maps imagery. Google may receive ordinary technical request information under its own privacy policy.

BrickPads may retain permitted availability metadata, such as a panorama identifier and check date, to reduce repeated requests. BrickPads does not download or permanently store Google image bytes.

Data sharing

Information is disclosed to the providers described above as needed to operate BrickPads, deliver requested functions, secure the service, and respond to Contact submissions. Information may also be disclosed when reasonably necessary to address abuse, protect users or the service, or respond to valid legal obligations.

Data retention

Account and application information may be retained while an account remains active and as needed to provide the service. Contact messages may remain with the email provider and receiving mailbox as needed to respond and maintain appropriate records.

BrickPads does not promise a single fixed retention period. Some information may remain longer for security, fraud prevention, legal compliance, backups, or legitimate recordkeeping even after an account-deletion request.

Security

BrickPads uses reasonable technical and organizational measures appropriate to the service, including authenticated routes, row-level access controls, server-side secret handling, field limits, bot verification, and provider security features. No internet service or storage system can guarantee absolute security.

User choices and account deletion

Users may request access to or correction of their personal information, ask questions about its handling, or request account deletion through the Contact page.

Deletion requests may require identity verification. Some information may be retained where reasonably necessary for security, fraud prevention, legal compliance, backups, or legitimate records.

Adults-only eligibility

BrickPads is intended only for people age 18 or older and is not directed to children. BrickPads does not request age-verification documents through the public service.

International access and U.S. property scope

Users may access BrickPads from different locations, but the current property data and analysis are limited to U.S. properties. Access from another country does not expand that scope or establish that BrickPads satisfies every local privacy requirement.

Changes to this policy

BrickPads may update this policy as the product, providers, and data practices change. A revised policy will display a new effective date and should be reviewed before continued use.

How to contact BrickPads

Submit privacy questions, access or correction requests, and account-deletion requests through the Contact page. Do not include passwords or sensitive financial information.